<?xml version="1.0" encoding="UTF-8"?>
<FEDREG xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="FRMergedXML.xsd">
    <VOL>90</VOL>
    <NO>3</NO>
    <DATE>Monday, January 6, 2025</DATE>
    <UNITNAME>Contents</UNITNAME>
    <CNTNTS>
        <AGCY>
            <EAR>
                Agricultural Marketing
                <PRTPAGE P="iii"/>
            </EAR>
            <HD>Agricultural Marketing Service</HD>
            <CAT>
                <HD>RULES</HD>
                <DOCENT>
                    <DOC>Formulas for Calculating Hourly and Unit Fees for Federal Grain Inspection Service Services, </DOC>
                    <PGS>531-535</PGS>
                    <FRDOCBP>2024-31140</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Agriculture</EAR>
            <HD>Agriculture Department</HD>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Agricultural Marketing Service</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Food and Nutrition Service</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Rural Business-Cooperative Service</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Rural Utilities Service</P>
            </SEE>
            <CAT>
                <HD>NOTICES</HD>
                <DOCENT>
                    <DOC>Agency Information Collection Activities; Proposals, Submissions, and Approvals, </DOC>
                    <PGS>583-584</PGS>
                    <FRDOCBP>2024-31627</FRDOCBP>
                      
                    <FRDOCBP>2024-31632</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Consumer Financial Protection</EAR>
            <HD>Bureau of Consumer Financial Protection</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Supervisory Highlights:</SJ>
                <SJDENT>
                    <SJDOC>Issue 37, Winter 2024, </SJDOC>
                    <PGS>607-613</PGS>
                    <FRDOCBP>2024-31670</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Board</EAR>
            <HD>Civil Rights Cold Case Records Review Board</HD>
            <CAT>
                <HD>NOTICES</HD>
                <DOCENT>
                    <DOC>Formal Determination on Records Release, </DOC>
                    <PGS>596</PGS>
                    <FRDOCBP>2024-31618</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Coast Guard</EAR>
            <HD>Coast Guard</HD>
            <CAT>
                <HD>RULES</HD>
                <SJ>Security Zone:</SJ>
                <SJDENT>
                    <SJDOC>Potomac River and Anacostia River and Adjacent Waters, Washington, DC, </SJDOC>
                    <PGS>565-566</PGS>
                    <FRDOCBP>2024-31636</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Commerce</EAR>
            <HD>Commerce Department</HD>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Foreign-Trade Zones Board</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Industry and Security Bureau</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>International Trade Administration</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>National Oceanic and Atmospheric Administration</P>
            </SEE>
        </AGCY>
        <AGCY>
            <EAR>Consumer Product</EAR>
            <HD>Consumer Product Safety Commission</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Agency Information Collection Activities; Proposals, Submissions, and Approvals:</SJ>
                <SJDENT>
                    <SJDOC>Bathtub Slip Resistance Study, </SJDOC>
                    <PGS>613-614</PGS>
                    <FRDOCBP>2024-31623</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Defense Department</EAR>
            <HD>Defense Department</HD>
            <CAT>
                <HD>NOTICES</HD>
                <DOCENT>
                    <DOC>Agency Information Collection Activities; Proposals, Submissions, and Approvals, </DOC>
                    <PGS>620-623, 627-628, 633-634</PGS>
                    <FRDOCBP>2024-31662</FRDOCBP>
                      
                    <FRDOCBP>2024-31663</FRDOCBP>
                      
                    <FRDOCBP>2024-31664</FRDOCBP>
                      
                    <FRDOCBP>2024-31665</FRDOCBP>
                      
                    <FRDOCBP>2024-31666</FRDOCBP>
                      
                    <FRDOCBP>2024-31660</FRDOCBP>
                      
                    <FRDOCBP>2024-31661</FRDOCBP>
                </DOCENT>
                <DOCENT>
                    <DOC>Arms Sales, </DOC>
                    <PGS>614-620, 623-633</PGS>
                    <FRDOCBP>2024-31697</FRDOCBP>
                      
                    <FRDOCBP>2024-31698</FRDOCBP>
                      
                    <FRDOCBP>2024-31699</FRDOCBP>
                      
                    <FRDOCBP>2024-31700</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Employee Benefits</EAR>
            <HD>Employee Benefits Security Administration</HD>
            <CAT>
                <HD>NOTICES</HD>
                <DOCENT>
                    <DOC>Agency Information Collection Activities; Proposals, Submissions, and Approvals, </DOC>
                    <PGS>671-675</PGS>
                    <FRDOCBP>2024-31607</FRDOCBP>
                </DOCENT>
                <SJ>Exemption:</SJ>
                <SJDENT>
                    <SJDOC>Associated General Contractors of America, San Diego Chapter, Inc. Apprenticeship and Training Fund, Located in San Diego, CA, </SJDOC>
                    <PGS>675-681</PGS>
                    <FRDOCBP>2024-31599</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Employment and Training</EAR>
            <HD>Employment and Training Administration</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Schedule of Remuneration:</SJ>
                <SJDENT>
                    <SJDOC>Unemployment Compensation for Ex-Servicemembers Program; Military Pay Increase Effective January 1, 2025, </SJDOC>
                    <PGS>681-682</PGS>
                    <FRDOCBP>2024-31608</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Energy Department</EAR>
            <HD>Energy Department</HD>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Federal Energy Regulatory Commission</P>
            </SEE>
        </AGCY>
        <AGCY>
            <EAR>Environmental Protection</EAR>
            <HD>Environmental Protection Agency</HD>
            <CAT>
                <HD>RULES</HD>
                <DOCENT>
                    <DOC>Implementing Statutory Addition of Certain Per- and Polyfluoroalkyl Substances to Toxics Release Inventory Beginning with Reporting Year 2025, </DOC>
                    <PGS>573-577</PGS>
                    <FRDOCBP>2024-31464</FRDOCBP>
                </DOCENT>
                <SJ>Significant New Uses:</SJ>
                <SJDENT>
                    <SJDOC>Certain Chemical Substances (19-5.F), </SJDOC>
                    <PGS>567-573</PGS>
                    <FRDOCBP>2024-30964</FRDOCBP>
                </SJDENT>
            </CAT>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Decision:</SJ>
                <SJDENT>
                    <SJDOC>California State Nonroad Engine Pollution Control Standards; Small Off-Road Engines Regulations, </SJDOC>
                    <PGS>640-642</PGS>
                    <FRDOCBP>2024-31123</FRDOCBP>
                </SJDENT>
                <SJ>Pesticide Registration Review:</SJ>
                <SJDENT>
                    <SJDOC>Decisions and Case Closures for Several Pesticides, </SJDOC>
                    <PGS>638</PGS>
                    <FRDOCBP>2024-31644</FRDOCBP>
                </SJDENT>
                <SJ>Risk Evaluation under the Toxic Substances Control Act:</SJ>
                <SJDENT>
                    <SJDOC>Diisodecyl Phthalate, </SJDOC>
                    <PGS>638-640</PGS>
                    <FRDOCBP>2024-31280</FRDOCBP>
                </SJDENT>
                <DOCENT>
                    <DOC>Toxic Substances Control Act Review of Confidential Business Information Claims for the Identity of Chemicals in the TSCA Inventory, </DOC>
                    <PGS>645-646</PGS>
                    <FRDOCBP>2024-31291</FRDOCBP>
                </DOCENT>
                <SJ>Waiver of Preemption; Decision:</SJ>
                <SJDENT>
                    <SJDOC>
                        California State Motor Vehicle and Engine and Nonroad Engine Pollution Control Standards; The “Omnibus” Low NO
                        <E T="52">X</E>
                         Regulation, 
                    </SJDOC>
                    <PGS>643-645</PGS>
                    <FRDOCBP>2024-31125</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>California State Motor Vehicle and Engine Pollution Control Standards; Advanced Clean Cars II, </SJDOC>
                    <PGS>642-643</PGS>
                    <FRDOCBP>2024-31128</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Equal</EAR>
            <HD>Equal Employment Opportunity Commission</HD>
            <CAT>
                <HD>NOTICES</HD>
                <DOCENT>
                    <DOC>Agency Information Collection Activities; Proposals, Submissions, and Approvals, </DOC>
                    <PGS>646-647</PGS>
                    <FRDOCBP>2024-31755</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Federal Aviation</EAR>
            <HD>Federal Aviation Administration</HD>
            <CAT>
                <HD>RULES</HD>
                <SJ>Airspace Designations and Reporting Points:</SJ>
                <SJDENT>
                    <SJDOC>Ashley, ND, </SJDOC>
                    <PGS>558-559</PGS>
                    <FRDOCBP>2024-31637</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Redfield, SD, </SJDOC>
                    <PGS>557-558</PGS>
                    <FRDOCBP>2024-31635</FRDOCBP>
                </SJDENT>
            </CAT>
            <CAT>
                <HD>PROPOSED RULES</HD>
                <SJ>Airworthiness Directives:</SJ>
                <SJDENT>
                    <SJDOC>Bombardier, Inc., Airplanes, </SJDOC>
                    <PGS>578-581</PGS>
                    <FRDOCBP>2024-31624</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Federal Election</EAR>
            <HD>Federal Election Commission</HD>
            <CAT>
                <HD>NOTICES</HD>
                <DOCENT>
                    <DOC>Meetings; Sunshine Act, </DOC>
                    <PGS>647</PGS>
                    <FRDOCBP>2025-00017</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Federal Emergency</EAR>
            <HD>Federal Emergency Management Agency</HD>
            <CAT>
                <HD>NOTICES</HD>
                <DOCENT>
                    <DOC>Public Assistance Program and Policy Guide, </DOC>
                    <PGS>659</PGS>
                    <FRDOCBP>2024-30084</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Federal Energy</EAR>
            <HD>Federal Energy Regulatory Commission</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Application:</SJ>
                <SJDENT>
                    <SJDOC>Turlock and Modesto Irrigation District; Reasonable Period of Time for Water Quality Certification, </SJDOC>
                    <PGS>636, 638</PGS>
                    <FRDOCBP>2024-31650</FRDOCBP>
                      
                    <FRDOCBP>2024-31651</FRDOCBP>
                </SJDENT>
                <DOCENT>
                    <DOC>Combined Filings, </DOC>
                    <PGS>634-637</PGS>
                    <FRDOCBP>2024-31652</FRDOCBP>
                      
                    <FRDOCBP>2024-31653</FRDOCBP>
                </DOCENT>
                <SJ>Environmental Assessments; Availability, etc.:</SJ>
                <SJDENT>
                    <SJDOC>Rover Pipeline LLC, Rover-Bulger Delivery Meter Station Project, </SJDOC>
                    <PGS>636-637</PGS>
                    <FRDOCBP>2024-31649</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>
                Federal Motor
                <PRTPAGE P="iv"/>
            </EAR>
            <HD>Federal Motor Carrier Safety Administration</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Agency Information Collection Activities; Proposals, Submissions, and Approvals:</SJ>
                <SJDENT>
                    <SJDOC>Financial Responsibility Motor Carriers, Freight Forwarders, and Brokers, </SJDOC>
                    <PGS>720-721</PGS>
                    <FRDOCBP>2024-31550</FRDOCBP>
                </SJDENT>
                <SJ>Exemption Application:</SJ>
                <SJDENT>
                    <SJDOC>Qualification of Drivers; Epilepsy and Seizure Disorders, </SJDOC>
                    <PGS>718-720</PGS>
                    <FRDOCBP>2024-31759</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Qualification of Drivers; Hearing, </SJDOC>
                    <PGS>722-724</PGS>
                    <FRDOCBP>2024-31758</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Federal Trade</EAR>
            <HD>Federal Trade Commission</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Analysis of Agreement Containing Consent Order to Aid Public Comment:</SJ>
                <SJDENT>
                    <SJDOC>Planned Companies, </SJDOC>
                    <PGS>649-651</PGS>
                    <FRDOCBP>2024-31763</FRDOCBP>
                </SJDENT>
                <SJ>Analysis of Proposed Consent Order to Aid Public Comment:</SJ>
                <SJDENT>
                    <SJDOC>accessiBe, </SJDOC>
                    <PGS>647-649</PGS>
                    <FRDOCBP>2024-31765</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Fish</EAR>
            <HD>Fish and Wildlife Service</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Environmental Impact Statements; Availability, etc.:</SJ>
                <SJDENT>
                    <SJDOC>Potential Land Exchange Involving Izembek National Wildlife Refuge Lands, </SJDOC>
                    <PGS>659-661</PGS>
                    <FRDOCBP>2024-31657</FRDOCBP>
                </SJDENT>
                <SJ>Hearings, Meetings, Proceedings, etc.:</SJ>
                <SJDENT>
                    <SJDOC>Convention on International Trade in Endangered Species of Wild Fauna and Flora, Conference of the Parties, </SJDOC>
                    <PGS>659</PGS>
                    <FRDOCBP>C1-2024-30698</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Food and Drug</EAR>
            <HD>Food and Drug Administration</HD>
            <CAT>
                <HD>RULES</HD>
                <SJ>Guidance:</SJ>
                <SJDENT>
                    <SJDOC>Considerations for Complying with 21 CFR 211.110, </SJDOC>
                    <PGS>563-565</PGS>
                    <FRDOCBP>2024-31356</FRDOCBP>
                </SJDENT>
            </CAT>
            <CAT>
                <HD>NOTICES</HD>
                <DOCENT>
                    <DOC>Food Contact Notifications That Are No Longer Effective, </DOC>
                    <PGS>653-655</PGS>
                    <FRDOCBP>2024-31692</FRDOCBP>
                </DOCENT>
                <SJ>Requests for Nominations:</SJ>
                <SJDENT>
                    <SJDOC>National Mammography Quality Assurance Advisory Committee, </SJDOC>
                    <PGS>655-656</PGS>
                    <FRDOCBP>2024-31703</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Food and Nutrition</EAR>
            <HD>Food and Nutrition Service</HD>
            <CAT>
                <HD>PROPOSED RULES</HD>
                <DOCENT>
                    <DOC>Provisions to Improve the Supplemental Nutrition Assistance Program's Quality Control System; Withdrawal, </DOC>
                    <PGS>578</PGS>
                    <FRDOCBP>2024-31263</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Foreign Assets</EAR>
            <HD>Foreign Assets Control Office</HD>
            <CAT>
                <HD>NOTICES</HD>
                <DOCENT>
                    <DOC>Sanctions Action, </DOC>
                    <PGS>739-741</PGS>
                    <FRDOCBP>2024-31655</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Foreign Trade</EAR>
            <HD>Foreign-Trade Zones Board</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Proposed Production Activity:</SJ>
                <SJDENT>
                    <SJDOC>Sanofi US Services Inc., Foreign-Trade Zone 49, Ridgefield, NJ, </SJDOC>
                    <PGS>596</PGS>
                    <FRDOCBP>2024-31702</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>General Services</EAR>
            <HD>General Services Administration</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Request for Membership Application:</SJ>
                <SJDENT>
                    <SJDOC>Federal Secure Cloud Advisory Committee, </SJDOC>
                    <PGS>651-653</PGS>
                    <FRDOCBP>2024-31554</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Saint Lawrence</EAR>
            <HD>Great Lakes St. Lawrence Seaway Development Corporation</HD>
            <CAT>
                <HD>RULES</HD>
                <DOCENT>
                    <DOC>Tariff of Tolls, </DOC>
                    <PGS>566-567</PGS>
                    <FRDOCBP>2024-31616</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Health and Human</EAR>
            <HD>Health and Human Services Department</HD>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Food and Drug Administration</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Health Resources and Services Administration</P>
            </SEE>
            <CAT>
                <HD>PROPOSED RULES</HD>
                <DOCENT>
                    <DOC>Health Insurance Portability and Accountability Act Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information, </DOC>
                    <PGS>898-1022</PGS>
                    <FRDOCBP>2024-30983</FRDOCBP>
                </DOCENT>
            </CAT>
            <CAT>
                <HD>NOTICES</HD>
                <DOCENT>
                    <DOC>Agency Information Collection Activities; Proposals, Submissions, and Approvals, </DOC>
                    <PGS>658</PGS>
                    <FRDOCBP>2024-31615</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Health Resources</EAR>
            <HD>Health Resources and Services Administration</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>National Vaccine Injury Compensation Program:</SJ>
                <SJDENT>
                    <SJDOC>List of Petitions Received, </SJDOC>
                    <PGS>656-658</PGS>
                    <FRDOCBP>2024-31614</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Homeland</EAR>
            <HD>Homeland Security Department</HD>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Coast Guard</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Federal Emergency Management Agency</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>U.S. Customs and Border Protection</P>
            </SEE>
            <CAT>
                <HD>RULES</HD>
                <DOCENT>
                    <DOC>Immigration Bond Notifications, </DOC>
                    <PGS>535-557</PGS>
                    <FRDOCBP>2024-31358</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Housing</EAR>
            <HD>Housing and Urban Development Department</HD>
            <CAT>
                <HD>RULES</HD>
                <SJ>Home Investment Partnerships Program:</SJ>
                <SJDENT>
                    <SJDOC>Program Updates and Streamlining, </SJDOC>
                    <PGS>746-895</PGS>
                    <FRDOCBP>2024-29824</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Indian Affairs</EAR>
            <HD>Indian Affairs Bureau</HD>
            <CAT>
                <HD>NOTICES</HD>
                <DOCENT>
                    <DOC>Documented Petition for Federal Acknowledgment as an American Indian Tribe, </DOC>
                    <PGS>661-662</PGS>
                    <FRDOCBP>2024-31647</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Industry</EAR>
            <HD>Industry and Security Bureau</HD>
            <CAT>
                <HD>RULES</HD>
                <DOCENT>
                    <DOC>Entity List, </DOC>
                    <PGS>559-563</PGS>
                    <FRDOCBP>2024-31468</FRDOCBP>
                </DOCENT>
            </CAT>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Denial of Export Privileges:</SJ>
                <SJDENT>
                    <SJDOC>Daniel Ray Lane, </SJDOC>
                    <PGS>599-600</PGS>
                    <FRDOCBP>2024-31654</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Derby Clerfe, </SJDOC>
                    <PGS>599</PGS>
                    <FRDOCBP>2024-31656</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Eric Nana Kofi Ampong-Coker, </SJDOC>
                    <PGS>597-598</PGS>
                    <FRDOCBP>2024-31667</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Joel Alejandro Garza-Corona, </SJDOC>
                    <PGS>597</PGS>
                    <FRDOCBP>2024-31669</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Interior</EAR>
            <HD>Interior Department</HD>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Fish and Wildlife Service</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Indian Affairs Bureau</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Land Management Bureau</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Ocean Energy Management Bureau</P>
            </SEE>
        </AGCY>
        <AGCY>
            <EAR>Internal Revenue</EAR>
            <HD>Internal Revenue Service</HD>
            <CAT>
                <HD>PROPOSED RULES</HD>
                <DOCENT>
                    <DOC>Section 30C Alternative Fuel Vehicle Refueling Property Credit; Hearing, </DOC>
                    <PGS>581-582</PGS>
                    <FRDOCBP>2024-31233</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>International Trade Adm</EAR>
            <HD>International Trade Administration</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Antidumping or Countervailing Duty Investigations, Orders, or Reviews:</SJ>
                <SJDENT>
                    <SJDOC>Raw Flexible Magnets from the People's Republic of China and Taiwan, </SJDOC>
                    <PGS>602-603</PGS>
                    <FRDOCBP>2024-31724</FRDOCBP>
                </SJDENT>
                <SJ>Sales at Less Than Fair Value; Determinations, Investigations, etc.:</SJ>
                <SJDENT>
                    <SJDOC>Crystalline Silicon Photovoltaic Cells, Whether or Not Assembled into Modules, from Malaysia, </SJDOC>
                    <PGS>601-602</PGS>
                    <FRDOCBP>2024-31764</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>
                International Trade Com
                <PRTPAGE P="v"/>
            </EAR>
            <HD>International Trade Commission</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Investigations; Determinations, Modifications, and Rulings, etc.:</SJ>
                <SJDENT>
                    <SJDOC>Certain Video Capable Electronic Devices, Including Computers, Streaming Devices, Televisions, and Components Thereof, </SJDOC>
                    <PGS>670-671</PGS>
                    <FRDOCBP>2024-31726</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Justice Department</EAR>
            <HD>Justice Department</HD>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Justice Programs Office</P>
            </SEE>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Proposed Settlement Agreement, Stipulation, Order, and Judgment, etc.:</SJ>
                <SJDENT>
                    <SJDOC>Clean Air Act, </SJDOC>
                    <PGS>671</PGS>
                    <FRDOCBP>2024-31760</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Justice Programs</EAR>
            <HD>Justice Programs Office</HD>
            <CAT>
                <HD>PROPOSED RULES</HD>
                <DOCENT>
                    <DOC>Victims of Crime Act Victim Compensation Grant Program; Withdrawal, </DOC>
                    <PGS>582</PGS>
                    <FRDOCBP>2024-31012</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Labor Department</EAR>
            <HD>Labor Department</HD>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Employee Benefits Security Administration</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Employment and Training Administration</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Occupational Safety and Health Administration</P>
            </SEE>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Agency Information Collection Activities; Proposals, Submissions, and Approvals:</SJ>
                <SJDENT>
                    <SJDOC>Department of Labor-Only Performance Accountability, Information, and Reporting System, </SJDOC>
                    <PGS>682-683</PGS>
                    <FRDOCBP>2024-31725</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Workforce Innovation and Opportunity Act Common Performance Reporting, </SJDOC>
                    <PGS>683</PGS>
                    <FRDOCBP>2024-31728</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Land</EAR>
            <HD>Land Management Bureau</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>New Recreation Fees:</SJ>
                <SJDENT>
                    <SJDOC>Special Recreation Permit for On-River Camping within the Upper Colorado River Special Recreation Management Areas, Colorado, </SJDOC>
                    <PGS>662-663</PGS>
                    <FRDOCBP>2024-31749</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Maritime</EAR>
            <HD>Maritime Administration</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Agency Information Collection Activities; Proposals, Submissions, and Approvals:</SJ>
                <SJDENT>
                    <SJDOC>Maritime Administration Jones Act Vessel Availability Determinations, </SJDOC>
                    <PGS>725</PGS>
                    <FRDOCBP>2024-31601</FRDOCBP>
                </SJDENT>
                <SJ>Coastwise Endorsement Eligibility Determination for a Foreign-Built Vessel:</SJ>
                <SJDENT>
                    <SJDOC>Open Seas (Motor), </SJDOC>
                    <PGS>724-725</PGS>
                    <FRDOCBP>2024-31604</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Regenero (Sail), </SJDOC>
                    <PGS>727-728</PGS>
                    <FRDOCBP>2024-31606</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Serenity (Motor), </SJDOC>
                    <PGS>728-729</PGS>
                    <FRDOCBP>2024-31603</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Skydancer (Sail), </SJDOC>
                    <PGS>725-726</PGS>
                    <FRDOCBP>2024-31600</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Yes Dear (Motor), </SJDOC>
                    <PGS>726-727</PGS>
                    <FRDOCBP>2024-31598</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>National Highway</EAR>
            <HD>National Highway Traffic Safety Administration</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Petition for Decision of Inconsequential Noncompliance:</SJ>
                <SJDENT>
                    <SJDOC>Gillig, LLC; Approval, </SJDOC>
                    <PGS>735-737</PGS>
                    <FRDOCBP>2024-31752</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Transamerica Tire Co. Ltd.; Approval, </SJDOC>
                    <PGS>729-731</PGS>
                    <FRDOCBP>2024-31753</FRDOCBP>
                </SJDENT>
                <DOCENT>
                    <DOC>Uniform Procedures for State Highway Safety Grant Programs, </DOC>
                    <PGS>731-735</PGS>
                    <FRDOCBP>2024-31487</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>National Oceanic</EAR>
            <HD>National Oceanic and Atmospheric Administration</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Inventory of Areas for Possible Designation as National Marine Sanctuaries:</SJ>
                <SJDENT>
                    <SJDOC>Cashes Ledge Site, </SJDOC>
                    <PGS>606-607</PGS>
                    <FRDOCBP>2024-30702</FRDOCBP>
                </SJDENT>
                <SJ>Taking or Importing of Marine Mammals:</SJ>
                <SJDENT>
                    <SJDOC>Geophysical Surveys Related to Oil and Gas Activities in the Gulf of Mexico, </SJDOC>
                    <PGS>603-606</PGS>
                    <FRDOCBP>2024-31750</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Nuclear Regulatory</EAR>
            <HD>Nuclear Regulatory Commission</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Hearings, Meetings, Proceedings, etc.:</SJ>
                <SJDENT>
                    <SJDOC>Advisory Committee on Reactor Safeguards, </SJDOC>
                    <PGS>686</PGS>
                    <FRDOCBP>2024-31633</FRDOCBP>
                </SJDENT>
                <DOCENT>
                    <DOC>Meetings; Sunshine Act, </DOC>
                    <PGS>686-687</PGS>
                    <FRDOCBP>2025-00117</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Occupational Safety Health Adm</EAR>
            <HD>Occupational Safety and Health Administration</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Agency Information Collection Activities; Proposals, Submissions, and Approvals:</SJ>
                <SJDENT>
                    <SJDOC>Commercial Diving Operations Standard, </SJDOC>
                    <PGS>683-685</PGS>
                    <FRDOCBP>2024-31727</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Ocean Energy Management</EAR>
            <HD>Ocean Energy Management Bureau</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Requests for Nominations:</SJ>
                <SJDENT>
                    <SJDOC>Commercial Leasing for Wind Power Development on the Guam Outer Continental Shelf, </SJDOC>
                    <PGS>663-669</PGS>
                    <FRDOCBP>2024-31231</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Postal Service</EAR>
            <HD>Postal Service</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Product Change:</SJ>
                <SJDENT>
                    <SJDOC>Priority Mail and USPS Ground Advantage Negotiated Service Agreement, </SJDOC>
                    <PGS>687, 689-693, 695-697</PGS>
                    <FRDOCBP>2024-31732</FRDOCBP>
                      
                    <FRDOCBP>2024-31672</FRDOCBP>
                      
                    <FRDOCBP>2024-31673</FRDOCBP>
                      
                    <FRDOCBP>2024-31674</FRDOCBP>
                      
                    <FRDOCBP>2024-31675</FRDOCBP>
                      
                    <FRDOCBP>2024-31722</FRDOCBP>
                      
                    <FRDOCBP>2024-31723</FRDOCBP>
                      
                    <FRDOCBP>2024-31729</FRDOCBP>
                      
                    <FRDOCBP>2024-31730</FRDOCBP>
                      
                    <FRDOCBP>2024-31731</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Priority Mail Express, Priority Mail, and USPS Ground Advantage Negotiated Service Agreement, </SJDOC>
                    <PGS>687-698</PGS>
                    <FRDOCBP>2024-31676</FRDOCBP>
                      
                    <FRDOCBP>2024-31677</FRDOCBP>
                      
                    <FRDOCBP>2024-31678</FRDOCBP>
                      
                    <FRDOCBP>2024-31679</FRDOCBP>
                      
                    <FRDOCBP>2024-31680</FRDOCBP>
                      
                    <FRDOCBP>2024-31681</FRDOCBP>
                      
                    <FRDOCBP>2024-31682</FRDOCBP>
                      
                    <FRDOCBP>2024-31683</FRDOCBP>
                      
                    <FRDOCBP>2024-31684</FRDOCBP>
                      
                    <FRDOCBP>2024-31685</FRDOCBP>
                      
                    <FRDOCBP>2024-31686</FRDOCBP>
                      
                    <FRDOCBP>2024-31687</FRDOCBP>
                      
                    <FRDOCBP>2024-31688</FRDOCBP>
                      
                    <FRDOCBP>2024-31689</FRDOCBP>
                      
                    <FRDOCBP>2024-31690</FRDOCBP>
                      
                    <FRDOCBP>2024-31691</FRDOCBP>
                      
                    <FRDOCBP>2024-31704</FRDOCBP>
                      
                    <FRDOCBP>2024-31705</FRDOCBP>
                      
                    <FRDOCBP>2024-31706</FRDOCBP>
                      
                    <FRDOCBP>2024-31707</FRDOCBP>
                      
                    <FRDOCBP>2024-31708</FRDOCBP>
                      
                    <FRDOCBP>2024-31709</FRDOCBP>
                      
                    <FRDOCBP>2024-31710</FRDOCBP>
                      
                    <FRDOCBP>2024-31711</FRDOCBP>
                      
                    <FRDOCBP>2024-31712</FRDOCBP>
                      
                    <FRDOCBP>2024-31713</FRDOCBP>
                      
                    <FRDOCBP>2024-31714</FRDOCBP>
                      
                    <FRDOCBP>2024-31715</FRDOCBP>
                      
                    <FRDOCBP>2024-31716</FRDOCBP>
                      
                    <FRDOCBP>2024-31717</FRDOCBP>
                      
                    <FRDOCBP>2024-31718</FRDOCBP>
                      
                    <FRDOCBP>2024-31719</FRDOCBP>
                      
                    <FRDOCBP>2024-31720</FRDOCBP>
                      
                    <FRDOCBP>2024-31721</FRDOCBP>
                      
                    <FRDOCBP>2024-31733</FRDOCBP>
                      
                    <FRDOCBP>2024-31734</FRDOCBP>
                      
                    <FRDOCBP>2024-31735</FRDOCBP>
                      
                    <FRDOCBP>2024-31736</FRDOCBP>
                      
                    <FRDOCBP>2024-31737</FRDOCBP>
                      
                    <FRDOCBP>2024-31738</FRDOCBP>
                      
                    <FRDOCBP>2024-31739</FRDOCBP>
                      
                    <FRDOCBP>2024-31740</FRDOCBP>
                      
                    <FRDOCBP>2024-31741</FRDOCBP>
                      
                    <FRDOCBP>2024-31742</FRDOCBP>
                      
                    <FRDOCBP>2024-31743</FRDOCBP>
                      
                    <FRDOCBP>2024-31744</FRDOCBP>
                      
                    <FRDOCBP>2024-31745</FRDOCBP>
                      
                    <FRDOCBP>2024-31746</FRDOCBP>
                      
                    <FRDOCBP>2024-31747</FRDOCBP>
                      
                    <FRDOCBP>2024-31748</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Presidential Documents</EAR>
            <HD>Presidential Documents</HD>
            <CAT>
                <HD>PROCLAMATIONS</HD>
                <SJ>Special Observances:</SJ>
                <SJDENT>
                    <SJDOC>National Human Trafficking Prevention Month (Proc. 10877), </SJDOC>
                    <PGS>529-530</PGS>
                    <FRDOCBP>2025-00078</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Rural Business</EAR>
            <HD>Rural Business-Cooperative Service</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Funding Opportunity:</SJ>
                <SJDENT>
                    <SJDOC>Rural Business Development Grant Program to Provide Technical Assistance for Rural Transportation Systems for Fiscal Year 2025, </SJDOC>
                    <PGS>584-589</PGS>
                    <FRDOCBP>2024-28767</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Rural Utilities</EAR>
            <HD>Rural Utilities Service</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Funding Opportunity:</SJ>
                <SJDENT>
                    <SJDOC>Distance Learning and Telemedicine Grants for Fiscal Year 2025, </SJDOC>
                    <PGS>589-595</PGS>
                    <FRDOCBP>2024-30465</FRDOCBP>
                </SJDENT>
                <DOCENT>
                    <DOC>Section 313A Guarantees for Bonds and Notes Issued for Utility Infrastructure Purposes for Fiscal Year 2025; Application Deadline Extension, </DOC>
                    <PGS>595-596</PGS>
                    <FRDOCBP>2024-31668</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Securities</EAR>
            <HD>Securities and Exchange Commission</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Self-Regulatory Organizations; Proposed Rule Changes:</SJ>
                <SJDENT>
                    <SJDOC>Cboe BYX Exchange, Inc., </SJDOC>
                    <PGS>698-699</PGS>
                    <FRDOCBP>2024-31770</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Cboe BZX Exchange, Inc., </SJDOC>
                    <PGS>703-704</PGS>
                    <FRDOCBP>2024-31773</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Cboe C2 Exchange, Inc., </SJDOC>
                    <PGS>701-702</PGS>
                    <FRDOCBP>2024-31772</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Cboe EDGA Exchange, Inc., </SJDOC>
                    <PGS>700</PGS>
                    <FRDOCBP>2024-31774</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Cboe EDGX Exchange, Inc., </SJDOC>
                    <PGS>715-716</PGS>
                    <FRDOCBP>2024-31775</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Cboe Exchange, Inc., </SJDOC>
                    <PGS>702</PGS>
                    <FRDOCBP>2024-31769</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Financial Industry Regulatory Authority, Inc., </SJDOC>
                    <PGS>700-701, 703</PGS>
                    <FRDOCBP>2024-31612</FRDOCBP>
                      
                    <FRDOCBP>2024-31768</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Long-Term Stock Exchange, Inc., </SJDOC>
                    <PGS>714-715</PGS>
                    <FRDOCBP>2024-31613</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>MEMX LLC, </SJDOC>
                    <PGS>715</PGS>
                    <FRDOCBP>2024-31767</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>Nasdaq ISE, LLC, </SJDOC>
                    <PGS>704-710</PGS>
                    <FRDOCBP>2024-31771</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>New York Stock Exchange LLC, </SJDOC>
                    <PGS>699-700</PGS>
                    <FRDOCBP>2024-31611</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>The Options Clearing Corp., </SJDOC>
                    <PGS>710-714</PGS>
                    <FRDOCBP>2024-31610</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Small Business</EAR>
            <HD>Small Business Administration</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Disaster Declaration:</SJ>
                <SJDENT>
                    <SJDOC>Georgia, </SJDOC>
                    <PGS>716-717</PGS>
                    <FRDOCBP>2024-31596</FRDOCBP>
                      
                    <FRDOCBP>2024-31597</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <PRTPAGE P="vi"/>
                    <SJDOC>North Carolina, </SJDOC>
                    <PGS>716</PGS>
                    <FRDOCBP>2024-31646</FRDOCBP>
                </SJDENT>
                <SJDENT>
                    <SJDOC>North Carolina; Public Assistance Only, </SJDOC>
                    <PGS>717</PGS>
                    <FRDOCBP>2024-31605</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>State Department</EAR>
            <HD>State Department</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Determination:</SJ>
                <SJDENT>
                    <SJDOC>Foreign Missions Act, </SJDOC>
                    <PGS>717</PGS>
                    <FRDOCBP>2024-31595</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Transportation Department</EAR>
            <HD>Transportation Department</HD>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Federal Aviation Administration</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Federal Motor Carrier Safety Administration</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Great Lakes St. Lawrence Seaway Development Corporation</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Maritime Administration</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>National Highway Traffic Safety Administration</P>
            </SEE>
            <CAT>
                <HD>NOTICES</HD>
                <DOCENT>
                    <DOC>Solicitation for Annual Combating Human Trafficking in Transportation Impact Award, </DOC>
                    <PGS>737-739</PGS>
                    <FRDOCBP>2024-31630</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Treasury</EAR>
            <HD>Treasury Department</HD>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Foreign Assets Control Office</P>
            </SEE>
            <SEE>
                <HD SOURCE="HED">See</HD>
                <P>Internal Revenue Service</P>
            </SEE>
        </AGCY>
        <AGCY>
            <EAR>Customs</EAR>
            <HD>U.S. Customs and Border Protection</HD>
            <CAT>
                <HD>NOTICES</HD>
                <DOCENT>
                    <DOC>Implementation of the Commonwealth of the Northern Mariana Islands Economic Vitality and Security Travel Authorization Program, </DOC>
                    <PGS>658-659</PGS>
                    <FRDOCBP>2024-31326</FRDOCBP>
                </DOCENT>
            </CAT>
        </AGCY>
        <AGCY>
            <EAR>Veteran Affairs</EAR>
            <HD>Veterans Affairs Department</HD>
            <CAT>
                <HD>NOTICES</HD>
                <SJ>Agency Information Collection Activities; Proposals, Submissions, and Approvals:</SJ>
                <SJDENT>
                    <SJDOC>Recordkeeping at Flight Schools, </SJDOC>
                    <PGS>741-742</PGS>
                    <FRDOCBP>2024-31628</FRDOCBP>
                </SJDENT>
                <SJ>Requests for Nominations:</SJ>
                <SJDENT>
                    <SJDOC>Advisory Committee on Former Prisoners of War, </SJDOC>
                    <PGS>742-743</PGS>
                    <FRDOCBP>2024-31625</FRDOCBP>
                </SJDENT>
            </CAT>
        </AGCY>
        <PTS>
            <HD SOURCE="HED">Separate Parts In This Issue</HD>
            <HD>Part II</HD>
            <DOCENT>
                <DOC>Housing and Urban Development Department, </DOC>
                <PGS>746-895</PGS>
                <FRDOCBP>2024-29824</FRDOCBP>
            </DOCENT>
            <HD>Part III</HD>
            <DOCENT>
                <DOC>Health and Human Services Department, </DOC>
                <PGS>898-1022</PGS>
                <FRDOCBP>2024-30983</FRDOCBP>
            </DOCENT>
        </PTS>
        <AIDS>
            <HD SOURCE="HED">Reader Aids</HD>
            <P>Consult the Reader Aids section at the end of this issue for phone numbers, online resources, finding aids, and notice of recently enacted public laws.</P>
            <P>To subscribe to the Federal Register Table of Contents electronic mailing list, go to https://public.govdelivery.com/accounts/USGPOOFR/subscriber/new, enter your e-mail address, then follow the instructions to join, leave, or manage your subscription.</P>
        </AIDS>
    </CNTNTS>
    <VOL>90</VOL>
    <NO>3</NO>
    <DATE>Monday, January 6, 2025</DATE>
    <UNITNAME>Rules and Regulations</UNITNAME>
    <RULES>
        <RULE>
            <PREAMB>
                <PRTPAGE P="531"/>
                <AGENCY TYPE="F">DEPARTMENT OF AGRICULTURE</AGENCY>
                <SUBAGY>Agricultural Marketing Service</SUBAGY>
                <CFR>7 CFR Part 800</CFR>
                <DEPDOC>[Doc. No. AMS-FGIS-24-0027]</DEPDOC>
                <RIN>RIN 0581-AE31</RIN>
                <SUBJECT>Formulas for Calculating Hourly and Unit Fees for FGIS Services</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Agricultural Marketing Service, Department of Agriculture (USDA).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Final rule.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Agricultural Marketing Service (AMS), Federal Grain Inspection Service (FGIS or Service) is amending its user fee regulations to establish standardized formulas the agency will use to calculate hourly and unit fees. The changes allow FGIS to charge reasonable fees sufficient to cover the costs of providing official services and re-establish a 3-to 6-month operating reserve, as required by the United States Grain Standards Act (USGSA). This final rule also makes specified conforming changes and minor technical changes to correct two typographical errors.</P>
                </SUM>
                <EFFDATE>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>This final rule is effective February 5, 2025.</P>
                </EFFDATE>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Denise Ruggles, Executive Program Analyst, USDA, AMS, FGIS, Telephone: 816-702-3897, Email: 
                        <E T="03">Denise.M.Ruggles@usda.gov;</E>
                         or Anthony Goodeman, Senior Policy Advisor, USDA, AMS, FGIS, Telephone: 202-720-2091, Email: 
                        <E T="03">Anthony.T.Goodeman@usda.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                     This final rule supersedes the provisions of the interim final rule titled “Fees for Official Inspection and Weighing Services under the United Stated Grain Standards Act,” and all associated rulemakings, and amends FGIS's user fee regulations to establish new formulas to calculate hourly and unit fees. The new formulas, which are similar to the standardized formulas used in other AMS user-fee funded grading programs, amend the regulations at 7 CFR 800.71. The formulas will enable the agency to sustain operations and comply with the USGSA, which requires FGIS to charge fees sufficient to cover the costs of the official services it provides and to adjust fees annually in order to maintain an operating reserve of not less than 3 and not more than 6 months. Prospective customers can find FGIS's fee schedules posted on AMS's public website at: 
                    <E T="03">https://www.ams.usda.gov/about-ams/fgis-program-directives.</E>
                </P>
                <HD SOURCE="HD1">Comment Review</HD>
                <P>
                    An interim final rule concerning user fees for grain inspection and weighing services was published in the 
                    <E T="04">Federal Register</E>
                     on June 6, 2024 (89 FR 48257). The interim final rule was effective on July 8, 2024. A proposed rule concerning fee formulas by which FGIS would calculate future grain inspection and weighing fees was published October 8, 2024 (89 FR 81396). Copies of the interim rule and proposed rule were sent via email to FGIS stakeholders. The interim rule and proposed rule were also made available through the internet by AMS via 
                    <E T="03">https://www.regulations.gov.</E>
                     AMS provided a 30-day comment period, ending July 8, 2024, to give interested persons an opportunity to respond to the interim final rule, and a 45-day comment period, ending November 22, 2024, to give interested persons an opportunity to respond to the proposed rule.
                </P>
                <P>FGIS received one comment to the proposed rule jointly submitted by two trade organizations. One of the trade organizations represents grain, feed, processing, exporting, and other grain handling companies who collectively operate over 8,000 facilities. The other trade association represents private and publicly owned companies and farmer-owned cooperatives that are involved in, and provide services to, the agri-bulk products international trading industry.</P>
                <HD SOURCE="HD2">Proposed Rule for Calculating Hourly Rates and Unit Fees</HD>
                <P>Two trade associations expressed support for the proposed rule fee formulas in a joint comment. Their comment urged FGIS to maintain transparency regarding the calculation data and to regularly share this information with industry stakeholders. By increasing the flow of information, the comment conveyed that stakeholders can collaborate more effectively with FGIS to discover additional solutions that meet current market rates and requirements. The comment reiterated, similar to feedback on FGIS's interim final rule that revised its user fees, that significant increases in fees paid by industry are unsustainable. Concern was expressed that there is too little transparency in the existing calculation process, which makes it “difficult for both the FGIS and [stakeholders] to budget and plan for services provided. User fees should be predictable and market-based to provide enough funding and properly reflect the work performed.” The comment also suggested that FGIS uncouple hourly fee calculations from the existing five-year rolling average calculation used for tonnage fees.</P>
                <P>FGIS agrees with the comment. The formulas adopted in this final rule will ensure greater transparency regarding the calculation of hourly rates for industry participants, as well as help mitigate large, one-time increases. This final rule also separates the calculation of hourly rates from the five-year rolling average calculation for tonnage fees.</P>
                <P>
                    After consideration of all relevant material presented in the comment and other available information, FGIS has determined that it is appropriate to finalize the proposed rule, as published in the 
                    <E T="04">Federal Register</E>
                     on October 8, 2024 (89 FR 81396), without change.
                </P>
                <HD SOURCE="HD1">Conforming Regulatory Changes</HD>
                <P>
                    In an interim rule published in the June 6, 2024, edition of the 
                    <E T="04">Federal Register</E>
                     (89 FR 48257), FGIS established revised fees for the remainder of 2024 (and until new fees are established using the formulas in this final rule). To implement the revised fees, the interim rule imposed a stay on §§ 800.71 and 800.72(b). To amend these sections, this rulemaking lifts the stay imposed on them by the interim rule.
                </P>
                <P>
                    This rule also makes certain conforming changes in 7 CFR part 800. Specifically, this rule restores references to §§ 800.71 and 800.72 that were amended by the interim rule. In order to implement revised fees for 2024, the interim rule replaced references to § 800.71, which was stayed, with references to a newly added temporary section, § 800.74. Because § 800.72(b) 
                    <PRTPAGE P="532"/>
                    was also stayed, the interim rule replaced a reference to that section in § 800.73(d) with a reference to §§ 800.72(a) and 800.74. As this final rule revises § 800.71 to incorporate the formulas, these internal substitutions are no longer needed. Accordingly, this rule replaces references to § 800.74 with references to § 800.71 in §§ 800.34, 800.36, 800.156(d)(5), and 800.197(b)(3). This rule also replaces the reference to §§ 800.72(a) and 800.74 in § 800.73(d) with a reference to § 800.72. Finally, because the changes to § 800.71 will render § 800.74 obsolete, this rule also removes that section.
                </P>
                <HD SOURCE="HD1">Technical Corrections</HD>
                <P>
                    This rule also corrects two typographical errors—a reference to 5 U.S.C. 6103 and a reference to Executive Order 10358—in the definition of 
                    <E T="03">Holiday</E>
                     in 7 CFR 800.0—Meaning of terms. These corrections do not create new or amend existing requirements or interpretations.
                </P>
                <HD SOURCE="HD1">Required Regulatory Analyses</HD>
                <HD SOURCE="HD1">Executive Orders 12866, 13563, and 14094</HD>
                <P>This rule is being issued in conformance with Executive Order 12866, “Regulatory Planning and Review,” Executive Order 13563, “Improving Regulation and Regulatory Review,” and Executive Order 14094, “Modernizing Regulatory Review.” Executive Orders 12866 and 13563 direct agencies to assess all costs and benefits of available regulatory alternatives and, if regulation is necessary, to select regulatory approaches that maximize net benefits (including potential economic, environmental, public health and safety effects, distributive impacts, and equity). Executive Order 13563 emphasizes the importance of quantifying both costs and benefits, reducing costs, harmonizing rules, and promoting flexibility. Executive Order 14094 reaffirms, supplements, and updates Executive Order 12866 and further directs agencies to solicit and consider input from a wide range of affected and interested parties through a variety of means.</P>
                <P>The Office of Management and Budget (OMB) has designated this rule as not significant under Executive Orders 12866, 13563, and 14094. Accordingly, OMB has not reviewed this rule under those orders. Since grain export volume can vary significantly from year to year, estimating the impact of future fee changes can be difficult. FGIS recognizes the need to provide predictability to the industry for inspection and weighing fees. The statutory requirement to maintain an operating reserve between 3 to 6 months of operating expenses ensures that FGIS can adequately cover its costs without imposing an undue burden on its customers.</P>
                <P>
                    FGIS regularly reviews its user-fee financed programs to determine whether the fees charged for performing official inspection and weighing services adequately cover the costs of providing those services. Due to limitations in the current regulations (7 CFR 800.71(b)(3)), which permit fee increases of no more than 5 percent per year, combined with four years of rate decreases, and noneconomic factors that led to the 2020-2023 period having highest inflation in more than 40 years,
                    <SU>1</SU>
                    <FTREF/>
                     FGIS faced an operating deficit that was forecasted to grow without corrective action.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         For example, the Consumer Price Index (CPI) Calculator (
                        <E T="03">https://data.bls.gov/cgi-bin/cpicalc.pl</E>
                        ) shows prices up 20 percent between January 2020 and February 2024, and up 31 percent between January 2016 and February 2024.
                    </P>
                </FTNT>
                <P>This rule revises the formulas under which FGIS adjusts fees annually to ensure stability of the program. The rule will also ensure that FGIS complies with the USGSA, which requires the agency to charge fees sufficient to cover its costs and maintain a 3- to 6-month operating reserve. FGIS will continue to seek out cost-saving measures and implement appropriate changes to reduce its costs to provide alternatives to fee increases.</P>
                <P>
                    This rule is unlikely to have an annual effect of $200 million or more or adversely affect the economy. FGIS has operated at a net loss for five consecutive years, and even with the maximum fee increases permitted under the current regulations, the agency has been unable to reduce the deficits and rebuild the operating reserve. While FGIS's interim final rule, published previously in the 
                    <E T="04">Federal Register</E>
                     (89 FR 48257), addresses the agency's current deficit, this rule seeks to prevent additional deficits in future years by revising FGIS's user fee regulations to enable more accurate calculation of its costs and greater flexibility in future rate changes.
                </P>
                <P>FGIS believes that the U.S. grain industry will be best served by revising the regulation at 7 CFR 800.71, which addresses the calculation of fees for official inspection and weighing services performed by FGIS in the U.S. and Canada. The industry is already familiar with the annual process for evaluating and updating fees and anticipates the changes in this rule. This rule allows FGIS to continue providing mandatory and voluntary grain inspection services that facilitate international and domestic trade. This rule also allows FGIS to adjust fees in the future in response to unforeseeable climate, logistical, and market conditions, and to maintain required operating reserves.</P>
                <HD SOURCE="HD1">Regulatory Flexibility Analysis</HD>
                <P>Under the requirements set forth in the Regulatory Flexibility Act (RFA) (5 U.S.C. 601-12), FGIS has considered the economic impact of this final rule on small entities. Accordingly, FGIS has prepared this regulatory flexibility analysis. The purpose of the Regulatory Flexibility Act is to fit regulatory actions to the scale of businesses subject to such actions. This ensures that small businesses will not be unduly or disproportionately burdened.</P>
                <P>The Small Business Administration (SBA) defines small businesses by their North American Industry Classification System Codes (NAICS). This final rule will affect customers of FGIS's official inspection and weighing services in the domestic and export grain markets (NAICS code 115114). Current guidance from the SBA provides a revenue cutoff at $34 million to differentiate large and small firms in this industry. Fees for the program which apply to this industry are provided on the FGIS website.</P>
                <P>Under the USGSA, all grain exported from the United States must be officially inspected and weighed, with few exceptions. FGIS provides mandatory inspection and weighing services at 29 export facilities in the United States. Five delegated State agencies provide mandatory inspection and weighing services at 20 facilities. All of these facilities are owned by multinational corporations, large cooperatives, or public entities that do not meet the requirements for small entities established by the SBA.</P>
                <P>The USGSA requires the registration of all persons engaged in the business of buying grain for sale in foreign commerce. In addition, those persons who handle, weigh, or transport grain for sale in foreign commerce must also register. The regulations found at 7 CFR 800.30 and 800.31 define a foreign commerce grain business as the business of regularly buying, handling, weighing, or transporting grain for sale in foreign commerce totaling 15,000 metric tons or more during the preceding or current calendar year. Currently, there are 174 businesses registered to export grain, most of which are not small businesses.</P>
                <P>
                    Although most exporters are not small businesses, most users of FGIS's official inspection and weighing services 
                    <PRTPAGE P="533"/>
                    (which include domestic grain businesses as well as exporters) meet the SBA requirements for small entities. Data on user fee receipts from FGIS for the past 5 years, plus 2024 through February, show a total of 2,123 different accounts over this time, though many firms are represented by multiple accounts. For the purpose of this regulatory flexibility analysis, FGIS will consider accounts as representing establishments, with multiple establishments associated with larger firms.
                </P>
                <P>FGIS identified a total of 31 large firms, as defined by the SBA firm size classification of receipts in excess of $34 million. FGIS also identified the total number of establishments affiliated with the 31 large firms to be 133. With a total number of establishments of 2,123, this means 1,990, or 94 percent, of the establishments that paid fees to FGIS over the 2019-2024 period are small businesses according to the SBA definition.</P>
                <P>Table 1 shows that while only 6 percent of the firms are considered large, in total they have contributed the vast majority of the fees paid to the program. In each of the five previous years, and for the year 2024 to date, the 31 large firms paid between 86 and 90 percent of all FGIS fees, with an average of 89 percent. The remaining 1,990 establishments paid on average 11 percent of total fees.</P>
                <GPOTABLE COLS="6" OPTS="L2,nj,i1" CDEF="s50,11,11,10,10,10">
                    <TTITLE>Table 1—FGIS Billed Accounts Summary Table for Regulatory Flexibility Analysis by Small Business Administration Size Classification</TTITLE>
                    <BOXHD>
                        <CHED H="1">Fiscal year</CHED>
                        <CHED H="1">All firms</CHED>
                        <CHED H="2">
                            Total
                            <LI>fees paid</LI>
                        </CHED>
                        <CHED H="1">Large firms</CHED>
                        <CHED H="2">
                            Total
                            <LI>fees paid</LI>
                        </CHED>
                        <CHED H="2">
                            Share
                            <LI>paid</LI>
                            <LI>(%)</LI>
                        </CHED>
                        <CHED H="1">Small firms</CHED>
                        <CHED H="2">
                            Total
                            <LI>fees paid</LI>
                        </CHED>
                        <CHED H="2">
                            Share
                            <LI>paid</LI>
                            <LI>(%)</LI>
                        </CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">2019</ENT>
                        <ENT>$32,314,848</ENT>
                        <ENT>$27,694,899</ENT>
                        <ENT>86</ENT>
                        <ENT>$4,619,949</ENT>
                        <ENT>14</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">2020</ENT>
                        <ENT>30,746,015</ENT>
                        <ENT>27,386,467</ENT>
                        <ENT>89</ENT>
                        <ENT>3,359,547</ENT>
                        <ENT>11</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">2021</ENT>
                        <ENT>34,320,110</ENT>
                        <ENT>30,693,195</ENT>
                        <ENT>89</ENT>
                        <ENT>3,626,915</ENT>
                        <ENT>11</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">2022</ENT>
                        <ENT>31,663,547</ENT>
                        <ENT>28,183,027</ENT>
                        <ENT>89</ENT>
                        <ENT>3,480,520</ENT>
                        <ENT>11</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">2023</ENT>
                        <ENT>27,734,760</ENT>
                        <ENT>25,069,234</ENT>
                        <ENT>90</ENT>
                        <ENT>2,665,526</ENT>
                        <ENT>10</ENT>
                    </ROW>
                    <ROW RUL="n,s">
                        <ENT I="01">Oct 2023-Feb 2024</ENT>
                        <ENT>10,702,712</ENT>
                        <ENT>9,679,943</ENT>
                        <ENT>90</ENT>
                        <ENT>1,022,769</ENT>
                        <ENT>10</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">Grand Total</ENT>
                        <ENT>167,481,991</ENT>
                        <ENT>148,706,765</ENT>
                        <ENT>89</ENT>
                        <ENT>18,775,226</ENT>
                        <ENT>11</ENT>
                    </ROW>
                </GPOTABLE>
                <P>The amendments to FGIS's user fee regulations will not change the relative burden of fees on small businesses. The provisions of this final rule will apply equally to all entities. In addition, use of standardized user-fee rate calculations will benefit all inspection applicants, regardless of size, as fees will more closely reflect the current costs of inspections, and the fee calculation process will be more transparent. Through its annual review, FGIS will be able to monitor the financial status of the grain inspection and weighing program to determine whether further adjustments are necessary. Finally, this final rule will not impose additional reporting, record keeping, or other compliance requirements on small entities. FGIS has not identified any other Federal rules which may duplicate, overlap, or conflict with this final rule.</P>
                <HD SOURCE="HD1">Executive Order 12988</HD>
                <P>This final rule has been reviewed under Executive Order 12988—Civil Justice Reform. It is not intended to have retroactive effect. Section 18 of the USGSA (7 U.S.C. 87g) provides that no State or subdivision thereof may require or impose any requirements or restrictions concerning the inspection, weighing, or description of grain under the USGSA. Otherwise, this final rule will not preempt any State or local laws, regulations, or policies unless they present an irreconcilable conflict with this final rule. There are no administrative procedures that must be exhausted prior to any judicial challenge to the provisions of this final rule.</P>
                <HD SOURCE="HD1">Executive Order 13175</HD>
                <P>This final rule has been reviewed under Executive Order 13175—Consultation and Coordination with Indian Tribal Governments, which requires agencies to consider whether their rulemaking actions would have Tribal implications. FGIS has determined that this final rule is unlikely to have substantial direct effects on one or more Indian Tribes, on the relationship between the Federal Government and Indian Tribes, or on the distribution of power and responsibilities between the Federal Government and Indian Tribes.</P>
                <HD SOURCE="HD1">Congressional Review Act</HD>
                <P>Pursuant to the Congressional Review Act (5 U.S.C. 801-808), the Office of Information and Regulatory Affairs designated this final rule as not a major rule, as defined by 5 U.S.C. 804(2).</P>
                <HD SOURCE="HD1">E-Government Act</HD>
                <P>USDA is committed to complying with the provisions of the E-Government Act (44 U.S.C. 3601-3616) by promoting the use of the internet and other information technologies to provide increased opportunities for citizen access to government information and services, and for other purposes.</P>
                <HD SOURCE="HD1">Paperwork Reduction Act</HD>
                <P>This final rule will not impose any additional reporting or recordkeeping requirements on either small or large FGIS customers. In compliance with the Paperwork Reduction Act of 1995 (44 U.S.C. chapter 35), FGIS reports and forms are periodically reviewed to reduce information collection requirements and duplication.</P>
                <LSTSUB>
                    <HD SOURCE="HED">List of Subjects in 7 CFR Part 800</HD>
                    <P>Administrative practice and procedure, Conflict of interests, Exports, Freedom of information, Grains, Intergovernmental relations, Penalties, Reporting and recordkeeping requirements.</P>
                </LSTSUB>
                <P>For the reasons set forth in the preamble, the Agricultural Marketing Service amends 7 CFR part 800 as follows:</P>
                <PART>
                    <HD SOURCE="HED">PART 800—GENERAL REGULATIONS </HD>
                </PART>
                <REGTEXT TITLE="7" PART="800">
                    <AMDPAR>1. The authority citation for part 800 continues to read as follows:</AMDPAR>
                    <AUTH>
                        <HD SOURCE="HED">Authority:</HD>
                        <P> 7 U.S.C. 71-87K. </P>
                    </AUTH>
                </REGTEXT>
                <SECTION>
                    <SECTNO>§ 800.0</SECTNO>
                    <SUBJECT> [Amended] </SUBJECT>
                </SECTION>
                <REGTEXT TITLE="7" PART="800">
                    <AMDPAR>
                        2. In § 800.0, in paragraph (b), in the definition of “Holiday”, remove the text 
                        <PRTPAGE P="534"/>
                        “Under section 610 and Executive Order No. 10357” and add, in its place, the text “Under section 6103 and Executive Order 10358”. 
                    </AMDPAR>
                </REGTEXT>
                <SECTION>
                    <SECTNO>§ 800.34</SECTNO>
                    <SUBJECT> [Amended] </SUBJECT>
                </SECTION>
                <REGTEXT TITLE="7" PART="800">
                    <AMDPAR>3. In § 800.34, in the first sentence, remove the citation “§ 800.74” and add, in its place, the citation “§ 800.71”.</AMDPAR>
                </REGTEXT>
                <SECTION>
                    <SECTNO>§ 800.36</SECTNO>
                    <SUBJECT> [Amended] </SUBJECT>
                </SECTION>
                <REGTEXT TITLE="7" PART="800">
                    <AMDPAR>4. In § 800.36, in the last sentence, remove the citation “§ 800.74” and add, in its place, the citation “§ 800.71”. </AMDPAR>
                </REGTEXT>
                <REGTEXT TITLE="7" PART="800">
                    <AMDPAR>5. Amend § 800.71 by lifting the stay and revising the section to read as follows:</AMDPAR>
                    <SECTION>
                        <SECTNO>§ 800.71</SECTNO>
                        <SUBJECT> Fees assessed by the Service.</SUBJECT>
                        <P>
                            (a) 
                            <E T="03">Official inspection and weighing services.</E>
                             The fees described for Direct Service in paragraph (a)(1) of this section apply to official inspection and weighing services performed by the Service in the U.S. and Canada. The fees described for Supervision in paragraph (a)(2) of this section apply to official domestic inspection and weighing services performed by delegated States and designated agencies, including land carrier shipments to Canada and Mexico. The fees charged to delegated States by the Service are set forth in the State's Delegation of Authority document. Failure of a delegated State or designated agency to pay the appropriate fees to the Service within 30 days after becoming due will result in an automatic termination of the delegation or designation. The delegation or designation may be reinstated by the Service if fees that are due, plus interest and any further expenses incurred by the Service because of the termination, are paid within 60 days of the termination.
                        </P>
                        <P>
                            (1) 
                            <E T="03">Direct Service—Fees for official inspection and weighing services performed by the Service in the United States and Canada.</E>
                             For each calendar year, the Service will calculate Direct Service fees as provided in paragraphs (b) and (c) of this section. The Service will publish a notice in the 
                            <E T="04">Federal Register</E>
                             and post Direct Service fees on its public website.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Supervision—Fees for supervision of official inspection and weighing services performed by delegated States and designated agencies in the United States.</E>
                             The Service will assess a Supervision fee per metric ton of domestic U.S. grain shipments inspected or weighed, or both, including land carrier shipments to Canada and Mexico. For each calendar year, the Service will calculate Supervision fees as provided in paragraph (d) of this section. The Service will publish a notice in the 
                            <E T="04">Federal Register</E>
                             and post the Supervision fees on its public website.
                        </P>
                        <P>
                            (b) 
                            <E T="03">Annual review of tonnage fees.</E>
                             For each calendar year, the Service will review and adjust fees included in this section and publish fees each year according to the following:
                        </P>
                        <P>
                            (1) 
                            <E T="03">Tonnage fees.</E>
                             Tonnage fees for Direct Service in paragraph (a)(1) of this section will consist of the national tonnage fee and local tonnage fees and the Service will calculate and round the fee to the nearest $0.001 per metric ton. All outbound grain officially inspected and/or weighed by the Field Offices will be assessed the national tonnage fee plus the appropriate local tonnage fee. Export grain officially inspected and/or weighed by delegated States and official agencies, excluding land carrier shipments to Canada and Mexico, will be assessed the national tonnage fee only. The fees will be set according to the following:
                        </P>
                        <P>
                            (i) 
                            <E T="03">National tonnage fee.</E>
                             The national tonnage fee is the national program administrative costs for the previous fiscal year divided by the average yearly tons of export grain officially inspected and/or weighed by delegated States and designated agencies, excluding land carrier shipments to Canada and Mexico, and outbound grain officially inspected and/or weighed by the Service, during the previous 5 fiscal years.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Local tonnage fee.</E>
                             The local tonnage fee is the Field Office administrative costs for the previous fiscal year divided by the average yearly tons of outbound grain officially inspected and/or weighed by the Field Office during the previous 5 fiscal years. The local tonnage fee is calculated individually for each Field Office.
                        </P>
                        <P>(2) [Reserved]</P>
                        <P>
                            (c) 
                            <E T="03">Annual review of hourly and unit fees.</E>
                             The Service will calculate the rate for program services, per hour per program employee using the following formulas:
                        </P>
                        <P>
                            (1) 
                            <E T="03">Regular rate.</E>
                             The total direct pay of program personnel performing grading, weighing, laboratory services, and equipment testing divided by the total direct hours for the previous year, which is then multiplied by the next year's percentage cost-of-living increase, plus the benefits rate, plus the operating rate, plus the allowance for bad debt rate. If applicable, travel expenses will be added to the cost of providing the service through the operating rate or the travel will be billed separately.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Overtime rate.</E>
                             The total direct pay of program personnel performing grading, weighing, laboratory services, and equipment testing divided by the total direct hours for the previous year, which is then multiplied by the next year's percentage cost-of-living increase and then multiplied by 1.5, plus the benefits rate, plus the operating rate, plus the allowance for bad debt rate. If applicable, travel expenses will be added to the cost of providing the service through the operating rate or the travel will be billed separately.
                        </P>
                        <P>
                            (3) 
                            <E T="03">Holiday rate.</E>
                             The total direct pay of program personnel performing grading, weighing, laboratory services, and equipment testing divided by the total direct hours for the previous year, which is then multiplied by the next year's percentage cost-of-living increase and then multiplied by 2, plus the benefits rate, plus the operating rate, plus the allowance for bad debt rate. If applicable, travel expenses will be added to the cost of providing the service through the operating rate or the travel will be billed separately.
                        </P>
                        <P>
                            (4) 
                            <E T="03">Benefits rate, operating rate, and allowance for bad debt rate.</E>
                             For each calendar year, based on previous fiscal year costs, the Service will calculate the benefits rate, operating rate, and allowance for bad debt rate as follows:
                        </P>
                        <P>
                            (i) 
                            <E T="03">Benefits rate.</E>
                             The total direct benefits costs of program personnel performing grading, weighing, laboratory services, and equipment testing divided by the total hours (regular, overtime, and holiday) worked, which is then multiplied by the next calendar year's percentage cost-of-living increase.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Operating rate.</E>
                             The total operating costs of program personnel performing grading, weighing, laboratory services, and equipment testing divided by total hours (regular, overtime, and holiday) worked, which is then multiplied by the percentage of inflation.
                        </P>
                        <P>
                            (iii) 
                            <E T="03">Allowance for bad debt rate.</E>
                             The total allowance for bad debt for personnel performing grading, weighing, laboratory services, and equipment testing divided by total hours (regular, overtime, and holiday) worked.
                        </P>
                        <P>
                            (5) 
                            <E T="03">Cost of living and inflation factors.</E>
                             The Service will use the most recent economic factors released by the Office of Management and Budget for budget development purposes to derive the cost-of-living expenses and percentage of inflation factors used in the formulas in this section.
                        </P>
                        <P>
                            (6) 
                            <E T="03">Operating reserve adjustment.</E>
                             The Service will review the operating reserve at the end of each fiscal year and adjust the fees as needed to ensure an operating reserve of 3 to 6 months of expenses. This adjustment is included in the calculation for operating cost.
                            <PRTPAGE P="535"/>
                        </P>
                        <P>
                            (d) 
                            <E T="03">Annual review of Supervision fees.</E>
                             Fees for Supervision in paragraph (a)(2) of this section will be set according to the following:
                        </P>
                        <P>
                            (1) 
                            <E T="03">Supervision tonnage fee.</E>
                             The supervision tonnage fee is the sum of the prior fiscal year program costs plus an operating reserve adjustment divided by the average yearly tons of domestic U.S. grain shipments inspected or weighed, or both, including land carrier shipments to Canada and Mexico, during the previous 5 fiscal years. If the calculated value is zero or a negative value, the Service will suspend the collection of supervision tonnage fees for 1 calendar year.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Operating reserve adjustment.</E>
                             The operating reserve adjustment is the supervision program costs for the previous fiscal year divided by 2, less the end of previous fiscal year operating reserve balance.
                        </P>
                        <P>
                            (e) 
                            <E T="03">Periodic review.</E>
                             The Service will periodically review and adjust all Direct Service and Supervision fees in paragraphs (a)(1) and (2) of this section, respectively, as necessary to ensure they reflect the true cost of providing and supervising official service. This process will incorporate any fee adjustments from paragraphs (b) through (d) of this section.
                        </P>
                        <P>
                            (f) 
                            <E T="03">Miscellaneous fees for other services.</E>
                             For each calendar year, the Service will review fees included in this section and publish fees in the 
                            <E T="04">Federal Register</E>
                             and on its public website.
                        </P>
                        <P>
                            (1) 
                            <E T="03">Registration certificates and renewals.</E>
                             The fee for registration certificates and renewals will be published annually in the 
                            <E T="04">Federal Register</E>
                             and on the Service's public website, and the Service will calculate the fee using the noncontract hourly rate published pursuant to paragraph (a)(1) of this section multiplied by 5. If you operate a business that buys, handles, weighs, or transports grain for sale in foreign commerce, or you are in a control relationship with respect to a business that buys, handles, weighs, or transports grain for sale in interstate commerce, you must complete an application and pay the published fee.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Designation amendments.</E>
                             The fee for amending designations will be published annually in the 
                            <E T="04">Federal Register</E>
                             and on the Service's public website. The Service will calculate the fee using the cost of publication plus 1 hour at the noncontract hourly rate. If submitting an application to amend a designation, the published fee must be paid.
                        </P>
                    </SECTION>
                </REGTEXT>
                <REGTEXT TITLE="7" PART="800">
                    <AMDPAR>6. In § 800.72:</AMDPAR>
                    <AMDPAR>a. Lift the stay on paragraph (b); and</AMDPAR>
                    <AMDPAR>b. Revise paragraph (b).</AMDPAR>
                    <P>The revision reads as follows:</P>
                    <SECTION>
                        <SECTNO>§ 800.72 </SECTNO>
                        <SUBJECT>Explanation of additional service fees for services performed in the United States only.</SUBJECT>
                        <STARS/>
                        <P>(b) In addition to a 2-hour minimum charge for service on Saturdays, Sundays, and holidays, an additional charge will be assessed when the revenue from the services in § 800.71(a)(1) does not equal or exceed what would have been collected at the applicable hourly rate. The additional charge will be the difference between the actual unit fee revenue and the hourly fee revenue. Hours accrued for travel and standby time shall apply in determining the hours for the minimum fee.</P>
                    </SECTION>
                </REGTEXT>
                <SECTION>
                    <SECTNO>§ 800.73 </SECTNO>
                    <SUBJECT>[Amended]</SUBJECT>
                </SECTION>
                <REGTEXT TITLE="7" PART="800">
                    <AMDPAR>7. In § 800.73, in paragraph (d), remove the citation “§§ 800.72(a) and 800.74” and add, in its place, the citation “§ 800.72”.</AMDPAR>
                </REGTEXT>
                <SECTION>
                    <SECTNO>§ 800.74 </SECTNO>
                    <SUBJECT>[Removed]</SUBJECT>
                </SECTION>
                <REGTEXT TITLE="7" PART="800">
                    <AMDPAR>8. Remove § 800.74.</AMDPAR>
                </REGTEXT>
                <SECTION>
                    <SECTNO>§ 800.156 </SECTNO>
                    <SUBJECT>[Amended]</SUBJECT>
                </SECTION>
                <REGTEXT TITLE="7" PART="800">
                    <AMDPAR>9. In § 800.156, in paragraph (d)(5), in the last sentence, remove the citation “§ 800.74” and add, in its place, the citation “§ 800.71”.</AMDPAR>
                </REGTEXT>
                <SECTION>
                    <SECTNO>§ 800.197 </SECTNO>
                    <SUBJECT>[Amended]</SUBJECT>
                </SECTION>
                <REGTEXT TITLE="7" PART="800">
                    <AMDPAR>10. In § 800.197, in paragraph (b)(3), remove the citation “§ 800.74” and add, in its place, the citation “§ 800.71”.</AMDPAR>
                </REGTEXT>
                <SIG>
                    <NAME>Melissa Bailey,</NAME>
                    <TITLE>Associate Administrator, Agricultural Marketing Service.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31140 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE P</BILCOD>
        </RULE>
        <RULE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF HOMELAND SECURITY</AGENCY>
                <CFR>8 CFR Part 103</CFR>
                <DEPDOC>[DHS Docket No. ICEB-2021-0015]</DEPDOC>
                <RIN>RIN 1653-AA85</RIN>
                <SUBJECT>Immigration Bond Notifications</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>U.S. Immigration and Customs Enforcement (ICE), Department of Homeland Security (DHS).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Final rule.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>On August 8, 2023, DHS issued an interim final rule which amended the regulations to authorize ICE to serve bond-related notices to obligors electronically. The rule allowed DHS to electronically serve demand and other immigration bond notices for delivery, order of supervision, or voluntary departure bonds to obligors who consent to electronic service. DHS is now issuing this final rule that introduces no substantive changes from the interim final rule.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>The effective date of this final rule is January 6, 2025.</P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sharon Hageman, Deputy Assistant Director, Office of Regulatory Affairs and Policy, U.S. Immigration and Customs Enforcement, Department of Homeland Security, 500 12th Street SW, Washington, DC 20536. Telephone 202-732-6960 (this is not a toll-free number).</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">I. Background</HD>
                <HD SOURCE="HD2">A. Purpose of the Regulatory Action</HD>
                <P>
                    The Department of Homeland Security (DHS) published an interim final rule (IFR) on August 8, 2023,
                    <SU>1</SU>
                    <FTREF/>
                     that established that DHS may electronically serve demand notices, and other bond notices for delivery, order of supervision, or voluntary departure bonds for obligors who consent to electronic service. 
                    <E T="03">See</E>
                     8 CFR 103.6(g) and (h). This final rule adopts the IFR provisions in 8 CFR 103.6(g) and (h) to electronically serve bond-related notices to obligors who consent to electronic service. This final rule also amends typographical errors, updates terminology for accuracy, and restructures regulatory text for clarity and consistency in 8 CFR 103.6(g) and (h). This final rule introduces no substantive changes from the IFR.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         Immigration Bond Notifications, 88 FR 53358 (Aug. 8, 2023).
                    </P>
                </FTNT>
                <HD SOURCE="HD2">B. Legal Authority</HD>
                <P>The Homeland Security Act of 2002, Public Law 107-296, section 102, 116 Stat. 2135 (Nov. 25, 2002), 6 U.S.C. 112, and the Immigration and Nationality Act of 1952 (INA), as amended, section 103(a)(1), 8 U.S.C. 1103(a)(1), charge the Secretary of DHS (the Secretary) with administration and enforcement of the immigration and naturalization laws. The Secretary promulgates this final rule under the broad authority to administer DHS, and the authorities provided under the Homeland Security Act of 2002, the immigration and nationality laws, and other delegated authority.</P>
                <P>
                    Over the past twenty years, Congress and the Executive Branch have promoted the use of electronic transactions and electronic records when feasible instead of relying solely upon in-person or paper transactions. 
                    <PRTPAGE P="536"/>
                    Under the Government Paperwork Elimination Act (GPEA), Public Law 105-277, tit. XVII, section 1703, 112 Stat. 2681, 2681-749 (Oct. 21, 1998), 44 U.S.C. 3504 note, federal agencies are required, when practicable, to provide the option of electronic maintenance, submission, or disclosure of information as a substitute for paper transactions. More recently, on June 28, 2019, the Office of Management and Budget (OMB) and the National Archives and Records Administration (NARA) jointly issued a memorandum that encouraged agencies to consider cost-effective opportunities to transition related business processes to an electronic environment.
                    <SU>2</SU>
                    <FTREF/>
                     Offering electronic processes in place of paper or in-person transactions has the benefits of making it “easier for the public to connect with the Federal Government, and apply for and receive services, improving customer satisfaction. Electronic records . . . reduce processing times and decrease the probability of lost or missing information . . . [and] . . . greatly improve agencies' ability to provide public access to Federal records, promoting transparency and accountability.” Executive Office of the President, 
                    <E T="03">Delivering Government Solutions in the 21st Century: Reform Plan and Reorganization Recommendations,</E>
                     at 100 (June 2018). The GPEA establishes the means for the use and acceptance of electronic signatures (e-signatures). This rule will enhance the ability of U.S. Immigration and Customs Enforcement (ICE) to fully implement the GPEA.
                </P>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         Office of Management and Budget, Transition to Electronic Records (OMB/NARA M-19-21) (June 28, 2019), 
                        <E T="03">https://www.archives.gov/files/records-mgmt/policy/m-19-21-transition-to-federal-records.pdf.</E>
                    </P>
                </FTNT>
                <P>
                    The Electronic Signatures in Global and National Commerce Act (E-SIGN Act), 15 U.S.C. 7001-7031, effective for most purposes on October 1, 2000, allows electronic records and signatures to be given the same effect as paper and ink documents. 
                    <E T="03">See</E>
                     15 U.S.C. 7001(a). The E-SIGN Act provides “legal parity” for electronic records with paper records, when the procedures an agency adopts for the creation, maintenance, and retention of electronic records comply with the Federal Records Act and NARA guidelines governing digitization of records.
                    <SU>3</SU>
                    <FTREF/>
                     Except for records maintained by government agencies (other than contracts to which it is a party), the E-SIGN Act does not require any person to agree to use or accept electronic records. 
                    <E T="03">Id.</E>
                     sec. 7001(b)(2); 
                    <E T="03">see also</E>
                     12 CFR 609.910(a) (noting that under the E-SIGN Act, “E-commerce is optional; all parties to a legally valid transaction must agree to the electronic use before it can be used”).
                    <SU>4</SU>
                    <FTREF/>
                     ICE intends to comply with this requirement by obtaining consent from immigration bond sureties and obligors to send electronic notices.
                </P>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         Robert A. Wittie &amp; Jane K. Winn, 
                        <E T="03">Electronic Records and Signatures under the Federal E-Sign Legislation and the UETA,</E>
                         56 Bus. Law. 293, 314 (2000).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         The provisions of the E-SIGN Act are generally inapplicable to federal government agencies. 
                        <E T="03">See</E>
                         15 U.S.C. 7003(b)(1) (“The provisions of [E-SIGN Act] shall not apply to—(1) court orders or notices, or official court documents (including briefs, pleadings, and other writings) required to be executed in connection with court proceedings;”). The Office of Management and Budget (OMB) has concluded that based on the legislative history, Congress explicitly excluded governmental transactions from coverage under the E-SIGN Act. 
                        <E T="03">See</E>
                         OMB Guidance on Implementing the Electronic Signatures in Global and National Commerce Act, M-00-15, Attachment at p.3., (September 2000), available at Memoranda 00-10—OMB Procedures and Guidance on Implementing the Government. The White House (
                        <E T="03">archives.gov</E>
                        ) and ESIGN guidance.PDF (
                        <E T="03">archives.gov</E>
                        ), updated by OMB M-04-04, E-Authentication Guidance for Federal Agencies (Dec. 16, 2003). Accordingly, although the electronic consent complies with E-SIGN requirements, such compliance is not required of DHS.
                    </P>
                </FTNT>
                <P>
                    The Secretary is charged with the administration and enforcement of laws relating to the immigration and naturalization of noncitizens and “shall . . . prescribe such forms of bond” as deemed necessary for carrying out the authority under the INA. 
                    <E T="03">See</E>
                     INA 103(a)(1), (3), 8 U.S.C. 1103(a)(1), (3). Additionally, where a noncitizen is arrested on a warrant and detained pending a decision on removal from the United States, the Secretary may be authorized to “release [the noncitizen] on . . . (A) bond of at least $1,500 with security approved by, and containing conditions prescribed by [the Secretary of Homeland Security].” INA 236(a)(2), 8 U.S.C. 1226(a)(2). Further, the Secretary “at any time may revoke a bond” authorized under INA 236(a)(2), re-arrest the noncitizen, and detain them. INA 236(b), 8 U.S.C. 1226(b). Under the terms and conditions provided in Form I-352, 
                    <E T="03">Immigration Bond,</E>
                     “Federal law shall apply to the interpretation of the bond.” ICE and the Department of Justice (DOJ) approve several types of immigration bonds such as delivery bonds, 8 CFR 236.1(c)(10); voluntary departure bonds, 8 CFR 240.25(b), 8 CFR 1240.26(b)(3)(i), (c)(3)(i); and order of supervision bonds, 8 CFR 241.5(b).
                </P>
                <P>
                    With respect to cash bonds, the Secretary delegated to the ICE Director the authority to “issue and execute detainers and warrants of arrest or removal, detain aliens, release aliens on bond and other appropriate conditions as provided by law. . . .” 
                    <SU>5</SU>
                    <FTREF/>
                     With respect to surety bonds, the Secretary delegated to the ICE Director the “[a]uthority to approve surety bonds issued pursuant to the immigration laws, to determine whether such surety bonds have been breached, and to take appropriate action to protect the interests of the United States with respect to such surety bonds.” 
                    <SU>6</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         DHS Delegation No. 7030.2, 
                        <E T="03">Delegation of Authority to the Assistant Secretary for U.S. Immigration and Customs Enforcement,</E>
                         ¶ 2(T) (signed Nov. 13, 2004) (effective Mar. 1, 2003), 
                        <E T="03">https://www.ice.gov/doclib/foia/policy/7030.2_DelegationAuthority_03.01.2003.pdf.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         DHS Delegation No. 7030.2, 
                        <E T="03">supra</E>
                         note 4, ¶ 2(U). In this context, “surety bonds” is used in the same manner as it is used in 8 CFR 103.6(b)(1) to include immigration bonds underwritten by a surety company or posted by an entity or individual who deposits cash equal to the face amount of the bond as security for performance.
                    </P>
                </FTNT>
                <HD SOURCE="HD2">C. Background</HD>
                <P>
                    ICE's mission is to protect America through criminal investigations and enforcing immigration laws to preserve national security and public safety.
                    <SU>7</SU>
                    <FTREF/>
                     ICE secures the nation's borders by enforcing more than 400 federal statutes and issuing a wide range of notices, decisions, and other documents to entities including universities, businesses, courts, and noncitizens.
                    <SU>8</SU>
                    <FTREF/>
                     Generally, Department of Homeland Security (DHS) regulations authorize ICE to serve notices, decisions, and other documents in person or through the U.S. Postal Service. DHS regulations distinguish between “personal” and “routine” service of notices, decisions, and other documents. 
                    <E T="03">See</E>
                     8 CFR 103.8(a).
                </P>
                <FTNT>
                    <P>
                        <SU>7</SU>
                         
                        <E T="03">See</E>
                         U.S. Immigration and Customs Enforcement, 
                        <E T="03">https://www.ice.gov/mission</E>
                         (last visited Nov. 14, 2024).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>8</SU>
                         The preamble of this Final Rule uses “noncitizen” as equivalent to the statutory term “alien.” 
                        <E T="03">See Barton</E>
                         v. 
                        <E T="03">Barr,</E>
                         590 U.S. 222, 226 n.2 (2020) (quoting 8 U.S.C. 1101(a)(3)).
                    </P>
                </FTNT>
                <P>
                    Current regulations define personal service as personal delivery; delivery at a person's home or usual residence by leaving a copy with a person of suitable age and discretion; delivery at an attorney's or corporate office by leaving a copy with a person in charge; mailing a copy by certified or registered mail, return receipt requested, addressed to a person at his or her last known address; or notifying the party by electronic mail and posting the decision to the party's account with U.S. Citizenship and Immigration Services (USCIS) if so requested by the party. 8 CFR 103.8(a)(2); 
                    <E T="03">cf.</E>
                     8 CFR 103.8(a)(3) (providing additional methods for “personal service involving notices of intention to fine”). Personal service of initiating notice and of notice of any 
                    <PRTPAGE P="537"/>
                    decision is required in any proceeding initiated by DHS that has a proposed adverse effect on the recipient, except as provided in section 239 of the INA. 8 CFR 103.8(c)(1). If the recipient is confined to a penal or mental institution or hospital, or if the recipient is a minor under the age of 14 or mentally incompetent, personal service to additional entities or individuals may be required. 8 CFR 103.8(c)(1) and (2).
                </P>
                <P>
                    When personal service is not required, the regulations allow routine service to be used. 
                    <E T="03">See</E>
                     8 CFR 103.8(d). Routine service includes mailing a notice by ordinary mail addressed to the affected party or the party's attorney or representative at his or her last known address or notifying the party by electronic mail and posting the decision to the party's USCIS account if so requested by the party. 8 CFR 103.8(a)(1); 
                    <E T="03">see also</E>
                     8 CFR part 292 (Representation and Appearances); and 8 CFR part 1292 (Representation and Appearances).
                </P>
                <HD SOURCE="HD2">D. Immigration Bonds</HD>
                <P>
                    An immigration bond is a formal written guarantee by an obligor (an individual, entity, or surety company) posted as security for the amount noted on the face of the immigration bond. The bond assures ICE that the obligor will perform the obligations for the type of bond indicated on Form I-352, 
                    <E T="03">Immigration Bond.</E>
                     The posting of immigration bonds can occur with the deposit of cash in the full principal amount of the bond, known as “cash bonds,” 
                    <SU>9</SU>
                    <FTREF/>
                     or where a surety company and its agent agree to pay the amount of the bond if there is a substantial violation of the bond's terms and conditions, known as a “surety bond.” ICE approved 20,494 immigration bonds in 2023,
                    <SU>10</SU>
                    <FTREF/>
                     of which 15,323 (75 percent) were cash bonds and 5,171 (25 percent) were surety bonds. If the noncitizen performs the conditions set forth in the bond, the bond will be cancelled. If the noncitizen substantially violates the conditions of the bond, the bond will be considered breached. 
                    <E T="03">See</E>
                     8 CFR 103.6(e).
                </P>
                <FTNT>
                    <P>
                        <SU>9</SU>
                         An immigration bond secured by a cash deposit posted by an individual, law firm, non-profit organization, or other entity.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>10</SU>
                         Immigration Bond Statistics maintained by ICE's Bonds Branch, Financial Service Center-Burlington, as of January 17, 2024.
                    </P>
                </FTNT>
                <P>
                    An immigration bond may be posted by a surety company or a cash bond obligor.
                    <SU>11</SU>
                    <FTREF/>
                     Surety bonds are bonds underwritten by a surety company certified to issue bonds on behalf of the federal government. 
                    <E T="03">See generally</E>
                     8 CFR 103.6(b) (identifying the parties that may serve as sureties on immigration bonds). Under the terms of the bond contract, the surety is the obligor, the agent that posts a bond on behalf of a surety is a co-obligor, the noncitizen (on whose behalf the bond is issued) is the principal, and ICE is the beneficiary of all bonds it authorizes. An acceptable surety is either a company that appears on the current Department of the Treasury Circular 570 as a company holding a certificate of authority to underwrite federal bonds pursuant to 31 U.S.C. 9304-9308 or is an entity or individual who deposits the amount of the bond with ICE. 
                    <E T="03">See</E>
                     8 CFR 103.6(b)(1). The surety (obligor) and its agent (co-obligor) guarantee the performance and fulfillment of the noncitizen's duties as set forth in the bond form. 
                    <E T="03">See</E>
                     Form I-352, at 1 (rev. 11/23).
                    <SU>12</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>11</SU>
                         Provided that the surety company or cash bond obligor satisfies all the requisite steps for ICE to accept the bond payment.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>12</SU>
                         Department of Homeland Security, Immigration and Customs Enforcement (Nov. 2023), 
                        <E T="03">https://www.ice.gov/doclib/forms/i352.pdf.</E>
                    </P>
                </FTNT>
                <P>ICE approves and issues three different types of bonds.</P>
                <P>
                    • 
                    <E T="03">Delivery Bonds:</E>
                     To release a noncitizen from DHS custody while removal proceedings are pending.
                </P>
                <P>
                    • 
                    <E T="03">Voluntary Departure Bonds:</E>
                     To ensure a noncitizen who is granted voluntary departure leaves the United States on or before the voluntary departure date set by an Immigration Judge (IJ) or the Board of Immigration Appeals (BIA).
                </P>
                <P>
                    • 
                    <E T="03">Order of Supervision Bonds:</E>
                     To ensure noncitizens released on an order of supervision comply with the material terms of the supervised release.
                </P>
                <P>
                    Out of the 20,494 immigration bonds that ICE issued in 2023, 91 percent were delivery bonds, 9 percent were voluntary departure bonds, and fewer than 1 percent were order of supervision bonds.
                    <SU>13</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>13</SU>
                         Immigration Bond Statistics maintained by ICE's Bond Management Unit, Non-Detained Management Division, Enforcement and Removal Operations, as of January 17, 2024.
                    </P>
                </FTNT>
                <P>
                    To trigger an obligor's performance, ICE issues a demand notice, Form I-340, 
                    <E T="03">Notice To Obligor To Deliver Alien.</E>
                     DHS regulations authorize ICE to use personal service as defined by 8 CFR 103.8 to deliver demand notices issued on delivery bonds so ICE can confirm receipt (the date the obligor receives the demand notice). ICE confirms receipt of demand notices (proof of service) issued on delivery bonds to confirm that timely notice was provided to an obligor of their duty to surrender a noncitizen at an ICE office on the designated date. For breach notices,
                    <SU>14</SU>
                    <FTREF/>
                     cancellation notices, and notices of bond breach reconsideration decisions, DHS regulations authorize ICE to use routine mail service to the obligor's last known address. 8 CFR 103.8(a)(1). ICE uses routine mail service as well to issue invoices and demand letters to surety companies and their agents, either by ordinary mail or a mail method that allows ICE to track and confirm delivery, or by email (electronically) with the co-obligors' consent.
                </P>
                <FTNT>
                    <P>
                        <SU>14</SU>
                         Immigration bonds are contracts subject to a regulatory scheme with the result that ICE bond breach determinations are reviewed by a court under the arbitrary and capricious standard of review set forth in the Administrative Procedure Act (APA), 5 U.S.C. 706(2)(A). 
                        <E T="03">See United States</E>
                         v. 
                        <E T="03">Gonzales &amp; Gonzales Bonds &amp; Ins. Agency, Inc.,</E>
                         728 F. Supp. 2d 1077, 1087-92 (N.D. Cal. 2010); 
                        <E T="03">Safety Nat'l Cas. Corp.</E>
                         v. 
                        <E T="03">DHS,</E>
                         711 F. Supp. 2d 697, 701 &amp; 708-09 (S.D. Tex. 2008), 
                        <E T="03">rev'd in part on other grounds, AAA Bonding Agency Inc.</E>
                         v. 
                        <E T="03">DHS,</E>
                         447 F. App'x 603 (5th Cir. 2011); 
                        <E T="03">United States</E>
                         v. 
                        <E T="03">Minnesota Trust Co.,</E>
                         59 F.3d 87, 90 (8th Cir. 1995).
                    </P>
                </FTNT>
                <P>If the noncitizen performs the conditions set forth in the bond, the bond will be cancelled. 8 CFR 103.6(c). ICE will send a demand notice to notify the obligor to deliver the noncitizen. 8 CFR 103.6(g). If the noncitizen substantially violates the conditions of the bond, the bond will be considered breached. 8 CFR 103.6(e).</P>
                <P>
                    Depending on the type of bond and action in accordance with the bond, ICE may issue certain bond notices. The IFR and this final rule currently apply to the following circumstances 
                    <SU>15</SU>
                    <FTREF/>
                     when ICE may serve a bond notice electronically to obligors:
                </P>
                <FTNT>
                    <P>
                        <SU>15</SU>
                         However, the list is non-exhaustive in the sense that more types of notices could be subject to electronic notice in the future. The rule does not limit electronic service to these four types of bond notices.
                    </P>
                </FTNT>
                <P>
                    1. 
                    <E T="03">Delivery Demand.</E>
                     Form I-340, 
                    <E T="03">Notice to Obligor to Deliver Alien,</E>
                     instructs the bond obligor to surrender the noncitizen to an ICE Office or to an immigration court on a designated date.
                    <SU>16</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>16</SU>
                         Form I-340 (rev. Dec. 2023).
                    </P>
                </FTNT>
                <P>
                    2. 
                    <E T="03">Breach Notice.</E>
                     Form I-323, 
                    <E T="03">Notice</E>
                    —
                    <E T="03">Immigration Bond Breached,</E>
                     informs the obligor that a condition of the bond was substantially violated, notating the date the bond was breached, and apprises the obligor of the right to file an administrative appeal of the breach determination.
                    <SU>17</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>17</SU>
                         Form I-323 (rev. Oct. 2020). 
                        <E T="03">See</E>
                         8 CFR 103.6(e).
                    </P>
                </FTNT>
                <P>
                    3. 
                    <E T="03">Cancellation Notice.</E>
                     Form I-391, 
                    <E T="03">Notice</E>
                    —
                    <E T="03">Immigration Bond Cancelled,</E>
                     informs the obligor that substantial compliance with the conditions of the bond was performed and that, for cash bonds, the deposit will be refunded.
                    <SU>18</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>18</SU>
                         Form I-391 (rev. Mar. 2023).
                    </P>
                </FTNT>
                <PRTPAGE P="538"/>
                <P>
                    4. 
                    <E T="03">Bond Breach Reconsideration.</E>
                     Form 71-042, 
                    <E T="03">Notice of Bond Breach Reconsideration Decision,</E>
                     rescinds a bond breach issued in error and informs the obligor either that the bond has been reinstated or cancelled.
                    <SU>19</SU>
                    <FTREF/>
                     For surety bonds that have been breached, ICE issues an invoice with information about the government's collection processes to satisfy the requirement to notify the co-obligors of the demand for payment under 31 CFR 901.2. ICE may issue a demand letter to the co-obligors summarizing the facts supporting the breach determination and attaching documents that support the determination that a debt is owed.
                </P>
                <FTNT>
                    <P>
                        <SU>19</SU>
                         Form 71-042 (rev. Jan. 2013).
                    </P>
                </FTNT>
                <P>In April 2023, ICE launched the Cash Electronic Bonds Online System (CeBONDS), a web-based system that provides the public an automated, secure online capability to verify bond information and post cash immigration bonds for detained noncitizens. CeBONDS also provides the capability for ICE to serve electronic notices to cash bond obligors who consent to receive bond notices electronically. CeBONDS has allowed obligors to initiate and process immigration bonds online without having to visit an ICE office in person, making the process more convenient for the public. Currently, the electronic service capability is being further developed and finalized, and the system has not electronically served bond notices to obligors yet.</P>
                <HD SOURCE="HD2">E. Interim Final Rule</HD>
                <P>
                    On August 8, 2023, DHS published the IFR, which authorized ICE to serve bond-related notices electronically to obligors who consent to electronic delivery of service.
                    <SU>20</SU>
                    <FTREF/>
                     DHS received 37 public comments before the close of the comment period. Most of the comments received do not focus on the limited scope of the rule, which only authorizes ICE to serve bond related notices electronically to consenting recipients. Rather, commenters expressed opposition to ICE's CeBONDS, primarily in the context of confirming bond information and posting payments electronically, and voiced concerns about the system's reliability and accessibility. DHS considered all public comments before issuing this final rule. A discussion of the public comments and responses follows later in this preamble.
                </P>
                <FTNT>
                    <P>
                        <SU>20</SU>
                         Immigration Bond Notification, 88 FR 53358 (Aug. 08, 2023); 8 CFR 103.6(g)-(h).
                    </P>
                </FTNT>
                <HD SOURCE="HD2">F. Changes From the Interim Final Rule</HD>
                <P>The IFR amended regulations to allow ICE to serve bond-related notices (such as Form I-340, Form I-391, Form 71-042, or Form I-323) electronically to obligors who consent to electronic delivery of service; these notices may pertain to delivery, order of supervision, or voluntary departure immigration bonds, such as bond breach or cancellations, and other immigration bond related notices. 8 CFR 103.6(g)-(h). As discussed in the comment and response sections below in this final rule, DHS has considered the input provided by commenters in response to the IFR. The changes from the IFR amend typographical errors, update terminology for accuracy, and restructure regulatory text for clarity and consistency in 8 CFR 103.6(g) and 8 CFR 103.6(h). This final rule introduces no substantive changes.</P>
                <HD SOURCE="HD3">Technical and Clarifying Changes</HD>
                <P>In this final rule, DHS is updating the terms “notice” and “notification,” “receipt” to “proof of service,” and “obligor” to “bond obligor.” DHS is updating “notification” to “notice,” to clarify the difference between the two. While the IFR used the terms “notification” and “notice” interchangeably, this final rule provides clarity and differentiation between the terms. “Notification” refers to the email that alerts the obligor to log into the CeBONDS system to view the bond notice. Notifications do not include any substantive or personal information. “Notice” refers to the forms related to bonds that are issued and served by ICE via CeBONDS. Opening the notice in the ICE bond system will constitute proof of service. Similarly, “receipt” is updated to “proof of service” which better describes when an obligor opens a notice in CeBONDS.</P>
                <HD SOURCE="HD1">II. Discussion of Public Comments on the Interim Final Rule</HD>
                <HD SOURCE="HD2">A. Summary of Public Comments</HD>
                <P>DHS received 37 public comments from a variety of persons and entities, including businesses, nonprofits, advocacy organizations, and individual members of the public. DHS reviewed all the public comments received in response to the IFR and addresses those comments in this final rule. Commenters primarily expressed concern about CeBONDS's technical issues, processing times, and potential implications on a noncitizen's liberty. DHS addresses these issues in more detail below. DHS reiterates that receiving bond-related notices electronically is entirely voluntary and ICE will continue to send notices by mail if ICE cannot confirm proof of service.</P>
                <P>
                    Several comments are concerned with technical issues related to posting bond payments electronically and concerns on whether the in-person payment option would remain available based on the promulgation of the IFR. The IFR and this final rule authorizes ICE to electronically serve immigration bond notices after a noncitizen has been released from custody following a bond payment by the obligor.
                    <SU>21</SU>
                    <FTREF/>
                     This final rule does not change the obligor's option to post bonds in-person, nor the requirements of the obligor as listed in Form I-352.
                </P>
                <FTNT>
                    <P>
                        <SU>21</SU>
                         In instances where the noncitizen has been granted voluntary departure by an IJ or the BIA, a noncitizen may not necessarily be in detention and may be posting bond to satisfy the requirements for the relief.
                    </P>
                </FTNT>
                <P>Some commenters requested additional time for the public to comment. DHS reviewed all the timely-filed public comments received in response to the IFR and addressed relevant comments in this final rule, grouped by subject. DHS received several comments on subjects unrelated to electronic bond notices that are outside the scope of the IFR. DHS has not individually responded to these comments but has summarized out of scope comments and provided a general response.</P>
                <HD SOURCE="HD2">B. Comments Expressing Support</HD>
                <P>
                    <E T="03">Comment:</E>
                     Commenters expressed their appreciation for DHS's efforts to improve the efficiency of the immigration bond process by modernizing the bond payment system. One commenter stated, “[i]f the system in this interim rulemaking helps build and promote a fair and efficient immigration process through equitable and impartial monitoring and enforcement it would be beneficial to the public.” This commenter recommended that this rulemaking should be considered for approval once the agency has reviewed all the public comments received.
                </P>
                <P>
                    <E T="03">Response:</E>
                     DHS appreciates the support from the commenters. DHS seeks to make it easier for the public to connect with ICE and improve customer satisfaction. Authorizing ICE to serve notices electronically to consenting obligors may reduce processing times and decrease the probability of lost or missing information. Specifically, serving electronic immigration bond notices will likely increase efficiency and reduce the cost of mail delivery by providing electronic transmission of bond notices. DHS appreciates these 
                    <PRTPAGE P="539"/>
                    commenters' support for the IFR and did not make any changes in this final rule based on the comments.
                </P>
                <HD SOURCE="HD2">C. Comments Expressing Opposition</HD>
                <P>
                    <E T="03">Comment:</E>
                     The majority of commenters expressed general opposition to the rule, including some comments that were outside the scope of this rule. Some commenters stated that the CeBONDS system is inaccessible, dysfunctional, and inconsistently implemented across ICE facilities. Other commenters stated the rule imposes various hurdles to using CeBONDS and that the lack of accessibility and transparency of CeBONDS hinders the effectiveness of the system. Commenters stated that CeBONDS needs to be user friendly, accessible, simple, and transparent. Commenters suggested DHS narrow the issue of notifications until CeBONDS accessibility and dysfunctional issues are addressed or defer the rule, so the system does not further perpetuate these challenges.
                </P>
                <P>
                    <E T="03">Response:</E>
                     The IFR did not implement CeBONDS. Rather, the rule allows ICE to serve bond notices (demand notices, bond breach, bond cancellation, and other bond notices) electronically to obligors who consent to receive electronic service, which is currently one of many functions of CeBONDS. Electronic service may reduce burdens, cost, and increase convenience to the public. Electronic notices provide expedited delivery and improve recordkeeping by tracking when notifications are sent and read. ICE will continue to make improvements to CeBONDS to decrease any technical issues experienced by users.
                </P>
                <HD SOURCE="HD2">D. Administrative Procedure Act (APA)</HD>
                <P>
                    <E T="03">Comment:</E>
                     Commenters stated ICE failed to provide timely and consistent information on its intent to fully transition to CeBONDS prior to implementing the rule.
                    <SU>22</SU>
                    <FTREF/>
                     Commenters pointed out that the IFR stated “ICE ERO is currently developing CeBONDS.” 
                    <E T="03">See</E>
                     88 FR at 53360. One commenter stated that ICE did not provide the public with sufficient notice and an opportunity to comment by setting the same date for the rule's effective date and the deadline for public comment. The commenter continued by stating this does not align with the APA which “typically requires agencies to give the public [g]eneral notice of [a] proposed rulemaking by publication in the 
                    <E T="04">Federal Register</E>
                    , and then to provide interested persons an opportunity to participate in the rule making through submission of written data, views, or arguments regarding the proposed rule.” 
                    <SU>23</SU>
                    <FTREF/>
                     Numerous commenters requested DHS provide more time for the public to review and comment on the rule and its objectives, and then convene a public hearing.
                </P>
                <FTNT>
                    <P>
                        <SU>22</SU>
                         
                        <E T="03">See</E>
                         5 U.S.C. 553(b)-(c); 
                        <E T="03">see also, e.g., Pickus</E>
                         v. 
                        <E T="03">U.S. Bd. of Parole,</E>
                         507 F.2d 1107, 1113 (D.C. Cir. 1974) (inapplicability of notice-and-comment requirement to agency actions “ `relating to practice or procedure' means technical regulation of the form of agency action and proceedings . . . [and] should not be deemed to include any action which goes beyond formality and substantially affects the rights of those over whom the agency exercises authority”).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>23</SU>
                         
                        <E T="03">Dep't of Educ.</E>
                         v. 
                        <E T="03">Brown,</E>
                         600 U.S. 551, 557-58 (2023).
                    </P>
                </FTNT>
                <P>
                    <E T="03">Response:</E>
                     The IFR and this final rule did not implement CeBONDS. This rule only authorizes an additional optional procedure for ICE to serve bond related notices (demand notices, bond breach, bond cancellation, and other bond notices) to obligors who consent to receive those notices electronically. 
                    <E T="03">See</E>
                     8 CFR 103.6(g)-(h). Neither DHS nor ICE are removing or limiting any of the current methods of service found in 8 CFR 103.8(a)(1) or (2). For these reasons, DHS believes that these changes are procedural in nature, improve the effectiveness and efficiency of agency operations, and do not alter substantive rights. Therefore, because the IFR and this final rule are procedural, notice and opportunity for public comment are not required by the APA. 
                    <E T="03">See</E>
                     5 U.S.C. 553(b)(A). DHS nevertheless invited the public to comment on the IFR and considered all timely-filed comments submitted during the 30-day public comment period.
                </P>
                <P>DHS believes the 30-day comment period was sufficient to allow for meaningful public input as evidenced by the 37 timely-filed public comments received. The IFR stated that “[c]omments providing the most assistance to DHS will reference a specific portion of the IFR, explain the reason for any recommended change, and include the data, information, or authority that supports the recommended change.” Commenters generally did not explain in their submissions what additional issues they would raise during a longer comment period or what issues would be deliberated during a public hearing after a longer comment period, but the number of comments—as well as their breadth—reflects an adequate consideration of issues during the comment period. Additionally, commenters primarily focused on the CeBONDS system, its capability and functionality, rather than the actual regulatory amendments on electronic service. In short, there is no indication that the comment period was insufficient.</P>
                <P>
                    Notably, the APA does not require a specific comment period length, 
                    <E T="03">see</E>
                     5 U.S.C. 553(b), (c), and although Executive Orders 12866 and 13563 recommend a comment period of at least 60 days, a 60-day period is not required. DHS is not aware of any case law holding that a 30-day comment period is categorically insufficient. Indeed, some courts have found 30 days to be a reasonable comment period length. For example, the D.C. Circuit has stated that, although a 30-day period is often the “shortest” period that will satisfy the APA, such a period is generally “sufficient for interested persons to meaningfully review a proposed rule and provide informed comment,” even when “substantial rule changes are proposed.” 
                    <E T="03">Nat'l Lifeline Ass'n</E>
                     v. 
                    <E T="03">FCC,</E>
                     921 F.3d 1102, 1117 (D.C. Cir. 2019) (citing 
                    <E T="03">Petry</E>
                     v. 
                    <E T="03">Block,</E>
                     737 F.2d 1193, 1201 (D.C. Cir. 1984)). Here, because the IFR did not require a public comment period under the APA and expanded service options for obligors, DHS believes the 30-day comment period was sufficient for interested persons to meaningfully review the rule and provide informed comment.
                </P>
                <HD SOURCE="HD2">E. Privacy</HD>
                <P>
                    <E T="03">Comment:</E>
                     Some commenters stated their preference to pay bonds in person and receive bond notices via mail because they are concerned about the security of their personal information. One commenter stated ICE has not published a Privacy Impact Assessment (PIA) to address how obligors' information entered into CeBONDS will be protected. The commenter highlighted ICE website's claim that it had “initiate[d] the Bonds Management Program PIA in January 2023.” 
                    <SU>24</SU>
                    <FTREF/>
                     However, the commenter was unable to locate the PIA information and assumes that ICE has not conducted a stand-alone PIA for CeBONDS. Further, the commenter stated that the documents ICE claims to have updated regarding privacy risks fail to indicate such updates. The commenter asserts the public has not been informed about the privacy impact of ICE's collection of information from obligors and ICE's statements about the updates are misleading.
                </P>
                <FTNT>
                    <P>
                        <SU>24</SU>
                         U.S. Immigration and Customs Enforcement, 
                        <E T="03">Post a Bond, https://www.ice.gov/detain/detention-management/bonds</E>
                         (last visited Sept. 6, 2023).
                    </P>
                </FTNT>
                <P>
                    <E T="03">Response:</E>
                     Commenters' comments are focused on the obligor's personal information entered in CeBONDS rather than the purpose of the rule, which allows ICE to serve bond-related notices 
                    <PRTPAGE P="540"/>
                    to obligors who consent to receive those notices electronically. 
                    <E T="03">See</E>
                     8 CFR 103.6(g)-(h).
                </P>
                <P>
                    Prior to the deployment of CeBONDS in 2023, the Bond Management Information System/Web Version (BMIS Web) 
                    <SU>25</SU>
                    <FTREF/>
                     and Bonds Online System (eBONDS) PIA were updated to assess the privacy risks associated with CeBONDS and to document ICE's privacy protections for the collection and maintenance of information on noncitizens and obligors involved in the processing and posting of immigration bonds.
                    <SU>26</SU>
                    <FTREF/>
                     Separately, due to the expansion of online bond posting capabilities, ICE initiated the Bonds Management Program PIA in January 2023 and will provide the PIA to the public once it is available.
                    <SU>27</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>25</SU>
                         U.S. Immigration and Customs Enforcement, 
                        <E T="03">Privacy Impact Assessment Update for the Bond Management Information System</E>
                         (Jan. 19, 2011), 
                        <E T="03">https://www.dhs.gov/sites/default/files/publications/ice-pia-005-v2-bmis-web-2011.pdf</E>
                        .
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>26</SU>
                         U.S. Immigration and Customs Enforcement, 
                        <E T="03">Privacy Impact Assessment Update for the Bonds Online System (eBONDS) Phase Two</E>
                         (Jan. 24, 2013), 
                        <E T="03">https://www.dhs.gov/sites/default/files/publications/ice-pia-008-a-ebonds-2013.pdf</E>
                        .
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>27</SU>
                         U.S. Immigration and Customs Enforcement, 
                        <E T="03">Post a Bond, What steps has ICE taken to ensure CeBONDS provides data privacy and security as part of its processes?</E>
                         (last updated Sept. 17, 2024), 
                        <E T="03">https://www.ice.gov/detain/detention-management/bonds</E>
                        .
                    </P>
                </FTNT>
                <HD SOURCE="HD2">F. Consent to Electronic Service</HD>
                <P>
                    <E T="03">Comment:</E>
                     Commenters stated their confusion regarding the option to opt-in to receive electronic bond notifications. Commenters stated the IFR implies obligors may choose to consent to receive notifications, which contrasts with obligors' requirement to consent to receive notifications as a prerequisite to use CeBONDS. One commenter stated that state laws, rules, and regulations can differ on how individuals “opt in or out” of receiving electronic mail. Commenters urged ICE to clearly convey to the public, obligors, and noncitizens the methods ICE will use to provide notifications about noncitizens conditions of release and what will constitute consent to electronic service.
                </P>
                <P>
                    <E T="03">Response:</E>
                     This rule authorizes ICE to serve bond related notices to obligors who consent to receive those notices electronically. 
                    <E T="03">See</E>
                     8 CFR 103.6(g)-(h). ICE will not utilize the electronic system to serve notices to obligors who have not consented to receiving electronic notices. As updates are made to the CeBONDS system, ICE will provide further guidance to users. ICE will add specific information that obligors may opt in to communicate electronically and consent to electronic delivery of bond notices and any other bond-related notices via CeBONDS and by electronic mail. Consent will mean that the obligor agrees to check their CeBONDS account, alerts, messages, and associated email to stay apprised of the important notices and information.
                </P>
                <P>
                    In instances where the obligor fails to open a notice electronically after receiving the notification and the system cannot confirm electronic proof of service, the CeBONDS system will generate a new notice that will be sent via mail as required by the regulations. If the obligor's address (mailing or email) changes after posting a bond, the obligor must promptly update contact information in CeBONDS or submit Form I-333, 
                    <E T="03">Obligor Change of Address,</E>
                     to ICE with the obligor's new address.
                </P>
                <P>
                    As noted in the IFR and in this final rule, an obligor must agree to receive bond related notices electronically. 
                    <E T="03">See</E>
                     8 CFR 103.6(g)-(h). The option to “opt in” to receive immigration bond related notices does not vary from state to state. Federal regulations, specifically in this rule, are not subject to state “opt in” laws or rules.
                </P>
                <P>If the obligor does not wish to post a bond or receive bond notices electronically, the obligor may still post the bond in-person at an ICE office and receive the notice by mail. In these instances, contact the nearest ICE office for guidance.</P>
                <P>General service of electronic notifications or notices to the noncitizen is outside the scope of this rule as this rule specifically pertains to electronic service of bond notices to the obligors.</P>
                <HD SOURCE="HD2">G. Proof of Electronic Service</HD>
                <P>
                    <E T="03">Comment:</E>
                     Commenters stated the action of logging into CeBONDS should not constitute proof of receipt of the notification and that clicking a link or opening a document through CeBONDS does not guarantee that the individual accessing the notice understands its contents. Commenters explained CeBONDS can and does fail, logging obligors out at random—regardless of whether the obligor has seen the notice. Additionally, commenters stated the mechanism to validate receipt of service is insufficient. One example raised by a commenter outlined that, if an obligor used their work email address to log into CeBONDS and later departs from that place of employment, there is no way to validate receipt of the bond notice. Commenters expressed concern and questioned how ICE will track unopened electronic notifications in CeBONDS and verify users' email addresses.
                </P>
                <P>Commenters requested ICE inform the public about how it intends to track notifications and provide the public a meaningful chance to voice its preferences, to ensure related accountability from ICE. Commenters stated the IFR does not specify a timeline when ICE will reissue a bond notification via mail to the CeBONDS users who do not open the notification. Furthermore, the IFR does not state if ICE will take action pending someone's receipt of paper-based notifications. One commenter stated that DHS and ICE should provide clear procedures that ensure notifications to CeBONDS users and confirm receipt of notification prior to engaging in adverse actions towards the obligor and noncitizen. Another commenter suggested adding a checkbox to the confirmation message.</P>
                <P>A commenter stated CeBONDS financially impacts obligors, as these events can determine whether ICE will return funds paid as bonds. If an obligor fails to receive timely notification of a breach, their opportunity to appeal the bond breach determination is limited, which may lead to the forfeiting of the bond amount.</P>
                <P>
                    <E T="03">Response:</E>
                     The ability to confirm delivery of electronic notices is essential to this rule which authorizes ICE to serve electronic notices. Importantly, an obligor merely logging into the CeBONDS account in and of itself does not constitute proof of electronic service. While some commenters voiced concerns about the technical issues, such as the system logging obligors out at random, the obligors can log back in to review these notices again at any time, as they will continue to be available in their CeBONDS accounts. As described further below, CeBONDS captures detailed information regarding the actions executed through the system and the electronic process to satisfy the requirements for electronic service. Electronic notices (Form I-340, Form I-391, Form 71-042, or Form I-323) are sent to the obligor's CeBONDS account. When the notices are sent to the obligor's CeBONDS account, a separate email notification is generated and sent to the obligor's email address on file to notify the obligor to log into their CeBONDS account. ICE captures a timestamp of these actions in the CeBONDS system—logging specifically the month, day, year, hour, minute, and ante or post-meridiem when the notices are sent to the obligor's CeBONDS account—
                    <E T="03">e.g.,</E>
                     “Form I-340 Sent to Obligor.” When the obligor opens the notice in CeBONDS, the system will track the action that the obligor has opened the notice—“Form I-340 Viewed by Obligor”—and log the timestamp. This event constitutes the point in time when the obligor received service of the notice. At each step of this process, CeBONDS tracks the actions 
                    <PRTPAGE P="541"/>
                    taken in the system by all users, including the actions of the obligor.
                </P>
                <P>
                    If the obligor does not open the notice, a new notice will be sent via mail to the last known address. 
                    <E T="03">See</E>
                     8 CFR 103.6(g) and (h) (specifying the backup method of service as certified mail for demand notices and ordinary mail for breach, bond cancellation, and other bond notices). During this time, when the notice is sent electronically and then via mail, generally, there is no impact to the noncitizen, as ICE will not take any custody action until service is completed and there is proof of service. Generally, ICE will confirm proof of service electronically or via certified mail for demand notices prior to taking any actions against the noncitizen. If the obligor's address (mailing or email) changes after posting a bond, the obligor must promptly update their address information in CeBONDS or submit Form I-333, 
                    <E T="03">Obligor Change of Address,</E>
                     to ICE with the obligor's new address. If the obligor does not update their address and contact information, ICE will use the last updated address to serve the notice via mail.
                </P>
                <P>To the extent that the commenters express concerns that the information about this timeline was not set forth in detail in the IFR, ICE did not provide a specific timeline for when it will reissue a bond notice via mail because ICE is continuously improving the system and implementing updates to better serve the public needs and improve communication. Therefore, as ICE seeks to implement various updates, this may impact the timeframe when a notice is mailed to the obligor. As technology improves, or related updates are made to CeBONDS, the information on the ICE website will also be updated for stakeholders' awareness. ICE notes, however, that the IFR specified that if ICE could not confirm proof of service of electronic notice, ICE would reissue the notices by an appropriate mailing method. 8 CFR 103.6(g)-(h). Additionally, as stated throughout this rule, if an obligor receives a notice electronically or by mail, and does not understand the content of the notice, the obligor can contact the nearest ICE office for guidance irrespective of how the notice was served.</P>
                <P>There is no data to suggest that CeBONDS will result in an increase in bond breaches. DHS believes the use of electronic notices may improve notification delivery time because these specific bond notices cannot be lost through physical mail, and obligors will receive a notification immediately via electronic means. Furthermore, obligors have the option to print or view the notice in CeBONDS at any time. This may reduce the possibility that an obligor will not be able to appeal a bond breach determination in time, because there is less likelihood of potential delays or errors associated with electronic mail service which would otherwise lead to the forfeiting of the bond amount.</P>
                <HD SOURCE="HD2">H. Governmental Actions and Interference With Constitutionally Protected Property Rights</HD>
                <P>
                    <E T="03">Comment:</E>
                     Commenters raised concerns that the rule implicates governmental takings of private property. A commenter indicated that the inefficiencies and delays caused by CeBONDS during the electronic payment process impacted property interests of the detained noncitizens and the obligors' bond funds. Another commenter stated that CeBONDS users' inability to access information through the system could result in governmental takings of bond payments. As such, the commenter disagreed with DHS' determination that the rule did not cause a taking of private property or have taking implications under Executive Order 12630, 
                    <E T="03">Governmental Actions and Interference with Constitutionality Protected Property Rights</E>
                    . Specifically, a commenter pointed that CeBONDS financially impacts obligors, as the bond notices served electronically are associated with events that can determine whether ICE will return the paid bond funds. If obligors fail to receive timely bond notices, their appeal rights may be affected for breach notices, which could lead to the forfeiting of paid bonds. It could also lead to obligors not requesting a refund of the paid bond amounts. The commenter stated that “the potential increases in the Breached Bond Discretionary Fund (BBDF) are linked directly to the prospect of expanding immigration detention bed space, a system with a record of abuses and medical neglect.” Furthermore, the commenter referenced a report indicating that ICE held more than $200 million in unclaimed bond funds in 2018.
                    <SU>28</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>28</SU>
                         Stanford Law School Immigrants' Rights Clinic et al., 
                        <E T="03">Following the Money: New Information about the Federal Government's Billion Dollar Immigration Detention and Bond Operations</E>
                         (May 9, 2019), 
                        <E T="03">https://law.stanford.edu/publications/following-the-money-new-information-about-the-federal-governments-billion-dollar-immigration-detention-and-bond-operations/</E>
                        .
                    </P>
                </FTNT>
                <P>
                    <E T="03">Response:</E>
                     DHS does not agree with commenters' concerns that this rule would lead to the taking of private property or have taking implications under Executive Order 12630. This rule narrowly provides a regulatory framework that allows ICE to serve certain bond notices electronically for obligors who consent to electronic service. 
                    <E T="03">See</E>
                     8 CFR 103.6(g)-(h). To confirm proof of service of an electronic bond notice, the system captures the exact date and time that the notices were opened. Notably, the rule provides safeguards in instances where electronic service is not confirmed. ICE must effectuate service via mail, which would be the equivalent method of service for an obligor who opts out of electronic service. Thus, an obligor who consented to electronic service would be in the same procedural posture as an obligor who opts to receive service by mail, as they would have the same due process rights and appellate opportunities. Accordingly, the rule itself would not lead to any changes in the course of action that would normally follow after the bond notices have been served by mail. In this aspect, the rule would have no impact on property rights nor implications of any governmental takings.
                </P>
                <P>There is no data to suggest that CeBONDS will result in an increase in bond breaches. DHS believes the use of electronic service may improve delivery time because these specific bond notices cannot be lost through physical mail, and obligors will receive a notification immediately via electronic means. This benefit is expected to reduce the likelihood that an obligor will be unable to appeal a bond breach determination in time, which would otherwise lead to the forfeiting of the bond amount.</P>
                <P>DHS appreciates the concerns raised by the commenters. The IFR and this final rule do not impact an individuals' ability to receive notices traditionally through the U.S. Postal Service, but rather authorizes ICE to issue bond-related notices to obligors electronically should obligors consent to receive them. That said, DHS believes that authorizing this electronic system will improve delivery time, thereby reducing the likelihood that an obligor will be unable to appeal a bond breach determination, which may lead to the forfeiting of the bond amount.</P>
                <HD SOURCE="HD2">I. Cost Analysis</HD>
                <P>
                    <E T="03">Comment:</E>
                     A commenter indicated that ICE's cost-analysis for this rule is deficient because the cost-analysis fails to address at least two critical issues. 
                    <E T="03">See</E>
                     88 FR at 53 366-69. First, the cost-analysis is silent about any investment by ICE to ensure that the proposed framework for notifications to CeBONDS users will comply with the requirements of the Rehabilitation Act 
                    <PRTPAGE P="542"/>
                    of 1973.
                    <SU>29</SU>
                    <FTREF/>
                     Second, the cost-analysis does not include any costs that the notification-scheme may pose to CeBONDS users. The commenter urges ICE to clarify to the public whether CeBONDS users may be subject to any such costs. A commenter stated CeBONDS financially impacts obligors, as these events can determine whether ICE will return funds paid as bonds. If an obligor fails to receive timely notification of a breach, their opportunity to appeal the bond breach determination is limited, which may lead to the forfeiting of the bond amount.
                </P>
                <FTNT>
                    <P>
                        <SU>29</SU>
                         Rehabilitation Act of 1973, 29 U.S.C. 701 
                        <E T="03">et seq.</E>
                    </P>
                </FTNT>
                <P>One commenter stated that ICE facilities require travel tickets for detained noncitizens before being released but if the noncitizen is not released on the scheduled day, the obligors would incur additional travel costs with having to travel to the ICE facility again and prolong the noncitizen's detention.</P>
                <P>
                    <E T="03">Response:</E>
                     Regarding the first point, section 508 of the Rehabilitation Act of 1973 requires that when Federal departments and agencies develop, procure, maintain, or use electronic and information technology, they ensure that the electronic and information technology is accessible to individuals with disabilities who are Federal employees, applicants for employment, or members of the public. ICE ensures policies meet 508 compliances. ICE accessibility policies and procedures ensure all employees, contractors, and members of the public, regardless of any disability, have access to, and use of, all ICE Information and Communication Technology. CeBONDS, which utilizes electronic bond notifications outlined in this final rule, was tested by DHS for section 508 compliance on July 17, 2023, and found to be compliant.
                    <SU>30</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>30</SU>
                         
                        <E T="03">See</E>
                         ICE Directive 8014.1, 
                        <E T="03">Section 508 Accessibility</E>
                         (Mar. 3, 2023), 
                        <E T="03">https://www.ice.gov/doclib/foia/policy/8014.1_Section508_Accessibility.pdf</E>
                        .
                    </P>
                </FTNT>
                <P>To the extent that the commenter references travel costs associated with the noncitizen's release, this comment pertains to the costs associated with posting a bond. It does not pertain to costs related to implementing this rule for electronic service of bond notices, which are applicable at later stages after the noncitizen has already been released on bond.</P>
                <P>The IFR authorized ICE to serve bond-related notices electronically to obligors who consent to receiving those notices electronically. DHS only accounted for the impacts to create an online account and noted that there can be additional technology-related costs for obligors without access to the internet. Obligors who consent to electronic service of notices will receive those notices without charge.</P>
                <P>Finally, DHS believes that authorizing electronic service will improve the timely delivery of notices, thereby reducing the likelihood that an obligor will be unable to appeal a bond breach determination, which may lead to the forfeiting of the bond amount.</P>
                <HD SOURCE="HD2">J. Family Impact</HD>
                <P>
                    <E T="03">Comment:</E>
                     Commenters stated DHS failed to examine the rule's implications on the mental, financial, and well-being of families. Specifically, a commenter stated DHS did not appraise the Treasury and General Government Appropriations Act, in which agencies assess the impact of proposed agency actions on the well-being of a family.
                    <SU>31</SU>
                    <FTREF/>
                     The commenter stated that ICE must provide notifications to CeBONDS users that contain critical information about the posting or status of an immigration bond. By its very nature, such information, and its present inaccessibility to many CeBONDS users, stand to have significant impacts on any family within the United States with a relative who is subject to an immigration bond. One commenter stated that ICE should explain why it believes this rule would not impact the well-being of a family.
                </P>
                <FTNT>
                    <P>
                        <SU>31</SU>
                         Commenter cited to Actions—H.R.4328—105th Congress (1997-1998): Omnibus Consolidated and Emergency Supplemental Appropriations Act, 1999, H.R.4328, 105th Cong. (1998), 
                        <E T="03">https://www.congress.gov/bill/105th-congress/house-bill/4328/actions</E>
                        .
                    </P>
                </FTNT>
                <P>
                    <E T="03">Response:</E>
                     DHS concluded that the rule does not have an impact on family-being within the meaning of section 654 of the Treasury and General Government Appropriations Act of 1999. However, the comments do not focus on the rule which allows ICE the ability to serve electronic bond notices to obligors who opt-in to receive those notifications. The rule allows obligors to consent to electronic service, at their discretion, and provides a backup procedure of service by mail. 
                    <E T="03">See</E>
                     8 CFR 103.6(g)-(h).
                </P>
                <P>
                    For obligors who consent to electronic notifications, they will receive an alert to log into their CeBONDS account. No personal information is included in the notification, but it simply alerts the obligor to log into CeBONDS. Electronic notices are served to only obligors who consent to receive those notifications. As discussed in Section II., G. 
                    <E T="03">Proof of Service,</E>
                     CeBONDS incorporates a timestamp when an obligor views the notice in the system. Viewing of the notice by the obligor constitutes service of the notice. At each step of this process, CeBONDS tracks all user actions taken in the system, including the actions of the obligor.
                </P>
                <P>
                    If the obligor does not open the notice, then DHS cannot confirm proof of service of the notice. Therefore, a new notice will be sent via mail to the last known address. 
                    <E T="03">See</E>
                     8 CFR 103.6(g)-(h). During this time, when the notice is served electronically and then via mail, DHS does not anticipate that there will be any impact to the noncitizen.
                </P>
                <P>Given the narrow regulatory framework for this rule and the safeguards in place, DHS does not believe that the rule pertaining to an alternate method of service would create any adverse impact on families. There is no data indicating that there is a correlation between adding another method of service and any negative effects to families. DHS is making no changes to its assessment of the impact of the regulation on families in this final rule.</P>
                <HD SOURCE="HD2">K. Inequality and Inaccessibility</HD>
                <HD SOURCE="HD3">1. General</HD>
                <P>
                    <E T="03">Comment:</E>
                     Commenters raised concerns that CeBONDS disproportionately impacts vulnerable populations including those with limited English proficiency, mental impairments or competency issues, limited technological literacy, physical disabilities, health problems or need of medical attention, people of color, indigenous groups, low-income and -resources, and limited access to computers and internet, financial establishments, and others. Commenters explained that using CeBONDS specifically burdens the populations who have limited English proficiency, lack the access to computers with internet, or lack online bank accounts. The commenters state that these burdens perpetuate inequalities toward those with low-incomes and increase racial disparities and injustices because most detained noncitizens are low-income and people of color. The commenters expressed that lack of income and knowledge of the CeBONDS system will impede noncitizens from receiving official immigration bond documents. Commenters suggested ICE preserve the option of posting immigration bonds in person to facilitate payment accessibility for everyone, irrespective of race or income level.
                </P>
                <P>
                    <E T="03">Response:</E>
                     DHS recognizes there may be difficulties faced by vulnerable populations navigating the immigration process due to various factors. This rule 
                    <PRTPAGE P="543"/>
                    authorizes ICE to serve bond-related notices electronically to obligors who consent to electronic delivery of service and is not dependent on how CeBONDS operates for posting bonds. The IFR and this final rule provide a regulatory framework for obligors who consent to electronic service, at their discretion, and provide a backup procedure of service by mail. 
                    <E T="03">See</E>
                     8 CFR 103.6(g)-(h). The option to receive electronic service is offered to all obligors and does not change the existing process of in-person bond payment and service of bond notices. The scope of this rule is limited to electronic service of bond notices. While the rule does not implement CeBONDS, ICE will utilize this immigration bond delivery system to effectuate service to those obligors who consent to electronic service.
                </P>
                <P>DHS designed CeBONDS to alleviate various burdens on the public such as posting bonds at an ICE facility, provide bond information in real time, increase record keeping and tracking, and expediate delivery of immigration bond notices. CeBONDS serves as an additional alternative method for conducting transactions electronically to better serve the needs of obligors who face accessibility barriers and resource constraints and does not replace the current existing process for posting bonds and receiving notices.</P>
                <P>The Coronavirus disease (COVID-19) pandemic prompted a shift in certain ICE business processes and highlighted the need to develop online capabilities to mitigate the risks associated with person-to-person contact, especially for those with vulnerable health risks. CeBONDS provides the public with the online capability to make requests for bond information, update contact information, upload necessary documents to verify eligibility to post the bond, post cash immigration bonds electronically for eligible detained noncitizens, and receive bond notices electronically.</P>
                <P>
                    Obligors who are concerned with accessibility or other factors continue to have the option to post bonds in-person and receive notices by mail. As elaborated in the sections below, DHS includes additional options and alternatives for those with limited means and accessibility. Any obligor who has a question about posting a bond in person can contact the nearest ICE office for guidance. ICE will continue to work with obligors who want to pay bonds at an ICE office and provide obligors assistance in-person. ICE offices have access to an ICE-wide 24/7 language services contract for interpretation (oral), translation (written), and transcription (audio to text).
                    <SU>32</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>32</SU>
                         U.S. Immigration and Customs Enforcement, 
                        <E T="03">Language Access Information and Resources</E>
                         (last updated May 7, 2024), 
                        <E T="03">https://www.ice.gov/detain/language-access</E>
                        .
                    </P>
                </FTNT>
                <P>
                    Moreover, DHS has Department-wide policy directives to ensure nondiscrimination for individuals with disabilities served by DHS-conducted programs and activities. Consistent with the requirements of the Rehabilitation Act of 1973 and Department of Homeland Security Directives, CeBONDS was designed to be section 508 compliant. If the format of any material on its website or system interferes with an individual's ability to access the information due to an issue with accessibility caused by a disability as defined in the Rehabilitation Act, the user can contact the ICE Section 508 Coordinator for assistance.
                    <SU>33</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>33</SU>
                         U.S. Immigration and Customs Enforcement, 
                        <E T="03">Site Policies</E>
                         (last updated Aug. 6, 2024), 
                        <E T="03">https://www.ice.gov/site-policies#accessibility</E>
                        .
                    </P>
                </FTNT>
                <HD SOURCE="HD3">2. Language Barrier</HD>
                <P>
                    <E T="03">Comment:</E>
                     Commenters stated that noncitizens and obligors have difficulty navigating CeBONDS due to language barriers. Commenters stated the ICE landing page 
                    <SU>34</SU>
                    <FTREF/>
                     is only accessible in English and Spanish and therefore deters payment from those with limited English or Spanish proficiency or may force obligors to rely on third parties for payment putting them at risk of fraud.
                </P>
                <FTNT>
                    <P>
                        <SU>34</SU>
                         U.S. Immigration and Customs Enforcement, 
                        <E T="03">Post a Bond, Frequently Asked Questions, How to Pay a Bond?, https://www.ice.gov/detain/detention-management/bonds</E>
                         (last visited Aug. 25, 2023).
                    </P>
                </FTNT>
                <P>Commenters stated the failure to provide translation into the languages of greatest frequency violates DHS's obligations to provide equal access to speakers of other languages and suggests DHS increase accessibility. Another commenter urged DHS to include a requirement that DHS examine the feasibility of translating the website into languages of greatest frequency and ensure that a mechanism exists for people with limited English proficiency to pay bonds in person.</P>
                <P>
                    <E T="03">Response:</E>
                     DHS recognizes the importance of being able to communicate effectively with individuals, including those with Limited English Proficiency (LEP). However, the rule authorizes an additional procedure for ICE to serve bond related notices (demand notices, bond breach, bond cancellation, and other bond notices) to obligors who consent to receive those notices electronically. This regulation does not implement CeBONDS. Therefore, if CeBONDS is not a viable option, LEP individuals continue to have the option to visit an ICE office for assistance to post a bond.
                </P>
                <P>
                    Currently the CeBONDS landing page is available in English and Spanish.
                    <SU>35</SU>
                    <FTREF/>
                     From the Spanish landing page, obligors are able to select their preferred language from the drop-down menu in the web browser.
                    <SU>36</SU>
                    <FTREF/>
                     Furthermore, ICE offices have access to an ICE-wide 24/7 language services contract for interpretation and translation, and guidance and best practices materials for identifying LEP individuals and their primary language to secure the necessary interpretation and translation services for them. ICE offices are pursuing several initiatives to help promote communication with LEP individuals encountered at ICE offices functions.
                    <SU>37</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>35</SU>
                         U.S. Immigration and Customs Enforcement, 
                        <E T="03">Pagar una fianza ICE</E>
                         (last updated Sept. 17, 2024), 
                        <E T="03">https://www.ice.gov/es/fianzas</E>
                        .
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>36</SU>
                         
                        <E T="03">Is CeBONDS accessible to people with limited English proficiency?,</E>
                          
                        <E T="03">supra</E>
                         note 36.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>37</SU>
                         U.S. Immigration and Customs Enforcement, 
                        <E T="03">Language Access Plan</E>
                         (June 14, 2015), 
                        <E T="03">https://www.dhs.gov/sites/default/files/publications/ICE%20Language%20Access%20Plan.pdf</E>
                        .
                    </P>
                </FTNT>
                <P>
                    DHS is striving to improve CeBONDS' accessibility for those with language barriers and limited resources by providing an alternative language on its website, instructions to select their preferred language through their web browser, and equipping the offices with language access programs to communicate with obligors.
                    <SU>38</SU>
                    <FTREF/>
                     Consistent with Executive Order 13166, 
                    <E T="03">Improving Access to Services for Persons with Limited English Proficiency,</E>
                     and DHS 
                    <SU>39</SU>
                    <FTREF/>
                     and ICE's Language Access Plan,
                    <SU>40</SU>
                    <FTREF/>
                     DHS will continue to assess and consider ways to enhance the system to expand accessibility, including the possibility of adding languages.
                </P>
                <FTNT>
                    <P>
                        <SU>38</SU>
                         
                        <E T="03">Id.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>39</SU>
                         U.S. Department of Homeland Security, 
                        <E T="03">Language Access at the Department of Homeland Security</E>
                         (last updated Feb. 28, 2024), 
                        <E T="03">https://www.dhs.gov/language-access</E>
                        .
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>40</SU>
                         Language Access Plan, 
                        <E T="03">supra</E>
                         note 39.
                    </P>
                </FTNT>
                <P>
                    Although not all ICE forms are translated into languages most frequently used,
                    <SU>41</SU>
                    <FTREF/>
                     ICE is committed to ensuring that external LEP stakeholders (including members of the public who seek access to programs, and noncitizens who are subject to ICE 
                    <PRTPAGE P="544"/>
                    enforcement actions and/or are in ICE custody) have meaningful access to its programs, services, and activities by providing quality language assistance services in a timely manner. ICE will consider processes for enhancing language access services for programs and activities that include external stakeholders, provided that such processes do not unduly burden the Agency mission.
                </P>
                <FTNT>
                    <P>
                        <SU>41</SU>
                         To the extent that the commenter believes that DHS may be violating its obligations to provide equal access to speakers of other languages, DHS notes that Executive Order 13166, 
                        <E T="03">Improving Access to Services for Persons with Limited English Proficiency,</E>
                         65 FR 50121 (Aug. 11, 2000), “does not create any right or benefit, substantive or procedural, enforceable at law or equity by a party against the United States, its agencies, its officers or employees, or any person.” 
                        <E T="03">Id.</E>
                         at 50121-22. The commenter has not provided any specific citations to show that CeBONDS violates any Federal law.
                    </P>
                </FTNT>
                <HD SOURCE="HD3">3. Bank Account</HD>
                <P>
                    <E T="03">Comment:</E>
                     Commenters stated that obligors are financially limited and lack access to banking services (whether managed or traditional), which increases the difficulty to post bonds and prolongs detention. Some commenters stated, without evidence, that over 63 million adults in the United States have limited to no access to bank accounts and services and therefore cannot use web applications like CeBONDS. Commenters suggested DHS ensure that the process of posting bonds does not create financial hardship on obligors or noncitizens and consider that there are almost six million U.S. households in which no adult has a bank account.
                    <SU>42</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>42</SU>
                         Federal Deposit Insurance Corporation, 
                        <E T="03">2021 FDIC National Survey of Unbanked and Underbanked Households, https://www.fdic.gov/analysis/household-survey/index.html</E>
                         (last visited Aug. 25, 2023).
                    </P>
                </FTNT>
                <P>Commenters stated the lack of payment options impedes equal access to pay bonds and creates a two-tiered system: obligors with financial resources who can post bonds quickly and obligors without resources that will experience delays, denials, and confusion. Another commenter stated the coronavirus pandemic highlighted the inequalities and differences in access to things society otherwise deemed ubiquitous, such as the internet and bank accounts.</P>
                <P>Another commenter asserted that CeBONDS has associated higher fees than paying a bond with a money order.</P>
                <P>
                    Commenters stated their confusion in learning the components of bank wiring systems and routing numbers. To post bonds, obligors can use either Fedwire, a system for the electronic transfer of funds operated by the Federal Reserve Bank; or the Automated Clearing House (ACH), an electronic network of banks that allows the transfer of money from one account to the other.
                    <SU>43</SU>
                    <FTREF/>
                     These payment options require identification, access to a computer or smartphone with internet capabilities, and access to a financial institution. One commenter stated using ACH was complicated and prolonged the process almost two weeks compared to paying the bond at an ICE facility. Another commenter stated the ICE's Bond Management Handbook 
                    <SU>44</SU>
                    <FTREF/>
                     claims obligors can pay bonds in cash, 
                    <E T="03">i.e.,</E>
                     currency, money order, certified check, or cashier's check which does not require a bank account. The commenter added that obligors may prefer to pay bonds with cash at an ICE office instead of going to a bank and dealing with the Fedwire or ACH systems. Another commenter stated, without evidence, that most obligors do not have access to a local bank or bank accounts (managed or traditional) which increases the difficulty to post bonds and prolongs detention.
                </P>
                <FTNT>
                    <P>
                        <SU>43</SU>
                         U.S. Immigration and Customs Enforcement, 
                        <E T="03">Post a Bond, Frequently Asked Questions, How can I pay a bond if I have little to no access to banking services, internet, or computing devices?, https://www.ice.gov/detain/detention-management/bonds</E>
                         (last visited on Aug. 25, 2023).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>44</SU>
                         U.S. Immigration and Customs Enforcement, Enforcement and Removal Operations, 
                        <E T="03">Bond Management Handbook,</E>
                         23 (Aug. 19, 2014), 
                        <E T="03">https://www.ice.gov/doclib/foia/dro_policy_memos/eroBondManagementHandbook2018-ICFO-31476.pdf</E>
                        .
                    </P>
                </FTNT>
                <P>Another commenter suggested CeBONDS accept other payment methods that do not require a bank account.</P>
                <P>
                    <E T="03">Response:</E>
                     Commenters' comments are specific to payment of bonds rather than the authorization of ICE to serve bond notices to obligors who consent to receive those notices electronically.
                </P>
                <P>ICE will continue to work with obligors who walk into an ICE office to post bonds. Obligors who post bonds at an ICE office are not required to have access to banking services in order to post bonds on behalf of noncitizens. While cash is not accepted at an ICE office, obligors can post bonds using a cashier's check or money order which can be acquired without a bank account. Furthermore, money orders can be purchased in places other than financial entities. Nevertheless, this rule does not impact or change the current method of payment, process of payment, or acceptable forms of payment. This rule focuses on electronic service of bond notices to consenting obligors.</P>
                <P>
                    Obligors who prefer to post a bond using CeBONDS have the option to use either Fedwire or an ACH to post an immigration bond, both of which charge for the use of service, with fees ranging from $0.20 to $1.50 per transaction.
                    <SU>45</SU>
                    <FTREF/>
                     Separately, there are no fees associated with the use of the CeBONDS system.
                </P>
                <FTNT>
                    <P>
                        <SU>45</SU>
                         Federal Reserve Bank Services, 
                        <E T="03">FedNow Service 2024 Fee Schedule, www.frbservices.org/resources/fees/fednow-2024</E>
                         (last visited July 24, 2024).
                    </P>
                </FTNT>
                <P>
                    Obligors without access to banking services may use an immigration bond company to post a bond or work with community-based organizations across the country that assist with immigration bonds.
                    <SU>46</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>46</SU>
                         U.S. Immigration and Customs Enforcement, 
                        <E T="03">Post a Bond, Frequently Asked Questions, How can I pay a bond if I have little to no access to banking services, internet, or computing devices?</E>
                         (last updated Sept. 17, 2024), 
                        <E T="03">https://www.ice.gov/detain/detention-management/bonds</E>
                        .
                    </P>
                </FTNT>
                <HD SOURCE="HD3">4. Computer and Internet</HD>
                <P>
                    <E T="03">Comment:</E>
                     A majority of commenters stated that DHS is unreasonable and should not assume obligors and noncitizens have access to computers, smart phones, etc., with reliable internet especially for people of color and low-income communities. Although the administration pushes to expand internet access, a large majority of people still do not have internet access. Commenters stated over 42 million people across the United States lack access to broadband and access to computers varies widely according to income levels. Commenters stated that obligors and noncitizens do not have routine or readily available computers or the internet to check emails. This mechanism falls short of meaningful access to important information.
                </P>
                <P>A commenter stated obligors with limited financial resources may rely on public libraries for computer and internet access to use CeBONDS. Another commenter indicated the struggles of the U.S. public library system and the movement to increase reliance on technology when technological access facilitated through public libraries is decreasing across the country is terribly timed.</P>
                <P>One commenter requested clarification if the bond documents are electronic, how will obligors receive those notifications and documents without these resources? Commenters suggested DHS ensure bond payments be completed in person and require ICE to accept in-person payments.</P>
                <P>
                    <E T="03">Response:</E>
                     DHS does not expect this rule to prevent any individual from paying an immigration bond because the rule pertains to ICE's ability to send electronic bond notices to obligors who consent to receive those notifications.
                </P>
                <P>
                    DHS assessed the impacts to the affected populations, and considered whether bond obligors would face technology costs to utilize these services. There are a variety of means by which obligors can access internet services to receive electronic notifications, including the use of smart phones, personal computers, or community services that can provide those services. The cost of these are either low or no-cost, such as the use of libraries or free Wi-Fi services which are 
                    <PRTPAGE P="545"/>
                    publicly available across the United States.
                </P>
                <P>The use of electronic service is voluntary. If the obligor does not open the notice in CeBONDS, a new notice will be sent via certified mail for demand notices and via ordinary mail for any other bond-related notice pertaining to this rule ICE does not expect this rule to prevent any obligors from paying immigration bonds.</P>
                <HD SOURCE="HD2">L. Detention</HD>
                <HD SOURCE="HD3">1. Prolonged Detention</HD>
                <P>
                    <E T="03">Comment:</E>
                     Commenters raised concerns of prolonged detention for noncitizens who are granted bonds because CeBONDS lacks up-to-date information. Commenters stated that CeBONDS take days or weeks to process bond payments—making the release of a noncitizen unpredictable compared to in-person payment which are processed the same day along with the release of the noncitizen. Commenters stated that CeBONDS prolongs a noncitizen's release because payments are only accepted between 9 a.m. and 3 p.m. in the time zone of the facility where the noncitizen is detained.
                </P>
                <P>Another commenter asserted that ICE developed a one-size-fits-all approach to an issue that should be tailored to the needs of those who pay (often thousands of dollars) to secure the liberty of those detained.</P>
                <P>Some commenters described the impact of prolonged detention on the noncitizen's mental health, finances, and families without providing data. A commenter stated that noncitizens are losing large periods of their lives being detained in prison which makes it harder for the noncitizen to reintegrate into society. The commenter wrote that incarcerated individuals experience trauma from the prison system, other inmates, and the correctional officers, due to incredibly inhumane treatment.</P>
                <P>
                    <E T="03">Response:</E>
                     The rule authorizes ICE to serve bond-related notices (ICE Form I-340, ICE Form I-391, ICE Form 71-042, or ICE Form I-323) electronically to obligors, who consent to electronic service, that pertain to delivery, order of supervision, or voluntary departure immigration bonds, such as bond breach or cancellations, and other immigration bond related notices. 
                    <E T="03">See</E>
                     8 CFR 103.6(g)-(h).
                </P>
                <P>Bond-related notices applicable to this rule are issued to the obligor months or years after the bond was posted and when the noncitizen is not in custody. Any correlation between the posting of bonds via CeBONDS and release dates, if applicable, is expected to be de minimis. Bond-related notices to which this rule applies are issued to obligors after the bond has been accepted by ICE and the noncitizen is not in custody. When the obligor starts the process of posting a bond, there has already been a custody determination. ICE will review the bond to confirm the bond matches the custody determination and verify nothing prevents the bond from being posted. Additionally, ICE must verify the funds have been transferred to ICE for the bond amount. The process to notify the detention facility after a bond is approved is the same for all bond posting methods (in-person, eBONDS, CeBONDS) and is not the type of notice that is encompassed under the regulations at 8 CFR 103.6(g)-(h).</P>
                <P>
                    If the obligor does not open the notice, a new notice will be sent via mail to the obligor's last known address. 
                    <E T="03">See</E>
                     8 CFR 103.6(g)-(h). During this time, when the notice is served electronically and later via mail, there is no impact to the noncitizen. Generally, ICE will confirm proof of service electronically or via certified mail for demand notices prior to taking any actions.
                </P>
                <P>CeBONDS is updated with information in real time during the bond posting process. Since CeBONDS was deployed, about 10,537 bonds have posted. Of those posted bonds, less than 1 percent, or 680 posted bonds, had release dates of 2 or more days after a bond was posted. More than 99 percent, or more than 9,850 posted bonds, had release dates within 2 days. Based on this information, there is little evidence that the use of CeBONDS results in “days or weeks” of delay. DHS will continue to make improvements to CeBONDS and other sites to decrease technical issues experienced.</P>
                <HD SOURCE="HD3">2. Impact on Proceedings</HD>
                <P>
                    <E T="03">Comment:</E>
                     A commenter indicated that DHS' shift to electronic notifications through CeBONDS, a system that is flawed and still under development, would undermine the liberty interests of noncitizens eligible for release from detention and increase the number of cases on the immigration court's detained docket. The commenter noted that the bond notifications could impact the outcome of removal proceedings for individuals released on bond, including instances where the notices inform obligors to bring the noncitizen to important appointments, but the deficiencies in service result in a noncitizen's failure to appear.
                </P>
                <P>
                    <E T="03">Response:</E>
                     There is no indication that this rule on electronic service of certain limited bond notices would impact removal proceedings or the custody status after a noncitizen has been released. This rule provides a regulatory framework to allow ICE to serve certain bond notices electronically for obligors who consent to electronic service. Under the rule, if the electronic notification system fails, the obligor would receive service by mail, which would be the equivalent method of service for an obligor who opts out of electronic service. Given the safeguards, the rule itself would not lead to any changes on the course of action that would normally follow when the bond notifications have been served by mail. An obligor who consents to electronic service would be in the same procedural posture as an obligor who opts to receive service by mail, as they would have the same due process rights and appellate opportunities. In this aspect, there is no correlation between electronic service of bond notices and a noncitizen's removal proceeding or custody status.
                </P>
                <P>
                    DHS believes that the use of electronic notices could potentially improve notification delivery time because these specific bond notices cannot be lost through physical mail and service via electronic means is instantly effectuated. As described in Section II.G., 
                    <E T="03">Proof of Service,</E>
                     the system is designed to capture the date and time of the actions taken to effectuate electronic service—namely, when the notification is sent and when the notice is opened by the obligor. Thus, electronic notices could improve the likelihood of a noncitizens' appearance at ICE appointments and court appearances and reduce the likelihood that an obligor will be unable to appeal a bond breach determination in time.
                </P>
                <HD SOURCE="HD2">M. CeBONDS Instructions (In-Person and Online)</HD>
                <P>
                    <E T="03">Comment:</E>
                     Commenters stated the inconsistent information and lack of guidance provided by DHS and on the CeBONDS web page complicate an already complex and difficult process for obligors to pay a bond for the release of a noncitizen. Obligors are subjected to inconsistent policies and practices at offices which hinder their ability to use CeBONDS.
                </P>
                <P>
                    Commenters expressed that obligors may not understand whether there is an option to pay in person and urge DHS and ICE to clarify, publicize, and enforce this option. Commenters stated that CeBONDS was deployed without notice or guidance to the public or proper training to ICE staff which has caused a multitude of problems. Commenters stated that detention centers are operating under arbitrary 
                    <PRTPAGE P="546"/>
                    rules, taking up to several days to process bonds. One commenter described being asked to provide business cards and authorization letters, which are not qualifying documents. Another commenter experienced the inability of the ICE staff to provide next steps after ICE deemed a noncitizen “not releasable” despite the existence of a bond order, slow email responses from the general Helpdesk, and slow response times from local ICE offices processing bonds because bond processing is still constrained to specific local business hours.
                </P>
                <P>Commenters stated that ICE employees are unfamiliar with the CeBONDS and unable to answer routine questions or provide crucial information such as where the bond request is being handled. One commenter stated ICE explained that bond requests were handled out of state, making it more difficult to obtain contact information, and suggested the commenter to wait until the next day, delaying release. Commenters stated the need to make several phone calls or emails to reach an ICE employee who was able to answer any bond-related questions.</P>
                <P>Commenters requested all public facing materials and web content provide consistent guidance, explicitly state what factors are considered when determining if bonds can be paid in person, and allow obligors the option to pay bonds in person at ICE facilities.</P>
                <P>
                    <E T="03">Response:</E>
                     Commenters' comments focus on using CeBONDS and public information on posting bonds. However, the purpose of the rule is to authorize ICE to serve bond-related notices electronically to obligors who consent to receive electronic bond related notices. 
                    <E T="03">See</E>
                     8 CFR 103.6(g)-(h).
                </P>
                <P>Prior to the deployment and implementation of CeBONDS, all ICE staff at ICE offices processing bonds were provided training on the system.</P>
                <P>CeBONDS provides an online capability for bond obligors to request bond information and post cash immigration bonds for detained noncitizens determined by the IJ or ICE to be eligible for release on bond. The process and procedures ICE officials utilize to verify an obligor's eligibility to post a bond, to approve the bond and payment, and to release the noncitizen from ICE custody are the same for bonds posted in CeBONDS, eBONDS, and walking into an ICE office.</P>
                <P>
                    The ICE website provides a video tutorial on using CeBONDS, a section on frequently asked questions, and categorically lists acceptable documents applicable to the obligor.
                    <SU>47</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>47</SU>
                         U.S. Immigration and Customs Enforcement, 
                        <E T="03">Post a Bond</E>
                         (last updated Sept. 17, 2024), 
                        <E T="03">https://www.ice.gov/detain/detention-management/bonds</E>
                        .
                    </P>
                </FTNT>
                <P>
                    As listed on the ICE website, an obligor must provide at least one (1) document to ICE from the applicable category below.
                    <SU>48</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>48</SU>
                         U.S. Immigration and Customs Enforcement, 
                        <E T="03">Post a Bond</E>
                         (last updated Sept. 17, 2024), 
                        <E T="03">https://www.ice.gov/detain/detention-management/bonds</E>
                        .
                    </P>
                </FTNT>
                <HD SOURCE="HD3">U.S. Citizen</HD>
                <FP SOURCE="FP-1">• U.S. Passport</FP>
                <FP SOURCE="FP-1">• U.S. Birth Certificate</FP>
                <FP SOURCE="FP-1">• U.S. Citizen Born Abroad Document</FP>
                <FP SOURCE="FP-1">• USCIS Naturalization Certificate</FP>
                <FP SOURCE="FP-1">• State-issued Driver's License (only REAL ID Card)</FP>
                <FP SOURCE="FP-1">• State-issued ID Card (only REAL ID Card)</FP>
                <FP SOURCE="FP-1">• Military Identification Card</FP>
                <HD SOURCE="HD3">Legal Permanent Resident (LPR)</HD>
                <FP SOURCE="FP-1">• Permanent Resident Card (commonly known as a “Green Card”)</FP>
                <FP SOURCE="FP-1">• Military Identification Card</FP>
                <HD SOURCE="HD3">Non-Profit Organization</HD>
                <FP SOURCE="FP-1">• IRS Letter 947—(Letter of Determination)</FP>
                <FP SOURCE="FP-1">• SS4 IRS Notification Letter (Employer identification number [EIN] approval letter)</FP>
                <FP SOURCE="FP-1">• Letter of authorization from the non-profit for representative/obligor posting the bond</FP>
                <FP SOURCE="FP-1">• Representative's identification</FP>
                <HD SOURCE="HD3">Law Firms</HD>
                <FP SOURCE="FP-1">• SS4 IRS Notification Letter (Employer identification number [EIN] approval letter)</FP>
                <FP SOURCE="FP-1">• Letter of authorization from the law firm for representative/obligor posting the bond</FP>
                <FP SOURCE="FP-1">• Representative's identification</FP>
                <HD SOURCE="HD3">Noncitizen Posting a Voluntary Departure (VD) or Order of Supervision Bond</HD>
                <FP SOURCE="FP-1">• Form I-862, Notice to Appear</FP>
                <FP SOURCE="FP-1">• VD Order (for VD Bond)</FP>
                <FP SOURCE="FP-1">• IJ Order (for Order of Supervision Bond)</FP>
                <FP SOURCE="FP-1">• ICE Form I-220B (Order of Supervision)</FP>
                <FP SOURCE="FP-1">• Form I-765—Employment Authorization Document (EAD)</FP>
                <P>ICE continues to allow obligors to post a bond in person at the appropriate ICE office. ICE will continue to work with obligors who want to pay bonds in person at an ICE office. DHS continues to work to improve the system and the process but makes no changes to the rule in response to these comments.</P>
                <HD SOURCE="HD2">N. Technical Issues</HD>
                <P>
                    <E T="03">Comment:</E>
                     Commenters stated that CeBONDS has numerous technical issues, and frequently crashes, which prevents payment and creates uncertainty whether the request or system failed. Commenters stated CeBONDS relies on human approvals at every stage of the bond-posting process, which results in lengthy wait times, or worse, the denial or failure of bond-posting requests. A commenter stated their payment was not instantaneous and waited over four hours for ICE to accept and process the bond request. Commenters stated they did not receive any information such as confirmation, receipt of payment, or status update while waiting for ICE to accept and process the bond request.
                </P>
                <P>Commenters stated CeBONDS does not contain accurate, up-to-date information. One commenter experienced a delay for several days between Executive Office for Immigration Review (EOIR), a sub-agency of the DOJ, setting a bond and information being properly entered into CeBONDS. Failures by the CeBONDS system to contain accurate, up-to-date information has frustrated sponsors attempting to pay bonds for bond-eligible noncitizens who provided the necessary documentation, leading to the noncitizens' prolonged detention. Another commenter stated after uploading documents to CeBONDS, the commenter needed to provide additional copies because the ICE employee was unable to locate the documents in CeBONDS. Commenters stated CeBONDS lacks a real-time way to solve problems that forces obligors to engage with ICE agents for help, and request status updates and information. Other commenters experienced slow email responses from the general Helpdesk and slow response times from local ICE offices processing bonds. Other commenters stated the ICE Information Technology (IT) support staff are unable to respond or provide timely remedies for detained noncitizens.</P>
                <P>Commenters stated CeBONDS is difficult and confusing to navigate regardless of English proficiency. Commenters stated that CeBONDS increases the complexity of paying bonds and using the system should not require obligors to be technologically savvy.</P>
                <P>
                    <E T="03">Response:</E>
                     These comments are focused on technical and functional issues related to CeBONDS, but this rule does not implement this system. Rather, the rule authorizes ICE to serve bond related notices to obligors who consent 
                    <PRTPAGE P="547"/>
                    to receive those notices electronically. Additionally, commenters did not provide specific dates or times of alleged outages.
                </P>
                <P>DHS has made various system updates to CeBONDS to improve functionality. Since CeBONDS deployed in April 2023, the system has not experienced any unscheduled system-wide outages, crashes, or failures. Furthermore, the number of customer-reported issues or incidents has substantially decreased. Comparably, from April to June 2023, there were 783 customer reported issues or incidents. That number was reduced by 62 percent or 487 reported issues or incidents from October to December of the same year.</P>
                <P>CeBONDS does not contain information from EOIR. Once a request to post bond is received either via CeBONDS or in-person at an ICE office, the process for validating all the bond information is the same and is performed by an ICE official. An obligor can utilize the CeBONDS system's comment section to communicate (send comments or upload documents) in real time with ICE officials throughout the bond process.</P>
                <P>CeBONDS payments are made via Fedwire or ACH. Depending on the time of day the payment is made, Fedwire payments are settled the same day and ACH payments typically settle 1 to 2 business days after they have been initiated. After the payment has been completed between the financial institutions, ICE can verify the payment. Next, the obligor will upload the payment receipt and bond contract and submit these documents. Thereafter, the obligor will receive correspondence via email and in their CeBONDS account that their request is under ICE review. Once the review and payment are confirmed, the obligor will receive an email and their CeBONDS account will reflect that the bond has been approved. When the noncitizen is released from custody, the obligor will receive correspondence via email and in their CeBONDS account that the noncitizen has been released from custody. At each step in the bond posting process, the actions from ICE and the obligor are both tracked in CeBONDS.</P>
                <P>
                    The system does not require anyone to be technologically savvy. ICE has provided a tutorial along with frequently asked questions on the 
                    <E T="03">ICE.gov/bonds</E>
                     web page to assist obligors. The tutorial is provided in English and Spanish. Additionally, obligors can contact their local ICE office for assistance or email any system related questions or concerns to 
                    <E T="03">ICECeBONDS-Helpdesk@ice.dhs.gov</E>
                    .
                </P>
                <HD SOURCE="HD2">O. In-Person Bond Payment</HD>
                <P>
                    <E T="03">Comment:</E>
                     The majority of commenters requested ICE allow obligors the option to pay bonds in-person indefinitely. Commenters stated that paying bonds in-person is quicker and completed within hours compared to CeBONDS which takes days to process. One commenter stated that eliminating the option of in-person bond payments to transition to CeBONDS will stymie obligors from complying with ICE requirements.
                </P>
                <P>Another commenter stated that bond notices delivered by mail increases the assurance of noncitizens and obligors receive and sign all notices. Without evidence, the commenter stated paying bonds in-person can reduce the likelihood of fraud and increase noncitizens presence for court hearings.</P>
                <P>Another commenter stated paying bonds in person facilitates an efficient process and alleviates stressful situations for noncitizens and obligors when dealing with immigration detention. The commenter continued that if ICE intended this electronic system provide organizations with a more convenient way to pay bonds, then it should honor its intention and maintain the option of in-person payments. This will ensure that the bond payment system is truly responsive to the needs of the community it serves and does not create unnecessary barriers for those grappling with challenging circumstances.</P>
                <P>One commenter suggested that in-person bond payment would increase ICE funds because CeBONDS is too difficult to understand, and obligors do not have bank accounts or computers.</P>
                <P>
                    Commenters stated the IFR does not intend to refuse obligors from posting bonds in-person. However, commenters asserted this contradicts the practice at ICE facilities and information on the ICE website.
                    <SU>49</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>49</SU>
                         U.S. Immigration and Customs Enforcement, 
                        <E T="03">Post a Bond</E>
                         (last updated Sept. 17, 2024), 
                        <E T="03">https://www.ice.gov/detain/detention-management/bonds</E>
                        .
                    </P>
                </FTNT>
                <P>Commenters stated that ICE's informational web page fails to inform the public when ICE may accept an in-person bond payment. Commenters expressed that obligors may not know or understand if there is an option to pay in person and urges DHS and ICE to clarify, publicize, and enforce this option.</P>
                <P>
                    <E T="03">Response:</E>
                     The rule does not impact the payment methods of obligors. This rule provides a regulatory framework that allows ICE to serve certain bond notices electronically for obligors who consent to electronic service. Notably, the rule provides safeguards in instances where electronic service is not confirmed, for which ICE must effectuate service via mail, which would be the equivalent method of service for an obligor who opts out of electronic service.
                </P>
                <P>To assure the notice is opened by the obligor, CeBONDS will track the timestamp when the notice is viewed in the system. Viewing of the notice in the system constitutes when the obligor is served with the notice. At each step of this process, CeBONDS tracks the actions taken in the system and the actions of the obligor. Furthermore, the notice in CeBONDS is available to the obligor anytime the obligor logs into the system.</P>
                <P>If the obligor does not open the notice, a new notice will be sent via ordinary or certified mail (depending on the notice) to the last known address.</P>
                <P>The requirements of the obligor are not dependent on how the obligor posts bond (in-person or electronically). Therefore, obligors who post a bond as security for performance and fulfillment of the bonded noncitizen's obligations to the government are not impacted. The obligor still must comply with the requirements in the contract with ICE.</P>
                <P>Regarding the comment about ICE funds increasing with in-person payment, there is no data to support this statement, and is irrelevant because the option of in-person payment is not removed by this rule. If electronic payment is unattainable, obligors can continue to use the in-person system.</P>
                <P>Obligors can still pay bonds in person. The intent of the IFR and this final rule are to improve the service delivery of bond notices to obligors. It does not impact an individual's ability to pay in person. The rule authorizes ICE to serve bond-related notices to obligors who opt-in to receive those notices electronically.</P>
                <P>From April 2023 to January 2024, 7,424 obligors paid bonds using CeBONDS or in-person. Forty percent of obligors (3,021) used CeBONDS and 60 percent (4,400) paid bonds in-person at an ICE facility. This highlights that the ability to pay in person remains an option. Any obligor who has a question about posting a bond in person can contact the nearest ICE office for guidance.</P>
                <HD SOURCE="HD2">P. Out of Scope</HD>
                <HD SOURCE="HD3">1. Alternatives to Detention</HD>
                <P>
                    <E T="03">Comment:</E>
                     One commenter provided a comment regarding ICE's Alternatives to Detention (ATD) program, which uses case management and technology tools to support noncitizen compliance with release conditions while on ICE's non-
                    <PRTPAGE P="548"/>
                    detained docket. The commenter suggested that DHS propose a mechanism for seizing and/or shutting off such electronic monitoring devices remotely for noncitizens who abscond. Additionally, the commenter noted various sources and statistics to indicate an increase in the use of ATD technology and stated that there are issues associated with such technology, such as inefficiency, lack of punishments for violations, and no deportations for noncitizens under SmartLink. The commenter generally raised concerns on releasing noncitizens under the ATD program; noncitizens working unlawfully; and how such releases may be perceived by human smugglers, cartels, and migrants.
                </P>
                <P>
                    <E T="03">Response:</E>
                     This comment is beyond the scope of the IFR and this final rule because it does not relate to immigration bond notifications or electronic service of immigration bond related notices. ICE's ATD program is utilized to ensure that a noncitizen complies with their release conditions.
                    <SU>50</SU>
                    <FTREF/>
                     The IFR and this final rule are not intended to address any such issues. Thus, no further response is required for this comment.
                </P>
                <FTNT>
                    <P>
                        <SU>50</SU>
                         U.S. Immigration and Customs Enforcement, ICE Alternatives to Detention (last updated June 24, 2024), 
                        <E T="03">https://www.ice.gov/features/atd</E>
                        .
                    </P>
                </FTNT>
                <HD SOURCE="HD3">2. 31 U.S.C. 5103, Legal Tender</HD>
                <P>
                    <E T="03">Comment:</E>
                     One commenter stated the rule challenges 31 U.S.C. 5103 which requires the acceptance of any legal tender for all debts, public charges, taxes, and dues.
                </P>
                <P>
                    <E T="03">Response:</E>
                     Section 5103 of Title 31 of the U.S. Code provides that “United States coins and currency (including Federal reserve notes and circulating notes of Federal reserve banks and national banks) are legal tender for all debts, public charges, taxes, and dues. Foreign gold or silver coins are not legal tender for debts.” The commenter did not explain how this statute is relevant to electronic service of bond notices and why this rule implicates the statute. If the commenter is implying that the statute requires the government to accept cash payments from an obligor, such comment is outside of the scope of this rule, as the rule focuses on electronic service of bond notices. Nevertheless, in the context of posting bond payments through CeBONDS, the commenter's interpretation misconstrues the meaning of the statute. The statute establishes what constitutes legal tender in the United States and does not impose a requirement on the government to accept cash payments.
                    <SU>51</SU>
                    <FTREF/>
                     Congress enacted this statute to “establish and maintain a uniform national currency” to avoid having a “system in which individual states can issue their own currency, or declare things other than federally-issued money to constitute legal tender.” 
                    <E T="03">Genesee Scrap &amp; Tin Baling Co.</E>
                     v. 
                    <E T="03">City of Rochester,</E>
                     558 F. Supp. 2d 432, 437 (W.D.N.Y. 2008). In any event, given that the statute does not have any bearing on immigration bond notifications and electronic service, this comment is beyond the scope of this rule and requires no further response.
                </P>
                <FTNT>
                    <P>
                        <SU>51</SU>
                         
                        <E T="03">See, e.g., Tennessee Scrap Recyclers Ass'n</E>
                         v. 
                        <E T="03">Bredesen,</E>
                         556 F.3d 442, 458 (6th Cir. 2009) (city ordinance requiring payment by check, money, or payment vouchers only did not violate or implicate 31 U.S.C. 5103); 
                        <E T="03">Genesee Scrap &amp; Tin Baling Co.</E>
                         v. 
                        <E T="03">City of Rochester,</E>
                         558 F. Supp. 2d 432, 434 (W.D.N.Y. 2008) (city ordinance specifying that cash may not be used for transactions did not violate 31 U.S.C. 5103); 
                        <E T="03">In re Reyes,</E>
                         482 B.R. 603, 606 (D. Ariz. 2012) (requiring debtors to make plan payments using only certified funds, automatic wage withdrawals, or electronic transfers did not violate 31 U.S.C. 5103). As the bankruptcy court 
                        <E T="03">In re Reyes</E>
                         explained, narrowly interpreting the statute “to forbid all but cash payments `would strain logic.' ” 482 B.R. at 606.
                    </P>
                </FTNT>
                <HD SOURCE="HD1">III. Statutory and Regulatory Requirements</HD>
                <P>DHS developed this final rule after considering numerous statutes and executive orders related to rulemaking. The below sections summarize the analyses based on a number of these statutes or executive orders.</P>
                <HD SOURCE="HD2">A. Administrative Procedure Act</HD>
                <P>
                    The Department has forgone the Administrative Procedure Act's (“APA”) delayed-effective-date procedure in implementing this rule because the APA's requirement for a 30-day delayed effective date applies to substantive rules, 
                    <E T="03">see</E>
                     5 U.S.C. 553(d), whereas this rule, like the IFR, is a rule of agency organization, procedure, or practice, 
                    <E T="03">see</E>
                     5 U.S.C. 553(b)(A). In the IFR, ICE invoked the procedural rule exception to bypass notice-and-comment rulemaking. ICE, in citing the D.C. Circuit's “oft-cited formulation,” explained the procedural-rule exception “ covers agency actions that do not themselves alter the rights or interests of parties, although it may alter the manner in which the parties present themselves or their viewpoints to the agency.” 
                    <E T="03">JEM Broad. Co., Inc.</E>
                     v. 
                    <E T="03">FCC,</E>
                     22 F.3d 320, 326 (D.C. Cir. 1994) (quoting 
                    <E T="03">Batterton</E>
                     v. 
                    <E T="03">Marshall,</E>
                     648 F.2d 694, 707 (D.C. Cir. 1980)); 
                    <E T="03">see also Mendoza</E>
                     v. 
                    <E T="03">Perez,</E>
                     754 F.3d 1002, 1023-24 (D.C. Cir. 2014). The IFR merely added another method (
                    <E T="03">e.g.,</E>
                     electronic service) for ICE to serve bond-related notifications for anyone enrolling in or using an ICE electronic bonds systems. ICE is not removing or limiting any of the current methods of service found in 8 CFR 103.8(a)(1) or (2). These changes were procedural in nature, improve the effectiveness and efficiency of agency operations, and did not alter substantive rights. The same is the case with this rule.
                </P>
                <P>
                    Even if the 30-day delayed-effective-date requirement did apply, the Department would find good cause to make this rule effective sooner. 5 U.S.C. 553(d)(3). The IFR is already in effect and the changes in the final rule are merely clarifying or technical. None of the amendments implicate the justifications for the 30-day waiting period. The purpose of the waiting period is “to give affected parties time to adjust their behavior before the final rule takes effect.” 
                    <E T="03">Riverbend Farms, Inc.</E>
                     v. 
                    <E T="03">Madigan,</E>
                     958 F.2d 1479, 1485 (9th Cir. 1992). Here, however, that purpose would not be served by delaying the effective date of the rule: The IFR has been in effect since September 7, 2023, and finalizing the provisions in this rule does not require anyone to change their conduct or to take any particular steps in advance of the effective date. 
                    <E T="03">See United States</E>
                     v. 
                    <E T="03">Gavrilovic,</E>
                     551 F.2d 1099, 1104 (8th Cir. 1977) (noting that the “legislative history of the APA” indicates that the waiting period “was not intended to unduly hamper agencies from making a rule effective immediately,” but intended “to `afford persons affected a reasonable time to prepare for the effective date of a rule . . . or to take other action which the issuance may prompt' ” (citing S. Rep. No. 752, 79th Cong., 1st Sess. 15 (1946); H.R. Rep. No. 1980, 79th Cong., 2d Sess. 25 (1946))). In fact, ICE has already implemented the IFR and the public will not need to adjust its behavior at all following the issuance of this final rule. Because there were no substantive changes from the IFR, the public has had sufficient notice of the provisions in this final rule and a delay in the rule's effective date is unnecessary.
                </P>
                <HD SOURCE="HD2">B. Executive Orders 12866, 13563, and 14094: Regulatory Review</HD>
                <P>
                    Executive Order 12866, 
                    <E T="03">Regulatory Planning and Review,</E>
                     as amended by Executive Order 14094, 
                    <E T="03">Modernizing Regulatory Review,</E>
                     and Executive Order 13563, 
                    <E T="03">Improving Regulation and Regulatory Review,</E>
                     direct agencies to assess the costs and benefits of available regulatory alternatives and, if regulation is necessary, to select regulatory approaches that maximize net benefits (including potential economic, environmental, public health and safety effects, distributive impacts, and equity). Executive Order 13563 emphasizes the importance of 
                    <PRTPAGE P="549"/>
                    quantifying both costs and benefits, of reducing costs, of harmonizing rules, and of promoting flexibility.
                </P>
                <P>This final rule has not been designated a “significant regulatory action,” under section 3(f) of Executive Order 12866, as amended by Executive Order 14094. Accordingly, the rule has not been reviewed by the Office of Management and Budget.</P>
                <HD SOURCE="HD3">Summary of the Analysis</HD>
                <P>
                    DHS estimates the effects of the final rule relative to a baseline condition without the 2023 IFR.
                    <SU>52</SU>
                    <FTREF/>
                     DHS estimates that the final rule will have public costs and unquantified benefits, and result in cost-savings and unquantified benefits to the government. The overall quantified impact of this rule is a net savings of $561,317 discounted at 3 percent and $182,870 discounted at 7 percent, with unquantified benefits expected to outweigh the unquantified costs. The rule is expected to expedite delivery and improve the reliability of service of bond-related notices. In accounting for the costs and cost-savings of this final rule, ICE has assumed that all obligors will adopt electronic service within the first year of the publishing of this final rule. New bond obligors who consent to enrolling in CeBONDS or eBONDS will use electronic notifications as a feature of using these systems, though they will have the option to utilize physical notification under certain circumstances, such as an obligor lacking the means to access the internet. Lastly, while the analysis assumes that bond obligors will enroll in these services sooner rather than later, full adoption may ultimately depend on several factors, such as obligors being made aware of these changes, understanding the benefits of these provisions, and possessing the means to access the internet. Table 1 summarizes the findings of this regulatory impact analysis (RIA).
                </P>
                <FTNT>
                    <P>
                        <SU>52</SU>
                         OMB Circular A-4 states that “the benefits and costs of a regulation are generally measured against a no-action baseline: an analytically reasonable forecast of the way the world would look absent the regulatory action being assessed.” Nov. 9, 2023, 
                        <E T="03">https://www.whitehouse.gov/wp-content/uploads/2023/11/CircularA-4.pdf</E>
                         (last visited September 26, 2024).  Consistent with OMB Circular A-4, DHS has analyzed finalization of the IFR as compared to a state of the world that (hypothetically) lacks the IFR. The “without-IFR baseline” is the primary baseline. This rule has no effects relative to a state of the world that includes the IFR (
                        <E T="03">i.e.,</E>
                         a “with-IFR baseline), because this rule's changes relative to the IFR are clarifying and technical in nature and have no real-world effects on the government or the public.
                    </P>
                </FTNT>
                <GPOTABLE COLS="03" OPTS="L2,nj,i1" CDEF="s100,r50,r20">
                    <TTITLE>Table 1—OMB Circular A-4 Accounting Statement 2023</TTITLE>
                    <TDESC>[Millions]</TDESC>
                    <BOXHD>
                        <CHED H="1">Category</CHED>
                        <CHED H="1">Impact</CHED>
                        <CHED H="1">Source</CHED>
                    </BOXHD>
                    <ROW EXPSTB="02" RUL="s">
                        <ENT I="21">
                            <E T="02">Benefits</E>
                        </ENT>
                    </ROW>
                    <ROW EXPSTB="00">
                        <ENT I="22">Annualized Monetized Benefits ($ Mil):</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">(3%)</ENT>
                        <ENT/>
                        <ENT>RIA.</ENT>
                    </ROW>
                    <ROW RUL="s">
                        <ENT I="03">(7%)</ENT>
                        <ENT/>
                        <ENT>RIA.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Annualized Quantified, but Unmonetized, Benefits</ENT>
                    </ROW>
                    <ROW RUL="s">
                        <ENT I="01">Unquantified Benefits</ENT>
                        <ENT>Improved program delivery. Reduced paper waste</ENT>
                        <ENT>RIA.</ENT>
                    </ROW>
                    <ROW EXPSTB="02" RUL="s">
                        <ENT I="21">
                            <E T="02">Costs</E>
                        </ENT>
                    </ROW>
                    <ROW EXPSTB="00">
                        <ENT I="22">Annualized Monetized Costs ($ Mil):</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">(3%)</ENT>
                        <ENT>.544</ENT>
                        <ENT>RIA.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">(7%)</ENT>
                        <ENT>.584</ENT>
                        <ENT>RIA.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Annualized Quantified, but Unmonetized, Costs</ENT>
                    </ROW>
                    <ROW RUL="s">
                        <ENT I="01">Unquantified Costs</ENT>
                        <ENT>Cost to public to access electronic system</ENT>
                        <ENT>RIA.</ENT>
                    </ROW>
                    <ROW EXPSTB="02" RUL="s">
                        <ENT I="21">
                            <E T="02">Transfers</E>
                        </ENT>
                    </ROW>
                    <ROW EXPSTB="00">
                        <ENT I="01">Annualized Monetized Transfers</ENT>
                    </ROW>
                    <ROW RUL="s">
                        <ENT I="01">From Whom to Whom</ENT>
                    </ROW>
                    <ROW EXPSTB="02" RUL="s">
                        <ENT I="21">
                            <E T="02">Other Analyses</E>
                        </ENT>
                    </ROW>
                    <ROW EXPSTB="00">
                        <ENT I="01">Effects on State, Local, and/or Tribal Governments</ENT>
                        <ENT>No Impact</ENT>
                        <ENT>FR.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Effects on Small Business</ENT>
                        <ENT>Undetermined</ENT>
                        <ENT>FR.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Effects on Wages</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Effects on Growth</ENT>
                    </ROW>
                </GPOTABLE>
                <PRTPAGE P="550"/>
                <HD SOURCE="HD3">Background and Purpose of Final Rule</HD>
                <P>As part of its mission to enforce U.S. immigration laws, ICE currently issues a wide range of notices, decisions, and other documents to entities such as, but not limited to, universities, businesses, noncitizens, courts, and employees. Prior to the IFR, the rules on service limited ICE to serving documents in person or by certified, registered, or regular mail. However, serving documents in this manner can take more time and be more costly compared to electronic methods of service. The final rule confirms the IFR in authorizing ICE to serve electronic bond-related notices and notifications to obligors who enroll in CeBONDS and eBONDS.</P>
                <P>
                    Currently, ICE uses certified mail for the service of demand notices issued on delivery bonds so that ICE can confirm the date upon which an obligor receives the demand notice. Since 2010, ICE has employed eBONDS, which is a web-based system used primarily by surety agents and ICE to facilitate the ICE immigration bond management process. This system was implemented to allow surety agents the option to post surety bonds electronically for noncitizens determined by ICE to be eligible for release on bond. Additionally, eBONDS was built with functionality that included the ability to serve electronic bond-related notifications to surety companies and their agents within eBONDS for those companies who opted-in to electronic service, but due to the regulatory requirements under 8 CFR 103.8(a)(1) and 103.8(a)(2) for personal and routine service (pre-IFR), that capability has not been implemented in eBONDS.
                    <SU>53</SU>
                    <FTREF/>
                     Similarly, ICE has developed CeBONDS to allow cash bond obligors to post cash immigration bonds online without obligors having to appear in person at an ICE office. CeBONDS offers to individuals posting cash bonds all the conveniences that eBONDS provides to surety companies. This final rule authorizes ICE to serve bond-related notices and notifications electronically for those who consent, setup an account, and utilize the eBONDS and CeBONDS systems.
                </P>
                <FTNT>
                    <P>
                        <SU>53</SU>
                         U.S. Dep't of Homeland Security, 
                        <E T="03">Privacy Impact Assessment Update for the Bonds Online System (eBONDS) Phase Two</E>
                         (Jan. 24, 2013), 
                        <E T="03">https://www.dhs.gov/sites/default/files/publications/ice-pia-008-a-ebonds-2013.pdf</E>
                        .
                    </P>
                </FTNT>
                <HD SOURCE="HD3">Time Horizon for the Analysis</HD>
                <P>ICE estimates the economic effects of this final rule will be sustained indefinitely. ICE assumes a 10-year timeframe to outline, quantify, and monetize the costs and benefits of the rule, and to demonstrate its net effects. DHS expresses quantified impacts in 2023 dollars and uses discount rates of 3 and 7 percent, pursuant to Circular A-4.</P>
                <HD SOURCE="HD3">Analysis Considerations</HD>
                <P>
                    With regard to bond-related notifications, ICE derived quantitative estimates of the costs that will be saved in ICE's operations, attributable to ICE serving the notifications electronically rather than through a non-electronic method. In order to calculate these estimates, this analysis assumes that full use of eBONDS and CeBONDS will entail that current obligors adopt electronic notifications as they become familiar with the changes presented in this final rule. Based on input from ICE subject matter experts, this analysis also assumes that all current bond obligors will adopt these services within the first year of publishing this rule to realize the benefits of electronic bond-related notifications and will elect to use these services sooner rather than later. While the analysis assumes that all bond obligors will utilize these systems, full adoption may ultimately depend on several factors, such as obligors being made aware of these changes, understanding the benefits of these provisions, and possessing the means to access the internet.
                    <SU>54</SU>
                    <FTREF/>
                     Lastly, this estimate does not account for any change in the total number of notices that will occur in the future, or under circumstances when ICE needs to send paper notices by mail if emails fail, or the possibility of less than full adoption by the public. With this final rule, obligors utilizing CeBONDS and eBONDS will automatically enroll in electronic notifications upon consent, though they will have the option to utilize physical service under certain circumstances—such as an obligor lacking the means to access the internet.
                </P>
                <FTNT>
                    <P>
                        <SU>54</SU>
                         ICE subject matter experts expressed that they expect nearly every obligor to utilize these systems, and that in the first year of the CeBONDS system being active only approximately five percent of obligors pay bonds in person. This analysis assumes the percentage of in-person payments will decline over time as adoption continues. Commenters and stakeholders did not present data that challenged this assumption broadly but provided anecdotal evidence of certain obligors not being able to use the electronic systems and needing an in-person option. DHS is committed to maintaining an in-person payment option for such exceptions, but for the purpose of not inserting additional uncertainty into this analysis, DHS has not changed this assumption.
                    </P>
                </FTNT>
                <HD SOURCE="HD3">Affected Population</HD>
                <P>The final rule affects ICE officers and all bond obligors who post immigration bonds online using CeBONDS or eBONDS. Once ICE has the ability to serve electronic notifications to bond obligors, ICE will begin to serve all bond-related notices electronically to any obligor who chooses to post a bond electronically.</P>
                <P>To account for these populations, ICE utilized its Bond Management Information System (BMIS) to collect and analyze data on surety companies and their agents that post bonds and data on individual obligors who post cash bonds. Using this information, ICE found that an average of 41,820 cash bonds were posted annually by obligors between fiscal years (FYs) 2018 and 2020. Additionally, ICE found that between FYs 2018 and 2020, a total of 15 agents and 11 surety companies posted ICE immigration bonds on behalf of surety bond obligors. Combined, these representatives posted bonds for an average 8,190 obligors. Table 2 displays this information below by fiscal year and category of bonds.</P>
                <GPOTABLE COLS="5" OPTS="L2,i1" CDEF="s50,12,12,12,12">
                    <TTITLE>Table 2—Total Bonds Posted by Cash and Surety Obligors</TTITLE>
                    <BOXHD>
                        <CHED H="1">Category</CHED>
                        <CHED H="1">FY 2018</CHED>
                        <CHED H="1">FY 2019</CHED>
                        <CHED H="1">FY 2020</CHED>
                        <CHED H="1">Average</CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">Surety Bonds</ENT>
                        <ENT>8,081</ENT>
                        <ENT>9,098</ENT>
                        <ENT>7,391</ENT>
                        <ENT>8,190</ENT>
                    </ROW>
                    <ROW RUL="n,s">
                        <ENT I="01">Cash Bonds</ENT>
                        <ENT>49,793</ENT>
                        <ENT>50,135</ENT>
                        <ENT>25,531</ENT>
                        <ENT>41,820</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">Total</ENT>
                        <ENT>57,874</ENT>
                        <ENT>59,233</ENT>
                        <ENT>32,922</ENT>
                        <ENT>50,010</ENT>
                    </ROW>
                    <TNOTE>Source: DHS/ICE Bond Management Information System (BMIS).</TNOTE>
                </GPOTABLE>
                <PRTPAGE P="551"/>
                <HD SOURCE="HD3">Baseline</HD>
                <P>This section details the regulatory baseline for this final rule. The table below provides a summary of the anticipated changes to baseline conditions due to this final rule.</P>
                <GPOTABLE COLS="5" OPTS="L2,nj,i1" CDEF="s50,r50,r50,r50,r50">
                    <TTITLE>Table 3—Summary of Expected Impacts</TTITLE>
                    <BOXHD>
                        <CHED H="1">Provision</CHED>
                        <CHED H="1">Description of change</CHED>
                        <CHED H="1">Affected population</CHED>
                        <CHED H="1">Cost impact</CHED>
                        <CHED H="1">Benefit impact</CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">Serve Bond-Related Notices Electronically</ENT>
                        <ENT>The electronic service process entails serving immigration (ICE) bond-related notices electronically and sending email notifications that notices have been posted to their account to bond obligors who have posted a bond using the eBONDS and CeBONDS systems</ENT>
                        <ENT>
                            • All bond obligors who post immigration bonds online using the CeBONDS or eBONDS system
                            <LI>• Federal Government</LI>
                        </ENT>
                        <ENT>
                            • Familiarization costs
                            <LI>• Potential technology costs</LI>
                            <LI>• Opportunity costs to create an CeBONDS account</LI>
                            <LI O="xl">• Program cost savings.</LI>
                        </ENT>
                        <ENT>
                            • Improved program delivery.
                            <LI>• Expedited service process.</LI>
                        </ENT>
                    </ROW>
                </GPOTABLE>
                <HD SOURCE="HD3">Operational Baseline</HD>
                <P>Currently, ICE uses routine service as defined by 8 CFR 103.8(a)(1) to serve breach notices, cancellation notices, and notices of bond breach reconsideration decisions. ICE performs the routine service by sending ordinary mail to the obligor's last known address. ICE also uses routine service to serve invoices and demand letters to surety companies and their agents, sending them either by ordinary mail, an alternative mailing method that allows ICE to track and confirm delivery, or email (with the co-obligors' consent).</P>
                <P>
                    Additionally, ICE uses personal service as defined by 8 CFR 103.8(a)(2) 
                    <SU>55</SU>
                    <FTREF/>
                     to effect service of demand notices issued on delivery bonds so that ICE may confirm the date on which the obligor receives the demand notice. Currently, for ICE, “personal service” may be utilized through any of the following methods: personal delivery; delivery at a person's home or usual residence by providing a copy to a person of suitable age and discretion; delivery at the office or residence of an attorney or representative; or mailing by certified or registered mail, with return receipt requested, to a person's last known address.
                </P>
                <FTNT>
                    <P>
                        <SU>55</SU>
                         Except that portion of 8 CFR 103.8(a)(2) that is applicable solely to USCIS.
                    </P>
                </FTNT>
                <P>To establish a baseline analysis for all bond-related notices, ICE calculated the average number of notices served by mail per year, of each type of immigration bond, based on data from fiscal year 2018 to 2020 (Table 4). ICE found the average number of all types of notices per year to be 45,358.</P>
                <GPOTABLE COLS="2" OPTS="L2,p7,7/8,i1" CDEF="s50,13">
                    <TTITLE>Table 4—Types of Immigration Bond Notices</TTITLE>
                    <BOXHD>
                        <CHED H="1">Notice type</CHED>
                        <CHED H="1">
                            Average annual
                            <LI>number of</LI>
                            <LI>notices mailed</LI>
                            <LI>(FY 2018-2020)</LI>
                        </CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">I-391 Cash Bond Cancellations</ENT>
                        <ENT>15,317</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">I-340 Cash Bond Obligor to Deliver Noncitizen</ENT>
                        <ENT>12,020</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">I-323 Cash Bond Breaches</ENT>
                        <ENT>7,128</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">I-340 Surety Bond Obligor to Deliver Noncitizen</ENT>
                        <ENT>6,080</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">I-391 Surety Bond Cancellations</ENT>
                        <ENT>2,841</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">I-323 Surety Bond Breaches</ENT>
                        <ENT>1,412</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Surety Bond Motion to Reopen or Reconsider</ENT>
                        <ENT>306</ENT>
                    </ROW>
                    <ROW RUL="n,s">
                        <ENT I="01">Cash Bond Motion to Reopen or Reconsider</ENT>
                        <ENT>254</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">Total</ENT>
                        <ENT>45,358</ENT>
                    </ROW>
                    <TNOTE>Source: DHS/ICE Bond Management Information System (BMIS).</TNOTE>
                </GPOTABLE>
                <P>ICE anticipates that, in the absence of this rulemaking, the agency would continue to serve all bond-related notices using personal or routine service, at a cost to both the federal government and the recipients. ICE would still be required to process and serve notices manually, and bond obligors would continue to receive physical notifications via an authorized form of paper-based service.</P>
                <HD SOURCE="HD3">Costs of the Final Rule</HD>
                <P>This alternative electronic method of ICE's process for serving bond notices will introduce familiarization, technology, and opportunity costs to the affected populations.</P>
                <HD SOURCE="HD3">Quantified Costs</HD>
                <P>
                    <E T="03">Familiarization</E>
                    —A likely impact of the final rule is that various individuals and other entities will incur costs associated with familiarization with the provisions of the rule. Familiarization costs involve the time spent reviewing and learning the provisions of a rule. Various offices throughout ICE may review the rule to determine how they are subject to the final rule. To the extent these entities are directly regulated by the rule, familiarization costs will be incurred, and those familiarization costs are a direct cost of the rule.
                </P>
                <P>
                    In addition to those being directly regulated by the rule, a wide variety of other entities will likely choose to read the rule and incur familiarization costs. For example, surety companies and noncitizens may want to become familiar with the provisions of this rule. At approximately 18,250 words, ICE estimates the time to read the final rule is approximately 61 to 73 minutes per person, resulting in opportunity costs of time. Congruent with other DHS impact analyses, ICE assumes the average professional reads technical documents at a rate of 250 to 300 words per minute.
                    <SU>56</SU>
                    <FTREF/>
                     An entity, such as a surety company may have more than one person who reads the final rule. Using the average hourly rate of total compensation of $44.27 for all occupations (both civilian and private),
                    <SU>57</SU>
                    <FTREF/>
                     ICE estimates that the opportunity cost of time will range from $44.88 to $53.86 per individual who must read and review the final rule (in 2023 dollars).
                    <SU>58</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>56</SU>
                         
                        <E T="03">See</E>
                         87 FR 10570 (Feb. 24, 2022) and 87 FR 18078 (Mar. 29, 2022).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>57</SU>
                         Average hourly total compensation $44.27 = ($45.42 civilian workers + $43.11 private industry workers) ÷ 2. Total Compensation for civilian workers and private industry workers, U.S. Dep't of Labor, Bureau of Labor Statistics, 
                        <E T="03">Employer Costs for Employe Compensation—December 2023,</E>
                         (March 13, 2024), 
                        <E T="03">https://www.bls.gov/news.release/archives/ecec_03132024.pdf.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>58</SU>
                         Calculation: Average total compensation for civilian and private industry ($44.27 = ($45.42 + 43.11) ÷ 2)), multiplied by the (lower and upper bound) number of hours required to read the rule 
                        <PRTPAGE/>
                        (1.014 and 1.217, respectively), equate to the per individual opportunity cost of time required to read the rule ($44.88 to $53.86, respectively). Word count estimated as of March 25, 2024.
                    </P>
                </FTNT>
                <PRTPAGE P="552"/>
                <P>
                    While the analysis assumes all bond obligors will utilize these systems, there are many factors which may impact the adoption of CeBONDS, such as awareness of the system and internet access. Given this, ICE provides an estimate for the number of people that will familiarize themselves with this rule based on expected users. To estimate this population, ICE utilized counts of bond obligors 
                    <SU>59</SU>
                    <FTREF/>
                     and surety companies 
                    <SU>60</SU>
                    <FTREF/>
                     between FY 2018 and FY 2020 to derive an annual average of 41,846 obligors (41,820 cash obligors + 11 surety companies + 15 agents). Assuming that at least one person from each entity or party will be responsible for reading the final rule, the total familiarization cost will range from $1,878,048 to $2,253,826 (in 2023 dollars).
                    <SU>61</SU>
                    <FTREF/>
                     The average of this estimated range for familiarization for bond obligor entities, $2,065,937, is used in the accounting of the first year of the cost of this final rule.
                </P>
                <FTNT>
                    <P>
                        <SU>59</SU>
                         Data was obtained from the DHS/ICE BMIS (obtained July 16, 2021, see Table 2). An average of 41,820 cash bonds were posted annually between 2018 and 2020. ICE used the average cash bonds posted as an estimate of the number of cash bond obligors. Cash bonds are generally posted by noncitizens or loved ones.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>60</SU>
                         This includes surety agents who post bonds of behalf of obligors. ICE found that between fiscal year 2018 and 2020, a total of 15 agents and 11 surety companies posted ICE immigration bonds on behalf of surety bond obligors.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>61</SU>
                         Range for total familiarization cost: lower bound $44.88 × 41,846 = $1,878,048; upper bound $53.86 × 41,846 = $2,253,826.
                    </P>
                </FTNT>
                <P>
                    <E T="03">Account Creation</E>
                    —In accounting for the costs of electronic bond-related notices, ICE considered whether bond obligors or surety companies will face opportunity costs to utilize eBONDS and CeBONDS. For ICE to send notifications electronically to bond obligors, the bond obligors will need to create a personal account to access bond-related notices and process bond payments. ICE estimates the time to create this account is no more than 10 minutes. Using the average total rate of compensation as $44.27 
                    <SU>62</SU>
                    <FTREF/>
                     per hour for all occupations, ICE estimates that the opportunity cost of time will be $7.38 per individual (or surety company) who creates an account. To estimate this population, ICE utilized a 3-year average population count 
                    <SU>63</SU>
                    <FTREF/>
                     of bond obligors between fiscal year 2018 and 2020 (from table 2) and assumes that all obligors will enroll into the program within the first year of implementation. The estimated total opportunity cost during the first-year adoption period for the current obligor population is $308,823.
                    <SU>64</SU>
                    <FTREF/>
                     To account for surety companies and surety agents, ICE also utilized BMIS to account for each representative which posted surety bonds between fiscal year 2018 and 2020, determining that a total of 15 agents and 11 surety companies had posted immigration bonds. The estimated total opportunity cost during the first-year adoption period for this population to adopt these systems is $191.88.
                    <SU>65</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>62</SU>
                         Average hourly total compensation $44.27 = ($45.42 civilian workers + $43.11 private industry workers) ÷ 2. Total Compensation for civilian workers and private industry workers, U.S. Dep't of Labor, Bureau of Labor Statistics, 
                        <E T="03">Employer Costs for Employe Compensation—December 2023,</E>
                         (Mar. 13, 2024), 
                        <E T="03">https://www.bls.gov/news.release/archives/ecec_03132024.pdf.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>63</SU>
                         Data was obtained from the DHS/ICE BMIS and utilized the number of unique Tax Identification Numbers (TIN) for bond obligors within a given set of years (obtained July 16, 2021).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>64</SU>
                         $308,361.60 = $7.38 × 41,820 annual average number of unique cash bond obligors (see Table 2).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>65</SU>
                         $191.88 = $7.38 × 26 annual average number of surety companies and surety agents FY2018-FY2020.
                    </P>
                </FTNT>
                <P>Lastly, in order to determine the cost of new obligors entering the pool and creating new accounts over the time horizon, ICE utilized prior cash bond obligor population data from fiscal years 2018 to 2020 to project that an average of 41,820 new cash bond obligors will create accounts each year. This will equate to a total cost to the public of $3,086,316 over 10 years.</P>
                <P>
                    <E T="03">CeBONDS Development &amp; Maintenance</E>
                    —CeBONDS began development in April of 2021, with the total development cost for ICE being estimated at roughly $1,507,000. The maintenance costs for ICE have been estimated to be $150,000 annually.
                    <SU>66</SU>
                    <FTREF/>
                     Similar to eBONDS, without this rule, ICE would still develop and implement CeBONDS to allow obligors to post cash bonds electronically, and ICE would continue to serve all bond-related notices using personal or routine service. Therefore, ICE did not include these development and maintenance costs as a part of the total costs in this analysis since the development and operation of the CeBONDS system is occurring independent of this final rule.
                </P>
                <FTNT>
                    <P>
                        <SU>66</SU>
                         Estimates provided by ERO, Bond Management Unit, July 14, 2022.
                    </P>
                </FTNT>
                <HD SOURCE="HD3">Unquantified Costs</HD>
                <P>ICE also identified additional unquantified costs that will result from this final rule.</P>
                <P>
                    <E T="03">Technology</E>
                    —In accounting for the costs of electronic bond-related notices and notifications, ICE considered whether bond obligors will face technology costs to utilize these services, namely the cost to access the internet. There are a variety of means by which obligors can access the internet to receive electronic bond-related notices and notifications, including the use of smart phones or personal computers. Due to the high prevalence and wide-ranging public and private access the internet, including access to free Wi-Fi in public and private locations, access to computers and internet at public libraries, as well as likely connections to family and friends who have ready access to the internet, ICE expects bond obligors who opt for electronic service will be able to gain access with de minimis cost. Furthermore, obligors can still opt out of electronic service and follow the same practice as in the baseline case. It is unclear how many obligors will choose to use the in-person option, but since the rule provides greater flexibility by permitting electronic service while retaining the existing method for paying bonds, ICE does not expect the rule to induce substantive access costs.
                </P>
                <P>
                    <E T="03">Validity Check—</E>
                    In creating the online account for obligors, ICE will perform a validity check as part of the sign-up process for receiving electronic bond-related notices and notifications, as users cannot complete their account creation if their email is not first validated. The time burden to perform this check will be based on how long it takes for ICE to submit a verification email to the provided email address and confirm the accuracy of that address. However, because this process will likely be automated via computer software that is already available to ICE (
                    <E T="03">see</E>
                     CeBONDS system development costs), ICE does not expect this process to produce a substantive cost.
                </P>
                <HD SOURCE="HD3">Total Estimated Costs</HD>
                <P>
                    Table 5 summarizes the quantified impact of this final rule. The total monetized costs of the rule do not include the development and annual maintenance costs required to operate the CeBONDS system given that they are not tied to this this final rule, as discussed above. The 10-year costs of the final rule are approximately $4.63 million and $4.09 million (in 2023 dollars) at 3 and 7 percent discount rates, respectively, and include the opportunity costs of familiarization and setting up an online account.
                    <PRTPAGE P="553"/>
                </P>
                <GPOTABLE COLS="4" OPTS="L2,i1" CDEF="s25,12,12,12">
                    <TTITLE>Table 5—Total Estimated Quantified Costs</TTITLE>
                    <BOXHD>
                        <CHED H="1">Year</CHED>
                        <CHED H="1">Undiscounted</CHED>
                        <CHED H="1">Discounted at 3%</CHED>
                        <CHED H="1">Discounted at 7%</CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">1</ENT>
                        <ENT>$2,374,761</ENT>
                        <ENT>$2,305,593</ENT>
                        <ENT>$2,219,402</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">2</ENT>
                        <ENT>308,632</ENT>
                        <ENT>290,915</ENT>
                        <ENT>269,571</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">3</ENT>
                        <ENT>308,632</ENT>
                        <ENT>282,442</ENT>
                        <ENT>251,935</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">4</ENT>
                        <ENT>308,632</ENT>
                        <ENT>274,215</ENT>
                        <ENT>235,454</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">5</ENT>
                        <ENT>308,632</ENT>
                        <ENT>266,228</ENT>
                        <ENT>220,050</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">6</ENT>
                        <ENT>308,632</ENT>
                        <ENT>258,474</ENT>
                        <ENT>205,654</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">7</ENT>
                        <ENT>308,632</ENT>
                        <ENT>250,946</ENT>
                        <ENT>192,200</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">8</ENT>
                        <ENT>308,632</ENT>
                        <ENT>243,637</ENT>
                        <ENT>179,626</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">9</ENT>
                        <ENT>308,632</ENT>
                        <ENT>236,540</ENT>
                        <ENT>167,875</ENT>
                    </ROW>
                    <ROW RUL="n,s">
                        <ENT I="01">10</ENT>
                        <ENT>308,632</ENT>
                        <ENT>229,651</ENT>
                        <ENT>156,893</ENT>
                    </ROW>
                    <ROW RUL="n,s">
                        <ENT I="03">Total</ENT>
                        <ENT>5,152,445</ENT>
                        <ENT>4,638,641</ENT>
                        <ENT>4,098,661</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="05">Annualized</ENT>
                        <ENT/>
                        <ENT>543,790</ENT>
                        <ENT>583,557</ENT>
                    </ROW>
                </GPOTABLE>
                <HD SOURCE="HD3">Cost Savings of the Final Rule</HD>
                <P>This alternative method of ICE's process for serving bond-related notices and issuing electronic bond-related notifications is expected to reduce labor costs for the government by reducing the time needed to process these notices, and it will eventually significantly reduce, if not eliminate, the costs of material items such as postage and paper that would otherwise be incurred for notices that are physically mailed. As mentioned above, ICE calculates quantitative benefits based on the assumption that new obligors are incentivized toward adoption into the eBONDS and CeBONDS systems within the first year of publishing this final rule.</P>
                <HD SOURCE="HD3">Cost Savings Due to Electronic Bond-Related Service Process</HD>
                <P>
                    <E T="03">Mailing Cost Savings</E>
                    —ICE estimated the cost-savings to government that will be obtained from a 100 percent adoption of electronic bond-related service process to be $609,594 per year (in 2023 dollars). To arrive at the full cost savings estimate, ICE calculated the average cost of sending physical notices by certified or first-class mail. Specifically, ICE calculated the time required for an ICE official to collect, process, and place in the mail each physical notice, which was 5 minutes. ICE divided the 5 minutes by 60 minutes per hour, and multiplied by $59.24, which is the fully loaded average hourly wage based on a General Schedule Grade 11, Step 10 salary, with a “Rest of U.S.” locality adjustment of 16.82 percent.
                    <SU>67</SU>
                    <FTREF/>
                     ICE based the fully loaded wage rate on the wage rate of $45.19 per hour, adjusted upward by 31.1 percent to account for compensation for benefits (in addition to wages).
                    <SU>68</SU>
                    <FTREF/>
                     This calculation resulted in an estimated labor cost of $4.94 per mailing. ICE then added this labor cost to the cost of materials (for the envelope, paper, etc.) 
                    <SU>69</SU>
                    <FTREF/>
                     and the postage per notice (which varies depending on the type of notice) to determine the various costs per notice. ICE then multiplied this total by the number of pieces that are mailed per notice (which also varies depending on the type of notice), and by the average total number of notices issued for each type. Table 6 displays how the total cost of $609,594 was derived.
                </P>
                <FTNT>
                    <P>
                        <SU>67</SU>
                         U.S. Office of Personnel Mgmt., Pay &amp; Leave (January 2024), 
                        <E T="03">https://www.opm.gov/policy-data-oversight/pay-leave/salaries-wages/salary-tables/24Tables/html/RUS_h.aspx</E>
                         (last visited Nov. 15, 2024).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>68</SU>
                         U.S. Dep't of Labor, Bureau of Labor Statistics, 
                        <E T="03">Employer Costs for Employe Compensation—December 2023</E>
                         (Mar. 13, 2024), 
                        <E T="03">https://www.bls.gov/news.release/archives/ecec_03132024.pdf.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>69</SU>
                         Cost per notice estimates provided by ERO Bond Management Unit and include, when applicable, costs for certified mail, postage, paper, envelopes, and materials (such as toner/ink), as of July 26, 2021.
                    </P>
                </FTNT>
                <GPOTABLE COLS="4" OPTS="L2,i1" CDEF="s100,13,12,12">
                    <TTITLE>Table 6—Government Cost Savings of Bond-Related Notices</TTITLE>
                    <BOXHD>
                        <CHED H="1">Notice type</CHED>
                        <CHED H="1">
                            Average
                            <LI>number of</LI>
                            <LI>notices mailed</LI>
                            <LI>(FY 2018-2020)</LI>
                        </CHED>
                        <CHED H="1">
                            Cost per
                            <LI>notice</LI>
                        </CHED>
                        <CHED H="1">Total cost</CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">I-391 Cash Bond Cancellations</ENT>
                        <ENT>15,317</ENT>
                        <ENT>$5.61</ENT>
                        <ENT>$85,928</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">I-340 Cash Bond Obligor to Deliver Alien</ENT>
                        <ENT>12,020</ENT>
                        <ENT>10.52</ENT>
                        <ENT>126,450</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">I-323 Cash Bond Breaches</ENT>
                        <ENT>7,128</ENT>
                        <ENT>10.52</ENT>
                        <ENT>74,987</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">I-340 Surety Bond Obligor to Deliver Alien</ENT>
                        <ENT>6,080</ENT>
                        <ENT>42.07</ENT>
                        <ENT>255,786</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">I-391 Surety Bond Cancellations</ENT>
                        <ENT>2,841</ENT>
                        <ENT>11.22</ENT>
                        <ENT>31,876</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">I-323 Surety Bond Breaches</ENT>
                        <ENT>1,412</ENT>
                        <ENT>21.04</ENT>
                        <ENT>29,708</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Surety Bond Motion to Reopen or Reconsider</ENT>
                        <ENT>306</ENT>
                        <ENT>11.22</ENT>
                        <ENT>3,433</ENT>
                    </ROW>
                    <ROW RUL="n,s">
                        <ENT I="01">Cash Bond Motion to Reopen or Reconsider</ENT>
                        <ENT>254</ENT>
                        <ENT>5.61</ENT>
                        <ENT>1,425</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">Totals</ENT>
                        <ENT>45,358</ENT>
                        <ENT>13.44</ENT>
                        <ENT>609,594</ENT>
                    </ROW>
                </GPOTABLE>
                <HD SOURCE="HD3">Total Estimated Quantified Savings</HD>
                <P>
                    Table 7 summarizes the quantified cost savings of this final rule. The total monetized savings of the rule includes the average cost savings for ICE of replacing physically mailed notices (by certified, registered, or regular mail) with electronic bond-related notices in the CeBONDS system, as well as emailed notifications. In order to capture these cost savings over the time horizon of the analysis, ICE assumed a 
                    <PRTPAGE P="554"/>
                    constant average rate of notices over a 10-year period. Thus, this estimate does not account for any change in the total number of notices that may occur in the future, or circumstances under which ICE needs to send paper notices by mail if emails fail, or the possibility of less than full adoption by the public. The 10-year cost-savings of the final rule in 2023 dollars are $5.1 million and $4.2 million at 3 and 7 percent discount rates, respectively.
                </P>
                <GPOTABLE COLS="4" OPTS="L2,i1" CDEF="s25,12,12,12">
                    <TTITLE>Table 7—Total Estimated Quantified Cost Savings</TTITLE>
                    <BOXHD>
                        <CHED H="1">Year</CHED>
                        <CHED H="1">Undiscounted</CHED>
                        <CHED H="1">Discounted at 3%</CHED>
                        <CHED H="1">Discounted at 7%</CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">1</ENT>
                        <ENT>$609,594</ENT>
                        <ENT>$591,839</ENT>
                        <ENT>$569,714</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">2</ENT>
                        <ENT>609,594</ENT>
                        <ENT>574,601</ENT>
                        <ENT>532,443</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">3</ENT>
                        <ENT>609,594</ENT>
                        <ENT>557,865</ENT>
                        <ENT>497,610</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">4</ENT>
                        <ENT>609,594</ENT>
                        <ENT>541,616</ENT>
                        <ENT>465,056</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">5</ENT>
                        <ENT>609,594</ENT>
                        <ENT>525,841</ENT>
                        <ENT>434,632</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">6</ENT>
                        <ENT>609,594</ENT>
                        <ENT>510,525</ENT>
                        <ENT>406,198</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">7</ENT>
                        <ENT>609,594</ENT>
                        <ENT>495,655</ENT>
                        <ENT>379,624</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">8</ENT>
                        <ENT>609,594</ENT>
                        <ENT>481,219</ENT>
                        <ENT>354,789</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">9</ENT>
                        <ENT>609,594</ENT>
                        <ENT>467,203</ENT>
                        <ENT>331,579</ENT>
                    </ROW>
                    <ROW RUL="n,s">
                        <ENT I="01">10</ENT>
                        <ENT>609,594</ENT>
                        <ENT>453,595</ENT>
                        <ENT>309,887</ENT>
                    </ROW>
                    <ROW RUL="n,s">
                        <ENT I="05">Total</ENT>
                        <ENT>6,095,937</ENT>
                        <ENT>5,199,958</ENT>
                        <ENT>4,281,531</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="05">Annualized</ENT>
                        <ENT/>
                        <ENT>609,594</ENT>
                        <ENT>609,594</ENT>
                    </ROW>
                </GPOTABLE>
                <HD SOURCE="HD3">Unquantified Benefits of the Final Rule</HD>
                <P>This alternative method of ICE's process, serving bond-related notices electronically and issuing electronic bond-related notifications, is expected to increase efficiency, accessibility, expedited delivery, and reliability of bond notices to the obligor. These benefits are described in more detail below.</P>
                <P>
                    <E T="03">Program Delivery</E>
                    —By serving bond-related notices electronically via the CeBONDS system and making bond obligors responsible for ensuring that electronic bond-related notifications can be received by email, ICE expects it will significantly reduce the number of bond-related notices that are not received by the obligor. A random sample of 100 delivery cash bonds that were declared as being breached during calendar years 2017-2019 indicates that approximately 28 percent of demand notices sent by certified mail to the obligor's address of record were returned as undeliverable or unclaimed.
                    <SU>70</SU>
                    <FTREF/>
                     The electronic bond-related service process will significantly reduce the occurrence of notices being lost in the mail during delivery, while still providing notifications in the event that obligors move from their physical address or are away from that address for an extended period of time. This process is also expected to reduce the likelihood that an obligor would miss the opportunity to appeal a bond breach determination in time, which would otherwise lead to the forfeiting of the bond amount. Additionally, in creating the online account for obligors, ICE will perform a validity check as part of the sign-up process for receiving electronic bond-related notices, as users cannot create an online account if their email is not validated. This use of a verified email address will ensure that the notifications have a high probability of being successfully delivered electronically to an email address that the obligor uses, ensuring that the notification reaches its proper recipient.
                </P>
                <FTNT>
                    <P>
                        <SU>70</SU>
                         Data obtained internally by DHS/ICE BMIS, Financial Service Center-Burlington, as of March 8, 2021.
                    </P>
                </FTNT>
                <P>ICE also intends to expedite delivery of notifications. For example, when an obligor chooses to post a bond online and receive bond-related notifications electronically, the system is designed to notify the obligor immediately by email when a notice has been issued. ICE, in turn, will also be able to confirm immediately the date that the cash bond obligor opens and views the notice. In this way, recipients can receive notifications without being present at their physical mailing address as long as they have access to the internet.</P>
                <P>
                    <E T="03">Paperless Records</E>
                    —The changes due to this final rule are consistent with the types of changes now being made across the federal government regarding the mechanisms through which federal offices deliver documents to the public. In accordance with the Government Paperwork Elimination Act,
                    <SU>71</SU>
                    <FTREF/>
                     electronic notifications will significantly reduce the use of paper and physical storage space.
                </P>
                <FTNT>
                    <P>
                        <SU>71</SU>
                         
                        <E T="03">See</E>
                         Public Law 105-277, tit. XVII, section 1703, 112 Stat. 2681, 2681-749 (Oct. 21, 1998), 44 U.S.C. 3504.
                    </P>
                </FTNT>
                <HD SOURCE="HD3">Alternative Analysis</HD>
                <P>Before proposing service of electronic bond-related notifications, ICE evaluated one alternative option that would affect the entities subject to the rule requirements, namely the no action alternative. The details of this option are described below, and Table 8 presents the unquantified costs and benefits for this alternative.</P>
                <GPOTABLE COLS="3" OPTS="L2,i1" CDEF="s50,r100,r100">
                    <TTITLE>Table 8—Summary of Alternatives</TTITLE>
                    <BOXHD>
                        <CHED H="1">Action</CHED>
                        <CHED H="1">Benefits</CHED>
                        <CHED H="1">Costs</CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">• Take No Action</ENT>
                        <ENT>• No familiarization, technology, or opportunity cost to public</ENT>
                        <ENT>
                            • Cost to process nonelectronic mail.
                            <LI>• Nonalignment with the Government Paperwork Elimination Act.</LI>
                        </ENT>
                    </ROW>
                    <ROW>
                        <ENT I="22"> </ENT>
                        <ENT O="xl"/>
                        <ENT>• No improvement in program delivery.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="22"> </ENT>
                        <ENT O="xl"/>
                        <ENT>• Costs to maintain physical records.</ENT>
                    </ROW>
                </GPOTABLE>
                <PRTPAGE P="555"/>
                <HD SOURCE="HD3">Alternative: Take No Action</HD>
                <P>ICE considered a “no action” alternative under which ICE would continue to serve bond-related notices to obligors for immigration bonds using personal or routine service, at a cost to both the federal government and the recipients.</P>
                <P>
                    The opportunity costs associated with electing a “no action” alternative would be equivalent to the current average cost to ICE of sending physical notices by certified or first-class mail, which ICE estimated to be $573,470 per year. ICE would still be required to process and mail notices by hand, and bond obligors would continue to receive physical notifications. This alternative also means that ICE would not be acting in alignment with government-wide efforts to shift agencies' business processes and recordkeeping to a fully electronic environment as encouraged by statutes like the Government Paperwork Elimination Act,
                    <SU>72</SU>
                    <FTREF/>
                     and more recently, the joint memorandum issued by OMB and the National Archives and Records Administration 
                    <SU>73</SU>
                    <FTREF/>
                     requiring the government to store records electronically. Additionally, this alternative of “no action” would also not result in any cost savings with regard to system development or deployment, because the eBONDS systems was already built and deployed independent of this final rule and the CeBONDS system is already being built and deployed independent of this final rule.
                </P>
                <FTNT>
                    <P>
                        <SU>72</SU>
                         Public Law 105-277, tit. XVII, section 1703, 112 Stat. 2681, 2681-749 (Oct. 21, 1998), 44 U.S.C. 3504.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>73</SU>
                         Office of Management and Budget, Transition to Electronic Records (OMB/NARA M-19-21) (June 28, 2019), 
                        <E T="03">https://www.archives.gov/files/records-mgmt/policy/m-19-21-transition-to-federal-records.pdf.</E>
                    </P>
                </FTNT>
                <P>The cost savings and benefits associated with this action involve the development, familiarization, technology, and opportunity costs associated with implementing this final rule. Absent the requirement to use the CeBONDS system, bond obligors would not face the potential costs associated with learning about the final rule, acquiring the necessary technological means to access the internet, or the expended time in creating an eBONDS or CeBONDS account.</P>
                <P>Additionally, any preference by obligors either to maintain physical records or to receive nonelectronic mail notices has already been considered in the development of final rule. As part of the process of deciding to post a bond electronically with ICE, the obligor will be informed that bond notices will be served electronically, and the obligor must agree to receive them electronically as well as bond-related electronic notifications. If the obligor does not wish to post a bond electronically or receive bond notices and notifications electronically, the obligor may post the bond in person at an ICE office and receive notices and other bond-related information via another form of authorized paper-based service.</P>
                <HD SOURCE="HD2">C. Regulatory Flexibility Act</HD>
                <P>
                    The Regulatory Flexibility Act of 1980 (RFA), 5 U.S.C. 601-612, as amended, requires Federal agencies to consider the potential impact of regulations on small entities during rulemaking. However, a regulatory flexibility analysis is not required when a rule is exempt from notice-and-comment rulemaking; therefore, since this action is exempt under the APA, it is not subject to the regulatory flexibility analysis requirements.
                    <SU>74</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>74</SU>
                         
                        <E T="03">See</E>
                         5 U.S.C. 604(a).
                    </P>
                </FTNT>
                <HD SOURCE="HD2">D. Small Business Regulatory Enforcement Fairness Act of 1996</HD>
                <P>
                    Under section 213(a) of the Small Business Regulatory Enforcement Fairness Act of 1996, Public Law 104-121, DHS wants to assist small entities in understanding this final rule so that they can better evaluate the effects on them and participate in the rulemaking. If the final rule would affect your small business, organization, or governmental jurisdiction, and you have questions concerning the provisions or options for compliance; please consult ICE using the contact information provided in the 
                    <E T="02">FOR FURTHER INFORMATION</E>
                     section above.
                </P>
                <HD SOURCE="HD2">E. Congressional Review Act</HD>
                <P>
                    This final rule is not a major rule as defined by 5 U.S.C. 804, also known as the “Congressional Review Act,” as enacted in section 251 of the Small Business Regulatory Enforcement Fairness Act of 1996, Public Law 104-121, 110 Stat. 847, 868 
                    <E T="03">et seq.</E>
                     This final rule would not result in an annual effect on the economy of $100 million or more; a major increase in costs or prices; or significant adverse effects on competition, employment, investment, productivity, innovation, or the ability of U.S.-based companies to compete with foreign based companies in domestic and export markets. A report about the issuance of this final rule has been submitted to Congress and the Comptroller General of the United States.
                </P>
                <HD SOURCE="HD2">F. Unfunded Mandates Reform Act</HD>
                <P>The Unfunded Mandates Reform Act of 1995 (2 U.S.C. 1531-1538) requires federal agencies to assess the effects of their discretionary regulatory actions. In particular, the Unfunded Mandates Reform Act addresses actions that may result in the expenditure by a State, local, or tribal government, in the aggregate, or by the private sector of $100,000,000 (adjusted for inflation) or more in any year. Though this final rule would not result in such an expenditure, DHS does discuss the effects of this rule elsewhere in this preamble.</P>
                <HD SOURCE="HD2">G. Paperwork Reduction Act—Collection of Information</HD>
                <P>
                    All Departments are required to submit to OMB for review and approval any reporting or recordkeeping requirements inherent in a rule under the Paperwork Reduction Act of 1995 (PRA), Public Law 104-13, 109 Stat. 163 (codified at 44 U.S.C. 3501 
                    <E T="03">et seq.</E>
                    ). Under the PRA, an agency may not conduct or sponsor, and a person is not required to respond to, a collection of information unless the agency obtains approval from OMB for the collection and the collection displays a valid OMB control number. 
                    <E T="03">See</E>
                     44 U.S.C. 3506, 3507.
                </P>
                <P>
                    With respect to immigration bonds, regardless of using either eBONDS or CeBONDS, there would be no changes to the reporting burden for the existing collection of information associated with Form I-352, 
                    <E T="03">Immigration Bond</E>
                     (OMB control number 1653-0022) or Form I-333, 
                    <E T="03">Obligor Change of Address</E>
                     (OMB control number 1653-0042). There are no substantive changes to those forms because of this rule. If DHS identifies any impacts that would modify or create a new collection, DHS will submit a revision to OMB at that time.
                </P>
                <HD SOURCE="HD2">H. Executive Order 13132: Federalism</HD>
                <P>
                    A rule has implications for federalism under Executive Order 13132, 
                    <E T="03">Federalism,</E>
                     if it has a substantial direct effect on State or local governments and would either preempt State law or impose a substantial direct cost of compliance on them. DHS has analyzed this final rule under Executive Order 13132 and determined that it does not have implications for federalism.
                </P>
                <HD SOURCE="HD2">I. Executive Order 12988: Civil Justice Reform</HD>
                <P>
                    This final rule meets applicable standards in sections 3(a) and 3(b)(2) of Executive Order 12988, 
                    <E T="03">Civil Justice Reform,</E>
                     to eliminate drafting errors and ambiguity, minimize litigation, provide 
                    <PRTPAGE P="556"/>
                    a clear legal standard for affected conduct, and promote simplification and burden reduction.
                </P>
                <HD SOURCE="HD2">J. Executive Order 13211: Actions Concerning Regulations That Significantly Affect Energy Supply, Distribution, or Use</HD>
                <P>
                    DHS analyzed this final rule under Executive Order 13211, 
                    <E T="03">Actions Concerning Regulations That Significantly Affect Energy Supply, Distribution, or Use.</E>
                     DHS has determined that it is not a “significant energy action” under that order because it is not a “significant regulatory action” under Executive Order 12866 and is not likely to have a significant adverse effect on the supply, distribution, or use of energy.
                </P>
                <HD SOURCE="HD2">K. National Environmental Policy Act (NEPA)</HD>
                <P>The U.S. Department of Homeland Security Management Directive (MD) 023-01, Rev. 01 establishes procedures that DHS and its Components use to comply with the National Environmental Policy Act of 1969 (NEPA), 42 U.S.C. 4321-4375, and the Council on Environmental Quality (CEQ) regulations for implementing NEPA, 40 CFR parts 1500-1508.</P>
                <P>CEQ regulations allow federal agencies to establish categories of actions, which do not individually or cumulatively have a significant effect on the human environment and, therefore, do not require an Environmental Assessment or Environmental Impact Statement. 40 CFR 1508.4. The DHS Categorical Exclusions are listed in IM 023-01-001-01 Rev. 01, Appendix A, Table 1.</P>
                <P>For an action to be categorically excluded, MD 023-01 requires the action to satisfy each of the following three conditions:</P>
                <P>(1) The entire action clearly fits within one or more of the Categorical Exclusions;</P>
                <P>(2) The action is not a piece of a larger action; and</P>
                <P>(3) No extraordinary circumstances exist that create the potential for a significant environmental effect. IM 023-01-001-01 Rev. 01 §  V(B)(2)(a)-(c). If the action does not clearly meet all three conditions, DHS or the Component prepares an Environmental Assessment or Environmental Impact Statement, according to CEQ requirements, MD 023-01, and IM 023-01-001-01 Rev. 01.</P>
                <P>ICE has analyzed this rule under MD 023-01 Rev. 01 and IM 023-01-001-01 Rev.01. ICE has made the determination that this rulemaking action is one of a category of actions, which does not individually or cumulatively have a significant effect on the human environment. This final rule clearly fits within the Categorical Exclusion found in IM 023-01-001-01 Rev. 01, Appendix A, Table 1, number A3(d): “Promulgation of rules . . . that interpret or amend an existing regulation without changing its environmental effect.” This final rule is not part of a larger action. This final rule presents no extraordinary circumstances creating the potential for significant environmental effects. Therefore, this final rule is categorically excluded from further NEPA review.</P>
                <HD SOURCE="HD2">L. Executive Order 13175: Consultation and Coordination With Indian Tribal Governments</HD>
                <P>
                    This final rule does not have tribal implications under Executive Order 13175, 
                    <E T="03">Consultation and Coordination with Indian Tribal Governments,</E>
                     because it would not have a substantial direct effect on one or more Indian tribes, on the relationship between the Federal Government and Indian tribes, or on the distribution of power and responsibilities between the Federal Government and Indian tribes.
                </P>
                <HD SOURCE="HD2">M. Executive Order 12630: Governmental Actions and Interference With Constitutionally Protected Property Rights</HD>
                <P>
                    This final rule would not cause a taking of private property or otherwise have taking implications under Executive Order 12630, 
                    <E T="03">Governmental Actions and Interference with Constitutionally Protected Property Rights.</E>
                </P>
                <HD SOURCE="HD2">N. Executive Order 13045: Protection of Children From Environmental Health Risks and Safety Risks</HD>
                <P>Executive Order 13045 requires agencies to consider the impacts of environmental health risk or safety risk that may disproportionately affect children. DHS has reviewed this final rule and determined that this final rule is not an economically significant rule and would not create an environmental risk to health or risk to safety that might disproportionately affect children. Therefore, DHS has not prepared a statement under this executive order.</P>
                <HD SOURCE="HD2">O. National Technology Transfer and Advancement Act</HD>
                <P>
                    The National Technology Transfer and Advancement Act of 1995 (15 U.S.C. 272 note) directs agencies to use voluntary consensus standards in their regulatory activities unless the agency provides Congress, through the Office of Management and Budget, with an explanation of why using these standards would be inconsistent with applicable law or otherwise impracticable. Voluntary consensus standards are technical standards (
                    <E T="03">e.g.,</E>
                     specifications of materials, performance, design, or operation; test methods; sampling procedures; and related management systems practices) that are developed or adopted by voluntary consensus standards bodies. This final rule does not use technical standards. Therefore, DHS did not consider the use of voluntary consensus standards.
                </P>
                <HD SOURCE="HD2">P. Family Assessment</HD>
                <P>DHS has determined that this final rule action will not affect family well-being within the meaning of section 654 of the Treasury and General Government Appropriations Act, enacted as part of the Omnibus Consolidated and Emergency Supplemental Appropriations Act of 1999 (Pub. L. 105-277, 112 Stat. 2681).</P>
                <LSTSUB>
                    <HD SOURCE="HED">List of Subjects</HD>
                    <CFR>8 CFR Part 103</CFR>
                    <P>Administrative practice and procedures, Authority delegations (government agencies), Fees, Freedom of Information, Immigration, Privacy, Reporting and recordkeeping requirements, Surety bonds. </P>
                </LSTSUB>
                <HD SOURCE="HD1">Regulatory Amendments</HD>
                <P>Accordingly, DHS amends chapter I of title 8 of the Code of Federal Regulations as follows:</P>
                <PART>
                    <HD SOURCE="HED">PART 103—IMMIGRATION BENEFITS; BIOMETRIC RECORDS; AVAILABILITY OF RECORDS</HD>
                </PART>
                <REGTEXT TITLE="8" PART="103">
                    <AMDPAR>1. The authority citation for part 103 continues to read as follows:</AMDPAR>
                    <AUTH>
                        <HD SOURCE="HED">Authority:</HD>
                        <P>
                             5 U.S.C. 301, 552, 552a; 8 U.S.C. 1101, 1103, 1304, 1356, 1356b, 1372; 31 U.S.C. 9701; Pub. L. 107-296, 116 Stat. 2135 (6 U.S.C. 101 
                            <E T="03">et seq.</E>
                            ); Pub. L. 112-54, 125 Stat 550 (8 U.S.C. 1185 note); E.O. 12356, 47 FR 14874, 15557, 3 CFR, 1982 Comp., p. 166; 8 CFR part 2; Pub. L. 112-54; 125 Stat. 550; 31 CFR part 223.
                        </P>
                    </AUTH>
                </REGTEXT>
                <REGTEXT TITLE="8" PART="103">
                    <AMDPAR>2. Amend § 103.6 by revising paragraphs (g) and (h) to read as follows:</AMDPAR>
                    <SECTION>
                        <SECTNO>§ 103.6 </SECTNO>
                        <SUBJECT>Immigration bonds.</SUBJECT>
                        <STARS/>
                        <P>
                            (g) 
                            <E T="03">Delivery bond notices to surrender aliens.</E>
                             Notwithstanding the requirements of § 103.8 for the service of other notices, ICE may serve demand notices electronically to bond obligors who consent to electronic delivery of service, or by any mail service that allows delivery confirmation to cause an alien who has been released from DHS custody on an immigration bond to 
                            <PRTPAGE P="557"/>
                            appear at an ICE office or an immigration court. An electronic record from the ICE bonds system showing that the bond obligor opened the demand notice will constitute valid proof of service of the notice. If ICE cannot confirm proof of service of the electronic notice, ICE will issue a new demand notice to the bond obligor's last known address using any mail service that allows delivery confirmation.
                        </P>
                        <P>
                            (h) 
                            <E T="03">Bond breach, bond cancellation, and other bond notices.</E>
                             Notwithstanding the service requirements for demand notices in paragraph (g) of this section, ICE may serve any other bond-related notices that pertain to delivery, order of supervision, or voluntary departure immigration bonds, such as bond breach or cancellation notices, electronically to obligors who consent to electronic delivery of service, or by ordinary mail. An electronic record from the ICE bonds system showing that the bond obligor opened the bond-related notice will constitute valid proof of service of the notice. If ICE cannot confirm proof of service of the electronic notice, ICE will reissue another notice to the bond obligor's last known address using ordinary mail.
                        </P>
                    </SECTION>
                </REGTEXT>
                <SIG>
                    <NAME>Alejandro N. Mayorkas,</NAME>
                    <TITLE>Secretary, U.S. Department of Homeland Security.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31358 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 9111-CB-P</BILCOD>
        </RULE>
        <RULE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <SUBAGY>Federal Aviation Administration</SUBAGY>
                <CFR>14 CFR Part 71</CFR>
                <DEPDOC>[Docket No. FAA-2023-2222; Airspace Docket No. 23-AGL-32]</DEPDOC>
                <RIN>RIN 2120-AA66</RIN>
                <SUBJECT>Establishment of Class E Airspace; Redfield, SD</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Federal Aviation Administration (FAA), DOT.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Final rule.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>This action establishes Class E airspace at Redfield, SD. This action due to the development of new public instrument procedures and to support instrument flight rule (IFR) operations.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Effective 0901 UTC, April 17, 2025. The Director of the Federal Register approves this incorporation by reference action under 1 CFR part 51, subject to the annual revision of FAA Order JO 7400.11 and publication of conforming amendments.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        A copy of the Notice of Proposed Rulemaking (NPRM), all comments received, this final rule, and all background material may be viewed online at 
                        <E T="03">www.regulations.gov</E>
                         using the FAA Docket number. Electronic retrieval help and guidelines are available on the website. It is available 24 hours each day, 365 days each year.
                    </P>
                    <P>
                        FAA Order JO 7400.11J, Airspace Designations and Reporting Points, and subsequent amendments can be viewed online at 
                        <E T="03">www.faa.gov/air_traffic/publications/</E>
                        . You may also contact the Rules and Regulations Group, Office of Policy, Federal Aviation Administration, 800 Independence Avenue SW, Washington, DC 20591; telephone: (202) 267-8783.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Jeffrey Claypool, Federal Aviation Administration, Operations Support Group, Central Service Center, 10101 Hillwood Parkway, Fort Worth, TX 76177; telephone (817) 222-5711.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">Authority for This Rulemaking</HD>
                <P>The FAA's authority to issue rules regarding aviation safety is found in Title 49 of the United States Code. Subtitle I, Section 106 describes the authority of the FAA Administrator. Subtitle VII, Aviation Programs, describes in more detail the scope of the agency's authority. This rulemaking is promulgated under the authority described in Subtitle VII, Part A, Subpart I, Section 40103. Under that section, the FAA is charged with prescribing regulations to assign the use of airspace necessary to ensure the safety of aircraft and the efficient use of airspace. This regulation is within the scope of that authority as it establishes Class E airspace extending upward from 700 feet above the surface at Redfield Municipal Airport, Redfield, SD, to support IFR operations at this airport.</P>
                <HD SOURCE="HD1">History</HD>
                <P>
                    The FAA published an NPRM for Docket No. FAA-2023-2222 in the 
                    <E T="04">Federal Register</E>
                     (88 FR 83874; December 1, 2023) proposing to establish Class E airspace at Redfield, SD. Interested parties were invited to participate in this rulemaking effort by submitting written comments on the proposal to the FAA. No comments were received.
                </P>
                <HD SOURCE="HD1">Incorporation by Reference</HD>
                <P>
                    Class E airspace designations are published in paragraph 6005 of FAA Order JO 7400.11, Airspace Designations and Reporting Points, which is incorporated by reference in 14 CFR 71.1 on an annual basis. This document amends the current version of that order, FAA Order JO 7400.11J, dated July 31, 2024, and effective September 15, 2024. FAA Order JO 7400.11J is publicly available as listed in the 
                    <E T="02">ADDRESSES</E>
                     section of this document. These amendments will be published in the next update to FAA Order JO 7400.11.
                </P>
                <P>FAA Order JO 7400.11J lists Class A, B, C, D, and E airspace areas, air traffic service routes, and reporting points.</P>
                <HD SOURCE="HD1">The Rule</HD>
                <P>This amendment to 14 CFR part 71 establishes Class E airspace extending upward from 700 feet above the surface to within a 6.3-mile radius of Redfield Municipal Airport, Redfield, SD.</P>
                <HD SOURCE="HD1">Regulatory Notices and Analyses</HD>
                <P>The FAA has determined that this regulation only involves an established body of technical regulations for which frequent and routine amendments are necessary to keep them operationally current. It, therefore: (1) is not a “significant regulatory action” under Executive Order 12866; (2) is not a “significant rule” under DOT Regulatory Policies and Procedures (44 FR 11034; February 26, 1979); and (3) does not warrant preparation of a regulatory evaluation as the anticipated impact is so minimal. Since this is a routine matter that only affects air traffic procedures and air navigation, it is certified that this rule, when promulgated, does not have a significant economic impact on a substantial number of small entities under the criteria of the Regulatory Flexibility Act.</P>
                <HD SOURCE="HD1">Environmental Review</HD>
                <P>The FAA has determined that this action qualifies for categorical exclusion under the National Environmental Policy Act in accordance with FAA Order 1050.1F, “Environmental Impacts: Policies and Procedures,” paragraph 5-6.5.a. This airspace action is not expected to cause any potentially significant environmental impacts, and no extraordinary circumstances exist that warrant preparation of an environmental assessment.</P>
                <LSTSUB>
                    <HD SOURCE="HED">Lists of Subjects in 14 CFR 71</HD>
                    <P>Airspace, Incorporation by reference, Navigation (air).</P>
                </LSTSUB>
                <HD SOURCE="HD1">The Amendment</HD>
                <P>In consideration of the foregoing, the Federal Aviation Administration amends 14 CFR part 71 as follows:</P>
                <PART>
                    <PRTPAGE P="558"/>
                    <HD SOURCE="HED">PART 71—DESIGNATION OF CLASS A, B, C, D, AND E AIRSPACE AREAS; AIR TRAFFIC SERVICE ROUTES; AND REPORTING POINTS</HD>
                </PART>
                <REGTEXT TITLE="14" PART="71">
                    <AMDPAR>1. The authority citation for 14 CFR part 71 continues to read as follows:</AMDPAR>
                    <AUTH>
                        <HD SOURCE="HED">Authority:</HD>
                        <P>49 U.S.C. 106(f); 40103, 40113, 40120; E.O. 10854, 24 FR 9565, 3 CFR, 1959-1963 Comp., p. 389.</P>
                    </AUTH>
                </REGTEXT>
                <SECTION>
                    <SECTNO>§ 71.1 </SECTNO>
                    <SUBJECT>[Amended]</SUBJECT>
                </SECTION>
                <REGTEXT TITLE="14" PART="71">
                    <AMDPAR>2. The incorporation by reference in 14 CFR 71.1 of FAA Order JO 7400.11J, Airspace Designations and Reporting Points, dated July 31, 2024, and effective September 15, 2024, is amended as follows:</AMDPAR>
                    <EXTRACT>
                        <HD SOURCE="HD2">Paragraph 6005 Class E Airspace Areas Extending Upward From 700 Feet or More Above the Surface of the Earth.</HD>
                        <STARS/>
                        <HD SOURCE="HD1">AGL SD E5 Redfield, SD [Establish]</HD>
                        <FP SOURCE="FP-2">Redfield Municipal Airport, SD</FP>
                        <FP SOURCE="FP1-2">(Lat. 44°51′24″ N, long. 98°31′52″ W)</FP>
                        <P>That airspace extending upward from 700 feet above the surface within a 6.3-mile radius of Redfield Municipal Airport.</P>
                    </EXTRACT>
                    <STARS/>
                </REGTEXT>
                <SIG>
                    <DATED>Issued in Fort Worth, Texas, on December 31, 2024.</DATED>
                    <NAME>Martin A. Skinner,</NAME>
                    <TITLE>Acting Manager, Operations Support Group, ATO Central Service Center.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31635 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4910-13-P</BILCOD>
        </RULE>
        <RULE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <SUBAGY>Federal Aviation Administration</SUBAGY>
                <CFR>14 CFR Part 71</CFR>
                <DEPDOC>[Docket No. FAA-2024-1710; Airspace Docket No. 24-AGL-15]</DEPDOC>
                <RIN>RIN 2120-AA66</RIN>
                <SUBJECT>Establishment of Class E Airspace; Ashley, ND</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Federal Aviation Administration (FAA), DOT.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Final rule.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>This action establishes Class E airspace at Ashley, ND. This action is due to the development of new public instrument procedures at Ashley Municipal Airport, Ashley, ND, and to support instrument flight rule (IFR) operations.</P>
                </SUM>
                <EFFDATE>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Effective 0901 UTC, April 17, 2025. The Director of the Federal Register approves this incorporation by reference action under 1 CFR part 51, subject to the annual revision of FAA Order JO 7400.11 and publication of conforming amendments.</P>
                </EFFDATE>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        A copy of the Notice of Proposed Rulemaking (NPRM), all comments received, this final rule, and all background material may be viewed online at 
                        <E T="03">www.regulations.gov</E>
                         using the FAA Docket number. Electronic retrieval help and guidelines are available on the website. It is available 24 hours each day, 365 days each year.
                    </P>
                    <P>
                        FAA Order JO 7400.11J, Airspace Designations and Reporting Points, and subsequent amendments can be viewed online at 
                        <E T="03">www.faa.gov/air_traffic/publications/.</E>
                         You may also contact the Rules and Regulations Group, Office of Policy, Federal Aviation Administration, 800 Independence Avenue SW, Washington, DC 20591; telephone: (202) 267-8783.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Jeffrey Claypool, Federal Aviation Administration, Operations Support Group, Central Service Center, 10101 Hillwood Parkway, Fort Worth, TX 76177; telephone (817) 222-5711.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">Authority for This Rulemaking</HD>
                <P>The FAA's authority to issue rules regarding aviation safety is found in Title 49 of the United States Code. Subtitle I, Section 106 describes the authority of the FAA Administrator. Subtitle VII, Aviation Programs, describes in more detail the scope of the agency's authority. This rulemaking is promulgated under the authority described in Subtitle VII, Part A, Subpart I, Section 40103. Under that section, the FAA is charged with prescribing regulations to assign the use of airspace necessary to ensure the safety of aircraft and the efficient use of airspace. This regulation is within the scope of that authority as it establishes Class E airspace extending upward from 700 feet above the surface at Ashley Municipal Airport, Ashley, ND, to support IFR operations at this airport.</P>
                <HD SOURCE="HD1">History</HD>
                <P>
                    The FAA published an NPRM for Docket No. FAA-2024-1710 in the 
                    <E T="04">Federal Register</E>
                     (89 FR 50540; June 14, 2024) proposing to establish Class E airspace at Ashley, ND. Interested parties were invited to participate in this rulemaking effort by submitting written comments on the proposal to the FAA. No comments were received.
                </P>
                <HD SOURCE="HD1">Incorporation by Reference</HD>
                <P>
                    Class E airspace designations are published in paragraph 6005 of FAA Order JO 7400.11, Airspace Designations and Reporting Points, which is incorporated by reference in 14 CFR 71.1 on an annual basis. This document amends the current version of that order, FAA Order JO 7400.11J, dated July 31, 2024, and effective September 15, 2024. FAA Order JO 7400.11J is publicly available as listed in the 
                    <E T="02">ADDRESSES</E>
                     section of this document. These amendments will be published in the next update to FAA Order JO 7400.11.
                </P>
                <P>FAA Order JO 7400.11J lists Class A, B, C, D, and E airspace areas, air traffic service routes, and reporting points.</P>
                <HD SOURCE="HD1">The Rule</HD>
                <P>This amendment to 14 CFR part 71 establishes Class E airspace extending upward from 700 feet above the surface to within a 7.2-mile radius of Ashley Municipal Airport, Ashley, ND.</P>
                <HD SOURCE="HD1">Regulatory Notices and Analyses</HD>
                <P>The FAA has determined that this regulation only involves an established body of technical regulations for which frequent and routine amendments are necessary to keep them operationally current. It, therefore: (1) is not a “significant regulatory action” under Executive Order 12866; (2) is not a “significant rule” under DOT Regulatory Policies and Procedures (44 FR 11034; February 26, 1979); and (3) does not warrant preparation of a regulatory evaluation as the anticipated impact is so minimal. Since this is a routine matter that only affects air traffic procedures and air navigation, it is certified that this rule, when promulgated, does not have a significant economic impact on a substantial number of small entities under the criteria of the Regulatory Flexibility Act.</P>
                <HD SOURCE="HD1">Environmental Review</HD>
                <P>The FAA has determined that this action qualifies for categorical exclusion under the National Environmental Policy Act in accordance with FAA Order 1050.1F, “Environmental Impacts: Policies and Procedures,” paragraph 5-6.5.a. This airspace action is not expected to cause any potentially significant environmental impacts, and no extraordinary circumstances exist that warrant preparation of an environmental assessment.</P>
                <LSTSUB>
                    <HD SOURCE="HED">Lists of Subjects in 14 CFR 71</HD>
                    <P>Airspace, Incorporation by reference, Navigation (air).</P>
                </LSTSUB>
                <HD SOURCE="HD1">The Amendment</HD>
                <P>In consideration of the foregoing, the Federal Aviation Administration amends 14 CFR part 71 as follows:</P>
                <PART>
                    <PRTPAGE P="559"/>
                    <HD SOURCE="HED">PART 71—DESIGNATION OF CLASS A, B, C, D, AND E AIRSPACE AREAS; AIR TRAFFIC SERVICE ROUTES; AND REPORTING POINTS</HD>
                </PART>
                <REGTEXT TITLE="14" PART="71">
                    <AMDPAR>1. The authority citation for 14 CFR part 71 continues to read as follows:</AMDPAR>
                    <AUTH>
                        <HD SOURCE="HED">Authority:</HD>
                        <P>49 U.S.C. 106(f); 40103, 40113, 40120; E.O. 10854, 24 FR 9565, 3 CFR, 1959-1963 Comp., p. 389.</P>
                    </AUTH>
                </REGTEXT>
                <SECTION>
                    <SECTNO>§ 71.1 </SECTNO>
                    <SUBJECT> [Amended]</SUBJECT>
                </SECTION>
                <REGTEXT TITLE="14" PART="71">
                    <AMDPAR>2. The incorporation by reference in 14 CFR 71.1 of FAA Order JO 7400.11J, Airspace Designations and Reporting Points, dated July 31, 2024, and effective September 15, 2024, is amended as follows:</AMDPAR>
                    <EXTRACT>
                        <HD SOURCE="HD2">Paragraph 6005 Class E Airspace Areas Extending Upward From 700 Feet or More Above the Surface of the Earth.</HD>
                        <STARS/>
                        <HD SOURCE="HD1">AGL ND E5 Ashley, ND [Establish]</HD>
                        <FP SOURCE="FP-2">Ashley Municipal Airport, ND</FP>
                        <FP SOURCE="FP1-2">(Lat. 46°01′23″ N, long. 99°21′09″ W)</FP>
                        <P>That airspace extending upward from 700 feet above the surface within a 7.2-mile radius of Ashley Municipal Airport.</P>
                    </EXTRACT>
                </REGTEXT>
                <STARS/>
                <SIG>
                    <DATED>Issued in Fort Worth, Texas, on December 31, 2024.</DATED>
                    <NAME>Martin A. Skinner,</NAME>
                    <TITLE>Acting Manager, Operations Support Group, ATO Central Service Center.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31637 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4910-13-P</BILCOD>
        </RULE>
        <RULE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF COMMERCE</AGENCY>
                <SUBAGY>Bureau of Industry and Security</SUBAGY>
                <CFR>15 CFR Part 744</CFR>
                <DEPDOC>[Docket No. 241217-0329]</DEPDOC>
                <RIN>RIN 0694-AJ99</RIN>
                <SUBJECT>Revisions to the Entity List</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Bureau of Industry and Security, Department of Commerce.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Final rule.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>In this rule, the Bureau of Industry and Security (BIS) amends the Export Administration Regulations (EAR) by adding 13 entities under 13 entries to the Entity List. These entries are listed on the Entity List under the destinations of Burma (1), China, People's Republic of (China) (11), and Pakistan (1). These entities have been determined by the U.S. Government to be acting contrary to the national security and/or foreign policy interests of the United States. This rule also amends the EAR by making certain editorial corrections and clarifications. BIS is making the corrections and clarifications in order to minimize confusion and not impede the free flow of commerce.</P>
                </SUM>
                <EFFDATE>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>This rule is effective January 6, 2025.</P>
                </EFFDATE>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Chair, End-User Review Committee, Office of the Assistant Secretary for Export Administration, Bureau of Industry and Security, Department of Commerce, Phone: (202) 482-5991, Email: 
                        <E T="03">ERC@bis.doc.gov</E>
                        .
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">Background</HD>
                <P>
                    The Entity List (supplement no. 4 to part 744 of the EAR (15 CFR parts 730-774)) identifies entities for which there is reasonable cause to believe, based on specific and articulable facts, have been involved, are involved, or pose a significant risk of being or becoming involved in activities contrary to the national security or foreign policy interests of the United States, pursuant to § 744.11(b) of the EAR. The EAR impose additional license requirements on and limit the availability of most license exceptions for exports, reexports, and transfers (in-country) when a listed entity is a party to the transaction. The license review policy for each listed entity is identified in the “License Review Policy” column on the Entity List, and the impact on the availability of license exceptions is described in the relevant 
                    <E T="04">Federal Register</E>
                     document that added the entity to the Entity List. BIS places entities on the Entity List pursuant to parts 744 (Control Policy: End-User and End-Use Based) and 746 (Embargoes and Other Special Controls) of the EAR.
                </P>
                <P>The End-User Review Committee (ERC), composed of representatives of the Departments of Commerce (Chair), State, Defense, Energy and, where appropriate, the Treasury, makes all decisions regarding additions to, removals from, or other modifications to the Entity List. The ERC makes all decisions to add an entry to the Entity List by majority vote and makes all decisions to remove or modify an entry by unanimous vote.</P>
                <HD SOURCE="HD2">Additions to the Entity List</HD>
                <P>The ERC determined to add Telecom International Myanmar Company Limited, under the destination of Burma, to the Entity List. This addition is based on actions and activities that are contrary to the national security and foreign policy interests of the United States under § 744.11 of the EAR. Specifically, this entity is being added for providing surveillance services and financial support to Burma's military regime, enabling the regime to carry out human rights abuses through the tracking and identification of target individuals and groups. A license is required for the export, reexport and transfer (in-country) of all items subject to the EAR to this entity and license applications will be reviewed under a presumption of denial.</P>
                <P>The ERC has determined to add Chengdu RML Technology Co., Ltd.; Chengdu Yaguang Electronics Co., Ltd.; Hefei Starwave Communication Technology Co., Ltd.; and Yaguang Technology Group Co., Ltd., all under the destination of China, to the Entity List. These entities are added for acquiring and attempting to acquire U.S.-origin items in support of China's military modernization. Specifically, Chengdu RML Technology Co., Ltd. has supplied the People's Liberation Army (PLA) with precision-guided missiles and satellite communication systems. Chengdu Yaguang Electronics Co., Ltd. and its parent company, Yaguang Technology Group Co., Ltd., have supplied the PLA and multiple Chinese parties on the Entity List with dual-use electronic components. Lastly, Hefei Starwave Communication Technology Co., Ltd. has supplied radio frequency/microwave products explicitly for military equipment application to the PLA and Chinese parties on the Entity List. These activities are contrary to the national security and foreign policy interests of the United States under § 744.11 of the EAR. These entities are added with a license requirement for the export, reexport and transfer (in-country) of all items subject to the EAR and a license review policy of a presumption of denial.</P>
                <P>
                    The ERC determined to add the following seven entities, all under the destination of China, to the Entity List: Chinese Academy of Sciences Changchun Institute of Optics, Fine Mechanics, and Physics; Ji Hua Laboratory; Nanjing Simite Optical Instruments Co., Ltd.; Peng Cheng Laboratory; Shanghai Institute of Optics and Fine Mechanics; Suzhou Ultranano Precision Optoelectronics Technology Co., Ltd.; and Wuhu Kewei Zhaofu Electronics Co., Ltd. These entities are being added for acquiring and attempting to acquire U.S.-origin items in support of China's military modernization. In addition, these entities have demonstrable ties to activities of concern, including hypersonic weapons development, design and modeling of vehicles in hypersonic flight, using proprietary software to model weapons design and damage; and otherwise supporting 
                    <PRTPAGE P="560"/>
                    China's military-civil fusion efforts. These activities are contrary to the national security and foreign policy interests of the United States under §  744.11 of the EAR. These entities are added with a license requirement for the export, reexport, and transfer (in-country) of all items subject to the EAR and a license review policy of presumption of denial.
                </P>
                <P>Finally, the ERC determined to add Emerging Future Solutions Private Limited, under the destination of Pakistan, to the Entity List. This addition is made as a result of the entity's contributions to Pakistan's ballistic missile program. This activity is contrary to U.S. national security and foreign policy interests under § 744.11 of the EAR. This entity is added with a license requirement for the export, reexport and transfer (in-country) of all items subject to the EAR and a license application review policy of a presumption of denial.</P>
                <P>For the reasons described above, this final rule adds the following 13 entities under 13 entries to the Entity List and includes, where appropriate, aliases:</P>
                <HD SOURCE="HD3">Burma</HD>
                <P>• Telecom International Myanmar Company Limited</P>
                <HD SOURCE="HD3">China</HD>
                <P>• Chengdu RML Technology Co., Ltd.,</P>
                <P>• Chengdu Yaguang Electronics Co., Ltd.,</P>
                <P>• Chinese Academy of Sciences Changchun Institute of Optics, Fine Mechanics, and Physics,</P>
                <P>• Hefei Starwave Communication Technology Co., Ltd.,</P>
                <P>• Ji Hua Laboratory,</P>
                <P>• Nanjing Simite Optical Instruments Co., Ltd.,</P>
                <P>• Peng Cheng Laboratory,</P>
                <P>• Shanghai Institute of Optics and Fine Mechanics,</P>
                <P>• Suzhou Ultranano Precision Optoelectronics Technology Co., Ltd.,</P>
                <P>
                    • Wuhu Kewei Zhaofu Electronics Co., Ltd., 
                    <E T="03">and</E>
                </P>
                <P>• Yaguang Technology Group Co., Ltd.</P>
                <HD SOURCE="HD3">Pakistan</HD>
                <P>• Emerging Future Solutions Private Limited.</P>
                <HD SOURCE="HD2">Corrections to the Entity List</HD>
                <P>This final rule also corrects one spelling error and two punctuation errors in the addresses listed for the entry of Shenzhen Guowei Sensing Technology Co., Ltd. This entity was originally added to the Entity List on December 2, 2024, in a final rule published on December 5, 2024 (89 FR 96830).</P>
                <HD SOURCE="HD2">Savings Clause</HD>
                <P>For the changes being made in this final rule, shipments of items removed from eligibility for a License Exception or export, reexport, or transfer (in-country) without a license (NLR) as a result of this regulatory action that were en route aboard a carrier to a port of export, reexport, or transfer (in-country), on January 6, 2025, pursuant to actual orders for export, reexport, or transfer (in-country) to or within a foreign destination, may proceed to that destination under the previous eligibility for a License Exception or export, reexport, or transfer (in-country) without a license (NLR) before February 5, 2025. Any such items not actually exported, reexported, or transferred (in-country) before midnight, on February 5, 2025, require a license in accordance with this final rule.</P>
                <HD SOURCE="HD1">Export Control Reform Act of 2018</HD>
                <P>On August 13, 2018, the President signed into law the John S. McCain National Defense Authorization Act for Fiscal Year 2019, which included the Export Control Reform Act of 2018 (ECRA) (50 U.S.C. 4801-4852). ECRA provides the legal basis for BIS's principal authorities and serves as the authority under which BIS issues this rule. In particular, section 1753 of ECRA (50 U.S.C. 4812) authorizes the regulation of exports, reexports, and transfers (in-country) of items subject to U.S. jurisdiction. Further, section 1754(a)(1)-(16) of ECRA (50 U.S.C. 4813(a)(1)-(16)) authorizes, inter alia, establishing and maintaining a list of foreign persons and end uses that are determined to be a threat to the national security and foreign policy of the United States pursuant to the policy set forth in section 1752(2)(A), and restricting exports, reexports, and in-country transfers of any controlled items to any foreign person or end-use so listed; apprising the public of changes in policy, regulations, and procedures; and any other action necessary to carry out ECRA that is not otherwise prohibited by law. Pursuant to section 1762(a) of ECRA (50 U.S.C. 4821(a)), these changes can be imposed in a final rule without prior notice and comment.</P>
                <HD SOURCE="HD1">Rulemaking Requirements</HD>
                <P>1. This rule has been determined to be not significant for purposes of Executive Order 12866.</P>
                <P>
                    2. Notwithstanding any other provision of law, no person is required to respond to or be subject to a penalty for failure to comply with a collection of information, subject to the requirements of the Paperwork Reduction Act of 1995 (PRA) (44 U.S.C. 3501 
                    <E T="03">et seq.</E>
                    ), unless that collection of information displays a currently valid Office of Management and Budget (OMB) Control Number. This regulation involves an information collection approved by OMB under control number 0694-0088, Simplified Network Application Processing System. BIS does not anticipate a change to the burden hours associated with this collection as a result of this rule. Information regarding the collection, including all supporting materials, can be accessed at: 
                    <E T="03">https://www.reginfo.gov/public/do/PRAMain</E>
                    .
                </P>
                <P>3. This rule does not contain policies with federalism implications as that term is defined in Executive Order 13132.</P>
                <P>4. Pursuant to section 1762 of the Export Control Reform Act of 2018, this action is exempt from the Administrative Procedure Act (APA) (5 U.S.C. 553) requirements for notice of proposed rulemaking, opportunity for public participation, and delay in effective date. While section 1762 of ECRA provides sufficient authority for such an exemption, this action is also independently exempt from these APA requirements because it involves a military or foreign affairs function of the United States (5 U.S.C. 553(a)(1)).</P>
                <P>
                    5. Because a notice of proposed rulemaking and an opportunity for public comment are not required to be given for this rule by 5 U.S.C. 553, or by any other law, the analytical requirements of the Regulatory Flexibility Act, 5 U.S.C. 601, 
                    <E T="03">et seq.,</E>
                     are not applicable. Accordingly, no regulatory flexibility analysis is required, and none has been prepared.
                </P>
                <LSTSUB>
                    <HD SOURCE="HED">List of Subjects in 15 CFR Part 744</HD>
                    <P>Exports, Reporting and recordkeeping requirements, Terrorism.</P>
                </LSTSUB>
                <P>Accordingly, part 744 of the Export Administration Regulations (15 CFR parts 730-774) is amended as follows:</P>
                <PART>
                    <HD SOURCE="HED">PART 744—CONTROL POLICY: END-USER AND END-USE BASED</HD>
                </PART>
                <REGTEXT TITLE="15" PART="744">
                    <AMDPAR>1. The authority citation for part 744 is revised to read as follows:</AMDPAR>
                    <AUTH>
                        <HD SOURCE="HED">Authority:</HD>
                        <P>
                            50 U.S.C. 4801-4852; 50 U.S.C. 4601 
                            <E T="03">et seq.;</E>
                             50 U.S.C. 1701 
                            <E T="03">et seq.;</E>
                             22 U.S.C. 3201 
                            <E T="03">et seq.;</E>
                             42 U.S.C. 2139a; 22 U.S.C. 7201 
                            <E T="03">et seq.;</E>
                             22 U.S.C. 7210; E.O. 12058, 43 FR 20947, 3 CFR, 1978 Comp., p. 179; E.O. 12851, 58 FR 33181, 3 CFR, 1993 Comp., p. 608; E.O. 12938, 59 FR 59099, 3 CFR, 1994 Comp., p. 950; E.O. 13026, 61 FR 58767, 3 CFR, 1996 Comp., p. 228; E.O. 13099, 63 FR 45167, 3 CFR, 1998 Comp., p. 208; E.O. 13222, 66 FR 44025, 3 CFR, 2001 Comp., p. 
                            <PRTPAGE P="561"/>
                            783; E.O. 13224, 66 FR 49079, 3 CFR, 2001 Comp., p. 786; Notice of September 18, 2024, 89 FR 77011 (September 20, 2024); Notice of November 7, 2024, 89 FR 88867 (November 8, 2024).
                        </P>
                    </AUTH>
                </REGTEXT>
                <REGTEXT TITLE="15" PART="744">
                    <AMDPAR>2. Supplement no. 4 to part 744 is amended:</AMDPAR>
                    <AMDPAR>a. Under BURMA, by adding, in alphabetical order, an entry for “Telecom International Myanmar Company Limited;”</AMDPAR>
                    <AMDPAR>b. Under CHINA, PEOPLE'S REPUBLIC OF, by:</AMDPAR>
                    <AMDPAR>i. Adding, in alphabetical order, entries for “Chengdu RML Technology Co., Ltd.;” “Chengdu Yaguang Electronics Co., Ltd.;” “Chinese Academy of Sciences Changchun Institute of Optics, Fine Mechanics, and Physics;” “Hefei Starwave Communication Technology Co.;” “Ji Hua Laboratory;” “Nanjing Simite Optical Instruments Co., Ltd.;” “Peng Cheng Laboratory;” and “Shanghai Institute of Optics and Fine Mechanics;”</AMDPAR>
                    <AMDPAR>ii. Revising the entry for “Shenzhen Guowei Sensing Technology Co., Ltd.;” and</AMDPAR>
                    <AMDPAR>
                        iii. Adding in alphabetical order, entries for “Suzhou Ultranano Precision Optoelectronics Technology Co., Ltd.;” “Wuhu Kewei Zhaofu Electronics Co., Ltd.;” 
                        <E T="03">and</E>
                         “Yaguang Technology Group Co., Ltd.;” 
                        <E T="03">and</E>
                    </AMDPAR>
                    <AMDPAR>c. Under PAKISTAN, by adding, in alphabetical order, an entry for “Emerging Future Solutions Private Limited.”</AMDPAR>
                    <P>The additions and revision read as follows:</P>
                    <HD SOURCE="HD1">Supplement No. 4 to Part 744—Entity List</HD>
                    <STARS/>
                    <GPOTABLE COLS="5" OPTS="L1,nj,tp0,p7,7/8,i1" CDEF="xs60,xl75,r50,xs66,r50">
                        <BOXHD>
                            <CHED H="1">Country</CHED>
                            <CHED H="1">Entity</CHED>
                            <CHED H="1">
                                License 
                                <LI>requirement</LI>
                            </CHED>
                            <CHED H="1">
                                License 
                                <LI>review policy</LI>
                            </CHED>
                            <CHED H="1">
                                <E T="02">Federal Register</E>
                                  
                                <LI>citation</LI>
                            </CHED>
                        </BOXHD>
                        <ROW>
                            <ENT I="22"> </ENT>
                        </ROW>
                        <ROW>
                            <ENT I="28">*         *         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">BURMA</ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Telecom International Myanmar Company Limited, a.k.a., the following two aliases: 
                                <LI>
                                    —Mytel; 
                                    <E T="03">and</E>
                                </LI>
                                <LI>—MyTel.</LI>
                                <LI>61-63 Zoological Garden Road, Yangon, Burma.</LI>
                            </ENT>
                            <ENT>For all items subject to the EAR. (See § 744.11 of the EAR)</ENT>
                            <ENT>Presumption of denial</ENT>
                            <ENT>90 FR [INSERT FR PAGE NUMBER AND 1/6/25.</ENT>
                        </ROW>
                        <ROW RUL="s">
                            <ENT I="22"> </ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                        </ROW>
                        <ROW RUL="s">
                            <ENT I="28">*         *         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">CHINA, PEOPLE'S REPUBLIC OF</ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Chengdu RML Technology Co., Ltd., a.k.a., the following two aliases:
                                <LI>
                                    —Chengdu Thunderbolt Micro Power Technology Co., Ltd.; 
                                    <E T="03">and</E>
                                </LI>
                                <LI>—RML Technology.</LI>
                            </ENT>
                            <ENT>For all items subject to the EAR. (See § 744.11 of the EAR)</ENT>
                            <ENT>Presumption of denial</ENT>
                            <ENT>90 FR [INSERT FR PAGE NUMBER AND 1/6/25.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                No. 19, Section 4, Huafu Avenue, Chengdu, China; 
                                <E T="03">and</E>
                                 Shiyang Industrial Park, No. 288, Yixin Avenue, Chengdu, China; 
                                <E T="03">and</E>
                                 the First Floor, Jinhe Hotel, 18 Jinhe Road, Chengdu, China.
                            </ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Chengdu Yaguang Electronics Co., Ltd., a.k.a., the following three aliases: 
                                <LI>—Chengdu Yaguang;</LI>
                                <LI>
                                    —Chengdu OPTO Electronics Co., Ltd.; 
                                    <E T="03">and</E>
                                </LI>
                                <LI>—970 Factory. </LI>
                            </ENT>
                            <ENT>For all items subject to the EAR. (See § 744.11 of the EAR)</ENT>
                            <ENT>Presumption of denial</ENT>
                            <ENT>90 FR [INSERT FR PAGE NUMBER AND 1/6/25.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                No. 66, Donghong Road, Chengdu, China; 
                                <E T="03">and</E>
                                 No. 36, Beisen Road, Chengdu, China.
                            </ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Chinese Academy of Sciences Changchun Institute of Optics, Fine Mechanics, and Physics, a.k.a., the following three aliases:
                                <LI>—Changchun Institute of Optics, Fine Mechanics, and Physics, CAS;</LI>
                                <LI>
                                    —CAS Institute of Optics, Fine Mechanics, and Physics; 
                                    <E T="03">and</E>
                                </LI>
                                <LI>—CIOMP.</LI>
                            </ENT>
                            <ENT>For all items subject to the EAR. (See §  744.11 of the EAR)</ENT>
                            <ENT>Presumption of denial</ENT>
                            <ENT>90 FR [INSERT FR PAGE NUMBER AND 1/6/25.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>3888 E Nanhu Road, Changchun, China.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Hefei Starwave Communication Technology Co., Ltd., a.k.a., the following three aliases:
                                <LI>—Starwave Comm Tech Corp;</LI>
                                <LI>
                                    —Star Wave Communication; 
                                    <E T="03">and</E>
                                </LI>
                                <LI>—Hefei Xingbo Communication Technology Co., Ltd.</LI>
                            </ENT>
                            <ENT>For all items subject to the EAR. (See § 744.11 of the EAR)</ENT>
                            <ENT>Presumption of denial</ENT>
                            <ENT>90 FR [INSERT FR PAGE NUMBER AND 1/6/25.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>No. 11, Mechanical and Electrical Industrial Park, No. 767, Yulan Avenue, Hefei, China.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Ji Hua Laboratory, a.k.a., the following four aliases:
                                <LI>—Guangdong Provincial Laboratory of Advanced Manufacturing Science and Technology;</LI>
                                <LI>—Guangdong Provincial Lab of Chemicals and Fine Chemicals;</LI>
                                <LI>
                                    —Ji Hua Lab; 
                                    <E T="03">and</E>
                                </LI>
                                <LI>—Yan Chang Ji Hua Lab.</LI>
                            </ENT>
                            <ENT>For all items subject to the EAR. (See §  744.11 of the EAR)</ENT>
                            <ENT>Presumption of denial</ENT>
                            <ENT>90 FR [INSERT FR PAGE NUMBER AND 1/6/25.</ENT>
                        </ROW>
                        <ROW>
                            <PRTPAGE P="562"/>
                            <ENT I="22"> </ENT>
                            <ENT>
                                No. 28, Huan Dao Nan Road, Guangdong Province, Foshan, 528000, China; 
                                <E T="03">and</E>
                                 No.28 Huandao South Road, Guicheng Street, Nanhai District, Foshan City, Guangdong Province, China; 
                                <E T="03">and</E>
                                 No. 27/28 Island Ring South Road, Guicheng St., Nanhai Dist., Foshan, Guangdong, China; 
                                <E T="03">and</E>
                                 No. 1 Xueyuan Road, Tuojiang Street, Jinping District, Shantou China; 
                                <E T="03">and</E>
                                 No. 88 Keling Road, Science and Technology City, Suzhou High Tech, Foshan, China; 
                                <E T="03">and</E>
                                 13 Chengye Road, Shunde District, Foshan, China; 
                                <E T="03">and</E>
                                 The Core Area of Sanlongwan High End Innovation Center, Foshan, China; 
                                <E T="03">and</E>
                                 13 Nanping West Road, Foshan, China.
                            </ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Nanjing Simite Optical Instruments Co., Ltd., a.k.a., the following two aliases:
                                <LI>
                                    —SMT Optical Instruments; 
                                    <E T="03">and</E>
                                </LI>
                                <LI>—Nanjing Schmidt Optical Instruments Co., Ltd.</LI>
                            </ENT>
                            <ENT>For all items subject to the EAR. (See §  744.11 of the EAR)</ENT>
                            <ENT>Presumption of denial</ENT>
                            <ENT>90 FR [INSERT FR PAGE NUMBER AND 1/6/25.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>Third Industrial Concentration Zone, Dongping Town, Lishui District, Nanjing, Jiangsu, China.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Peng Cheng Laboratory, a.k.a., the following five aliases:
                                <LI>—Pengcheng Laboratory;</LI>
                                <LI>—Peng Cheng Lab;</LI>
                                <LI>—Pengcheng Lab;</LI>
                                <LI>
                                    —Shenzhen Provincial Laboratory of Cyberspace Science and Technology; 
                                    <E T="03">and</E>
                                </LI>
                                <LI>—PCL</LI>
                            </ENT>
                            <ENT>For all items subject to the EAR. (See §  744.11 of the EAR)</ENT>
                            <ENT>Presumption of denial</ENT>
                            <ENT>90 FR [INSERT FR PAGE NUMBER AND 1/6/25.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                No. 2 Xingke First Street, Nanshan District, Shenzhen, Guangdong, China; 
                                <E T="03">and</E>
                                 Building 8, Phase 1, Vanke Cloud City, Liuxiandong, Xili Street, Nanshan District, Shenzhen, China; 
                                <E T="03">and</E>
                                 Wan Ke Yun Cheng, Yi Qi 8 Dong, Shenzhen, China. Zhigu 2nd Street, Songbei District, Harbin, Heilongjiang, 15000, China.
                            </ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Shanghai Institute of Optics and Fine Mechanics, a.k.a., the following seven aliases:
                                <LI>—SIOM;</LI>
                                <LI>—CAS SIOM;</LI>
                                <LI>—Hangzhou Spectrometer Laser PH;</LI>
                                <LI>—Lab of Information Optics;</LI>
                                <LI>—Shanghai Institute of Optics;</LI>
                                <LI>
                                    —Shanghai Institute of Optics &amp; Fine Mechanics; 
                                    <E T="03">and</E>
                                </LI>
                            </ENT>
                            <ENT>For all items subject to the EAR. (See §  744.11 of the EAR)</ENT>
                            <ENT>Presumption of denial</ENT>
                            <ENT>90 FR [INSERT FR PAGE NUMBER AND 1/6/25.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>—SIOM Chinese Academy of Sciences.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                No. 899, Huiwang East Road, Jiading District, Shanghai, China; 
                                <E T="03">and</E>
                                 No. 390, Qinghe Road, Jiading District, Shanghai, 201801, China; 
                                <E T="03">and</E>
                                 295 Tacheng Road, Jiading, Shanghai, China; 
                                <E T="03">and</E>
                                 52 Sanlihe Road, Shanghai, China; 
                                <E T="03">and</E>
                                 768 Zhaojiabang Road, Shanghai, China; 
                                <E T="03">and</E>
                                 9900 North Shengxin Road, Shanghai, China; 
                                <E T="03">and</E>
                                 200 Zhaoxian Rd, Jiading District, Shanghai, China; 
                                <E T="03">and</E>
                                 No. 4775, Shuangzhu Road, Shanghai, China; 
                                <E T="03">and</E>
                                 Rm. 904-905, Kuen Yang International Business Plaza, Shanghai, China.
                            </ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Shenzhen Guowei Sensing Technology Co., Ltd., a.k.a., the following one alias:
                                <LI>—SMIT Sense.</LI>
                            </ENT>
                            <ENT>For all items subject to the EAR. (See § 744.11 of the EAR)</ENT>
                            <ENT>Presumption of denial</ENT>
                            <ENT>
                                89 FR 96837, 12/5/2024.
                                <LI>90 FR [INSERT FR PAGE NUMBER AND 1/6/25.</LI>
                            </ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Room 22B, Guoshi Building, No. 1801 Shahe West Road, High-tech Zone Community, Yuehai Street, Nanshan District, Shenzhen, China; 
                                <E T="03">and</E>
                                 Floor 23, Building 3, Chongwen Park, Nanshan Intelligence Valley, No. 3370 Liuxian Avenue, Shenzhen, China; 
                                <E T="03">and</E>
                                 Floor 23, Building 3, Chongwen Park, Nanshan Zhiyuan, No. 3370 Liuxian Avenue, Shenzhen, China.
                            </ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Suzhou Ultranano Precision Optoelectronics Technology Co., Ltd., a.k.a., the following two aliases:
                                <LI>
                                    —Suzhou Chaona Precision Optoelectronics Technology Co., Ltd.; 
                                    <E T="03">and</E>
                                </LI>
                                <LI>—Suzhou Ultranano.</LI>
                            </ENT>
                            <ENT>For all items subject to the EAR. (See §  744.11 of the EAR)</ENT>
                            <ENT>Presumption of denial</ENT>
                            <ENT>90 FR [INSERT FR PAGE NUMBER AND 1/6/25.</ENT>
                        </ROW>
                        <ROW>
                            <PRTPAGE P="563"/>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Room 2005, Building 6, No. 77 Heshun Road, Suzhou Industrial Park, Suzhou, Jiangsu, 215000, China; 
                                <E T="03">and</E>
                                 Room 301 Building 3, No. 99 Jinyahu Avenue, Suzhou Industrial Park, Jiangsu Pilot Free Trade Zone, China.
                            </ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Wuhu Kewei Zhaofu Electronics Co., Ltd.,
                                <LI>
                                    West side of North Jiuhua Road, Economic and Technological Development Zone, Wuhu, Anhui, China; 
                                    <E T="03">and</E>
                                     No.10 Ruifu Road, Longshan Avenue, Wuhu Economic and Technological Development Zone, Wuhu, Anhui, 241000, China.
                                </LI>
                            </ENT>
                            <ENT>For all items subject to the EAR. (See §  744.11 of the EAR)</ENT>
                            <ENT>Presumption of denial</ENT>
                            <ENT>90 FR [INSERT FR PAGE NUMBER AND 1/6/25.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Yaguang Technology Group Co., Ltd., a.k.a., the following one alias:
                                <LI>—Sunbird Yachting Co., Ltd.</LI>
                            </ENT>
                            <ENT>For all items subject to the EAR. (See § 744.11 of the EAR)</ENT>
                            <ENT>Presumption of denial</ENT>
                            <ENT>90 FR [INSERT FR PAGE NUMBER AND 1/6/25.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Yacht Industrial Park, Yuanjiang, China; 
                                <E T="03">and</E>
                                 No. 18, Shijihu Road, Yuanjiang City, Yiyang City, China; 
                                <E T="03">and</E>
                                 Yaguang Science and Technology Park, No. 1820 Yuelu West Avenue, Changsha, China.
                            </ENT>
                        </ROW>
                        <ROW RUL="s">
                            <ENT I="22"> </ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                        </ROW>
                        <ROW RUL="s">
                            <ENT I="28">*         *         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">PAKISTAN</ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>
                                Emerging Future Solutions Private Limited, a.k.a., the following four aliases:
                                <LI>—Emerging Future Solutions;</LI>
                                <LI>—Emerging Future Solutions (Pvt) Ltd Pakistan;</LI>
                                <LI>
                                    —Emerging Future Solutions Pvt Ltd.; 
                                    <E T="03">and</E>
                                </LI>
                                <LI>—Emerging Future Solutions Limited.</LI>
                            </ENT>
                            <ENT>For all items subject to the EAR. (See § 744.11 of the EAR)</ENT>
                            <ENT>Presumption of denial</ENT>
                            <ENT>90 FR [INSERT FR PAGE NUMBER AND 1/6/25.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT>Office No. 46-A, Street No. 5, Chaklala Scheme-III, Rawalpindi, 46000, Pakistan.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                            <ENT A="03">*         *         *         *         *         *</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="22"> </ENT>
                        </ROW>
                        <ROW>
                            <ENT I="28">*         *         *         *         *         *         *</ENT>
                        </ROW>
                    </GPOTABLE>
                    <STARS/>
                </REGTEXT>
                <SIG>
                    <NAME>Matthew S. Borman,</NAME>
                    <TITLE>Principal Deputy Assistant Secretary for Strategic Trade and Technology Security.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31468 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 3510-33-P</BILCOD>
        </RULE>
        <RULE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF HEALTH AND HUMAN SERVICES</AGENCY>
                <SUBAGY>Food and Drug Administration</SUBAGY>
                <CFR>21 CFR Part 211</CFR>
                <DEPDOC>[Docket No. FDA-2024-D-5374]</DEPDOC>
                <SUBJECT>Considerations for Complying With 21 CFR 211.110; Draft Guidance for Industry; Availability</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Food and Drug Administration, HHS.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Availability of draft guidance.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Food and Drug Administration (FDA or Agency) is announcing the availability of a draft guidance for industry entitled “Considerations for Complying With 21 CFR 211.110.” This guidance, when finalized, will describe considerations for complying with the requirements for ensuring batch uniformity and drug product integrity. In addition, this guidance discusses related quality considerations for drug products that are manufactured using advanced manufacturing. FDA is committed to supporting and enabling pharmaceutical innovation and modernization as part of the Agency's mission to protect and promote the public health. FDA encourages industry representatives and manufactures who are interested in using innovative control strategies to contact the Agency.</P>
                </SUM>
                <EFFDATE>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Submit either electronic or written comments on the draft guidance by April 7, 2025 to ensure that the Agency considers your comment on this draft guidance before it begins work on the final version of the guidance.</P>
                </EFFDATE>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may submit comments on any guidance at any time as follows:</P>
                </ADD>
                <HD SOURCE="HD2">Electronic Submissions</HD>
                <P>Submit electronic comments in the following way:</P>
                <P>
                    • 
                    <E T="03">Federal eRulemaking Portal: https://www.regulations.gov</E>
                    . Follow the instructions for submitting comments. Comments submitted electronically, including attachments, to 
                    <E T="03">https://www.regulations.gov</E>
                     will be posted to the docket unchanged. Because your comment will be made public, you are solely responsible for ensuring that your comment does not include any confidential information that you or a third party may not wish to be posted, such as medical information, your or anyone else's Social Security number, or confidential business information, such as a manufacturing process. Please note that if you include your name, contact information, or other information that identifies you in the body of your comments, that information will be posted on 
                    <E T="03">https://www.regulations.gov</E>
                    .
                </P>
                <P>• If you want to submit a comment with confidential information that you do not wish to be made available to the public, submit the comment as a written/paper submission and in the manner detailed (see “Written/Paper Submissions” and “Instructions”).</P>
                <HD SOURCE="HD2">Written/Paper Submissions</HD>
                <P>Submit written/paper submissions as follows:</P>
                <P>
                    • 
                    <E T="03">Mail/Hand Delivery/Courier (for written/paper submissions):</E>
                     Dockets Management Staff (HFA-305), Food and Drug Administration, 5630 Fishers Lane, Rm. 1061, Rockville, MD 20852.
                </P>
                <P>
                    • For written/paper comments submitted to the Dockets Management 
                    <PRTPAGE P="564"/>
                    Staff, FDA will post your comment, as well as any attachments, except for information submitted, marked and identified, as confidential, if submitted as detailed in “Instructions.”
                </P>
                <P>
                    <E T="03">Instructions:</E>
                     All submissions received must include the Docket No. FDA-2024-D-5374 for “Considerations for Complying With 21 CFR 211.110.” Received comments will be placed in the docket and, except for those submitted as “Confidential Submissions,” publicly viewable at 
                    <E T="03">https://www.regulations.gov</E>
                     or at the Dockets Management Staff between 9 a.m. and 4 p.m., Monday through Friday, 240-402-7500.
                </P>
                <P>
                    • Confidential Submissions—To submit a comment with confidential information that you do not wish to be made publicly available, submit your comments only as a written/paper submission. You should submit two copies total. One copy will include the information you claim to be confidential with a heading or cover note that states “THIS DOCUMENT CONTAINS CONFIDENTIAL INFORMATION.” The Agency will review this copy, including the claimed confidential information, in its consideration of comments. The second copy, which will have the claimed confidential information redacted/blacked out, will be available for public viewing and posted on 
                    <E T="03">https://www.regulations.gov</E>
                    . Submit both copies to the Dockets Management Staff. If you do not wish your name and contact information to be made publicly available, you can provide this information on the cover sheet and not in the body of your comments and you must identify this information as “confidential.” Any information marked as “confidential” will not be disclosed except in accordance with 21 CFR 10.20 and other applicable disclosure law. For more information about FDA's posting of comments to public dockets, see 80 FR 56469, September 18, 2015, or access the information at: 
                    <E T="03">https://www.govinfo.gov/content/pkg/FR-2015-09-18/pdf/2015-23389.pdf</E>
                    .
                </P>
                <P>
                    <E T="03">Docket:</E>
                     For access to the docket to read background documents or the electronic and written/paper comments received, go to 
                    <E T="03">https://www.regulations.gov</E>
                     and insert the docket number, found in brackets in the heading of this document, into the “Search” box and follow the prompts and/or go to the Dockets Management Staff, 5630 Fishers Lane, Rm. 1061, Rockville, MD 20852, 240-402-7500.
                </P>
                <P>You may submit comments on any guidance at any time (see 21 CFR 10.115(g)(5)).</P>
                <P>
                    Submit written requests for single copies of this draft guidance to the Division of Drug Information, Center for Drug Evaluation and Research, Food and Drug Administration, 10001 New Hampshire Ave., Hillandale Building, 4th Floor, Silver Spring, MD 20993-0002; the Office of Communication, Outreach and Development, Center for Biologics Evaluation and Research, Food and Drug Administration, 10903 New Hampshire Ave., Bldg. 71, Rm. 3128, Silver Spring, MD 20993-0002; or Policy and Regulations Staff, HFV-6, Center for Veterinary Medicine, Food and Drug Administration, 7500 Standish Place, Rockville, MD 20855. Send one self-addressed adhesive label to assist that office in processing your requests. See the 
                    <E T="02">SUPPLEMENTARY INFORMATION</E>
                     section for electronic access to the draft guidance document.
                </P>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Brittany Avaritt, Center for Drug Evaluation and Research, Food and Drug Administration, 10903 New Hampshire Ave., Bldg. 75, Rm. 6649, Silver Spring, MD 20993-0002, 240-402-5982; James Myers, Center for Biologics Evaluation and Research, Food and Drug Administration, 10903 New Hampshire Ave., Bld. 71, Rm. 7301, Silver Spring, MD 20993-002, 240-402-7911; or Kevin Rice, Center for Veterinary Medicine, Food and Drug Administration, 7500 Standish Place, Rockville, MD 20855, 240-402-0680.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">I. Background</HD>
                <P>FDA is announcing the availability of a draft guidance for industry entitled “Considerations for Complying with 21 CFR 211.110.” This guidance, when finalized, will describe considerations for complying with the requirements in § 211.110 (21 CFR 211.110) to ensure batch uniformity and drug product integrity. In addition, this guidance discusses related quality considerations for drug products that are manufactured using advanced manufacturing. It also discusses how manufacturers can incorporate process models into commercial manufacturing control strategies. This guidance applies to the manufacture of human drug products, including biological products, and animal drug products. This guidance does not apply to the manufacture of active ingredients.</P>
                <P>
                    To ensure batch uniformity and drug product integrity, the current good manufacturing practice (CGMP) regulations 
                    <SU>1</SU>
                    <FTREF/>
                     require, among other things, that manufacturing processes are designed and controlled to ensure that in-process materials consistently and reliably meet predetermined quality requirements.
                    <SU>2</SU>
                    <FTREF/>
                     This guidance explains the requirements for drug product manufacturing in § 211.110. This guidance also describes considerations for the use of advanced manufacturing (
                    <E T="03">e.g.,</E>
                     3D printing, continuous manufacturing) and the use of process models as a part of commercial manufacturing control strategies. FDA supports the adoption of advanced manufacturing as a foundation for improving the overall quality and availability of drug products for patients.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         See 21 CFR parts 210 and 211. Positron emission tomography drug products are subject to CGMP regulations at 21 CFR part 212 and are not covered by this guidance.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         See § 211.110.
                    </P>
                </FTNT>
                <P>All manufacturers, regardless of whether they are using advanced manufacturing, should apply a scientific- and risk-based approach to controlling processes and ensuring drug product quality. This approach should be based on robust product and process understanding. Advanced manufacturing (such as continuous manufacturing) generally lends itself to more extensive understanding and control of the manufacturing process; thus, it is generally suitable for implementing process models as part of the control strategy. FDA is aware of industry's interest in using in-process control strategies that rely solely on process models to satisfy the requirements of § 211.110. However, control strategies that rely solely on current process models would be insufficient to satisfy the requirements of § 211.110.</P>
                <P>FDA is committed to supporting and enabling pharmaceutical innovation and modernization as part of the Agency's mission to protect and promote the public health. This guidance provides information on how process models can be paired with in-process material testing or process monitoring to meet current regulatory requirements. As the science supporting innovative in-process control tools and methods continues to develop, FDA anticipates that these scientific advancements can be leveraged to pursue in-process control strategies that increasingly rely on process models. FDA encourages industry representatives and manufacturers to discuss their proposed innovative control strategies with the Agency to help inform future policy development.</P>
                <P>
                    This draft guidance is being issued consistent with FDA's good guidance practices regulation (21 CFR 10.115). The draft guidance, when finalized, will represent the current thinking of FDA on “Considerations for Complying With 
                    <PRTPAGE P="565"/>
                    21 CFR 211.110.” It does not establish any rights for any person and is not binding on FDA or the public. You can use an alternative approach if it satisfies the requirements of the applicable statutes and regulations.
                    <SU>3</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         The Office of the Federal Register has published this document under the category “Rules and Regulations” pursuant to its interpretation of 1 CFR 5.9(b). We note that the categorization as such for purposes of publication in the 
                        <E T="04">Federal Register</E>
                         does not affect the content or intent of the document. See 1 CFR 5.1(c).
                    </P>
                </FTNT>
                <HD SOURCE="HD1">II. Paperwork Reduction Act of 1995</HD>
                <P>While this guidance contains no collection of information, it does refer to previously approved FDA collections of information. The previously approved collections of information are subject to review by the Office of Management and Budget (OMB) under the Paperwork Reduction Act of 1995 (44 U.S.C. 3501-3521). The collections of information in parts 210 and 211 relating to CGMP have been approved under OMB control number 0910-0139.</P>
                <HD SOURCE="HD1">III. Electronic Access</HD>
                <P>
                    Persons with access to the internet may obtain an electronic version of the draft guidance at 
                    <E T="03">https://www.fda.gov/drugs/guidance-compliance-regulatory-information/guidances-drugs, https://www.fda.gov/vaccines-blood-biologics/guidance-compliance-regulatory-information-biologics, https://www.fda.gov/AnimalVeterinary/GuidanceComplianceEnforcement/GuidanceforIndustry/default.htm, https://www.fda.gov/regulatory-information/search-fda-guidance-documents,</E>
                     or 
                    <E T="03">https://www.regulations.gov.</E>
                </P>
                <SIG>
                    <DATED>Dated: December 23, 2024.</DATED>
                    <NAME>P. Ritu Nalubola,</NAME>
                    <TITLE>Associate Commissioner for Policy.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31356 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4164-01-P</BILCOD>
        </RULE>
        <RULE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF HOMELAND SECURITY</AGENCY>
                <SUBAGY>Coast Guard</SUBAGY>
                <CFR>33 CFR Part 165</CFR>
                <DEPDOC>[Docket No. USCG-2024-1099]</DEPDOC>
                <SUBJECT>Security Zone; Potomac River and Anacostia River, and Adjacent Waters, Washington, DC</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Coast Guard, Department of Homeland Security (DHS).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notification of enforcement of regulation.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Coast Guard will enforce a security zone along the Potomac River, Anacostia River, and adjacent waters at Washington, DC, for the State Funeral for former President James Carter. This action is necessary to protect government officials, mitigate potential terrorist acts and incidents, and enhance public and maritime safety and security immediately before, during, and after this activity. During the enforcement period, entry into or remaining within the zone is prohibited unless authorized by the Captain of the Port or their designated representative.</P>
                </SUM>
                <EFFDATE>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>The regulations in 33 CFR 165.508 will be enforced from 8 a.m., January 7, 2025, through 4 p.m., January 9, 2025, for the security zone location identified in 33 CFR 16.508(a)(6).</P>
                </EFFDATE>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        If you have questions about this notification of enforcement, call or email LCDR Kate Newkirk, U.S. Coast Guard Sector Maryland-National Capital Region, Waterways Management Division; telephone 410-576-2596, email 
                        <E T="03">Kate.M.Newkirk@uscg.mil</E>
                        .
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>The Coast Guard will enforce regulations in 33 CFR 165.508 for the locations identified in paragraph (a)(6) from 8 a.m., January 7, 2025, through 4 p.m., January 9, 2025. This action is being taken to protect government officials, mitigate potential terrorist acts and incidents, and enhance public and maritime safety and security immediately before, during, and after this event. Our regulations for the Security Zone; Potomac River and Anacostia River, and adjacent waters at Washington, DC. The regulation at 33 CFR 165.508(a)(6) specifies the location for this security zone as an area that includes all navigable waters described in paragraphs (a)(1) through (3), which includes Zones 1, 2, and 3.</P>
                <P>• Security Zone 1, paragraph (a)(1); all navigable waters of the Potomac River, from shoreline to shoreline, bounded to the north by the Francis Scott Key (US-29) Bridge, at mile 113, and bounded to the south by a line drawn from the Virginia shoreline at Ronald Reagan Washington National Airport at 38°51′21.3″ N, 077°02′00.0″ W, eastward across the Potomac River to the District of Columbia shoreline at Hains Point at position 38°51′24.3″ N, 077°01′19.8″ W, including the waters of the Boundary Channel, Pentagon Lagoon, Georgetown Channel Tidal Basin, and Roaches Run.</P>
                <P>• Security Zone 2, paragraph (a)(2); all navigable waters of the Anacostia River, from shoreline to shoreline, bounded to the north by the John Philip Sousa (Pennsylvania Avenue) Bridge, at mile 2.9, and bounded to the south by a line drawn from the District of Columbia shoreline at Hains Point at position 38°51′24.3″ N, 077°01′19.8″ W, southward across the Anacostia River to the District of Columbia shoreline at Giesboro Point at position 38°50′52.4″ N, 077°01′10.9″ W, including the waters of the Washington Channel.</P>
                <P>• Security Zone 3 paragraph (a)(3); all navigable waters of the Potomac River, from shoreline to shoreline, bounded to the north by a line drawn from the Virginia shoreline at Ronald Reagan Washington National Airport, at 38°51′21.3″ N, 077°02′00.0″ W, eastward across the Potomac River to the District of Columbia shoreline at Hains Point at position 38°51′24.3″ N, 077°01′19.8″ W, thence southward across the Anacostia River to the District of Columbia shoreline at Giesboro Point at position 38°50′52.4″ N, 077°01′10.9″ W, and bounded to the south by the Woodrow Wilson Memorial (I-95/I-495) Bridge, at mile 103.8.</P>
                <P>During the enforcement period, as specified in § 165.508(b), entry into or remaining in these zones is prohibited unless authorized by the Coast Guard Captain of the Port Maryland-National Capital Region. Public vessels and vessels already at berth at the time of the security zone is implemented do not have to depart the security zone. All vessels underway within the security zone at the time the security zone is implemented are to depart the zone. To seek permission to transit the zone, the Captain of the Port Maryland-National Capital Region can be contacted at telephone number (410) 576-2525 or on Marine Band Radio, VHF-FM channel 16 (156.8 MHz). Coast Guard vessels enforcing this zone can be contacted on Marine Band Radio, VHF-FM channel 16 (156.8 MHz). The Coast Guard may be assisted by other Federal, state, or local law enforcement agencies in enforcing this regulation. If the Captain of the Port or his designated on-scene patrol personnel determines the security zone need not be enforced for the full duration stated in this notification, a Broadcast Notice to Mariners may be used to suspend enforcement and grant general permission to enter the security zone.</P>
                <P>
                    In addition to this notification of enforcement in the 
                    <E T="04">Federal Register</E>
                    , the Coast Guard plans to provide notification to this enforcement period via the Local Notice to Mariners, and marine information broadcasts.
                </P>
                <SIG>
                    <PRTPAGE P="566"/>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>Patrick C. Burkett,</NAME>
                    <TITLE>Captain, U.S. Coast Guard, Captain of the Port Maryland-National Capital Region.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31636 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 9110-04-P</BILCOD>
        </RULE>
        <RULE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <SUBAGY>Great Lakes St. Lawrence Seaway Development Corporation</SUBAGY>
                <CFR>33 CFR Part 402</CFR>
                <RIN>RIN 2135-AA58</RIN>
                <SUBJECT>Tariff of Tolls</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Great Lakes St. Lawrence Seaway Development Corporation, Department of Transportation (DOT).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Final rule.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Great Lakes St. Lawrence Seaway Development Corporation (GLS) and the St. Lawrence Seaway Management Corporation (SLSMC) of Canada, under international agreement, jointly publish and presently administer the St. Lawrence Seaway Tariff of Tolls in their respective jurisdictions. The Tariff sets forth the level of tolls assessed on all commodities and vessels transiting the facilities operated by the GLS and the SLSMC. The GLS is revising its regulations to reflect the fees and charges levied by the SLSMC in Canada starting in the 2025 navigation season, which are effective only in Canada.</P>
                </SUM>
                <EFFDATE>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>This rule is effective on January 6, 2025</P>
                </EFFDATE>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        <E T="03">Docket:</E>
                         For access to the docket to read background documents or comments received, go to 
                        <E T="03">https://www.regulations.gov;</E>
                         or in person at the Docket Management Facility; U.S. Department of Transportation, 1200 New Jersey Avenue SE, West Building Ground Floor, Room W12-140, Washington, DC 20590-001, between 9 a.m. and 5 p.m., Monday through Friday, except Federal holidays.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Carrie Mann Lavigne, Chief Counsel, Great Lakes St. Lawrence Seaway Development Corporation, 180 Andrews Street, Massena, New York 13662; (315) 764-3200.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>The GLS and SLSMC of Canada, under international agreement, jointly publish and presently administer the St. Lawrence Seaway Tariff of Tolls (Schedule of Fees and Charges in Canada) in their respective jurisdictions.</P>
                <P>The Tariff sets forth the level of tolls assessed on all commodities and vessels transiting the facilities operated by the GLS and the SLSMC. The GLS is revising 33 CFR 402.12, “Schedule of tolls”, to reflect the fees and charges levied by the SLSMC in Canada beginning in the 2025 navigation season. The GLS finds there is good cause to make the Tariff of Tolls effective on the date of publication to harmonize the effective dates on both sides of the border.</P>
                <P>
                    <E T="03">Regulatory Notices: Privacy Act:</E>
                     Anyone is able to search the electronic form of all comments received into any of our dockets by the name of the individual submitting the comment (or signing the comment, if submitted on behalf of an association, business, labor union, etc.). You may review DOT's complete Privacy Act Statement in the 
                    <E T="04">Federal Register</E>
                     published on April 11, 2000 (65 FR 19477-78) or you may visit 
                    <E T="03">https://www.regulations.gov.</E>
                </P>
                <HD SOURCE="HD1">Regulatory Evaluation</HD>
                <P>This regulation involves a foreign affairs function of the United States and therefore, Executive Order 12866 does not apply and evaluation under the Department of Transportation's Regulatory Policies and Procedures is not required.</P>
                <HD SOURCE="HD1">Regulatory Flexibility Act Determination</HD>
                <P>The GLS certifies that this regulation will not have a significant economic impact on a substantial number of small entities. The St. Lawrence Seaway Regulations and Rules primarily relate to commercial users of the Seaway, the vast majority of whom are foreign vessel operators. Therefore, any resulting costs will be borne mostly by foreign vessels.</P>
                <HD SOURCE="HD1">Environmental Impact</HD>
                <P>
                    This regulation does not require an environmental impact statement under the National Environmental Policy Act (49 U.S.C. 4321, 
                    <E T="03">et seq.</E>
                    ) because it is not a major Federal action significantly affecting the quality of the human environment.
                </P>
                <HD SOURCE="HD1">Federalism</HD>
                <P>The Corporation has analyzed this rule under the principles and criteria in Executive Order 13132, dated August 4, 1999, and has determined that this rule does not have sufficient federalism implications to warrant a Federalism Assessment.</P>
                <HD SOURCE="HD1">Unfunded Mandates</HD>
                <P>The Corporation has analyzed this rule under title II of the Unfunded Mandates Reform Act of 1995 (Pub. L. 104-4, 109 Stat. 48) and determined that it does not impose unfunded mandates on State, local, and Tribal governments and the private sector requiring a written statement of economic and regulatory alternatives.</P>
                <HD SOURCE="HD1">Paperwork Reduction Act</HD>
                <P>This regulation has been analyzed under the Paperwork Reduction Act of 1995 and does not contain new or modified information collection requirements subject to the Office of Management and Budget review.</P>
                <LSTSUB>
                    <HD SOURCE="HED">List of Subjects in 33 CFR Part 402</HD>
                    <P>Vessels, Waterways.</P>
                </LSTSUB>
                <P>Accordingly, the Great Lakes St. Lawrence Seaway Development Corporation is amending 33 CFR part 402 as follows:</P>
                <PART>
                    <HD SOURCE="HED">PART 402—TARIFF OF TOLLS</HD>
                </PART>
                <REGTEXT TITLE="33" PART="402">
                    <AMDPAR>1. The authority citation for part 402 continues to read as follows:</AMDPAR>
                    <AUTH>
                        <HD SOURCE="HED">Authority:</HD>
                        <P> 33 U.S.C. 983(a), 984(a)(4), and 988, as amended; 49 CFR 1.101.</P>
                    </AUTH>
                </REGTEXT>
                <REGTEXT TITLE="33" PART="402">
                    <AMDPAR>2. Revise § 402.12 to read as follows:</AMDPAR>
                    <SECTION>
                        <SECTNO>§ 402.12 </SECTNO>
                        <SUBJECT>Schedule of tolls.</SUBJECT>
                        <GPOTABLE COLS="4" OPTS="L2,nj,p7,7/8,i1" CDEF="xs40,r100,r50,r50">
                            <TTITLE>Table 1 to § 402.12</TTITLE>
                            <BOXHD>
                                <CHED H="1">Item</CHED>
                                <CHED H="1">Column 1</CHED>
                                <CHED H="2">Description of charges</CHED>
                                <CHED H="1">Column 2</CHED>
                                <CHED H="2">
                                    Rate ($)
                                    <LI>Montreal to or from Lake Ontario</LI>
                                    <LI>(5 locks)</LI>
                                </CHED>
                                <CHED H="1">Column 3</CHED>
                                <CHED H="2">
                                    Rate ($)
                                    <LI>Welland Canal—Lake Ontario to or from Lake Erie</LI>
                                    <LI>(8 locks)</LI>
                                </CHED>
                            </BOXHD>
                            <ROW>
                                <ENT I="01">1.</ENT>
                                <ENT O="xl">Subject to item 3, for complete transit of the Seaway, a composite toll, comprising:</ENT>
                            </ROW>
                            <ROW>
                                <PRTPAGE P="567"/>
                                <ENT I="22"> </ENT>
                                <ENT O="oi3" O1="xl">
                                    (1) a charge per gross registered ton of the ship, applicable whether the ship is wholly or partially laden, or is in ballast, and the gross registered tonnage being calculated according to prescribed rules for measurement or under the International Convention on Tonnage Measurement of Ships
                                    <E T="03">,</E>
                                     1969, as amended from time to time: 
                                    <SU>1</SU>
                                </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                                <ENT O="oi5">(a) all vessels excluding passenger vessels</ENT>
                                <ENT>0.1311</ENT>
                                <ENT>0.2098.</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                                <ENT O="oi5">(b) passenger vessels</ENT>
                                <ENT>0.3934</ENT>
                                <ENT>0.6293.</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                                <ENT O="oi3" O1="xl">(2) a charge per metric ton of cargo as certified on the ship's manifest or other document, as follows:</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                                <ENT O="oi5">
                                    (
                                    <E T="03">a</E>
                                    ) bulk cargo
                                </ENT>
                                <ENT>1.3593</ENT>
                                <ENT>0.9278.</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                                <ENT O="oi5">
                                    (
                                    <E T="03">b</E>
                                    ) general cargo
                                </ENT>
                                <ENT>3.2753</ENT>
                                <ENT>1.4849.</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                                <ENT O="oi5">
                                    (
                                    <E T="03">c</E>
                                    ) steel slab
                                </ENT>
                                <ENT>2.9643</ENT>
                                <ENT>1.0630.</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                                <ENT O="oi5">
                                    (
                                    <E T="03">d</E>
                                    ) containerized cargo
                                </ENT>
                                <ENT>1.3593</ENT>
                                <ENT>0.9278.</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                                <ENT O="oi5">
                                    (
                                    <E T="03">e</E>
                                    ) government aid cargo
                                </ENT>
                                <ENT>n/a</ENT>
                                <ENT>n/a.</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                                <ENT O="oi5">
                                    (
                                    <E T="03">f</E>
                                    ) grain
                                </ENT>
                                <ENT>0.8351</ENT>
                                <ENT>0.9278.</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                                <ENT O="oi5">
                                    (
                                    <E T="03">g</E>
                                    ) coal
                                </ENT>
                                <ENT>0.8351</ENT>
                                <ENT>0.9278.</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                                <ENT O="oi3">(3) a charge per passenger per lock</ENT>
                                <ENT>0.0000</ENT>
                                <ENT>0.0000.</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                                <ENT O="oi3" O1="xl">(4) a lockage charge per Gross Registered Ton of the vessel, as defined in item 1(1), applicable whether the ship is wholly or partially laden, or is in ballast, for transit of the Welland Canal in either direction by cargo ships,</ENT>
                                <ENT>n/a</ENT>
                                <ENT>0.3495.</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                                <ENT O="oi3">Up to a maximum charge per vessel</ENT>
                                <ENT>n/a</ENT>
                                <ENT>4,889.00.</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">2.</ENT>
                                <ENT>Subject to item 3, for partial transit of the Seaway</ENT>
                                <ENT>20 per cent per lock of the applicable charge under items 1(1), 1(2) and 1(4) plus the applicable charge under items 1(3)</ENT>
                                <ENT>13 per cent per lock of the applicable charge under items 1(1), 1(2) and 1(4) plus the applicable charge under items 1(3).</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">3.</ENT>
                                <ENT>Minimum charge per vessel per lock transited for full or partial transit of the Seaway</ENT>
                                <ENT>
                                    33.93 
                                    <SU>2</SU>
                                </ENT>
                                <ENT>33.93.</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">4.</ENT>
                                <ENT>
                                    A charge per pleasure craft per lock transited for full or partial transit of the Seaway, including applicable Federal taxes 
                                    <SU>3</SU>
                                </ENT>
                                <ENT>
                                    25.00 
                                    <SU>4</SU>
                                </ENT>
                                <ENT>25.00.</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">5.</ENT>
                                <ENT>Under the New Business Initiative Program, for cargo accepted as New Business, a percentage rebate on the applicable cargo charges for the approved period</ENT>
                                <ENT>20%</ENT>
                                <ENT>20%.</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">6.</ENT>
                                <ENT>Under the Volume Rebate Incentive program, a retroactive percentage rebate on cargo tolls on the incremental volume calculated based on the pre-approved maximum volume</ENT>
                                <ENT>10%</ENT>
                                <ENT>10%.</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">7.</ENT>
                                <ENT>Under the New Service Incentive Program, for New Business cargo moving under an approved new service, an additional percentage refund on applicable cargo tolls above the New Business rebate</ENT>
                                <ENT>20%</ENT>
                                <ENT>20%.</ENT>
                            </ROW>
                            <TNOTE>
                                <SU>1</SU>
                                 Or under the US GRT for vessels prescribed prior to 2002.
                            </TNOTE>
                            <TNOTE>
                                <SU>2</SU>
                                 The applicable charged under item 3 at the Great Lakes St. Lawrence Seaway Development Corporation's locks (Eisenhower, Snell) will be collected in U.S. dollars. The collection of the U.S. portion of tolls for commercial vessels is waived by law (33 U.S.C. 988a(a)). The other charges are in Canadian dollars and are for the Canadian share of tolls.
                            </TNOTE>
                            <TNOTE>
                                <SU>3</SU>
                                 Includes a $5.00 discount per lock with use of online reservation and payment system for Canadian locks.
                            </TNOTE>
                            <TNOTE>
                                <SU>4</SU>
                                 The applicable charge at the Great Lakes St. Lawrence Seaway Development Corporation's locks (Eisenhower, Snell) for pleasure craft is $30 USD or $30 CAD per lock.
                            </TNOTE>
                        </GPOTABLE>
                    </SECTION>
                </REGTEXT>
                <SIG>
                    <P>Issued at Washington, DC, under authority delegated at 49 CFR 1.101. Great Lakes St. Lawrence Seaway Development Corporation.</P>
                    <NAME>Carrie Lavigne,</NAME>
                    <TITLE>Chief Counsel.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31616 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4910-61-P</BILCOD>
        </RULE>
        <RULE>
            <PREAMB>
                <AGENCY TYPE="N">ENVIRONMENTAL PROTECTION AGENCY</AGENCY>
                <CFR>40 CFR Parts 9 and 721</CFR>
                <DEPDOC>[EPA-HQ-OPPT-2019-0530; FRL-7645-02-OCSPP]</DEPDOC>
                <RIN>RIN 2070-AB27</RIN>
                <SUBJECT>Significant New Use Rules on Certain Chemical Substances (19-5.F)</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Environmental Protection Agency (EPA).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Final rule.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>EPA is issuing significant new use rules (SNURs) under the Toxic Substances Control Act (TSCA) for certain chemical substances that were the subject of premanufacture notices (PMNs). The SNURs require persons to notify EPA at least 90 days before commencing manufacture (defined by statute to include import) or processing of any of these chemical substances for an activity that is designated as a significant new use in the SNUR. The required notification initiates EPA's evaluation of the use, under the conditions of use for that chemical substance, within the applicable review period. Persons may not commence manufacture or processing for the significant new use until they have submitted a Significant New Use Notice (SNUN), and EPA has conducted a review of the notice, made an appropriate determination on the notice, and has taken any risk management actions as are required as a result of that determination.</P>
                </SUM>
                <EFFDATE>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>This rule is effective on March 7, 2025. For purposes of judicial review, this rule shall be promulgated at 1 p.m. (EST) on January 21, 2025.</P>
                </EFFDATE>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        The docket for this action, identified under docket identification (ID) number EPA-HQ-OPPT-2019-0530, is available online at 
                        <E T="03">https://www.regulations.gov</E>
                         or in person at the Office of Pollution Prevention and Toxics Docket (OPPT Docket) in the Environmental Protection Agency Docket Center (EPA/DC). Please review the visitor instructions and additional 
                        <PRTPAGE P="568"/>
                        information about the docket available at 
                        <E T="03">https://www.epa.gov/dockets.</E>
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P/>
                    <P>
                        <E T="03">For technical information:</E>
                         James Yan, New Chemicals Division (7405M), Office of Pollution Prevention and Toxics, Environmental Protection Agency, 1200 Pennsylvania Ave. NW, Washington, DC 20460-0001; telephone number: (202) 564-2138; email address: 
                        <E T="03">yan.james@epa.gov.</E>
                    </P>
                    <P>
                        <E T="03">For technical information:</E>
                         William Wysong, New Chemicals Division (7405M), Office of Pollution Prevention and Toxics, Environmental Protection Agency, 1200 Pennsylvania Ave. NW, Washington, DC 20460-0001; telephone number: (202) 564-4163; email address: 
                        <E T="03">wysong.william@epa.gov.</E>
                    </P>
                    <P>
                        <E T="03">For general information:</E>
                         The TSCA-Hotline, ABVI-Goodwill, 422 South Clinton Ave., Rochester, NY 14620; telephone number: (202) 554-1404; email address: 
                        <E T="03">TSCA-Hotline@epa.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">I. Executive Summary</HD>
                <HD SOURCE="HD2">A. What is the Agency's authority for taking this action?</HD>
                <P>TSCA section 5(a)(2) (15 U.S.C. 2604(a)(2)) authorizes EPA to determine that a use of a chemical substance is a “significant new use.” EPA must make this determination by rule after considering all relevant factors, including the factors in TSCA section 5(a)(2) (see also the discussion in Unit II.).</P>
                <HD SOURCE="HD2">B. What action is the Agency taking?</HD>
                <P>EPA is finalizing SNURs under TSCA section 5(a)(2) for chemical substances that were the subject of PMNs P-16-541, P-17-299, P-18-172, P-19-99, P-19-118, and P-19-120. The SNURs require persons who intend to manufacture or process any of these chemical substances for an activity that is designated as a significant new use in the SNURs to notify EPA at least 90 days before commencing that activity.</P>
                <P>
                    Previously, in the 
                    <E T="04">Federal Register</E>
                     of December 6, 2019 (84 FR 66855) (FRL-10001-48), EPA proposed SNURs for these chemical substances along with nineteen other SNURs. EPA finalized the proposed SNURs for P-17-393, P-19-86, P-19-87, P-19-89, P-19-90, P-19-91, P-19-92, P-19-93, P-19-97, P-19-100, P-19-101, P-19-102, P-19-103, P-19-104, P-19-105, P-19-106, P-19-107, P-19-108, and P-19-110 in a previous 
                    <E T="04">Federal Register</E>
                     notice of August 18, 2021 (86 FR 46133) (FRL-8000-02-OCSPP). EPA is not currently finalizing the SNURs for the chemical substances which were the subject of PMNs P-18-387 and P-18-388 and will address these SNURs in a future notice in order to consider new information about exposures. More information on the specific chemical substances subject to this final rule can be found in the 
                    <E T="04">Federal Register</E>
                     document proposing the SNURs. The docket includes information considered by the Agency in developing the proposed and final rules, including the public comments received on the proposed rules that are described in Unit II.
                </P>
                <HD SOURCE="HD2">C. Does this action apply to me?</HD>
                <HD SOURCE="HD3">1. General Applicability</HD>
                <P>
                    This action may apply to you if you manufacture (defined by statute to include import), process, or use the chemical substances addressed in this 
                    <E T="04">Federal Register</E>
                     document. The following list of North American Industrial Classification System (NAICS) codes is not intended to be exhaustive, but rather provides a guide to help readers determine whether this document applies to them. Potentially affected entities may include:
                </P>
                <P>
                    • Manufacturers or processors of one or more subject chemical substances (NAICS codes 325 and 324110), 
                    <E T="03">e.g.,</E>
                     chemical manufacturing and petroleum refineries.
                </P>
                <HD SOURCE="HD3">2. Applicability to Importers and Exporters</HD>
                <P>This action may also affect certain entities through pre-existing import certification and export notification requirements under TSCA. Chemical importers are subject to TSCA section 13 (15 U.S.C. 2612), the import provisions promulgated at 19 CFR 12.118 through 12.127 (see also 19 CFR 127.28), and the EPA policy in support of import certification at 40 CFR part 707, subpart B. Importers of chemical substances in bulk form, as part of a mixture, or as part of an article (if required by rule) must certify that the shipment of the chemical substance complies with all applicable rules and Orders under TSCA, including regulations issued under TSCA sections 5, 6, 7 and Title IV.</P>
                <P>In addition, pursuant to 40 CFR 721.20, any persons who export or intend to export a chemical substance identified in this document are subject to the export notification provisions of TSCA section 12(b) (15 U.S.C. 2611(b)) (see 40 CFR 721.20), and must comply with the export notification requirements in 40 CFR part 707, subpart D.</P>
                <HD SOURCE="HD2">D. What are the estimated incremental impacts of this action?</HD>
                <P>EPA has evaluated the potential costs of establishing SNUN reporting requirements for potential manufacturers (including importers) and processors of the chemical substances included in these SNURs. This analysis, which is available in the docket, is briefly summarized here.</P>
                <HD SOURCE="HD3">1. Estimated Costs for SNUN Submissions</HD>
                <P>If a SNUN is submitted, costs are an estimated $45,000 per SNUN submission for large business submitters and $14,500 for small business submitters. These estimates include the cost to prepare and submit the SNUN (including registration for EPA's Central Data Exchange (CDX)), and the payment of a user fee. Businesses that submit a SNUN would be subject to either a $37,000 user fee required by 40 CFR 700.45(c)(2)(ii) and (d), or, if they are a small business as defined at 13 CFR 121.201, a reduced user fee of $6,480 (40 CFR 700.45(c)(1)(ii) and (d)) per fiscal year 2022. The costs of submission for SNUNs will not be incurred by any company unless a company decides to pursue a significant new use as defined in these SNURs. Additionally, these estimates reflect the costs and fees as they are known at the time of this rulemaking.</P>
                <HD SOURCE="HD3">2. Estimated Costs for Export Notifications</HD>
                <P>
                    EPA has also evaluated the potential costs associated with the export notification requirements under TSCA section 12(b) and the implementing regulations at 40 CFR part 707, subpart D. For persons exporting a substance that is the subject of a SNUR, a one-time notice to EPA must be provided for the first export or intended export to a particular country. The total costs of export notification will vary by chemical, depending on the number of required notifications (
                    <E T="03">i.e.,</E>
                     the number of countries to which the chemical is exported). While EPA is unable to make any estimate of the likely number of export notifications for the chemical substances covered by these SNURs, as stated in the accompanying economic analysis, the estimated cost of the export notification requirement on a per unit basis is approximately $106.
                </P>
                <HD SOURCE="HD1">II. Background</HD>
                <P>
                    Unit II. of the proposed rule provides general information about SNURs, and additional information about EPA's new chemical program is available at 
                    <E T="03">https://www.epa.gov/reviewing-new-chemicals-under-toxic-substances-control-act-tsca.</E>
                    <PRTPAGE P="569"/>
                </P>
                <HD SOURCE="HD2">A. Significant New Uses Claimed as Confidential Business Information (CBI)</HD>
                <P>EPA is establishing certain significant new uses which have been claimed as CBI subject to Agency confidentiality regulations at 40 CFR part 2 and 40 CFR part 703. Absent a final determination or other disposition of the confidentiality claim under these regulations, EPA is required to keep this information confidential. EPA promulgated a procedure at 40 CFR 721.11 to deal with the situation where a specific significant new use is CBI.</P>
                <P>
                    Under these procedures a manufacturer or processor may request EPA to identify the confidential significant new use under the rule. The manufacturer or processor must show that it has a 
                    <E T="03">bona fide</E>
                     intent to manufacture or process the chemical substance. If EPA concludes that the person has shown a 
                    <E T="03">bona fide</E>
                     intent to manufacture or process the chemical substance, EPA will identify the confidential significant new use to that person. Since most of the chemical identities of the chemical substances subject to these SNURs are also CBI, manufacturers and processors can combine the 
                    <E T="03">bona fide</E>
                     submission under the procedure in 40 CFR 721.11 into a single step.
                </P>
                <HD SOURCE="HD2">B. Applicability of the Significant New Use Designation</HD>
                <P>Any use that EPA determines in the final rule was ongoing as of the date of publication of the proposal and did not cease prior to issuance of the final rule, will not be designated as a significant new use in the final rule. EPA has no information to suggest that any of the significant new uses identified in this rule meet those criteria.</P>
                <P>
                    As discussed in the 
                    <E T="04">Federal Register</E>
                     of April 24, 1990 (55 FR 17376 (FRL-3658-5)), EPA believes that the intent of TSCA section 5(a)(1)(B) is best served by designating a use as a significant new use as of the date of publication of the proposed rule rather than as of the effective date of the final rule. The objective of EPA's approach is to ensure that a person cannot impede finalization of a SNUR by initiating a significant new use after publication of the proposed rule but before the effective date of the final rule. Uses arising after the publication of the proposed rule are distinguished from uses that are identified in the final rule as having been ongoing on the date of publication of the proposed rule. The former would be new uses, the latter ongoing uses, except that uses that are identified as ongoing as of the publication of the proposed rule would not be considered ongoing uses if they have ceased by the date of issuance of a final rule.
                </P>
                <P>In the unlikely event that before a final rule becomes effective a person begins commercial manufacturing (including importing) or processing of the chemical substances for a use that is designated as a significant new use in that final rule, such a person would have to cease any such activity upon the effective date of the final rule. To resume their activities, these persons would have to first comply with all applicable SNUR notification requirements and wait until all TSCA prerequisites for the commencement of manufacture or processing have been satisfied.</P>
                <P>
                    Issuance of a SNUR for a chemical substance does not signify that the chemical substance is listed on the TSCA Chemical Substance Inventory (TSCA Inventory). Guidance on how to determine if a chemical substance is on the TSCA Inventory is available on the internet at 
                    <E T="03">https://www.epa.gov/tsca-inventory.</E>
                </P>
                <HD SOURCE="HD2">C. Important Information About SNUN Submissions</HD>
                <HD SOURCE="HD3">1. SNUN Submissions</HD>
                <P>
                    SNUNs must be submitted on EPA Form No. 7710-25, generated using e-PMN software, and submitted to the Agency in accordance with the procedures set forth in 40 CFR 720.40 and 721.25. E-PMN software is available electronically at 
                    <E T="03">https://www.epa.gov/reviewing-new-chemicals-under-toxic-substances-control-act-tsca.</E>
                </P>
                <HD SOURCE="HD3">2. Development and Submission of Information</HD>
                <P>
                    EPA recognizes that TSCA section 5 does not require development of any particular new information (
                    <E T="03">e.g.,</E>
                     generating test data) before submission of a SNUN. There is an exception: If a person is required to submit information for a chemical substance pursuant to a rule, order or consent agreement under TSCA section 4, then TSCA section 5(b)(1)(A) requires such information to be submitted to EPA at the time of submission of the SNUN.
                </P>
                <P>In the absence of a rule, TSCA order, or consent agreement under TSCA section 4 covering the chemical substance, persons are required only to submit information in their possession or control and to describe any other information known to or reasonably ascertainable by them (see 40 CFR 720.50). However, upon review of PMNs and SNUNs, the Agency has the authority to require appropriate testing. To assist with EPA's analysis of the SNUN, submitters are encouraged, but not required, to provide the potentially useful information identified for the chemical substance in Unit IV of the proposed rule.</P>
                <P>
                    EPA strongly encourages persons, before performing any testing, to consult with the Agency pertaining to protocol selection. Furthermore, pursuant to TSCA section 4(h), which pertains to reduction of testing in vertebrate animals, EPA encourages consultation with the Agency on the use of alternative test methods and strategies (also called New Approach Methodologies, or NAMs), if available, to generate the recommended test data. EPA encourages dialog with Agency representatives to help determine how best the submitter can meet both the data needs and the objective of TSCA section 4(h). For more information on alternative test methods and strategies to reduce vertebrate animal testing, visit 
                    <E T="03">https://www.epa.gov/assessing-and-managing-chemicals-under-tsca/alternative-test-methods-and-strategies-reduce.</E>
                </P>
                <P>The potentially useful information described in Unit IV of the proposed rule may not be the only means of providing information to evaluate the chemical substance associated with the significant new uses. However, submitting a SNUN without any test data may increase the likelihood that EPA will take action under TSCA sections 5(e) or 5(f). EPA recommends that potential SNUN submitters contact EPA early enough so that they will be able to conduct the appropriate tests.</P>
                <P>SNUN submitters should be aware that EPA will be better able to evaluate SNUNs which provide detailed information on the following:</P>
                <P>• Human exposure and environmental release that may result from the significant new use of the chemical substances.</P>
                <HD SOURCE="HD2">D. Public Comments on Proposed Rule and EPA Responses</HD>
                <P>
                    EPA received public comments from two identifying entities and two confidential entities pertaining to the SNURs that the Agency is finalizing with this rule. One comment was generally critical of the rule but did not identify specific changes or issues with the rule requirements; therefore, no response is required. Two of the comments identified ongoing uses of two different chemical substances in the proposed rule. As a result, EPA is issuing a modified final rule for those chemical substances that do not designate the ongoing uses as significant new uses. Specifically, for the chemical substance that was the subject of P-17-299, EPA will no longer designate as a 
                    <PRTPAGE P="570"/>
                    significant new use the use of the chemical substance in a manner that generates a dust, mist, or aerosol. EPA is instead designating as a significant new use the use of the chemical substance by workers unless specific respiratory protection is provided. For the chemical substance that was the subject of P-18-172, EPA is not designating use of the chemical substance in architectural coatings that are consumer products as a significant new use. A summary of all of the comments and the Agency's responses to these comments are presented in the Response to Public Comments document. The comments and the Response to Public Comments are available in the docket for this rule.
                </P>
                <HD SOURCE="HD1">III. Chemical Substances Subject to These SNURs</HD>
                <HD SOURCE="HD2">A. What is the designated cutoff date for determining whether the new use is ongoing for these chemical substances?</HD>
                <P>EPA designates December 6, 2019, as the cutoff date for determining whether the new use is ongoing. This designation is explained in more detail in Unit VI of the proposed rule.</P>
                <HD SOURCE="HD2">B. What information is provided for each chemical substance?</HD>
                <P>In Unit IV. of the proposed rule, EPA provided the following information for each chemical substance subject to these SNURs:</P>
                <P>• PMN number (the CFR citation assigned in the regulatory text section of this document).</P>
                <P>• Chemical name (generic name, if the specific name is claimed as CBI).</P>
                <P>• Chemical Abstracts Service Registry Number (CASRN) (if assigned for non-confidential chemical identities).</P>
                <P>• Potentially useful information.</P>
                <P>The regulatory text section specifies the activities designated as significant new uses. Certain new uses, including exceeding production volume limits and other uses designated in the proposed rules, may be claimed as CBI.</P>
                <P>In addition, as discussed in Unit V.A. of the proposed rule, for the chemical substances that have undergone premanufacture review, EPA has identified certain conditions of use and other circumstances of use apart from those intended by the PMN submitter as significant new uses. All uses identified as significant new uses in this rule cannot occur without first going through a separate EPA review and determination process associated with a SNUN.</P>
                <HD SOURCE="HD1">IV. Statutory and Executive Order Reviews</HD>
                <P>
                    Additional information about these statutes and Executive orders can be found at 
                    <E T="03">https://www.epa.gov/laws-regulations-and-executive-orders.</E>
                </P>
                <HD SOURCE="HD2">A. Executive Order 12866: Regulatory Planning and Review and Executive Order 14094: Modernizing Regulatory Review</HD>
                <P>This action establishes SNURs for new chemical substances that were the subject of PMNs. The Office of Management and Budget (OMB) has exempted these types of actions from review under Executive Order 12866 (58 FR 51735, October 4, 1993), as amended by Executive Order 14094 (88 FR 21879, April 11, 2023).</P>
                <HD SOURCE="HD2">B. Paperwork Reduction Act (PRA)</HD>
                <P>
                    According to PRA, 44 U.S.C. 3501 
                    <E T="03">et seq.,</E>
                     an agency may not conduct or sponsor, and a person is not required to respond to a collection of information that requires OMB approval under PRA, unless it has been approved by OMB and displays a currently valid OMB control number. The OMB control numbers for EPA's regulations in title 40 of the CFR, after appearing in the 
                    <E T="04">Federal Register</E>
                    , are listed in 40 CFR part 9, and included on the related collection instrument or form, if applicable.
                </P>
                <P>The information collection requirements associated with SNURs have already been approved by OMB pursuant to the PRA under OMB control number 2070-0038 (EPA ICR No. 1188.13). This action does not impose any burden requiring additional OMB approval. If an entity were to submit a SNUN to the Agency, the annual burden is estimated to average between 30 and 170 hours per submission. This burden estimate includes the time needed to review instructions, search existing data sources, gather and maintain the data needed, and complete, review, and submit the required SNUN.</P>
                <P>EPA always welcomes your feedback on the burden estimate. Send any comments about the accuracy of the burden estimate, and any suggested methods for minimizing respondent burden, including through the use of automated collection techniques.</P>
                <HD SOURCE="HD2">C. Regulatory Flexibility Act (RFA)</HD>
                <P>
                    I certify that this action will not have a significant economic impact on a substantial number of small entities under the RFA (5 U.S.C. 601 
                    <E T="03">et seq.</E>
                    ). The requirement to submit a SNUN applies to any person (including small or large entities) who intends to engage in any activity described in the final rule as a “significant new use.” Because these uses are “new,” based on all information currently available to EPA, EPA has concluded that no small or large entities presently engage in such activities.
                </P>
                <P>A SNUR requires that any person who intends to engage in such activity in the future must first notify EPA by submitting a SNUN. Although some small entities may decide to pursue a significant new use in the future, EPA cannot presently determine how many, if any, there may be. However, EPA's experience to date is that, in response to the promulgation of SNURs covering over 1,000 chemicals, the Agency receives only a small number of notices per year. For example, the number of SNUNs received was 16 in Federal fiscal year (FY) FY2018, five in FY2019, seven in FY2020, 13 in FY2021, 11 in FY2022, and 15 in FY2023, and only a fraction of these submissions were from small businesses.</P>
                <P>
                    In addition, the Agency currently offers relief to qualifying small businesses by reducing the SNUN submission fee from $37,000 to 6,480. This lower fee reduces the total reporting and recordkeeping cost of submitting a SNUN to about $14,500 per SNUN submission for qualifying small firms. Therefore, the potential economic impacts of complying with these SNURs are not expected to be significant or adversely impact a substantial number of small entities. In a SNUR that published in the 
                    <E T="04">Federal Register</E>
                     of June 2, 1997 (62 FR 29684) (FRL-5597-1), the Agency presented its general determination that SNURs are not expected to have a significant economic impact on a substantial number of small entities, which was provided to the Chief Counsel for Advocacy of the Small Business Administration.
                </P>
                <HD SOURCE="HD2">D. Unfunded Mandates Reform Act (UMRA)</HD>
                <P>
                    This action does not contain an unfunded mandate of $100 million or more (in 1995 dollars) in any one year as described in UMRA, 2 U.S.C. 1531-1538, and does not significantly or uniquely affect small governments. Based on EPA's experience with proposing and finalizing SNURs, State, local, and Tribal governments have not been impacted by SNURs, and EPA does not have any reasons to believe that any State, local, or Tribal government will be impacted by these SNURs. In addition, the estimated costs of this action to the private sector do not exceed $183 million or more in any one year (the 1995 dollars are adjusted to 2023 dollars for inflation using the GDP implicit price deflator). The estimated 
                    <PRTPAGE P="571"/>
                    costs for this action are discussed in Unit I.D.
                </P>
                <HD SOURCE="HD2">E. Executive Order 13132: Federalism</HD>
                <P>This action will not have federalism implications as specified in Executive Order 13132 (64 FR 43255, August 10, 1999), because it is not expected to have a substantial direct effect on States, on the relationship between the national government and the States, or on the distribution of power and responsibilities among the various levels of government. Accordingly, the requirements of Executive Order 13132 do not apply to this action.</P>
                <HD SOURCE="HD2">F. Executive Order 13175: Consultation and Coordination With Indian Tribal Governments</HD>
                <P>This action will not have Tribal implications as specified in Executive Order 13175 (65 FR 67249, November 9, 2000), because it is not expected to have substantial direct effects on Indian Tribes or significantly or uniquely affect the communities of Indian Tribal governments and does not involve or impose any requirements that affect Indian Tribes. Accordingly, the requirements of Executive Order 13175 do not apply to this action.</P>
                <HD SOURCE="HD2">G. Executive Order 13045: Protection of Children From Environmental Health Risks and Safety Risks</HD>
                <P>This action is not subject to Executive Order 13045 (62 FR 19885, April 23, 1997), because it does not concern an environmental health or safety risk. Since this action does not concern a human health risk, EPA's 2021 Policy on Children's Health also does not apply. Although the establishment of these SNURs do not address an existing children's environmental health concern because the chemical uses involved are not ongoing uses, SNURs require that persons notify EPA at least 90 days before commencing manufacture (defined by statute to include import) or processing of any of these chemical substances for an activity that is designated as a significant new use by this rule. This notification allows EPA to assess the intended uses to identify potential risks and take appropriate actions before the activities commence.</P>
                <HD SOURCE="HD2">H. Executive Order 13211: Actions Concerning Regulations That Significantly Affect Energy Supply, Distribution, or Use</HD>
                <P>This action is not a “significant energy action” as defined in Executive Order 13211 (66 FR 28355, May 22, 2001), because it is not likely to have a significant adverse effect on the supply, distribution, or use of energy.</P>
                <HD SOURCE="HD2">I. National Technology Transfer and Advancement Act (NTTAA)</HD>
                <P>This action does not involve any technical standards subject to NTTAA section 12(d) (15 U.S.C. 272 note).</P>
                <HD SOURCE="HD2">J. Executive Order 12898: Federal Actions To Address Environmental Justice in Minority Populations and Low-Income Populations and Executive Order 14096: Revitalizing Our Nation's Commitment to Environmental Justice for All</HD>
                <P>This action does not concern human health or environmental conditions and therefore cannot be evaluated with respect to the potential for disproportionate impacts on non-white and low-income populations in accordance with Executive Order 12898 (59 FR 7629, February 16, 1994) and Executive Order 14096 (88 FR 25251, April 26, 2023). Although this action does not concern human health or environmental conditions, the premanufacture notifications required by these SNURs allow EPA to assess the intended uses to identify potential disproportionate risks and take appropriate actions before the activities commence.</P>
                <HD SOURCE="HD2">K. Congressional Review Act (CRA)</HD>
                <P>
                    This action is subject to the CRA (5 U.S.C. 801 
                    <E T="03">et seq.</E>
                    ), and EPA will submit a rule report to each House of the Congress and to the Comptroller General of the United States. This action is not a “major rule” as defined by 5 U.S.C. 804(2).
                </P>
                <LSTSUB>
                    <HD SOURCE="HED">List of Subjects</HD>
                    <CFR>40 CFR Part 9</CFR>
                    <P>Environmental protection, Reporting and recordkeeping requirements.</P>
                    <CFR>40 CFR Part 721</CFR>
                    <P>Environmental protection, Chemicals, Hazardous substances, Reporting and recordkeeping requirements.</P>
                </LSTSUB>
                <SIG>
                    <DATED>Dated: December 20, 2024.</DATED>
                    <NAME>Mary Elissa Reaves,</NAME>
                    <TITLE>Director, Office of Pollution Prevention and Toxics.</TITLE>
                </SIG>
                <P>Therefore, for the reasons stated in the preamble, 40 CFR chapter I is amended as follows:</P>
                <PART>
                    <HD SOURCE="HED">PART 9—OMB APPROVALS UNDER THE PAPERWORK REDUCTION ACT</HD>
                </PART>
                <REGTEXT TITLE="40" PART="9">
                    <AMDPAR>1. The authority citation for part 9 continues to read as follows:</AMDPAR>
                    <AUTH>
                        <HD SOURCE="HED">Authority:</HD>
                        <P>
                             7 U.S.C. 135 
                            <E T="03">et seq.,</E>
                             136-136y; 15 U.S.C. 2001, 2003, 2005, 2006, 2601-2671; 21 U.S.C. 331j, 346a; 31 U.S.C. 9701; 33 U.S.C. 1251 
                            <E T="03">et seq.,</E>
                             1311, 1313d, 1314, 1318, 1321, 1326, 1330, 1342, 1344, 1345 (d) and (e), 1361; E.O. 11735, 38 FR 21243, 3 CFR, 1971-1975 Comp. p. 973; 42 U.S.C. 241, 242b, 243, 246, 300f, 300g, 300g-1, 300g-2, 300g-3, 300g-4, 300g-5, 300g-6, 300j-1, 300j-2, 300j-3, 300j-4, 300j-9, 1857 
                            <E T="03">et seq.,</E>
                             6901-6992k, 7401-7671q, 7542, 9601-9657, 11023, 11048.
                        </P>
                    </AUTH>
                </REGTEXT>
                <REGTEXT TITLE="40" PART="9">
                    <AMDPAR>2. Amend the table in § 9.1, by adding entries for §§ 721.11420 and 721.11421, 721.11423, and 721.11444 through 721.11446 in numerical order under the undesignated center heading “Significant New Uses of Chemical Substances” to read as follows:</AMDPAR>
                    <SECTION>
                        <SECTNO>§ 9.1</SECTNO>
                        <SUBJECT> OMB approvals under the Paperwork Reduction Act.</SUBJECT>
                        <STARS/>
                        <GPOTABLE COLS="2" OPTS="L1,tp0,i1" CDEF="s25,16">
                            <TTITLE> </TTITLE>
                            <BOXHD>
                                <CHED H="1">40 CFR citation</CHED>
                                <CHED H="1">OMB control No.</CHED>
                            </BOXHD>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW RUL="s">
                                <ENT I="28">*    *    *    *    *</ENT>
                            </ROW>
                            <ROW EXPSTB="01" RUL="s">
                                <ENT I="21">
                                    <E T="02">Significant New Uses of Chemical Substances</E>
                                </ENT>
                            </ROW>
                            <ROW EXPSTB="00">
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*    *    *    *    *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">721.11420</ENT>
                                <ENT>2070-0012</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">721.11421</ENT>
                                <ENT>2070-0012</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*    *    *    *    *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">721.11423</ENT>
                                <ENT>2070-0012</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*    *    *    *    *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">721.11444</ENT>
                                <ENT>2070-0012</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">721.11445</ENT>
                                <ENT>2070-0012</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">721.11446</ENT>
                                <ENT>2070-0012</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*    *    *    *    *</ENT>
                            </ROW>
                        </GPOTABLE>
                        <STARS/>
                    </SECTION>
                </REGTEXT>
                <PART>
                    <HD SOURCE="HED">PART 721—SIGNIFICANT NEW USES OF CHEMICAL SUBSTANCES</HD>
                </PART>
                <REGTEXT TITLE="40" PART="721">
                    <AMDPAR>3. The authority citation for part 721 continues to read as follows:</AMDPAR>
                    <AUTH>
                        <HD SOURCE="HED">Authority:</HD>
                        <P>15 U.S.C. 2604, 2607, and 2625(c).</P>
                    </AUTH>
                </REGTEXT>
                <SUBPART>
                    <HD SOURCE="HED">Subpart E—Significant New Uses for Specific Chemical Substances</HD>
                </SUBPART>
                <REGTEXT TITLE="40" PART="721">
                    <AMDPAR>4. Add §§ 721.11420, 721.11421, 721.11423, and 721.11444 through 721.11446 to Subpart E to read as follows:</AMDPAR>
                    <EXTRACT>
                        <FP>Sec.</FP>
                        <FP>*  *  *  *  *</FP>
                        <FP SOURCE="FP-2">721.11420 Soybean meal, reaction products with phosphoric trichloride.</FP>
                        <FP SOURCE="FP-2">721.11421 2-propenoic acid, alkyl, polymers with alkyl acrylate and polyethylene glycol methacrylate alkyl ether (generic).</FP>
                        <FP>
                            *  *  *  *  *
                            <PRTPAGE P="572"/>
                        </FP>
                        <FP SOURCE="FP-2">721.11423 Calcium, carbonate 2-ethylhexanoate neodecanoate propionate complexes.</FP>
                        <FP>*  *  *  *  *</FP>
                        <FP SOURCE="FP-2">721.11444 Propanoic acid, 3-hydroxy-2-(hydroxymethyl)-2-methyl-, polymer with dimethyl carbonate, 1,2-ethanediamine, 2-ethyl-2-(hydroxymethyl)-1,3-propanediol, 1,6-hexanediol and 1,1′-methylenebis[4-isocyanatocyclohexane], compd. with N,N-diethylethanamine.</FP>
                        <FP SOURCE="FP-2">721.11445 Substituted polyalkylenepoly, reaction products with alkene polymer (generic).</FP>
                        <FP SOURCE="FP-2">721.11446 Alkenoic acid, polymer with alkanediyl bis substituted alkylene bis heteromonocycle, substituted carbomonocycle and (alkylalkenyl) carbomonocycle, alkali metal salt (generic).</FP>
                    </EXTRACT>
                    <STARS/>
                    <SECTION>
                        <SECTNO>§ 721.11420</SECTNO>
                        <SUBJECT> Soybean meal, reaction products with phosphoric trichloride.</SUBJECT>
                        <P>
                            (a) 
                            <E T="03">Chemical substance and significant new uses subject to reporting.</E>
                             (1) The chemical substance identified as soybean meal, reaction products with phosphoric trichloride (PMN P-16-541, CASRN 1962913-92-3) is subject to reporting under this section for the significant new uses described in paragraph (a)(2) of this section.
                        </P>
                        <P>(2) The significant new uses are:</P>
                        <P>
                            (i) 
                            <E T="03">Release to water.</E>
                             Requirements as specified in § 721.90(a)(4), (b)(4), and (c)(4), where N=22.
                        </P>
                        <P>(ii) [Reserved]</P>
                        <P>
                            (b) 
                            <E T="03">Specific requirements.</E>
                             The provisions of Subpart A of this part apply to this section except as modified by this paragraph (b).
                        </P>
                        <P>
                            (1) 
                            <E T="03">Recordkeeping.</E>
                             Recordkeeping requirements as specified in § 721.125(a) through (c), and (k) are applicable to manufacturers and processors of this substance.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Limitation or revocation of certain notification requirements.</E>
                             The provisions of § 721.185 apply to this section.
                        </P>
                    </SECTION>
                    <SECTION>
                        <SECTNO>§ 721.11421</SECTNO>
                        <SUBJECT> 2-propenoic acid, alkyl, polymers with alkyl acrylate and polyethylene glycol methacrylate alkyl ether (generic).</SUBJECT>
                        <P>
                            (a) 
                            <E T="03">Chemical substance and significant new uses subject to reporting.</E>
                             (1) The chemical substance identified generically as 2-propenoic acid, alkyl, polymers with alkyl acrylate and polyethylene glycol methacrylate alkyl ether (PMN P-17-299) is subject to reporting under this section for the significant new uses described in paragraph (a)(2) of this section.
                        </P>
                        <P>(2) The significant new uses are:</P>
                        <P>
                            (i) 
                            <E T="03">Protection in the workplace.</E>
                             Requirements as specified in § 721.63(a)(4) through (6), and (c). When determining which persons are reasonably likely to be exposed as required for § 721.63(4), engineering control measures (
                            <E T="03">e.g.,</E>
                             enclosure or confinement of the operation, general and local ventilation) or administrative control measures (
                            <E T="03">e.g.,</E>
                             workplace policies and procedures) shall be considered and implemented to prevent exposure, where feasible. For purposes of § 721.63(a)(5), respirators must provide a National Institute for Occupational Safety and Health (NIOSH) assigned protection factor (APF) of at least 1,000.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Industrial, commercial, and consumer activities.</E>
                             Requirements as specified in § 721.80(f). It is a significant new use to use the substance other than as a thickener in paint. It is a significant new use to use the substance in concentrations greater than 1% in formulated products.
                        </P>
                        <P>
                            (b) 
                            <E T="03">Specific requirements.</E>
                             The provisions of Subpart A of this part apply to this section except as modified by this paragraph (b).
                        </P>
                        <P>
                            (1) 
                            <E T="03">Recordkeeping.</E>
                             Recordkeeping requirements as specified in § 721.125(a) through (c), and (i) are applicable to manufacturers and processors of this substance.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Limitation or revocation of certain notification requirements.</E>
                             The provisions of § 721.185 apply to this section.
                        </P>
                        <STARS/>
                    </SECTION>
                    <SECTION>
                        <SECTNO>§ 721.11423</SECTNO>
                        <SUBJECT> Calcium, carbonate 2-ethylhexanoate neodecanoate propionate complexes.</SUBJECT>
                        <P>
                            (a) 
                            <E T="03">Chemical substance and significant new uses subject to reporting.</E>
                             (1) The chemical substance identified as calcium, carbonate 2-ethylhexanoate neodecanoate propionate complexes (PMN P-18-172) is subject to reporting under this section for the significant new uses described in paragraph (a)(2) of this section.
                        </P>
                        <P>(2) The significant new uses are:</P>
                        <P>
                            (i) 
                            <E T="03">Industrial, commercial, and consumer activities.</E>
                             It is a significant new use to use the substance in a consumer product except for use in architectural coatings. It is a significant new use to use the substance other than as an auxiliary drier for architectural paints, industrial coatings and stains.
                        </P>
                        <P>(ii) [Reserved]</P>
                        <P>
                            (b) 
                            <E T="03">Specific requirements.</E>
                             The provisions of Subpart A of this part apply to this section except as modified by this paragraph (b).
                        </P>
                        <P>
                            (1) 
                            <E T="03">Recordkeeping.</E>
                             Recordkeeping requirements as specified in § 721.125(a) through (c), and (i) are applicable to manufacturers and processors of this substance.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Limitation or revocation of certain notification requirements.</E>
                             The provisions of § 721.185 apply to this section.
                        </P>
                        <STARS/>
                    </SECTION>
                    <SECTION>
                        <SECTNO>§ 721.11444</SECTNO>
                        <SUBJECT> Propanoic acid, 3-hydroxy-2-(hydroxymethyl)-2-methyl-, polymer with dimethyl carbonate, 1,2-ethanediamine, 2-ethyl-2-(hydroxymethyl)-1,3-propanediol, 1,6-hexanediol and 1,1′-methylenebis[4-isocyanatocyclohexane], compd. with N,N-diethylethanamine.</SUBJECT>
                        <P>
                            (a) 
                            <E T="03">Chemical substance and significant new uses subject to reporting.</E>
                             (1) The chemical substance identified as propanoic acid, 3-hydroxy-2-(hydroxymethyl)-2-methyl-, polymer with dimethyl carbonate, 1,2-ethanediamine, 2-ethyl-2-(hydroxymethyl)-1,3-propanediol, 1,6-hexanediol and 1,1′-methylenebis[4-isocyanatocyclohexane], compd. with N,N-diethylethanamine (PMN P-19-99, CASRN 1178511-46-0) is subject to reporting under this section for the significant new uses described in paragraph (a)(2) of this section. (2) The significant new uses are:
                        </P>
                        <P>
                            (i) 
                            <E T="03">Industrial, commercial, and consumer activities.</E>
                             Requirements as specified in § 721.80(o). It is a significant new use to use the substance other than as a clear coat for wood.
                        </P>
                        <P>(ii) [Reserved]</P>
                        <P>
                            (b) 
                            <E T="03">Specific requirements.</E>
                             The provisions of Subpart A of this part apply to this section except as modified by this paragraph (b).
                        </P>
                        <P>
                            (1) 
                            <E T="03">Recordkeeping.</E>
                             Recordkeeping requirements as specified in § 721.125(a) through (c), and (i) are applicable to manufacturers and processors of this substance.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Limitation or revocation of certain notification requirements.</E>
                             The provisions of § 721.185 apply to this section.
                        </P>
                    </SECTION>
                    <SECTION>
                        <SECTNO>§ 721.11445</SECTNO>
                        <SUBJECT> Substituted polyalkylenepoly, reaction products with alkene polymer (generic).</SUBJECT>
                        <P>
                            (a) 
                            <E T="03">Chemical substance and significant new uses subject to reporting.</E>
                             (1) The chemical substance identified generically as substituted polyalkylenepoly, reaction products with alkene polymer (PMN P-19-118) is subject to reporting under this section for the significant new uses described in paragraph (a)(2) of this section. (2) The significant new uses are:
                        </P>
                        <P>
                            (i) 
                            <E T="03">Industrial, commercial, and consumer activities.</E>
                             It is a significant new use to manufacture, process, or use the substance in any manner that results in inhalation exposure.
                        </P>
                        <P>(ii) [Reserved]</P>
                        <P>
                            (b) 
                            <E T="03">Specific requirements.</E>
                             The provisions of subpart A of this part 
                            <PRTPAGE P="573"/>
                            apply to this section except as modified by this paragraph (b).
                        </P>
                        <P>
                            (1) 
                            <E T="03">Recordkeeping.</E>
                             Recordkeeping requirements as specified in § 721.125(a) through (c), and (i) are applicable to manufacturers and processors of this substance.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Limitation or revocation of certain notification requirements.</E>
                             The provisions of § 721.185 apply to this section.
                        </P>
                    </SECTION>
                    <SECTION>
                        <SECTNO>§ 721.11446</SECTNO>
                        <SUBJECT> Alkenoic acid, polymer with alkanediyl bis substituted alkylene bis heteromonocycle, substituted carbomonocycle and (alkylalkenyl) carbomonocycle, alkali metal salt (generic).</SUBJECT>
                        <P>
                            (a) 
                            <E T="03">Chemical substance and significant new uses subject to reporting.</E>
                             (1) The chemical substance identified generically as alkenoic acid, polymer with alkanediyl bis substituted alkylene bis heteromonocycle, substituted carbomonocycle and (alkylalkenyl) carbomonocycle, alkali metal salt (PMN P-19-120) is subject to reporting under this section for the significant new uses described in paragraph (a)(2) of this section. (2) The significant new uses are:
                        </P>
                        <P>
                            (i) 
                            <E T="03">Release to water.</E>
                             Requirements as specified in § 721.90(a)(4), (b)(4), and (c)(4) where N=78.
                        </P>
                        <P>(ii) [Reserved]</P>
                        <P>
                            (b) 
                            <E T="03">Specific requirements.</E>
                             The provisions of Subpart A of this part apply to this section except as modified by this paragraph (b).
                        </P>
                        <P>
                            (1) 
                            <E T="03">Recordkeeping.</E>
                             Recordkeeping requirements as specified in § 721.125(a) through (c), and (k) are applicable to manufacturers and processors of this substance.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Limitation or revocation of certain notification requirements.</E>
                             The provisions of § 721.185 apply to this section.
                        </P>
                    </SECTION>
                </REGTEXT>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-30964 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6560-50-P</BILCOD>
        </RULE>
        <RULE>
            <PREAMB>
                <AGENCY TYPE="S">ENVIRONMENTAL PROTECTION AGENCY</AGENCY>
                <CFR>40 CFR Part 372</CFR>
                <DEPDOC>[EPA-HQ-OPPT-2024-0044; FRL 9427.2-01-OCSPP]</DEPDOC>
                <RIN>RIN 2070-AL23</RIN>
                <SUBJECT>Implementing Statutory Addition of Certain Per- and Polyfluoroalkyl Substances (PFAS) to Toxics Release Inventory (TRI) Beginning With Reporting Year 2025</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Environmental Protection Agency (EPA).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Final rule.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Environmental Protection Agency (EPA) is updating the list of chemicals subject to toxic chemical release reporting under the Emergency Planning and Community Right-to-Know Act (EPCRA) and the Pollution Prevention Act (PPA). Specifically, this action updates the regulations to identify nine per- and polyfluoroalkyl substances (PFAS) that must be reported pursuant to the National Defense Authorization Act for Fiscal Year 2020 (FY2020 NDAA) enacted on December 20, 2019. As this action is being taken to conform the regulations to a Congressional legislative mandate, notice and comment rulemaking is unnecessary.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>This final rule is effective February 5, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        The docket for this action, identified by docket identification (ID) number EPA-HQ-OPPT-2024-0044, is available at 
                        <E T="03">https://www.regulations.gov.</E>
                         Additional instructions on visiting the docket, along with more information about dockets generally, is available at 
                        <E T="03">https://www.epa.gov/dockets.</E>
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Daniel R. Ruedy, Data Gathering, Management and Policy Division (7607M), Office of Pollution Prevention and Toxics, Environmental Protection Agency, 1200 Pennsylvania Ave. NW, Washington, DC 20460-0001; telephone number: (202) 564-7974; email address: 
                        <E T="03">ruedy.daniel@epa.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">I. General Information</HD>
                <HD SOURCE="HD2">A. Does this action apply to me?</HD>
                <P>You may be potentially affected by this action if you manufacture, process, or otherwise use any of the PFAS listed in this rule, including but not limited to entities identified with the following North American Industry Classification System (NAICS) codes.</P>
                <P>• Facilities included in the following NAICS manufacturing codes (corresponding to Standard Industrial Classification (SIC) codes 20 through 39): 311*, 312*, 313*, 314*, 315*, 316, 321, 322, 323*, 324, 325*, 326*, 327*, 331, 332, 333, 334*, 335*, 336, 337*, 339*, 111998*, 113310, 211130*, 212323*, 212390*, 488390*, 512230*, 512250*, 5131*, 516210*, 519290*, 541713*, 541715* or 811490*. *Exceptions and/or limitations exist for these NAICS codes.</P>
                <P>
                    • Facilities included in the following NAICS codes (corresponding to SIC codes other than SIC codes 20 through 39): 211130* (corresponds to SIC code 1321, Natural Gas Liquids, and SIC 2819, Industrial Inorganic Chemicals, Not Elsewhere Classified); or 212114, 212115, 212220, 212230, 212290*; or 2211*, 221210*, 221330 (limited to facilities that combust coal and/or oil for the purpose of generating power for distribution in commerce) (corresponds to SIC codes 4911, 4931, and 4939, Electric Utilities); or 424690, 424710 (corresponds to SIC code 5171, Petroleum Bulk Terminals and Plants); 425120 (limited to facilities previously classified in SIC code 5169, Chemicals and Allied Products, Not Elsewhere Classified); or 562112 (limited to facilities primarily engaged in solvent recovery services on a contract or fee basis (previously classified under SIC code 7389, Business Services, NEC)); or 562211*, 562212*, 562213*, 562219*, 562920 (limited to facilities regulated under the Resource Conservation and Recovery Act, subtitle C, 42 U.S.C. 6921 
                    <E T="03">et seq.</E>
                    ) (corresponds to SIC code 4953, Refuse Systems). *Exceptions and/or limitations exist for these NAICS codes.
                </P>
                <P>• Federal facilities.</P>
                <P>
                    A more detailed description of the types of facilities subject to reporting under EPCRA section 313 can be found at: 
                    <E T="03">https://www.epa.gov/toxics-release-inventory-tri-program/tri-covered-industry-sectors.</E>
                     To determine whether your facility would be affected by this action, you should carefully examine the applicability criteria in 40 CFR part 372, subpart B. If you have questions regarding the applicability of this action to a particular entity, consult the person listed under 
                    <E T="02">FOR FURTHER INFORMATION CONTACT</E>
                    .
                </P>
                <HD SOURCE="HD2">B. What action is the Agency taking?</HD>
                <P>EPA is codifying the addition of the nine PFAS added to the EPCRA section 313 list of reportable chemicals (more commonly known as the Toxics Release Inventory (TRI)) since the last conforming rule pursuant to the FY2020 NDAA ((89 FR 43331; May 17, 2024) (FRL-9427.1-01-OCSPP)).</P>
                <HD SOURCE="HD2">C. What is the Agency's authority for taking this action?</HD>
                <P>
                    This action is issued under authority of EPCRA section 313 (42 U.S.C. 11001 
                    <E T="03">et seq.</E>
                    ), PPA section 6607 (42 U.S.C. 13106), and FY2020 NDAA section 7321 (Pub. L. 116-92).
                </P>
                <HD SOURCE="HD1">II. Background</HD>
                <HD SOURCE="HD2">A. What is NDAA Section 7321?</HD>
                <P>
                    The FY2020 NDAA was signed into law on December 20, 2019. Among other provisions, section 7321(c) identifies certain regulatory activities that automatically add PFAS or classes of PFAS to the EPCRA section 313 list of reportable chemicals. PFAS or classes of PFAS shall be added to the EPCRA 
                    <PRTPAGE P="574"/>
                    section 313 list of reportable chemicals beginning January 1 of the calendar year after any one of the following dates:
                </P>
                <P>• Final Toxicity Value. The date on which the Administrator finalizes a toxicity value for the PFAS or class of PFAS;</P>
                <P>• Significant New Use Rule. The date on which the Administrator makes a covered determination for the PFAS or class of PFAS;</P>
                <P>• Addition to Existing Significant New Use Rule. The date on which the PFAS or class of PFAS is added to a list of substances covered by a covered determination;</P>
                <P>• Addition as an Active Chemical Substance. The date on which the PFAS or class of PFAS to which a covered determination applies is:</P>
                <P>
                    (1) Added to the list published under section 8(b)(1) of the Toxic Substances Control Act (TSCA) (15 U.S.C. 2601 
                    <E T="03">et seq.</E>
                    ) and designated as an active chemical substance under TSCA section 8(b)(5)(A); or
                </P>
                <P>(2) Designated as an active chemical substance under TSCA section 8(b)(5)(B) on the list published under TSCA section 8(b)(1).</P>
                <P>The FY2020 NDAA defines “covered determination” as a determination made by rule under TSCA section 5(a)(2) that a use of a PFAS or class of PFAS is a significant new use (except such a determination made in connection with a determination described in TSCA sections 5(a)(3)(B) or 5(a)(3)(C)).</P>
                <P>Under FY2020 NDAA section 7321(e), EPA must review confidential business information (CBI) claims before PFAS are added to the list pursuant to FY2020 NDAA sections 7321(b)(1), (c)(1), or (d)(3) whose identities are subject to a claim of protection from disclosure under 5 U.S.C. 552(a), pursuant to 5 U.S.C. 552(b)(4). Under the FY2020 NDAA EPA must:</P>
                <P>• Review a claim of protection from disclosure; and</P>
                <P>• Require that person to reassert and substantiate or re-substantiate that claim in accordance with TSCA section 14(f) (15 U.S.C. 2613(f)).</P>
                <P>In addition, if EPA determines that the chemical identity of a PFAS or class of PFAS qualifies for protection from disclosure, EPA must include the PFAS or class of PFAS on the TRI in a manner that does not disclose the protected information.</P>
                <HD SOURCE="HD2">B. What PFAS have been added to the TRI list?</HD>
                <P>EPA has reviewed the above-listed criteria and found nine chemicals that meet the requirements of this part of the FY2020 NDAA and have an identity not claimed as CBI.</P>
                <GPOTABLE COLS="3" OPTS="L2,tp0,i1" CDEF="s100,r50,12">
                    <TTITLE> </TTITLE>
                    <BOXHD>
                        <CHED H="1">Chemical name/CASRN *</CHED>
                        <CHED H="1">Triggering action</CHED>
                        <CHED H="1">
                            Effective
                            <LI>date</LI>
                        </CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">Ammonium perfluorodecanoate (PFDA NH4) (3108-42-7)</ENT>
                        <ENT>Final Toxicity Value (Ref. 1)</ENT>
                        <ENT>1/1/25</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Sodium perfluorodecanoate (PFDA-Na) (3830-45-3)</ENT>
                        <ENT>Final Toxicity Value (Ref. 1)</ENT>
                        <ENT>1/1/25</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Perfluoro-3-methoxypropanoic acid (377-73-1)</ENT>
                        <ENT>Final Toxicity Value (Ref. 2)</ENT>
                        <ENT>1/1/25</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">6:2 Fluorotelomer sulfonate acid (27619-97-2)</ENT>
                        <ENT>Final Toxicity Value (Ref. 3)</ENT>
                        <ENT>1/1/25</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">6:2 Fluorotelomer sulfonate anion (425670-75-3)</ENT>
                        <ENT>Final Toxicity Value (Ref. 3)</ENT>
                        <ENT>1/1/25</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">6:2 Fluorotelomer sulfonate potassium salt (59587-38-1)</ENT>
                        <ENT>Final Toxicity Value (Ref. 3)</ENT>
                        <ENT>1/1/25</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">6:2 Fluorotelomer sulfonate ammonium salt (59587-39-2)</ENT>
                        <ENT>Final Toxicity Value (Ref. 3)</ENT>
                        <ENT>1/1/25</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">6:2 Fluorotelomer sulfonate sodium salt (27619-94-9)</ENT>
                        <ENT>Final Toxicity Value (Ref. 3)</ENT>
                        <ENT>1/1/25</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Acetic acid, [(γ-ω-perfluoro-C8-10-alkyl)thio] derivs., Bu esters (3030471-22-5)</ENT>
                        <ENT>CBI Declassification (Ref. 4)</ENT>
                        <ENT>1/1/25</ENT>
                    </ROW>
                    <TNOTE>* CASRN means Chemical Abstracts Service Registry Number.</TNOTE>
                </GPOTABLE>
                <P>
                    Under FY2020 NDAA section 7321(e), EPA must review CBI claims before PFAS with identities subject to a claim of protection from disclosure under 5 U.S.C. 552(a) (pursuant to 5 U.S.C. 552(b)(4)) are added to the list. The substance with the CASRN 3030471-22-5 met the criteria under FY2020 NDAA section 7321(c)(1)(A)(iii) but was subject to a claim of protection from disclosure under 5 U.S.C. 552(b)(4) at that time (
                    <E T="03">i.e.,</E>
                     when the FY2020 NDAA was enacted). This substance's identity was published on the non-confidential portion of the TSCA Inventory in 2024; therefore, pursuant to FY2020 NDAA section 7321(e) the chemical was added to the TRI list and is being codified in the CFR by this rulemaking.
                </P>
                <P>
                    As established by the FY2020 NDAA, the addition of these PFAS to the EPCRA section 313 list of reportable chemicals is effective January 1 of the calendar year following any of the dates identified in FY2020 NDAA section 7321(c)(1)(A). Accordingly, these nine PFAS are reportable beginning with the 2025 reporting year (
                    <E T="03">i.e.,</E>
                     reports due by July 1, 2026), and EPA is issuing this final rule to amend the EPCRA section 313 list of reportable chemicals in 40 CFR 372.65 to include the nine non-CBI PFAS added pursuant to the FY2020 NDAA.
                </P>
                <P>Note that pursuant to the rule, entitled “Changes to Reporting Requirements for Per- and Polyfluoroalkyl Substances and to Supplier Notifications for Chemicals of Special Concern; Community Right-to-Know Toxic Chemical Release Reporting; Final Rule” (88 FR 74360, October 31, 2023 (FRL-8741-04-OCSPP)), all PFAS added to TRI pursuant to FY2020 NDAA sections 7321(b) and (c), are designated as chemicals of special concern (40 CFR 372.28), which also applies to the nine PFAS identified in this rulemaking. Chemicals of special concern are excluded from the de minimis exemption, may not be reported on a Form A (Alternate Threshold Certification Statement), and have limits related to reporting requirements. For more information on the addition of PFAS to the list of chemicals of special concern, see 40 CFR 372.28.</P>
                <HD SOURCE="HD1">III. Good Cause Exception</HD>
                <P>Section 553(b)(B) of the Administrative Procedure Act (APA), 5 U.S.C. 553(b)(B), provides that, when an agency for good cause finds that public notice and comment procedures are impracticable, unnecessary, or contrary to the public interest, the agency may issue a rule without providing notice and an opportunity for public comment. EPA has determined that there is good cause for making this rule final without prior proposal and opportunity for comment because such notice and opportunity for comment is unnecessary. This action is being taken to comply with a mandate in an Act of Congress, in which Congress identified actions that automatically add these chemicals to the TRI. Thus, EPA has no discretion as to the outcome of this rule, which aligns the regulations with the self-effectuating changes provided by the FY2020 NDAA.</P>
                <HD SOURCE="HD1">IV. References</HD>
                <P>
                    The following is a listing of the documents that are specifically referenced in this document. The docket includes these documents and other 
                    <PRTPAGE P="575"/>
                    information considered by EPA, including documents that are referenced within the documents that are included in the docket, even if the referenced document is not itself physically located in the docket. For assistance in locating these other documents, please consult the person listed under 
                    <E T="02">FOR FURTHER INFORMATION CONTACT</E>
                    .
                </P>
                <EXTRACT>
                    <FP SOURCE="FP-2">1. EPA. IRIS Toxicological Review of Perfluorodecanoic Acid (PFDA) and Related Salts. U.S. Environmental Protection Agency, Washington, DC, EPA/635/R-24/172Fa. 2024.</FP>
                    <FP SOURCE="FP-2">2. EPA. EPA Transcriptomic Assessment Product (ETAP) for Perfluoro-3-Methoxypropanoic Acid. U.S. Environmental Protection Agency, Washington, DC, EPA/600/X-24/066. 2024.</FP>
                    <FP SOURCE="FP-2">3. EPA. ORD Human Health Toxicity Value for 6:2 Fluorotelomer Sulfonic Acid. U.S. Environmental Protection Agency, Washington, DC, EPA/600/R-24/315. 2024.</FP>
                    <FP SOURCE="FP-2">4. EPA. Non-CBI TSCA Inventory, May 2024.</FP>
                </EXTRACT>
                <HD SOURCE="HD1">V. Statutory and Executive Order Reviews</HD>
                <P>
                    Additional information about these statutes and Executive orders can be found at 
                    <E T="03">https://www.epa.gov/laws-regulations/laws-and-executive-orders.</E>
                </P>
                <HD SOURCE="HD2">A. Executive Order 12866: Regulatory Planning and Review and 14094: Modernizing Regulatory Review</HD>
                <P>This action is not a significant regulatory action as defined in Executive Order 12866 (58 FR 51735, October 4, 1993), as amended by Executive Order 14094 (88 FR 21879, April 11, 2023), and was therefore not subject to a requirement for Executive Order 12866 review.</P>
                <HD SOURCE="HD2">B. Paperwork Reduction Act (PRA)</HD>
                <P>
                    This action does not impose any new information collection burden under the PRA, 44 U.S.C. 3501 
                    <E T="03">et. seq.</E>
                     Burden is defined in 5 CFR 1320.3(b). The Office of Management and Budget (OMB) has previously approved the information collection activities contained in the existing regulations and assigned OMB control numbers 2070-0212 and 2050-0078.
                </P>
                <P>
                    Currently, the facilities subject to the reporting requirements under EPCRA section 313 and PPA section 6607 must use EPA Toxic Chemicals Release Inventory Form R (EPA Form 9350-1). The nine newly added PFAS are subject to the same reporting requirements as other chemicals of special concern and are excluded from certain burden-reduction reporting options (
                    <E T="03">i.e.,</E>
                     the 
                    <E T="03">de minimis</E>
                     exemption and the option to use Form A, range reporting). The Form R must be completed if a facility manufactures, processes, or otherwise uses any listed chemical above threshold quantities and meets certain other criteria.
                </P>
                <P>Respondents may designate the specific chemical identity of a substance as a trade secret pursuant to EPCRA section 322 (42 U.S.C. 11042) and 40 CFR part 350. OMB has approved the reporting and recordkeeping requirements related to Form R, supplier notification, and petitions under OMB Control No. 2070-0212 (EPA Information Collection Request (ICR) No. 2613.04) and those related to trade secret designations under OMB Control No. 2050-0078 (EPA ICR No. 1428.12).</P>
                <P>
                    An agency may not conduct or sponsor, and a person is not required to respond to, a collection of information unless it displays a currently valid OMB control number. The OMB control numbers relevant to EPA's regulations in 40 CFR are listed in 40 CFR part 9 and displayed on the information collection instruments (
                    <E T="03">e.g.,</E>
                     forms, instructions).
                </P>
                <HD SOURCE="HD2">C. Regulatory Flexibility Act (RFA)</HD>
                <P>
                    This action is not subject to the RFA, 5 U.S.C. 601 
                    <E T="03">et seq.</E>
                     The RFA applies only to rules subject to notice and comment rulemaking requirements under the APA, 5 U.S.C. 553, or any other statute. As discussed in Unit III., this rule is not subject to notice and comment requirements because the Agency has invoked the APA “good cause” exception under 5 U.S.C. 553(b).
                </P>
                <HD SOURCE="HD2">D. Unfunded Mandates Reform Act (UMRA)</HD>
                <P>This action does not contain any unfunded mandate of $100 million or more as described in UMRA, 2 U.S.C. 1531-1538, and does not significantly or uniquely affect small governments. The action imposes no enforceable duty on any State, local, or Tribal governments or the private sector.</P>
                <HD SOURCE="HD2">E. Executive Order 13132: Federalism</HD>
                <P>This action does not have federalism implications, as specified in Executive Order 13132 (64 FR 43255, August 10, 1999), because it will not have substantial direct effects on states, on the relationship between the National Government and the States, or on the distribution of power and responsibilities among the various levels of government.</P>
                <HD SOURCE="HD2">F. Executive Order 13175: Consultation and Coordination With Indian Tribal Governments</HD>
                <P>This action does not have Tribal implications, as specified in Executive Order 13175 (65 FR 67249, November 9, 2000) because it will not have substantial direct effects on Tribal governments, on the relationship between the Federal government and the Indian Tribes, or on the distribution of power and responsibilities between the Federal Government and Indian Tribes. It does not have substantial direct effects on Tribal governments because EPA does not anticipate that reporting of the PFAS added to the TRI list in this action will be conducted by Tribes, so this rulemaking is not expected to impose substantial direct compliance costs on Tribal governments.</P>
                <HD SOURCE="HD2">G. Executive Order 13045: Protection of Children From Environmental Health Risks and Safety Risks</HD>
                <P>This action is not subject to Executive Order 13045 (62 FR 19885, April 23, 1997) because it does not concern an environmental health or safety risk. Since this action does not concern human health, EPA's 2021 Policy on Children's Health also does not apply.</P>
                <P>Although this action does not concern an environmental health or safety risk, this reporting rule will aid in collecting information regarding PFAS. This rule will be of use in identifying releases of PFAS to which children may be exposed. EPA believes that the information obtained as a result of this action could also be used by the public, government agencies and others to identify potential problems, set priorities, and take appropriate steps to reduce any potential human health or environmental risks related to PFAS, including those that may disproportionately affect children.</P>
                <HD SOURCE="HD2">H. Executive Order 13211: Actions Concerning Regulations That Significantly Affect Energy Supply, Distribution, or Use</HD>
                <P>This action is not a significant energy action as defined in Executive Order 13211 (66 FR 28355, May 22, 2001), because it is not likely to have a significant adverse effect on the supply, distribution or use of energy.</P>
                <HD SOURCE="HD2">I. National Technology Transfer and Advancement Act (NTTAA)</HD>
                <P>
                    This rulemaking does not involve technical standards. As such, NTTAA section 12(d), 15 U.S.C. 272, does not apply to this action.
                    <PRTPAGE P="576"/>
                </P>
                <HD SOURCE="HD2">J. Executive Order 12898: Federal Actions To Address Environmental Justice in Minority Populations and Low-Income Populations and Executive Order 14096: Revitalizing Our Nation's Commitment to Environmental Justice for All</HD>
                <P>Executive Order 12898 (59 FR 7629, February 16, 1994) directs Federal agencies, to the greatest extent practicable and permitted by law, to make environmental justice a part of their mission by identifying and addressing, as appropriate, disproportionately high and adverse human health or environmental effects of their programs, policies, and activities on minority populations (people of color) and low-income populations.</P>
                <P>EPA believes that this type of action does not concern human health or environmental conditions and therefore cannot be evaluated with respect to potentially disproportionate and adverse effects on communities with environmental justice concerns. This action involves additions to reporting requirements that will not affect the level of protection provided to human health or the environment.</P>
                <P>Although this action does not concern human health or environmental conditions, EPA may identify and address environmental justice concerns through information collected under TRI. The information obtained as a result of this rulemaking will lead to a better understanding of PFAS releases, which can help inform and tailor future EPA actions regarding PFAS. For example, EPA may identify and address environmental justice concerns as a result of the new PFAS information collected under this rule. The action will also better inform communities living near facilities that report to TRI, by providing them with information about PFAS releases and waste management practices occurring in their communities. Overall, EPA believes that the information obtained as a result of this action could be used by the public (including people of color, low-income populations and/or indigenous peoples) to inform their behavior as it relates to potential exposure to PFAS and by government agencies and others to identify potential problems, set priorities, and take appropriate steps to reduce any potential human health or environmental risks from PFAS.</P>
                <HD SOURCE="HD2">K. Congressional Review Act (CRA)</HD>
                <P>
                    This action is subject to the CRA, 5 U.S.C. 801 
                    <E T="03">et seq.,</E>
                     and EPA will submit a rule report to each House of the Congress and to the Comptroller General of the United States. This action is not a “major rule” as defined by 5 U.S.C. 804(2).
                </P>
                <HD SOURCE="HD1">List of Subjects in 40 CFR Part 372</HD>
                <P>Environmental protection, Community right-to-know, Reporting and recordkeeping requirements, Toxic chemicals.</P>
                <SIG>
                    <DATED>Dated: December 26, 2024.</DATED>
                    <NAME>Michal Freedhoff,</NAME>
                    <TITLE>Assistant Administrator, Office of Chemical Safety and Pollution Prevention.</TITLE>
                </SIG>
                <P>Therefore, for the reasons stated in the preamble, EPA is amending 40 CFR part 372 as follows:</P>
                <PART>
                    <HD SOURCE="HED">PART 372—TOXIC CHEMICAL RELEASE REPORTING: COMMUNITY RIGHT-TO-KNOW </HD>
                </PART>
                <REGTEXT TITLE="40" PART="372">
                    <AMDPAR>1. The authority citation for part 372 continues to read as follows:</AMDPAR>
                    <AUTH>
                        <HD SOURCE="HED">Authority:</HD>
                        <P> 42 U.S.C. 11023 and 11048.</P>
                    </AUTH>
                </REGTEXT>
                  
                <REGTEXT TITLE="40" PART="372">
                    <AMDPAR>2. Amend § 372.65 by:</AMDPAR>
                    <AMDPAR>a. In paragraph (d) in table 4, adding in alphabetical order entries for “Acetic acid, [(γ- ω-perfluoro-C8-10-alkyl)thio] derivs., Bu esters”; “Ammonium perfluorodecanoate (PFDA NH4)”; “6:2 Fluorotelomer sulfonate acid”; “6:2 Fluorotelomer sulfonate ammonium salt”; “6:2 Fluorotelomer sulfonate anion”; “6:2 Fluorotelomer sulfonate potassium salt”; “6:2 Fluorotelomer sulfonate sodium salt”; “Perfluoro-3-methoxypropanoic acid”; “Sodium perfluorodecanoate (PFDA-Na)”.</AMDPAR>
                    <AMDPAR>b. In paragraph (e) in table 5, adding in numerical order entries for “377-73-1”; “3108-42-7”; “3830-45-3”; “27619-94-9”; “27619-97-2”; “59587-38-1”; “59587-39-2”; “425670-75-3”; “3030471-22-5”.</AMDPAR>
                    <P>The additions read as follows:</P>
                    <SECTION>
                        <SECTNO>§ 372.65</SECTNO>
                        <SUBJECT> Chemicals and chemical categories to which this part applies.</SUBJECT>
                        <STARS/>
                        <P>(d) * * *</P>
                        <GPOTABLE COLS="3" OPTS="L1,i1" CDEF="s50,12,12">
                            <TTITLE>
                                Table 4 to Paragraph (
                                <E T="01">d</E>
                                )
                            </TTITLE>
                            <BOXHD>
                                <CHED H="1">Chemical name</CHED>
                                <CHED H="1">
                                    CASRN 
                                    <SU>1</SU>
                                </CHED>
                                <CHED H="1">Effective date</CHED>
                            </BOXHD>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*         *         *         *         *         *         *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">Acetic acid, [(γ-ω-perfluoro-C8-10-alkyl)thio] derivs., Bu esters</ENT>
                                <ENT>3030471-22-5</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*         *         *         *         *         *         *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">Ammonium perfluorodecanoate (PFDA NH4)</ENT>
                                <ENT>3108-42-7</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*         *         *         *         *         *         *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">6:2 Fluorotelomer sulfonate acid</ENT>
                                <ENT>27619-97-2</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">6:2 Fluorotelomer sulfonate ammonium salt</ENT>
                                <ENT>59587-39-2</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">6:2 Fluorotelomer sulfonate anion</ENT>
                                <ENT>425670-75-3</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">6:2 Fluorotelomer sulfonate potassium salt</ENT>
                                <ENT>59587-38-1</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">6:2 Fluorotelomer sulfonate sodium salt</ENT>
                                <ENT>27619-94-9</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*         *         *         *         *         *         *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">Perfluoro-3-methoxypropanoic acid</ENT>
                                <ENT>377-73-1</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*         *         *         *         *         *         *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">Sodium perfluorodecanoate (PFDA-Na)</ENT>
                                <ENT>3830-45-3</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*         *         *         *         *         *         *</ENT>
                            </ROW>
                            <TNOTE>
                                <SU>1</SU>
                                 CASRN means Chemical Abstracts Service Registry Number.
                            </TNOTE>
                        </GPOTABLE>
                        <PRTPAGE P="577"/>
                        <P>(e) * * *</P>
                        <GPOTABLE COLS="3" OPTS="L1,i1" CDEF="xs50,r100,12">
                            <TTITLE>
                                Table 5 to Paragraph (
                                <E T="01">e</E>
                                )
                            </TTITLE>
                            <BOXHD>
                                <CHED H="1">
                                    CASRN 
                                    <SU>1</SU>
                                </CHED>
                                <CHED H="1">Chemical name</CHED>
                                <CHED H="1">
                                    Effective
                                    <LI>date</LI>
                                </CHED>
                            </BOXHD>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*         *         *         *         *         *         *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">377-73-1</ENT>
                                <ENT>Perfluoro-3-methoxypropanoic acid</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*         *         *         *         *         *         *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">3108-42-7</ENT>
                                <ENT>Ammonium perfluorodecanoate (PFDA NH4)</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*         *         *         *         *         *         *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">3830-45-3</ENT>
                                <ENT>Sodium perfluorodecanoate (PFDA-Na)</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*         *         *         *         *         *         *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">27619-94-9</ENT>
                                <ENT>6:2 Fluorotelomer sulfonate sodium salt</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*         *         *         *         *         *         *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">27619-97-2</ENT>
                                <ENT>6:2 Fluorotelomer sulfonate acid</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*         *         *         *         *         *         *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">59587-38-1</ENT>
                                <ENT>6:2 Fluorotelomer sulfonate potassium salt</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*         *         *         *         *         *         *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">59587-39-2</ENT>
                                <ENT>6:2 Fluorotelomer sulfonate ammonium salt</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*         *         *         *         *         *         *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">425670-75-3</ENT>
                                <ENT>6:2 Fluorotelomer sulfonate anion</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*         *         *         *         *         *         *</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="01">3030471-22-5</ENT>
                                <ENT>Acetic acid, [(γ-ω-perfluoro-C8-10-alkyl)thio] derivs., Bu esters</ENT>
                                <ENT>1/1/25</ENT>
                            </ROW>
                            <ROW>
                                <ENT I="22"> </ENT>
                            </ROW>
                            <ROW>
                                <ENT I="28">*         *         *         *         *         *         *</ENT>
                            </ROW>
                            <TNOTE>
                                <SU>1</SU>
                                 CASRN means Chemical Abstracts Service Registry Number.
                            </TNOTE>
                        </GPOTABLE>
                    </SECTION>
                </REGTEXT>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31464 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6560-50-P</BILCOD>
        </RULE>
    </RULES>
    <VOL>90</VOL>
    <NO>3</NO>
    <DATE>Monday, January 6, 2025</DATE>
    <UNITNAME>Proposed Rules</UNITNAME>
    <PRORULES>
        <PRORULE>
            <PREAMB>
                <PRTPAGE P="578"/>
                <AGENCY TYPE="F">DEPARTMENT OF AGRICULTURE</AGENCY>
                <SUBAGY>Food and Nutrition Service</SUBAGY>
                <CFR>7 CFR Parts 271 and 275</CFR>
                <DEPDOC>[FNS-2020-0016]</DEPDOC>
                <RIN>RIN 0584-AE79</RIN>
                <SUBJECT>Provisions To Improve the Supplemental Nutrition Assistance Program's Quality Control System; Withdrawal</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Food and Nutrition Service (FNS), USDA.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of Proposed Rulemaking; withdrawal.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        This document informs the public that FNS is withdrawing the proposed rule titled, “Provisions to Improve the Supplemental Nutrition Assistance Program's Quality Control System,” that published in the 
                        <E T="04">Federal Register</E>
                         on September 19, 2023, and its correction on December 19, 2023. This rule proposed amendments to Supplemental Nutrition Assistance Program (SNAP) regulations to strengthen and improve the integrity and accuracy of the SNAP quality control (QC) system as requested by the Agriculture Improvement Act of 2018.
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>As of January 6, 2025, the proposed rule published on September 19, 2023, at 88 FR 64756, and its correction on December 19, 2023, at 88 FR 87725, are officially withdrawn.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>SNAP, FNS, USDA, 1320 Braddock Place, Alexandria, VA 22314.</P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Catherine Buhrig, 703-305-2022, Food and Nutrition Service, 1320 Braddock Place, 5th Floor, Alexandria, Virginia 22314, 
                        <E T="03">SM.FN.SNAPQCRules-ICR@usda.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    Upon further deliberation, FNS has decided to consider additional provisions to the proposed rule titled, “Provisions to Improve the Supplemental Nutrition Assistance Program's Quality Control System.” As such, FNS has decided to withdraw the proposed rule published in the 
                    <E T="04">Federal Register</E>
                     on September 19, 2023, and its correction published on December 19, 2023. FNS will continue to engage with stakeholders on possible regulatory improvements to the SNAP QC system and will consider additional approaches to strengthen and improve the integrity and accuracy of the SNAP QC system. FNS will also continue to focus on improving monitoring and oversight efforts, including providing State agencies with technical assistance on corrective actions, to address existing state performance issues related to payment accuracy, major system failures, and application timeliness.
                </P>
                <SIG>
                    <NAME>Dr. Tameka Owens,</NAME>
                    <TITLE>Acting Administrator, Food and Nutrition Service.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31263 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 3410-30-P</BILCOD>
        </PRORULE>
        <PRORULE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <SUBAGY>Federal Aviation Administration</SUBAGY>
                <CFR>14 CFR Part 39</CFR>
                <DEPDOC>[Docket No. FAA-2024-2720; Project Identifier MCAI-2024-00129-T]</DEPDOC>
                <RIN>RIN 2120-AA64</RIN>
                <SUBJECT>Airworthiness Directives; Bombardier, Inc., Airplanes</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Federal Aviation Administration (FAA), DOT.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of proposed rulemaking (NPRM).</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The FAA proposes to adopt a new airworthiness directive (AD) for certain Bombardier, Inc., Model BD-700-1A10 and BD-700-1A11 airplanes. This proposed AD was prompted by reports of engine-driven pump hydraulic pressure hoses for hydraulic systems number 1 and 2 chafing against the pylon in the aft equipment bay. This proposed AD would require an inspection of the engine-driven pump pressure hoses for any damage and minimum clearance between the engine-driven pump hydraulic pressure hose and case drain, suction pressure hose, and surrounding pylon structure; and corrective actions if necessary. The FAA is proposing this AD to address the unsafe condition on these products.</P>
                </SUM>
                <EFFDATE>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>The FAA must receive comments on this proposed AD by February 20, 2025.</P>
                </EFFDATE>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may send comments, using the procedures found in 14 CFR 11.43 and 11.45, by any of the following methods:</P>
                    <P>
                        • 
                        <E T="03">Federal eRulemaking Portal:</E>
                         Go to 
                        <E T="03">regulations.gov.</E>
                         Follow the instructions for submitting comments.
                    </P>
                    <P>
                        • 
                        <E T="03">Fax:</E>
                         202-493-2251.
                    </P>
                    <P>
                        • 
                        <E T="03">Mail:</E>
                         U.S. Department of Transportation, Docket Operations, M-30, West Building Ground Floor, Room W12-140, 1200 New Jersey Avenue SE, Washington, DC 20590.
                    </P>
                    <P>
                        • 
                        <E T="03">Hand Delivery:</E>
                         Deliver to Mail address above between 9 a.m. and 5 p.m., Monday through Friday, except Federal holidays.
                    </P>
                    <P>
                        <E T="03">AD Docket:</E>
                         You may examine the AD docket at 
                        <E T="03">regulations.gov</E>
                         under Docket No. FAA-2024-2720; or in person at Docket Operations between 9 a.m. and 5 p.m., Monday through Friday, except Federal holidays. The AD docket contains this NPRM, the mandatory continuing airworthiness information (MCAI), any comments received, and other information. The street address for Docket Operations is listed above.
                    </P>
                    <P>
                        <E T="03">Material Incorporated by Reference:</E>
                    </P>
                    <P>
                        • For Bombardier material identified in this proposed AD, contact Bombardier Business Aircraft Customer Response Center, 400 Côte-Vertu Road West, Dorval, Québec H4S 1Y9, Canada; telephone 514-855-2999; email 
                        <E T="03">ac.yul@aero.bombardier.com;</E>
                         website 
                        <E T="03">bombardier.com.</E>
                    </P>
                    <P>• You may view this material at the FAA, Airworthiness Products Section, Operational Safety Branch, 2200 South 216th St., Des Moines, WA. For information on the availability of this material at the FAA, call 206-231-3195.</P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Joseph Catanzaro, Aviation Safety Engineer, FAA, 1600 Stewart Avenue, Suite 410, Westbury, NY 11590; telephone 516-228-7300; email 
                        <E T="03">9-avs-nyaco-cos@faa.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">Comments Invited</HD>
                <P>
                    The FAA invites you to send any written relevant data, views, or arguments about this proposal. Send your comments to an address listed under the 
                    <E T="02">ADDRESSES</E>
                     section. Include “Docket No. FAA-2024-2720; Project Identifier MCAI-2024-00129-T” at the 
                    <PRTPAGE P="579"/>
                    beginning of your comments. The most helpful comments reference a specific portion of the proposal, explain the reason for any recommended change, and include supporting data. The FAA will consider all comments received by the closing date and may amend the proposal because of those comments.
                </P>
                <P>
                    Except for Confidential Business Information (CBI) as described in the following paragraph, and other information as described in 14 CFR 11.35, the FAA will post all comments received, without change, to 
                    <E T="03">regulations.gov,</E>
                     including any personal information you provide. The agency will also post a report summarizing each substantive verbal contact received about this NPRM.
                </P>
                <HD SOURCE="HD1">Confidential Business Information</HD>
                <P>
                    CBI is commercial or financial information that is both customarily and actually treated as private by its owner. Under the Freedom of Information Act (FOIA) (5 U.S.C. 552), CBI is exempt from public disclosure. If your comments responsive to this NPRM contain commercial or financial information that is customarily treated as private, that you actually treat as private, and that is relevant or responsive to this NPRM, it is important that you clearly designate the submitted comments as CBI. Please mark each page of your submission containing CBI as “PROPIN.” The FAA will treat such marked submissions as confidential under the FOIA, and they will not be placed in the public docket of this NPRM. Submissions containing CBI should be sent to Joseph Catanzaro, Aviation Safety Engineer, FAA, 1600 Stewart Avenue, Suite 410, Westbury, NY 11590; telephone 516-228-7300; email 
                    <E T="03">9-avs-nyaco-cos@faa.gov.</E>
                     Any commentary that the FAA receives which is not specifically designated as CBI will be placed in the public docket for this rulemaking.
                </P>
                <HD SOURCE="HD1">Background</HD>
                <P>Transport Canada, which is the aviation authority for Canada, has issued Transport Canada AD CF-2024-07, dated February 21, 2024 (Transport Canada AD CF-2024-07) (also referred to as the MCAI), to correct an unsafe condition on certain Bombardier, Inc., Model BD-700-1A10 and BD-700-1A11 airplanes. The MCAI states that there have been reports of engine-driven pump hydraulic pressure hoses for hydraulic systems number 1, left-hand side (LHS), and number 2, right-hand side (RHS), chafing against the pylon in the aft equipment bay.</P>
                <P>
                    The FAA is proposing this AD to address the chafing of the hydraulic systems engine-driven pump hoses against the pylon, which may lead to hydraulic system leaks and failures and result in the loss of the affected hydraulic system. Loss of both hydraulic systems number 1 and 2 would substantially reduce the airplane's functional capabilities. You may examine the MCAI in the AD docket at 
                    <E T="03">regulations.gov</E>
                     under Docket No. FAA-2024-2720.
                </P>
                <HD SOURCE="HD1">Material Incorporated by Reference Under 1 CFR Part 51</HD>
                <P>The FAA reviewed the following material issued by Bombardier:</P>
                <P>• Service Bulletin 700-29-5502, dated November 29, 2023.</P>
                <P>• Service Bulletin 700-29-6011, dated November 29, 2023.</P>
                <P>• Service Bulletin 700-29-6502, dated November 29, 2023.</P>
                <P>
                    This material describes procedures for a borescope inspection for routing of hydraulic systems number 1 (LHS) and number 2 (RHS) engine-driven pump pressure hoses for any damage (including fouling or chafing) and for minimum clearance between the engine-driven pump hydraulic pressure hose and case drain, suction pressure hose, and surrounding pylon structure. Corrective actions include replacing and adjusting the pressure hoses. These documents are distinct since they apply to different airplane models. This material is reasonably available because the interested parties have access to it through their normal course of business or by the means identified in the 
                    <E T="02">ADDRESSES</E>
                     section.
                </P>
                <HD SOURCE="HD1">FAA's Determination</HD>
                <P>This product has been approved by the aviation authority of another country and is approved for operation in the United States. Pursuant to the FAA's bilateral agreement with this State of Design Authority, it has notified the FAA of the unsafe condition described in the MCAI and material referenced above. The FAA is issuing this NPRM after determining that the unsafe condition described previously is likely to exist or develop on other products of the same type design.</P>
                <HD SOURCE="HD1">Proposed AD Requirements in This NPRM</HD>
                <P>This proposed AD would require accomplishing the actions specified in the material already described.</P>
                <HD SOURCE="HD1">Clarification of Referenced Material</HD>
                <P>Paragraph 1.A, “Effectivity” of Bombardier Service Bulletin 700-29-5502, dated November 29, 2023, inadvertently identifies “Model BD-700-1A10 aircraft,” instead of “Model BD-700-1A11 aircraft.” Paragraph (g)(1) of this proposed AD would require replacing the incorrect text with the correct text.</P>
                <HD SOURCE="HD1">Costs of Compliance</HD>
                <P>The FAA estimates that this AD, if adopted as proposed, would affect 36 airplanes of U.S. registry. The FAA estimates the following costs to comply with this proposed AD:</P>
                <GPOTABLE COLS="4" OPTS="L2,nj,i1" CDEF="s50,11C,16C,12C">
                    <TTITLE>Estimated Costs for Required Actions</TTITLE>
                    <BOXHD>
                        <CHED H="1">Labor cost</CHED>
                        <CHED H="1">Parts cost</CHED>
                        <CHED H="1">Cost per product</CHED>
                        <CHED H="1">
                            Cost on U.S.
                            <LI>operators</LI>
                        </CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">2 work-hours × $85 per hour = $170</ENT>
                        <ENT>$0</ENT>
                        <ENT>$170</ENT>
                        <ENT>$6,120</ENT>
                    </ROW>
                </GPOTABLE>
                <P>The FAA estimates the following costs to do any necessary on-condition actions that would be required based on the results of any required actions. The FAA has no way of determining the number of aircraft that might need these on-condition actions:</P>
                <GPOTABLE COLS="3" OPTS="L2,i1" CDEF="s100,11C,16C">
                    <TTITLE>Estimated Costs of On-Condition Actions</TTITLE>
                    <BOXHD>
                        <CHED H="1">Labor cost</CHED>
                        <CHED H="1">Parts cost</CHED>
                        <CHED H="1">Cost per product</CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">2 work-hours × $85 per hour = $170</ENT>
                        <ENT>$1,226</ENT>
                        <ENT>$1,396</ENT>
                    </ROW>
                </GPOTABLE>
                <PRTPAGE P="580"/>
                <P>The FAA has included all known costs in its cost estimate. According to the manufacturer, however, some or all of the costs of this proposed AD may be covered under warranty, thereby reducing the cost impact on affected operators.</P>
                <HD SOURCE="HD1">Authority for This Rulemaking</HD>
                <P>Title 49 of the United States Code specifies the FAA's authority to issue rules on aviation safety. Subtitle I, section 106, describes the authority of the FAA Administrator. Subtitle VII: Aviation Programs, describes in more detail the scope of the Agency's authority.</P>
                <P>The FAA is issuing this rulemaking under the authority described in Subtitle VII, Part A, Subpart III, Section 44701: General requirements. Under that section, Congress charges the FAA with promoting safe flight of civil aircraft in air commerce by prescribing regulations for practices, methods, and procedures the Administrator finds necessary for safety in air commerce. This regulation is within the scope of that authority because it addresses an unsafe condition that is likely to exist or develop on products identified in this rulemaking action.</P>
                <HD SOURCE="HD1">Regulatory Findings</HD>
                <P>The FAA determined that this proposed AD would not have federalism implications under Executive Order 13132. This proposed AD would not have a substantial direct effect on the States, on the relationship between the national government and the States, or on the distribution of power and responsibilities among the various levels of government.</P>
                <P>For the reasons discussed above, I certify this proposed regulation:</P>
                <P>(1) Is not a “significant regulatory action” under Executive Order 12866,</P>
                <P>(2) Would not affect intrastate aviation in Alaska, and</P>
                <P>(3) Would not have a significant economic impact, positive or negative, on a substantial number of small entities under the criteria of the Regulatory Flexibility Act.</P>
                <LSTSUB>
                    <HD SOURCE="HED">List of Subjects in 14 CFR Part 39</HD>
                    <P>Air transportation, Aircraft, Aviation safety, Incorporation by reference, Safety.</P>
                </LSTSUB>
                <HD SOURCE="HD1">The Proposed Amendment</HD>
                <P>Accordingly, under the authority delegated to me by the Administrator, the FAA proposes to amend 14 CFR part 39 as follows:</P>
                <PART>
                    <HD SOURCE="HED">PART 39—AIRWORTHINESS DIRECTIVES</HD>
                </PART>
                <AMDPAR>1. The authority citation for part 39 continues to read as follows:</AMDPAR>
                <AUTH>
                    <HD SOURCE="HED">Authority:</HD>
                    <P>49 U.S.C. 106(g), 40113, 44701.</P>
                </AUTH>
                <SECTION>
                    <SECTNO>§ 39.13</SECTNO>
                    <SUBJECT> [Amended]</SUBJECT>
                </SECTION>
                <AMDPAR>2. The FAA amends § 39.13 by adding the following new airworthiness directive:</AMDPAR>
                <EXTRACT>
                    <FP SOURCE="FP-2">
                        <E T="04">Bombardier, Inc.:</E>
                         Docket No. FAA-2024-2720; Project Identifier MCAI-2024-00129-T.
                    </FP>
                    <HD SOURCE="HD1">(a) Comments Due Date</HD>
                    <P>The FAA must receive comments on this airworthiness directive (AD) by February 20, 2025.</P>
                    <HD SOURCE="HD1">(b) Affected ADs</HD>
                    <P>None.</P>
                    <HD SOURCE="HD1">(c) Applicability</HD>
                    <P>This AD applies to Bombardier, Inc., Model BD-700-1A10 and BD-700-1A11 airplanes, certificated in any category, serial numbers (S/Ns) 60001 through 60076 inclusive, 60083, 60087, and 60089.</P>
                    <HD SOURCE="HD1">(d) Subject</HD>
                    <P>Air Transport Association (ATA) of America Code 29, Hydraulic Power.</P>
                    <HD SOURCE="HD1">(e) Unsafe Condition</HD>
                    <P>This AD was prompted by reports of engine-driven pump hydraulic pressure hoses for hydraulic systems number 1 and 2 chafing against the pylon in the aft equipment bay. The FAA is issuing this AD to address the chafing of the hydraulic systems engine-driven pump hydraulic pressure hoses for the hydraulic system against the pylon, which may lead to hydraulic system leaks and failures and result in the loss of the affected hydraulic system. Loss of both hydraulic systems number 1 and 2 would substantially reduce the airplane's functional capabilities.</P>
                    <HD SOURCE="HD1">(f) Compliance</HD>
                    <P>Comply with this AD within the compliance times specified, unless already done.</P>
                    <HD SOURCE="HD1">(g) Inspection of Engine-Driven Pump Hydraulic Hoses</HD>
                    <P>Within 500 flight hours or 18 months, whichever occurs first after the effective date of this AD, do a borescope inspection of the routing of hydraulic systems number 1, left-hand side (LHS), and number 2, right-hand side (RHS), engine-driven pump pressure hoses over the length of the hoses for any damage and for minimum clearance between the engine-driven pump hydraulic pressure hose and case drain, suction pressure hose, and surrounding pylon structure, in accordance with Section 2.B. of the Accomplishment Instructions of the applicable service information identified in paragraph (g)(1) through (3) of this AD.</P>
                    <P>(1) For airplanes identified in Bombardier Service Bulletin 700-29-5502, dated November 29, 2023: Bombardier Service Bulletin 700-29-5502, dated November 29, 2023. Where paragraph 1.A. of Bombardier Service Bulletin 700-29-5502, dated November 29, 2023, identifies “Model BD-700-1A10 aircraft,” this AD requires replacing that text with “Model BD-700-1A11 aircraft.”</P>
                    <P>(2) For airplanes identified in Bombardier Service Bulletin 700-29-6011, dated November 29, 2023: Bombardier Service Bulletin 700-29-6011, dated November 29, 2023.</P>
                    <P>(3) For airplanes identified in Bombardier Service Bulletin 700-29-6502, dated November 29, 2023: Bombardier Service Bulletin 700-29-6502, dated November 29, 2023.</P>
                    <HD SOURCE="HD1">(h) Corrective Actions</HD>
                    <P>(1) If clearance is found to be less than 0.500 inch (12.70 mm) during the inspection required by paragraph (g) of this AD: Before further flight, adjust the applicable hose(s) to obtain minimum clearance between the engine-driven pump hydraulic pressure hose and case drain, suction pressure hose, and surrounding pylon structure, in accordance with Section 2.C. of the Accomplishment Instructions of the applicable service information identified in paragraphs (g)(1) through (3) of this AD.</P>
                    <P>(2) If any damage (including fouling or chafing) is found during the inspection required by paragraph (g) of this AD: Before further flight, replace all damaged pressure hoses, in accordance with Section 2.D. of the Accomplishment Instructions of the applicable service information identified in paragraphs (g)(1) through (3) of this AD.</P>
                    <HD SOURCE="HD1">(i) Additional AD Provisions</HD>
                    <P>The following provisions also apply to this AD:</P>
                    <P>
                        (1) 
                        <E T="03">Alternative Methods of Compliance (AMOCs):</E>
                         The Manager, International Validation Branch, FAA, has the authority to approve AMOCs for this AD, if requested using the procedures found in 14 CFR 39.19. In accordance with 14 CFR 39.19, send your request to your principal inspector or responsible Flight Standards Office, as appropriate. If sending information directly to the manager of the International Validation Branch, send it to the attention of the person identified in paragraph (j) of this AD and email to: 
                        <E T="03">AMOC@faa.gov.</E>
                         Before using any approved AMOC, notify your appropriate principal inspector, or lacking a principal inspector, the manager of the responsible Flight Standards Office.
                    </P>
                    <P>
                        (2) 
                        <E T="03">Contacting the Manufacturer:</E>
                         For any requirement in this AD to obtain instructions from a manufacturer, the instructions must be accomplished using a method approved by the Manager, International Validation Branch, FAA; or Transport Canada; or Bombardier, Inc.'s Transport Canada Design Approval Organization (DAO). If approved by the DAO, the approval must include the DAO-authorized signature.
                    </P>
                    <HD SOURCE="HD1">(j) Additional Information</HD>
                    <P>
                        For more information about this AD, contact Joseph Catanzaro, Aviation Safety Engineer, FAA, 1600 Stewart Avenue, Suite 410, Westbury, NY 11590; telephone 516-228-7300; email 
                        <E T="03">9-avs-nyaco-cos@faa.gov.</E>
                        <PRTPAGE P="581"/>
                    </P>
                    <HD SOURCE="HD1">(k) Material Incorporated by Reference</HD>
                    <P>(1) The Director of the Federal Register approved the incorporation by reference of the material listed in this paragraph under 5 U.S.C. 552(a) and 1 CFR part 51.</P>
                    <P>(2) You must use this material as applicable to do the actions required by this AD, unless this AD specifies otherwise.</P>
                    <P>(i) Bombardier Service Bulletin 700-29-5502, dated November 29, 2023.</P>
                    <P>(ii) Bombardier Service Bulletin 700-29-6011, dated November 29, 2023.</P>
                    <P>(iii) Bombardier Service Bulletin 700-29-6502, dated November 29, 2023.</P>
                    <P>
                        (3) For Bombardier material identified in this AD, contact Bombardier Business Aircraft Customer Response Center, 400 Côte-Vertu Road West, Dorval, Québec H4S 1Y9, Canada; telephone 514-855-2999; email 
                        <E T="03">ac.yul@aero.bombardier.com;</E>
                         website 
                        <E T="03">bombardier.com.</E>
                    </P>
                    <P>(4) You may view this material at the FAA, Airworthiness Products Section, Operational Safety Branch, 2200 South 216th St., Des Moines, WA. For information on the availability of this material at the FAA, call 206-231-3195.</P>
                    <P>
                        (5) You may view this material at the National Archives and Records Administration (NARA). For information on the availability of this material at NARA, visit 
                        <E T="03">www.archives.gov/federal-register/cfr/ibr-locations,</E>
                         or email 
                        <E T="03">fr.inspection@nara.gov.</E>
                    </P>
                </EXTRACT>
                <SIG>
                    <DATED>Issued on December 30, 2024.</DATED>
                    <NAME>Steven W. Thompson,</NAME>
                    <TITLE>Acting Deputy Director, Compliance &amp; Airworthiness Division, Aircraft Certification Service.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31624 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4910-13-P</BILCOD>
        </PRORULE>
        <PRORULE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF THE TREASURY</AGENCY>
                <SUBAGY>Internal Revenue Service</SUBAGY>
                <CFR>26 CFR Part 1</CFR>
                <DEPDOC>[REG-118269-23]</DEPDOC>
                <RIN>RIN 1545-BR19</RIN>
                <SUBJECT>Section 30C Alternative Fuel Vehicle Refueling Property Credit; Hearing</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Internal Revenue Service (IRS), Treasury.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of proposed rulemaking; notice of hearing.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>This document provides a notice of public hearing on proposed regulations regarding the Federal Income tax credit under the Inflation Reduction Act of 2022 for certain costs relating to qualified alternative fuel vehicle refueling property that is placed in service within a low-income community or within a non-urban census tract.</P>
                </SUM>
                <EFFDATE>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>The public hearing on these proposed regulations is scheduled to be held on February 12, 2025, at 10 a.m. Eastern Time (ET). The IRS must receive speakers' outlines of topic to be discussed at the public hearing by January 10, 2025. If no outlines of testimony are received by January 10, 2025, the public hearing will be cancelled.</P>
                </EFFDATE>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>The public hearing is being held in the Auditorium, at the Internal Revenue Service Building, 1111 Constitution Avenue NW, Washington, DC. Due to security procedures, visitors must enter at the Constitution Avenue entrance. In addition, all visitors must present a valid photo identification to enter the building. Because of access restrictions, visitors will not be admitted beyond the immediate entrance area more than 30 minutes before the hearing starts. Participants may alternatively attend the public hearing by telephone.</P>
                    <P>
                        Send an outline of topic submissions electronically via the eRulemaking Portal at 
                        <E T="03">www.regulations.gov</E>
                         (Preferred) (indicate IRS and REG-118269-23). Send paper submissions to CC:PA:01:PR (REG-118269-23), Room 5205, Internal Revenue Service, P.O. Box 7604, Ben Franklin Station, Washington, DC 20044.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Concerning the proposed regulations, contact Kevin I. Babitz or Whitney E. Brady at (202) 317-6853 (not a toll-free number); concerning submissions of comments, the hearing and/or to be placed on the building access list to attend the public hearing, contact the Publications and Regulation Section at (202-317-6901) (not a toll-free number) or by email to 
                        <E T="03">publichearings@irs.gov</E>
                         (preferred).
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The subject of the public hearing is the notice of proposed rulemaking (REG-118269-23) that was published in the 
                    <E T="04">Federal Register</E>
                     on Thursday, September 19, 2024 (89 FR 76759).
                </P>
                <P>The rules of 26 CFR 601.601(a)(3) apply to the hearing. Persons who wish to present oral comments at the hearing must submit an outline of the topics to be discussed and the time to be devoted to each topic by January 10, 2025.</P>
                <P>
                    A period of 10 minutes will be allotted to each person for making comments. An agenda showing the scheduling of the speakers will be prepared after the deadline for receiving outlines has passed. Copies of the agenda will be available free of charge at the hearing, and via the Federal eRulemaking Portal (
                    <E T="03">https://www.Regulations.gov</E>
                    ) under the title of Supporting &amp; Related Material. If no outline of the topics to be discussed at the hearing is received by January 10, 2025, the public hearing will be cancelled. If the public hearing is cancelled, a notice of cancellation of the public hearing will be published in the 
                    <E T="04">Federal Register</E>
                    .
                </P>
                <P>
                    Individuals who want to testify in person at the public hearing must send an email to 
                    <E T="03">publichearings@irs.gov</E>
                     to have your legal name added to the building access list. The subject line of the email must contain the regulation number REG-118269-23 and the language “TESTIFY In Person.” For example, the subject line may say: Request to TESTIFY In Person at Hearing for REG-118269-23.
                </P>
                <P>
                    Individuals who want to testify by telephone at the public hearing must send an email to 
                    <E T="03">publichearings@irs.gov</E>
                     to receive the telephone number and access code for the hearing. The subject line of the email must contain the regulation number REG-118269-23 and the language “TESTIFY Telephonically.” For example, the subject line may say: Request to TESTIFY Telephonically at Hearing for REG-118269-23.
                </P>
                <P>
                    Individuals who want to attend the public hearing in person without testifying must also send an email to 
                    <E T="03">publichearings@irs.gov</E>
                     to have your legal name added to the building access list. The subject line of the email must contain the regulation number REG-118269-23 and the language “ATTEND In Person.” For example, the subject line may say: Request to ATTEND In Person for REG-118269-23. Requests to attend the public hearing must be received by 5 p.m. ET by February 10, 2025.
                </P>
                <P>
                    Individuals who want to attend the public hearing by telephone without testifying must also send an email to 
                    <E T="03">publichearings@irs.gov</E>
                     to receive the telephone number and access code for the hearing. The subject line of the email must contain the regulation number REG-118269-23, and the language “ATTEND Hearing Telephonically.” For example, the subject line may say: Request to ATTEND Hearing Telephonically for REG-118269-23. Requests to attend the public hearing must be received by 5 p.m. ET by February 10, 2025.
                </P>
                <P>
                    Hearings will be made accessible to people with disabilities. To request special assistance during a hearing please contact the Publications and Regulations Section of the Office of Associate Chief Counsel (Procedure and Administration) by sending an email to 
                    <E T="03">publichearings@irs.gov</E>
                     (preferred) or by telephone at (202) 317-6901 (not a toll-free number) by 5 p.m. ET on February 5, 2025.
                    <PRTPAGE P="582"/>
                </P>
                <P>
                    Any questions regarding speaking at or attending a public hearing may also be emailed to 
                    <E T="03">publichearings@irs.gov.</E>
                </P>
                <SIG>
                    <NAME>Oluwafunmilayo A. Taylor,</NAME>
                    <TITLE>Section Chief, Publications and Regulations Section, Associate Chief Counsel, (Procedure and Administration).</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31233 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4830-01-P</BILCOD>
        </PRORULE>
        <PRORULE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF JUSTICE</AGENCY>
                <SUBAGY>Office of Justice Programs</SUBAGY>
                <CFR>28 CFR Part 94</CFR>
                <DEPDOC>[Docket No. OJP (OVC) 1808]</DEPDOC>
                <RIN>RIN 1121-AA89</RIN>
                <SUBJECT>Victims of Crime Act Victim Compensation Grant Program; Withdrawal</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Office for Victims of Crime, Office of Justice Programs, Justice.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Withdrawal of proposed rule.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        The Office of Justice Programs (“OJP”), a bureau of the Department of Justice and the component under which the Office for Victims of Crime (“OVC”) resides, is withdrawing a proposed rule that was published in the 
                        <E T="04">Federal Register</E>
                         on February 5, 2024, which proposed to add a subpart to its regulations to replace the existing Victim Compensation Program Guidelines under the Victims of Crime Act, and update and codify requirements for that Program.
                    </P>
                </SUM>
                <EFFDATE>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        As of January 6, 2025, the proposed rule that was published in the 
                        <E T="04">Federal Register</E>
                         on February 5, 2024 (89 FR 7639), is withdrawn.
                    </P>
                </EFFDATE>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Kathrina Peterson, Senior Policy Advisor, Office for Victims of Crime at (202) 616-3579 (please note that this is not a toll-free number).</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The Victim Compensation Program is authorized by the Victims of Crime Act of 1984, 34 U.S.C. 20102, and supports an annual grant to each state and several territories to support their victim compensation programs. On February 5, 2024, the Office of Justice Programs (OJP) published a notice of proposed rulemaking (NPRM) in the 
                    <E T="04">Federal Register</E>
                     proposing to add a subpart to its regulations to replace the existing Victim Compensation Program Guidelines, published on May 16, 2001, at 66 FR 27158, and update and codify requirements for that Program. In response to the NPRM, OJP received several thousand comments on the proposed rule.
                </P>
                <P>In light of the diversity and abundance of feedback received in response to the NPRM, OJP has identified the need for additional consideration of topics addressed in this rulemaking. Given the scope of comments and the limited time remaining in the current Administration, OJP has decided to withdraw the NPRM and terminate the rulemaking, leaving the existing Victim Compensation Program Guidelines in place, and ensuring that the agency can benefit from the latest information on these issues when exploring options with stakeholders in the future.</P>
                <P>
                    OJP does not intend to issue a final rule based on this published NPRM. Despite the decision not to move forward with the rule at this time, OJP and its component Office for Victims of Crime (OVC) are grateful for the effort, thought, and insights evident in the comments on the proposed rule, especially those provided by crime victims and survivors who shared their personal stories and perspectives. OJP and OVC will continue engaging with their stakeholders as they undertake the work of enhancing care and expanding access to compensation for all victims of crime. In the event OJP and OVC may ultimately conclude that a new rulemaking action would be appropriate, a new NPRM would be published in the 
                    <E T="04">Federal Register</E>
                     at that time.
                </P>
                <SIG>
                    <NAME>Brent J. Cohen,</NAME>
                    <TITLE>Acting Assistant Attorney General, Office of Justice Programs.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31012 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4410-18-P</BILCOD>
        </PRORULE>
    </PRORULES>
    <VOL>90</VOL>
    <NO>3</NO>
    <DATE>Monday, January 6, 2025</DATE>
    <UNITNAME>Notices</UNITNAME>
    <NOTICES>
        <NOTICE>
            <PREAMB>
                <PRTPAGE P="583"/>
                <AGENCY TYPE="F">DEPARTMENT OF AGRICULTURE</AGENCY>
                <SUBJECT>Submission for OMB Review; Comment Request</SUBJECT>
                <P>The Department of Agriculture has submitted the following information collection requirement(s) to OMB for review and clearance under the Paperwork Reduction Act of 1995, Public Law 104-13. Comments are requested regarding; whether the collection of information is necessary for the proper performance of the functions of the agency, including whether the information will have practical utility; the accuracy of the agency's estimate of burden including the validity of the methodology and assumptions used; ways to enhance the quality, utility and clarity of the information to be collected; and ways to minimize the burden of the collection of information on those who are to respond, including through the use of appropriate automated, electronic, mechanical, or other technological collection techniques or other forms of information technology.</P>
                <P>
                    Comments regarding this information collection received by February 5, 2025 will be considered. Written comments and recommendations for the proposed information collection should be submitted within 30 days of the publication of this notice on the following website 
                    <E T="03">www.reginfo.gov/public/do/PRAMain.</E>
                     Find this particular information collection by selecting “Currently under 30-day Review—Open for Public Comments” or by using the search function. An agency may not conduct or sponsor a collection of information unless the collection of information displays a currently valid OMB control number and the agency informs potential persons who are to respond to the collection of information that such persons are not required to respond to the collection of information unless it displays a currently valid OMB control number.
                </P>
                <HD SOURCE="HD1">Food and Nutrition Service</HD>
                <P>
                    <E T="03">Title:</E>
                     Evaluating the Interview Requirement for SNAP Certification.
                </P>
                <P>
                    <E T="03">OMB Control Number:</E>
                     0584-NEW.
                </P>
                <P>
                    <E T="03">Summary of Collection:</E>
                     The Food and Nutrition Service (FNS), part of the U.S. Department of Agriculture (USDA), is authorized to collect these data under Section 17 of the Food and Nutrition Act of 2008, as amended through Public Law 118-5, enacted June 3, 2023. The Supplemental Nutrition Assistance Program (SNAP) is the foundation of the nation's nutrition assistance safety net and is a core source of support to millions of Americans, particularly during economic downturns. To help States handle increased need and participation amid the health risks of the pandemic, the Food and Nutrition Service (FNS) offered States a range of flexibilities which provided support to States administering the program and clients in the application process, including the option to waive the certification and recertification interview requirement. This allowed States to continue administering SNAP during the public health emergency with minimal client contact. FNS required States that waived the interview requirement to document their experiences processing cases without the interview. However, more rigorous evidence is needed to confidently understand the effects of waiving the interview requirement.
                </P>
                <P>
                    <E T="03">Need and Use of the Information:</E>
                     The Evaluating the Interview Requirement for SNAP Certification study will collect information in five States to assess how eliminating interviews affects outcomes, including administrative efficiency, costs, benefit accuracy, and client access. The project will include a randomized control trial (RCT) to analyze the impacts of outcomes between those clients assigned to receive an interview (the regular interview process group) and those assigned to not receive an interview (the no-interview group).
                </P>
                <P>
                    <E T="03">Description of Respondents:</E>
                     State and Local Governments, Businesses (Not-for-profit), and Individuals and Households.
                </P>
                <P>
                    <E T="03">Number of Respondents:</E>
                     494.
                </P>
                <P>
                    <E T="03">Frequency of Responses:</E>
                     Reporting: Once.
                </P>
                <P>
                    <E T="03">Total Burden Hours:</E>
                     1,807.33.
                </P>
                <SIG>
                    <NAME>Rachelle Ragland-Greene,</NAME>
                    <TITLE>Departmental Information Collection Clearance Officer.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31632 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 3410-30-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF AGRICULTURE</AGENCY>
                <SUBJECT>Submission for OMB Review; Comment Request</SUBJECT>
                <P>The Department of Agriculture has submitted the following information collection requirement(s) to OMB for review and approval under the Paperwork Reduction Act of 1995, Public Law 104-13. Comments are requested regarding: whether the collection of information is necessary for the proper performance of the functions of the agency, including whether the information will have practical utility; the accuracy of the agency's estimate of burden including the validity of the methodology and assumptions used; ways to enhance the quality, utility and clarity of the information to be collected; and ways to minimize the burden of the collection of information on those who are to respond, including through the use of appropriate automated, electronic, mechanical, or other technological collection techniques or other forms of information technology.</P>
                <P>
                    Comments regarding this information collection received by February 5, 2025 will be considered. Written comments and recommendations for the proposed information collection should be submitted within 30 days of the publication of this notice on the following website 
                    <E T="03">www.reginfo.gov/public/do/PRAMain.</E>
                     Find this particular information collection by selecting “Currently under 30-day Review—Open for Public Comments” or by using the search function.
                </P>
                <P>
                    An agency may not conduct or sponsor a collection of information unless the collection of information displays a currently valid OMB control number and the agency informs potential persons who are to respond to the collection of information that such persons are not required to respond to the collection of information unless it displays a currently valid OMB control number.
                    <PRTPAGE P="584"/>
                </P>
                <HD SOURCE="HD1">Rural Business-Cooperative Service</HD>
                <P>
                    <E T="03">Title:</E>
                     Annual Survey of Farmer Cooperatives.
                </P>
                <P>
                    <E T="03">OMB Control Number:</E>
                     0570-0007.
                </P>
                <P>
                    <E T="03">Summary of Collection:</E>
                     The Rural Business Cooperative Service (RBS) was mandated the responsibility to acquire and disseminate information pertaining to agricultural cooperatives under the Cooperative Marketing Act of 1926: 7 U.S.C. 451-457 and Public Law 450. The primary objective of RBS is to promote understanding, use and development of the cooperative form of business as a viable option for enhancing the income of agricultural producers and other rural residents. The annual survey collects basic statistics on cooperative business volume, net income, members, financial status, employees, and other selected information to support RBS' objective and role. RBS will use a variety of forms to collect information.
                </P>
                <P>
                    <E T="03">Need and Use of the Information:</E>
                     RBS uses the information collected to summarize for program planning, evaluation service work and cooperative analysis and education. The information collected and published in the annual report on farmer cooperatives supports and enhances most of the major functions of RBS. By not collecting this information, the RBS would have difficulties in carrying out its policy on farmer cooperatives.
                </P>
                <P>
                    <E T="03">Description of Respondents:</E>
                     Business or other for-profit.
                </P>
                <P>
                    <E T="03">Number of Respondents:</E>
                     1,035.
                </P>
                <P>
                    <E T="03">Frequency of Responses:</E>
                     Reporting: Annually.
                </P>
                <P>
                    <E T="03">Total Burden Hours:</E>
                     806.
                </P>
                <HD SOURCE="HD1">Rural Business-Cooperative Service</HD>
                <P>
                    <E T="03">Title:</E>
                     Voluntary Labeling Program for Biobased Products.
                </P>
                <P>
                    <E T="03">OMB Control Number:</E>
                     0570-0072.
                </P>
                <P>
                    <E T="03">Summary of Collection:</E>
                     The Rural Business-Cooperative Service (RBCS or the Agency), a Rural Development agency of the United States Department of Agriculture (USDA), announced the availability of approximately $450 million, under section 22003 of the Inflation Reduction Act of 2022, in competitive grants to eligible entities for activities designed to expand the sales and use of renewable fuels under the Higher Blends Infrastructure Incentive Program (HBIIP). Cost-share grants of up to 75 percent of total eligible project costs, but not more than $5 million, are made available to assist transportation fueling facilities and fuel distribution facilities with converting to higher blend friendly status for ethanol (
                    <E T="03">i.e.,</E>
                     greater than 10 percent ethanol) and biodiesel (greater than 5 percent biodiesel) by sharing the costs related to the installation, and/or retrofitting, and/or otherwise upgrading of fuel dispenser or pumps and related equipment, storage tank system components, and other required infrastructure. All applicants are responsible for expenses incurred in developing their applications.
                </P>
                <P>HBIIP is intended to encourage a more comprehensive approach to marketing higher blends biofuels by sharing the costs related to building out biofuel-related infrastructure. To be eligible for this program, a project's sole purpose must be to assist transportation fueling and biodiesel distribution facilities with converting to higher ethanol and biodiesel blend friendly status by sharing the costs related to the installation, and/or retrofitting, and/or otherwise upgrading of fuel storage, dispenser/pumps, related equipment, and infrastructure. An eligible project must conform to all applicable Federal, State and local regulatory requirements.</P>
                <P>
                    <E T="03">Need and Use of the Information:</E>
                     Pursuant to section 22003 of the Inflation Reduction Act of 2022 (Pub. L. 117-169), RBCS will collect information to determine whether participants meet the eligibility requirements to be a recipient of grant funds, project eligibility, conduct the technical evaluation, calculate a priority score, rank and compete the application, as applicable, in order to be considered. Lack of adequate information to make the determination could result in the improper administration and appropriation of Federal grant funds.
                </P>
                <P>
                    <E T="03">Description of Respondents:</E>
                     Business or other for-profit.
                </P>
                <P>
                    <E T="03">Number of Respondents:</E>
                     641.
                </P>
                <P>
                    <E T="03">Frequency of Responses:</E>
                     Recordkeeping; Reporting: Other (once).
                </P>
                <P>
                    <E T="03">Total Burden Hours:</E>
                     84,177.
                </P>
                <SIG>
                    <NAME>Levi S. Harrell,</NAME>
                    <TITLE>Departmental Information Collection Clearance Officer.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31627 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 3410-XY-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF AGRICULTURE</AGENCY>
                <SUBAGY>Rural Business-Cooperative Service</SUBAGY>
                <DEPDOC>[DOCKET #: RBS-X24BUSINESS-0016]</DEPDOC>
                <SUBJECT>Notice of Funding Opportunity for the Rural Business Development Grant Program To Provide Technical Assistance for Rural Transportation Systems for Fiscal Year 2025</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Rural Business-Cooperative Service, USDA.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Rural Business-Cooperative Service (RBCS or Agency), a Rural Development (RD) agency of the United States Department of Agriculture (USDA), is issuing this notice to invite applications for grants to provide technical assistance for passenger Rural Transportation (RT) systems under the Rural Business Development Grant (RBDG) program and the terms for such funding. Grant funds will provide technical assistance for RT systems including designated funds to provide technical assistance to RT systems operating within Tribal lands of Federally Recognized Native American Tribes (FRNAT) (collectively “Programs”). This notice is being issued in order to allow applicants sufficient time to leverage financing, prepare and submit their applications, and give the Agency time to process applications within fiscal year (FY) 2025. Based on FY 2024 appropriated funding, the Agency estimates that approximately $750,000 will be made available for FY 2025. Successful applications will be selected by the Agency for funding and subsequently awarded to the extent that funding may ultimately be made available through appropriations. All applicants are responsible for any expenses incurred in developing their applications.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Completed applications may be submitted in paper or electronic format and must be received in the USDA RD State Office no later than 4:30 p.m. (local time) on April 7, 2025, to be eligible for FY 2025 grant funding. Applications received after the deadline will be ineligible for funding.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        This funding announcement will also be announced on 
                        <E T="03">Grants.gov</E>
                        . Applications must be submitted to the USDA RD State Office where the Project is located. A list of the USDA RD State Office contacts can be found at: 
                        <E T="03">rd.usda.gov/contact-us/state-offices.</E>
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Cindy Mason at 
                        <E T="03">cindy.mason@usda.gov,</E>
                         Business Loan and Grant Analyst, Program Management Division, RBCS, USDA, 1400 Independence Avenue SW, Mail Stop 3226, Room 5160-South, Washington, DC 20250-3226, or call 202-720-1400.
                    </P>
                    <P>
                        For further information on submitting program applications under this notice, please contact the USDA RD office for the State in which the applicant is located. A list of USDA RD Office contacts is provided at the following link: 
                        <E T="03">rd.usda.gov/contact-us/state-offices.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">
                    SUPPLEMENTARY INFORMATION:
                    <PRTPAGE P="585"/>
                </HD>
                <HD SOURCE="HD1">Overview</HD>
                <P>
                    <E T="03">Federal Awarding Agency Name:</E>
                     Rural Business-Cooperative Service.
                </P>
                <P>
                    <E T="03">Funding Opportunity Title:</E>
                     Rural Business Development Grants—Technical Assistance for Rural Transportation Systems.
                </P>
                <P>
                    <E T="03">Announcement Type:</E>
                     Notice of Funding Opportunity.
                </P>
                <P>
                    <E T="03">Funding Opportunity Number:</E>
                     RDBCP-RBDG-2025.
                </P>
                <P>
                    <E T="03">Assistance Listing:</E>
                     10.351.
                </P>
                <P>
                    <E T="03">Dates:</E>
                     The deadline for completed applications to be received in the USDA RD State Office is no later than 4:30 p.m. (local time) on April 7, 2025, to be eligible for FY 2025 grant funding. Applications received after the deadline will be ineligible for funding.
                </P>
                <P>
                    <E T="03">Rural Development Key Priorities:</E>
                     The Agency encourages applicants to consider projects that will advance the following key priorities (more details available at 
                    <E T="03">rd.usda.gov/priority-points</E>
                    ):
                </P>
                <P>
                    • 
                    <E T="03">Creating More and Better Markets:</E>
                     Assist rural communities to recover economically through more and better market opportunities and through improved infrastructure;
                </P>
                <P>
                    • 
                    <E T="03">Addressing Climate Change and Environmental Justice:</E>
                     Reduce climate pollution and increase resilience to the impacts of climate change through economic support for rural communities; and
                </P>
                <P>
                    • 
                    <E T="03">Advancing Racial Justice, Place-Based Equity, and Opportunity:</E>
                     Ensure all rural residents have equitable access to RD programs and benefits from RD funded projects.
                </P>
                <HD SOURCE="HD2">A. Program Description</HD>
                <P>
                    1. 
                    <E T="03">Purpose of the Program.</E>
                     The purpose of this program is to improve the economic conditions of rural areas by providing technical assistance that will enhance the operation of rural transportation systems.
                </P>
                <P>
                    2. 
                    <E T="03">Statutory Authority.</E>
                     This program is authorized under section 310B(c) of the Consolidated Farm and Rural Development Act (7 U.S.C. 1932(c)) and implemented by 7 CFR part 4280, subpart E. The program is administered on behalf of RBCS by the USDA RD State Offices. Assistance provided to rural areas under the program has historically included the provision of on-site technical assistance to Tribal, local and regional governments, public transit agencies, and related nonprofit and for-profit organizations in rural areas; the development of training materials; and the provision of necessary training assistance to local officials and agencies in rural areas.
                </P>
                <P>Section 736 of title VII of division B of the Consolidated Appropriations Act, 2024, designated funding for projects in Persistent Poverty counties. Persistent Poverty counties is defined in section 736 as “any county that has had 20 percent or more of its population living in poverty over the past 30 years, as measured by the 1990 and 2000 decennial censuses, and 2007-2011 American Community Survey 5-year average, or any territory or possession of the United States”. Section 736 expanded the eligible population in Persistent Poverty counties to include any county seat of such a persistent poverty county that had a population that does not exceed the authorized population limit by more than 10 percent, expanding the current 50,000 population limit to 55,000 for only county seats located in Persistent Poverty counties. Therefore, beneficiaries of technical assistance services located in Persistent Poverty County seats with populations up to 55,000 are eligible. Therefore, assuming the Appropriations Act for 2025 has similar language, applicants and/or beneficiaries located in persistent poverty county seats with populations up to 55,000 (per the 2020 Census) are eligible.</P>
                <P>
                    3. 
                    <E T="03">Definitions.</E>
                     The definitions applicable to this notice are published at 7 CFR 4280.403.
                </P>
                <P>
                    4. 
                    <E T="03">Application of Awards.</E>
                     The Agency will review, evaluate, and score applications received in response to this notice based on the provisions in 7 CFR part 4280, subpart E, and as indicated in this notice. Awards under the RBDG Technical Assistance for RT Systems program will be made on a competitive basis using specific selection criteria contained in 7 CFR part 4280, subpart E, and in accordance with section 310B(c) of the Consolidated Farm and Rural Development Act (7 U.S.C. 1932(c)). The Agency advises all interested parties that the applicant bears the burden in preparing and submitting an application in response to this notice whether or not funding is appropriated for this program in FY 2025.
                </P>
                <HD SOURCE="HD2">B. Federal Award Information</HD>
                <P>
                    <E T="03">Type of Award:</E>
                     Grants.
                </P>
                <P>
                    <E T="03">Fiscal Year Funds:</E>
                     FY 2025.
                </P>
                <P>
                    <E T="03">Available Funds:</E>
                     $750,000. RBCS may at its discretion, increase the total level of funding available in this funding round, or in any category in this funding round, from any available source provided the awards meet the requirements of the statute which made the funding available to the Agency.
                </P>
                <P>
                    <E T="03">Award Amounts:</E>
                     The Agency will award a maximum of $500,000 for RT systems and $250,000 for FRNAT RT projects. The amounts are determined by the specific funding provided for the program in the FY 2025 Appropriations Act.
                </P>
                <P>
                    <E T="03">Anticipated Award Date:</E>
                     Prior to September 30, 2025.
                </P>
                <P>
                    <E T="03">Performance Period:</E>
                     October 1, 2025, through September 30, 2026.
                </P>
                <P>
                    <E T="03">Renewal or Supplemental Awards:</E>
                     None.
                </P>
                <P>
                    <E T="03">Type of Assistance Instrument:</E>
                     Financial Assistance Agreement.
                </P>
                <HD SOURCE="HD2">C. Eligibility Information</HD>
                <P>
                    1. 
                    <E T="03">Eligible Applicants.</E>
                     Eligible applicants must meet the eligibility requirements of 7 CFR 4280.416, Applicant Eligibility. The Agency requires the information provided in 7 CFR 4280.427 to make an eligibility determination that an applicant is a national organization.
                </P>
                <P>For the funding for Technical Assistance for RT systems, applicants must be qualified national organizations with experience in providing technical assistance and training to rural communities nationwide for the purpose of improving passenger transportation services or facilities. To be considered “national,” RBCS requires a qualified organization to provide evidence that it can operate RT assistance programming nationwide. An entity can qualify if they can work in partnership with other entities to fulfill the national requirement as long as the applicant will have ultimate control of the grant administration. For the funding for RT systems to FRNATs, an entity can qualify if it can work in partnership with other entities to support all federally recognized Tribes, as long as the applicant will have ultimate control of the grant administration. There is not a requirement to use the grant funds in a multi-State area. Grants will be made to qualified national organizations for the provision of technical assistance and training to rural communities for the purpose of improving passenger transportation services or facilities.</P>
                <P>For the FRNAT grant, which must benefit FRNATs, at least 75 percent of the benefits of the Project must be received by members of FRNATs.</P>
                <P>
                    2. 
                    <E T="03">Cost Sharing or Matching.</E>
                     There are no cost sharing or matching requirements associated with this grant.
                </P>
                <P>
                    3. 
                    <E T="03">Other.</E>
                     Applications will only be accepted from qualified national organizations to provide Technical Assistance for RT. Applicants proposing projects with Tribes must submit documentation in support of the application from the Tribes they propose to serve. This support is best documented through a resolution from 
                    <PRTPAGE P="586"/>
                    the appropriate Tribal council/government. Alternative documentation of support may be considered on a case-by-case basis.
                </P>
                <HD SOURCE="HD2">D. Application and Submission Information</HD>
                <P>
                    1. 
                    <E T="03">Address to Request Application Package.</E>
                     Entities wishing to apply for assistance should contact the USDA RD State Office provided in the 
                    <E T="02">ADDRESSES</E>
                     section of this notice to obtain copies of the application package.
                </P>
                <P>
                    2. 
                    <E T="03">Content and Form of Application Submission.</E>
                     An application must contain all of the required elements listed in 7 CFR 4280.427 and the following:
                </P>
                <P>(a) Environmental documentation in accordance with 7 CFR part 1970, “Environmental Policies and Procedures;”</P>
                <P>(b) SF LLL, “Disclosure of Lobbying Activities;”</P>
                <P>(c) RD 400-1, “Equal Opportunity Agreement;”</P>
                <P>(d) RD 400-4, “Assurance Agreement;” and</P>
                <P>(e) Letter providing Board authorization to obtain assistance.</P>
                <P>
                    Each application received in a USDA RD State Office will be reviewed to determine if it is consistent with the eligible purposes contained in section 310B(c) of the Consolidated Farm and Rural Development Act (7 U.S.C. 1932(c)). Each selection scoring criterion outlined in 7 CFR 4280.435 must be addressed in the application. Failure to address any of the criteria will result in a zero-point score for that criterion and will impact the overall evaluation of the application. The regulation governing this program, 7 CFR part 4280, subpart E, is available at 
                    <E T="03">ecfr.gov/current/title-7/subtitle-B/chapter-XLII/part-4280/subpart-E,</E>
                     or will be provided to any interested applicant making a request to a USDA RD State Office.
                </P>
                <P>All projects to receive technical assistance through these passenger transportation grant funds are to be identified when the applications are submitted to the USDA RD State Office. Multiple project applications must identify each individual project, indicate the amount of funding requested for each individual project, and address the criteria as stated above for each individual project.</P>
                <P>
                    3. 
                    <E T="03">System for Award Management and Unique Entity Identifier.</E>
                </P>
                <P>
                    (a) At the time of application, each applicant must have an active registration in the System for Award Management (SAM) before submitting its application in accordance with 2 CFR part 25 (
                    <E T="03">ecfr.gov/current/title-2/subtitle-A/chapter-I/part-25</E>
                    ). To register in SAM, entities will be required to obtain a Unique Entity Identifier (UEI). Instructions for obtaining the UEI are available at 
                    <E T="03">https://sam.gov/content/entity-registration.</E>
                </P>
                <P>(b) Applicant must maintain an active SAM registration, with current, accurate, and complete information, while it has an active Federal award or an application under consideration by a Federal awarding agency.</P>
                <P>(c) Applicants must ensure they complete the Financial Assistance General Certifications and Representations in SAM.</P>
                <P>
                    (d) Applicants must provide a valid UEI in its application, unless determined exempt under 2 CFR 25.110 (
                    <E T="03">ecfr.gov/current/title-2/subtitle-A/chapter-I/part-25/subpart-A/section-25.110</E>
                    ).
                </P>
                <P>(e) The Agency will not make an award until the applicant has complied with all SAM requirements including providing the UEI. If an applicant has not fully complied with the requirements by the time the Agency is ready to make an award, the Agency may determine that the applicant is not qualified to receive a Federal award and use that determination as a basis for making a Federal award to another applicant.</P>
                <P>
                    4. 
                    <E T="03">Submission Dates and Times.</E>
                </P>
                <P>
                    (a) 
                    <E T="03">Application Technical Assistance Deadline Date.</E>
                     Prior to official submission of grant applications, applicants may request technical assistance or other application guidance from the Agency. All requests for technical assistance or application guidance must be made prior to February 5, 2025. Technical assistance is not meant to be an analysis or assessment of the quality of the materials submitted, a substitute for Agency review of completed applications, or a determination of eligibility, if such determination requires in-depth analysis.
                </P>
                <P>
                    (b) 
                    <E T="03">Application Deadline Date.</E>
                     Applications (paper or electronic format) must be submitted to the appropriate RD State Office no later than 4:30 p.m. (local time) on April 7, 2025. If completed applications are not received by the deadline date, the application will neither be reviewed nor considered for funding under any circumstances.
                </P>
                <P>The Agency will not solicit or consider scoring or eligibility information that is submitted after the application deadline. The Agency reserves the right to contact applicants to seek clarification information on materials contained in the submitted application.</P>
                <P>The deadline date means that the completed application package must be received in the USDA RD State Office by the deadline date established above. If the due date falls on a Saturday, Sunday, or Federal holiday, the application is due the next business day. All application documents identified in this notice and in 7 CFR part 4280, subpart E, are required to be considered a complete application.</P>
                <P>
                    (c) 
                    <E T="03">Applications Received After Deadline Date.</E>
                     If a complete application is not received by the deadline established above, the application will neither be reviewed nor considered under any circumstances. The Agency will not solicit or consider scoring or eligibility information that is submitted after the application deadline. The Agency reserves the right to contact applicants to seek clarification information on materials contained in the submitted application.
                </P>
                <P>
                    5. 
                    <E T="03">Intergovernmental Review.</E>
                     Executive Order (E.O.) 12372, “Intergovernmental Review of Federal Programs,” applies to this program. This E.O. requires that Federal agencies provide opportunities for consultation on proposed assistance with State and local governments. Many States have established a Single Point of Contact (SPOC) to facilitate this consultation. For a list of States that maintain a SPOC, please see the White House website: 
                    <E T="03">whitehouse.gov/omb/management/office-federal-financial-management/.</E>
                     If your State has a SPOC, you may submit a copy of the application directly for review. Any comments obtained through the SPOC must be provided to your State Office for consideration as part of your application. If your State has not established a SPOC, or if you do not want to submit a copy of the application, our State Offices will submit your application to the SPOC or other appropriate agency or agencies.
                </P>
                <P>
                    6. 
                    <E T="03">Funding Restrictions.</E>
                     These grants are for RT Technical Assistance grants only and no construction or equipment purchases are permitted. If the grantee has a previously approved indirect cost rate, it is permissible, otherwise, the applicant may elect to charge the 15 percent indirect cost permitted under 2 CFR 200.414(f) or request a determination of its Indirect Cost Rate. Due to the time required to evaluate Indirect Cost Rates, it is likely that all funds will be awarded by the time the Indirect Cost Rate is determined. No foreign travel is permitted. Pre-Federal award costs will only be permitted with prior written approval by the Agency.
                </P>
                <P>
                    None of the funds made available may be used to enter into a contract, memorandum of understanding, or 
                    <PRTPAGE P="587"/>
                    cooperative agreement with, make a grant to, or provide a loan or loan guarantee to:
                </P>
                <P>(a) Any corporation that has any unpaid Federal tax liability that has been assessed, for which all judicial and administrative remedies have been exhausted or have lapsed, and that is not being paid in a timely manner pursuant to an agreement with the authority responsible for collecting the tax liability.</P>
                <P>(b) Any corporation that was convicted of a felony criminal violation under any Federal law within the preceding 24 months where the awarding agency is aware of the unpaid tax liability and/or conviction, unless a Federal agency has considered suspension or debarment of the corporation and has determined that further action is not necessary to protect the interests of the Government.</P>
                <P>
                    7. 
                    <E T="03">Other Submission Requirements.</E>
                </P>
                <P>
                    <E T="03">General Submission Requirements.</E>
                     The organization submitting the application will be considered the lead entity. The program manager must be associated with the lead entity submitting the application. Applications will not be considered for funding if they do not provide sufficient information to determine eligibility or are missing required elements.
                </P>
                <P>There is no limit on the number of applications an applicant may submit under this announcement. There are no specific formats, specific limitations on number of pages, font size and type face, margins, paper size, number of copies, sequence, or assembly requirements. The component pieces of this application should contain original signatures on the original application.</P>
                <P>
                    <E T="03">Electronic Submittals.</E>
                     Applicants submitting an electronic application, should contact the State Office serving the State where the Project will primarily take place. A list of State Offices may be found at 
                    <E T="03">rd.usda.gov/about-rd/state-offices.</E>
                </P>
                <P>
                    <E T="03">Paper Submittals.</E>
                     Applicants submitting a paper application should send it to the USDA RD State Office located in the State where the Project will primarily take place. You can find State Office contact information at: 
                    <E T="03">rd.usda.gov/contact-us/state-offices.</E>
                </P>
                <P>
                    All forms requiring signatures must include an original signature. If the applicant wishes to hand deliver its application, the addresses for these deliveries are in the 
                    <E T="02">ADDRESSES</E>
                     section of this notice.
                </P>
                <HD SOURCE="HD2">E. Application Review Information</HD>
                <P>
                    1. 
                    <E T="03">Criteria.</E>
                     All eligible and complete applications will be evaluated and scored based on the scoring criteria contained in 7 CFR 4280.435. The Agency will select grantees subject to the grantees' satisfactory submission of the items required by 7 CFR 4280.427, and the USDA RD Letter of Conditions. Failure to address any criteria in 7 CFR 4280.427 by the application deadline will result in the application being determined ineligible, and the application will not be considered for funding. The amount of an RT grant may be adjusted, at the Agency's discretion, to enable the Agency to award RT grants to the applications with the highest priority scores in each category.
                </P>
                <P>
                    2. 
                    <E T="03">Review and Selection Process.</E>
                     USDA RD State Offices will review applications to determine if they are eligible for assistance based on the application and project eligibility requirements contained in 7 CFR 4280.416 and 4280.417, respectively, and as stated in this notice. If determined eligible, the applicable State Office will submit your application to the National Office. Funding of the projects is subject to the applicant's satisfactory submission of the additional items required by subpart E and the USDA RD Letter of Conditions. The Agency reserves the right to offer the applicant a grant award in an amount less than the amount the applicant requested.
                </P>
                <P>The Agency reserves the right to award additional discretionary points under 7 CFR 4280.435(k). Discretionary points may only be assigned to initial grants. Assignment of discretionary points must include a written justification. Permissible justifications include projects that meet special Secretary of Agriculture initiatives such as projects:</P>
                <P>
                    (a) Assisting rural communities recover economically through more and better market opportunities and through improved infrastructure. Applicants receive priority points if the project is located in or serving a rural community whose economic well-being ranks in the most distressed tier (distress score of 80 or higher) of the Distressed Communities Index using the Distressed Communities Look-Up Map available at 
                    <E T="03">rd.usda.gov/priority-points.</E>
                </P>
                <P>
                    (b) Ensuring all rural residents have equitable access to RD programs and benefits from RD funded projects. Using the Social Vulnerability Index (SVI) Look-Up Map (available at 
                    <E T="03">rd.usda.gov/priority-points</E>
                    ), an applicant would receive priority points if the:
                </P>
                <P>• The Project is located in or serving a community with score 0.75 or above on the SVI;</P>
                <P>• The applicant is a federally recognized Tribe, including Tribal instrumentalities and entities that are wholly owned by Tribes; or</P>
                <P>• Is a project where at least 50 percent of the project beneficiaries are members of federally recognized Tribes and non-Tribal applicants include a Tribal Resolution of Consent from the Tribe or Tribes that the applicant is proposing to serve.</P>
                <P>
                    • The application is from or benefiting a Rural Partner's Network's (RPN) community network. Currently RPN Networks exist in Alaska, Arizona, Georgia, Kentucky, Mississippi, Nevada, New Mexico, North Carolina, Puerto Rico, West Virginia and Wisconsin. Use the Community Look-Up map (available at 
                    <E T="03">rd.usda.gov/priority-points</E>
                    ) to determine if your project qualifies for priority points.
                </P>
                <P>
                    (c) Reducing climate pollution and increasing resilience to the impacts of climate change through economic support to rural communities. Using the Disadvantaged Community and Energy Community Look-up Map (available at 
                    <E T="03">rd.usda.gov/priority-points</E>
                    ), applicants will receive priority points in three ways:
                </P>
                <P>• If a project is located in or serves a Disadvantaged Community as defined by the Climate and Economic Justice Screening Tool (CEJST), from the White House Council on Environmental Quality (CEQ),</P>
                <P>• If the project is located in or serves an Energy Community as defined by the Inflation Reduction Act of 2022 (Pub. L. 117-169, “IRA”), and</P>
                <P>• If applicants can demonstrate through a written narrative how the proposed climate-impact projects will improve the livelihoods of community residents and meet pollution mitigation or clean energy goals.</P>
                <HD SOURCE="HD2">F. Federal Award Administration Information</HD>
                <P>
                    1. 
                    <E T="03">Federal Award Notices.</E>
                     Successful applicants will receive notification for funding from their USDA RD State Office. Applicants must comply with all applicable statutes and regulations before the grant award will be approved. Unsuccessful applications will receive notification by mail.
                </P>
                <P>
                    2. 
                    <E T="03">Administrative and National Policy Requirements.</E>
                </P>
                <P>
                    (a) 
                    <E T="03">Additional Requirements.</E>
                </P>
                <P>
                    (1) All successful applicants will be notified by letter, which will include a Letter of Conditions, and a Letter of Intent to Meet Conditions. This letter is not an authorization to begin performance. If the applicant wishes to consider beginning performance prior to the grant being officially closed, all pre-award costs must be approved in writing and in advance by the Agency. 
                    <PRTPAGE P="588"/>
                    The grant will be considered officially awarded when all conditions in the Letter of Conditions have been met and the Agency obligates the funding for the Project.
                </P>
                <P>(2) Additional requirements that apply to grantees selected for this program can be found in 7 CFR part 4280, subpart E; the Grants and Agreements regulations applicable to USDA in 2 CFR part 400, which incorporates the Office of Management and Budget (OMB) regulations at 2 CFR part 200, and successor regulations. In addition, all recipients of Federal financial assistance are required to report information about first tier subawards and executive compensation (see 2 CFR part 170). You will be required to have the necessary processes and systems in place to comply with the Federal Funding Accountability and Transparency Act of 2006 (Pub. L. 109-282) reporting requirements (see 2 CFR 170.200(b), unless you are exempt under 2 CFR 170.105).</P>
                <P>
                    (3) Program participants will be required to collect and maintain data provided by recipients on race, sex, and national origin and ensure recipients collect and maintain this data. Race and ethnicity data will be collected in accordance with OMB 
                    <E T="04">Federal Register</E>
                     notice, “Revisions to the Standards for the Classification of Federal Data on Race and Ethnicity,” (62 FR 58782), October 30, 1997. Data on recipients' sex will be collected in accordance with title IX of the Education Amendments Act of 1972. These items should not be submitted with the application but should be available upon request by the Agency.
                </P>
                <P>(4) The following additional requirements apply to grantees selected for this program:</P>
                <P>(i) Form RD 4280-2 “Rural Business-Cooperative Service Financial Assistance Agreement.”</P>
                <P>(ii) Letter of Conditions.</P>
                <P>(iii) Form RD 1940-1, “Request for Obligation of Funds.”</P>
                <P>(iv) Form RD 1942-46, “Letter of Intent to Meet Conditions.”</P>
                <P>(v) SF LLL, “Disclosure of Lobbying Activities,” if applicable.</P>
                <P>(vi) Form SF 270, “Request for Advance or Reimbursement.”</P>
                <P>
                    (b) 
                    <E T="03">Geospatial Information.</E>
                     Awardee, and any and all contracts entered into by the Awardee with respect to the Award, shall ensure that geospatial data required to be collected and provided to the agency, conforms with the requirements of USDA Department Regulation DR-3465-001 and the Geospatial Metadata Standards set forth in DM 3465-001, which can be obtained online at 
                    <E T="03">www.usda.gov/directives/dr-3465-001</E>
                     and 
                    <E T="03">www.usda.gov/directives/dm-3465-001.</E>
                </P>
                <P>
                    3. 
                    <E T="03">Reporting.</E>
                     A Financial Status Report and a Project Performance Activity Report will be required of all grantees on a quarterly basis until initial funds are expended and yearly thereafter, if applicable, based on the Federal fiscal year. The grantee will complete the Project within the total time available to it in accordance with the Scope of Work and any necessary modifications thereof prepared by the grantee and approved by the Agency. A final Project Performance Report will be required with the final Financial Status Report. The final report may serve as the last quarterly report. The final report must provide complete information regarding the jobs created and supported as a result of the grant if applicable. Grantees must continuously monitor performance to ensure that time schedules are being met, projected work by time periods is being accomplished, and other performance objectives are being achieved. Grantees must submit an original of each report to the Agency no later than 30 days after the end of the quarter. The Project Performance Reports must include, but not be limited to, the following:
                </P>
                <P>(a) A comparison of actual accomplishments to the objectives established for that period;</P>
                <P>(b) Problems, delays, or adverse conditions, if any, which have affected or will affect attainment of overall Project objectives, prevent meeting time schedules or objectives, or preclude the attainment of Project work elements during established time periods. This disclosure shall be accompanied by a statement of the action taken or planned to resolve the situation;</P>
                <P>(c) Objectives and timetable established for the next reporting period;</P>
                <P>(d) Any special reporting requirements, such as jobs supported and created, businesses assisted, or Economic Development which results in improvements in median household incomes, and any other specific requirements, should be placed in the reporting section in the Letter of Conditions; and</P>
                <P>(e) Within 120 days after the conclusion of the Project, the grantee will provide a final Project Evaluation Report. The last quarterly payment will be withheld until the final report is received and approved by the Agency. Even though the grantee may request reimbursement monthly, the last three months of reimbursements will be withheld until a final Project, Project Performance, and Financial Status Report are received and approved by the Agency.</P>
                <HD SOURCE="HD2">G. Federal Awarding Agency Contact(s)</HD>
                <P>
                    For general questions about this announcement, please contact your USDA RD State Office provided in the 
                    <E T="02">ADDRESSES</E>
                     section of this notice.
                </P>
                <HD SOURCE="HD2">H. Other Information</HD>
                <P>
                    1. 
                    <E T="03">Paperwork Reduction Act.</E>
                     In accordance with the Paperwork Reduction Act of 1995 (44 U.S.C. chapter 35), the information collection requirements associated with this program, as covered in this notice, have been approved by the Office of Management and Budget (OMB) under OMB Control Number 0570-0070.
                </P>
                <P>
                    2. 
                    <E T="03">National Environmental Policy Act.</E>
                     All recipients under this notice are subject to the requirements of 7 CFR part 1970. However, awards for technical assistance and training under this notice are classified as a Categorical Exclusion in accordance with 7 CFR 1970.53(b), and usually do not require any additional documentation. RBCS will review each grant application to determine its compliance with 7 CFR part 1970. The applicant may be asked to provide additional information or documentation to assist RBCS with this determination.
                </P>
                <P>
                    3. 
                    <E T="03">Federal Funding Accountability and Transparency Act.</E>
                     All applicants, in accordance with 2 CFR part 25, must be registered in SAM and have a UEI number as stated in section D.3 of this notice. All recipients of Federal financial assistance are required to report information about first tier subawards and executive total compensation in accordance with 2 CFR part 170.
                </P>
                <P>
                    4. 
                    <E T="03">Civil Rights Act.</E>
                     All grants made under this notice are subject to title VI of the Civil Rights Act of 1964 as required by the USDA (7 CFR part 15, subpart A—Nondiscrimination in Federally-Assisted Programs of the Department of Agriculture—Effectuation of Title VI of the Civil Rights Act of 1964), section 504 of the Rehabilitation Act of 1973, title VIII of the Civil Rights Act of 1968, title IX, Executive Order 13166 (Limited English Proficiency), Executive Order 11246, and the Equal Credit Opportunity Act of 1974.
                </P>
                <P>
                    5. 
                    <E T="03">Equal Opportunity for Religious Organizations.</E>
                </P>
                <P>
                    (a) Faith-based organizations may apply for this award on the same basis as any other organization, as set forth at, and subject to the protections and requirements of, this part and any applicable constitutional and statutory requirements, including 42 U.S.C. 2000bb 
                    <E T="03">et seq.</E>
                     USDA will not, in the 
                    <PRTPAGE P="589"/>
                    selection of recipients, discriminate for or against an organization on the basis of the organization's religious character, motives, or affiliation, or lack thereof, or on the basis of conduct that would not be considered grounds to favor or disfavor a similarly situated secular organization.
                </P>
                <P>(b) A faith-based organization that participates in this program will retain its independence from the Government and may continue to carry out its mission consistent with religious freedom and conscience protections in Federal law. Religious accommodations may also be sought under many of these religious freedom and conscience protection laws.</P>
                <P>(c) A faith-based organization may not use direct Federal financial assistance from USDA to support or engage in any explicitly religious activities except when consistent with the Establishment Clause of the First Amendment and any other applicable requirements. An organization receiving Federal financial assistance also may not, in providing services funded by USDA, or in their outreach activities related to such services, discriminate against a program beneficiary or prospective program beneficiary on the basis of religion, a religious belief, a refusal to hold a religious belief, or a refusal to attend or participate in a religious practice.</P>
                <P>
                    6. 
                    <E T="03">Nondiscrimination Statement.</E>
                     In accordance with Federal civil rights laws and USDA civil rights regulations and policies, the USDA, its Mission Areas, agencies, staff offices, employees, and institutions participating in or administering USDA programs are prohibited from discriminating based on race, color, national origin, religion, sex, gender identity (including gender expression), sexual orientation, disability, age, marital status, family/parental status, income derived from a public assistance program, political beliefs, or reprisal or retaliation for prior civil rights activity, in any program or activity conducted or funded by USDA (not all bases apply to all programs). Remedies and complaint filing deadlines vary by program or incident.
                </P>
                <P>
                    Program information may be made available in languages other than English. Persons with disabilities who require alternative means of communication to obtain program information (
                    <E T="03">e.g.,</E>
                     Braille, large print, audiotape, American Sign Language) should contact the responsible Mission Area, agency, or staff office; or the 711 Relay Service.
                </P>
                <P>
                    To file a program discrimination complaint, a complainant should complete a Form AD-3027, USDA Program Discrimination Complaint Form, which can be obtained online at 
                    <E T="03">usda.gov/sites/default/files/documents/ad-3027.pdf,</E>
                     from any USDA office, by calling (866) 632-9992, or by writing a letter addressed to USDA. The letter must contain the complainant's name, address, telephone number, and a written description of the alleged discriminatory action in sufficient detail to inform the Assistant Secretary for Civil Rights (ASCR) about the nature and date of an alleged civil rights violation. The completed AD-3027 form or letter must be submitted to USDA by:
                </P>
                <P>
                    (1) 
                    <E T="03">Mail:</E>
                     U.S. Department of Agriculture, Office of the Assistant Secretary for Civil Rights, 1400 Independence Avenue SW, Washington, DC 20250-9410; or
                </P>
                <P>
                    (2) 
                    <E T="03">Fax:</E>
                     (833) 256-1665 or (202) 690-7442; or
                </P>
                <P>
                    (3) 
                    <E T="03">Email: program.intake@usda.gov.</E>
                </P>
                <P>USDA is an equal opportunity provider, employer, and lender.</P>
                <SIG>
                    <NAME>Kathryn E. Dirksen Londrigan,</NAME>
                    <TITLE>Administrator, Rural Business-Cooperative Service, USDA Rural Development.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-28767 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 3410-XY-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF AGRICULTURE</AGENCY>
                <SUBAGY>Rural Utilities Service</SUBAGY>
                <DEPDOC>[Docket#: RUS-24-TELECOM-0034]</DEPDOC>
                <SUBJECT>Notice of Funding Opportunity for the Distance Learning and Telemedicine Grants for Fiscal Year 2025</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Rural Utilities Service, USDA</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Rural Utilities Service (RUS or the Agency), a Rural Development (RD) agency of the United States Department of Agriculture (USDA), announces the acceptance of applications under the Distance Learning and Telemedicine (DLT) grant program for fiscal year (FY) 2025, subject to the availability of funding. This notice is being issued prior to passage of a FY 2025 Appropriations Act in order to allow applicants sufficient time to leverage financing, prepare and submit their applications, and give the Agency time to process applications within FY 2025. Based on FY 2024 appropriated funding, the Agency estimates that approximately $40 million will be available for FY 2025. Successful applications will be selected by the Agency for funding and subsequently awarded to the extent that funding may ultimately be made available through appropriations. All applicants are responsible for any expenses incurred in developing their applications.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        Applications must be submitted through 
                        <E T="03">www.grants.gov/</E>
                         and received no later than March 6, 2024 to be eligible for funding under this grant opportunity. Late or incomplete applications will not be eligible for funding under this grant opportunity.
                    </P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        All applications must be submitted electronically at 
                        <E T="03">www.grants.gov.</E>
                         Instructions and additional resources, to include an Application Guide, are available at 
                        <E T="03">www.rd.usda.gov/programs-services/telecommunications-programs/distance-learning-telemedicine-grants,</E>
                         under the “To Apply” tab.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        For inquiries regarding eligibility concerns, please contact program staff at 
                        <E T="03">www.usda.gov/reconnect/contact-us.</E>
                         Other inquiries, please contact Randall Millhiser, Deputy Assistant Administrator, Office of Loan Origination and Approval, RUS, USDA, 1400 Independence Avenue SW, Mail Stop 1590, Room 4121-S, Washington, DC 20250-1590, telephone: (202) 720-0800, email: 
                        <E T="03">randall.millhiser@usda.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">Overview</HD>
                <P>
                    <E T="03">Federal Awarding Agency Name:</E>
                     Rural Utilities Service (RUS).
                </P>
                <P>
                    <E T="03">Funding Opportunity Title:</E>
                     Distance Learning and Telemedicine (DLT) Grants.
                </P>
                <P>
                    <E T="03">Announcement Type:</E>
                     Notice of Funding Opportunity (NOFO).
                </P>
                <P>
                    <E T="03">Funding Opportunity Number:</E>
                     RUS-25-01-DLT.
                </P>
                <P>
                    <E T="03">Assistance Listing Number:</E>
                     10.855.
                </P>
                <P>
                    <E T="03">Dates:</E>
                     Applications must be submitted through 
                    <E T="03">www.grants.gov</E>
                     and received no later than March 6, 2024 to be eligible for funding under this grant opportunity. Late or incomplete applications will not be eligible for funding under this grant opportunity.
                </P>
                <P>
                    <E T="03">Rural Development Key Priorities:</E>
                     The Agency encourages applicants to consider projects that will advance the following key priorities (more details available at 
                    <E T="03">www.rd.usda.gov/priority-points</E>
                    ):
                </P>
                <P>
                    • 
                    <E T="03">Creating More and Better Markets:</E>
                     Assist rural communities to recover economically through more and better market opportunities and through improved infrastructure.
                </P>
                <P>
                    • 
                    <E T="03">Advancing Racial Justice, Place-Based Equity, and Opportunity:</E>
                     Ensure all rural residents have equitable access to RD programs and benefits from RD funded projects; and
                    <PRTPAGE P="590"/>
                </P>
                <P>
                    • 
                    <E T="03">Addressing Climate Change and Environmental Justice:</E>
                     Reduce climate pollution and increase resilience to the impacts of climate change through economic support to rural communities.
                </P>
                <HD SOURCE="HD2">A. Program Description</HD>
                <P>
                    1. 
                    <E T="03">Purpose of the Program.</E>
                     The DLT program provides financial assistance to enable and improve distance learning and telemedicine services in rural areas. DLT grant funds support the use of telecommunications-enabled information, audio and video equipment, and related advanced technologies by students, teachers, medical professionals, and rural residents. These grants are intended to increase rural access to education, training, and health care resources that are otherwise unavailable or limited in scope.
                </P>
                <P>
                    2. 
                    <E T="03">Statutory and Regulatory Authority.</E>
                     The DLT program is authorized under 7 U.S.C. 950aaa and implemented by 7 CFR part 1734.
                </P>
                <P>
                    3. 
                    <E T="03">Definitions.</E>
                     The definitions applicable to this notice are published at 7 CFR 1734.3. Additional definitions applicable to this notice are listed below.
                </P>
                <P>
                    <E T="03">Federally Recognized Tribe</E>
                     is classified as any Indian or Alaska Native tribe, band, nation, pueblo, village or community as defined by the Federally Recognized Indian Tribe List Act of 1994 (Pub. L. 103-454). A list of Federally Recognized Tribes is available at: 
                    <E T="03">www.federalregister.gov/documents/2023/01/12/2023-00504/indian-entities-recognized-by-and-eligible-to-receive-services-from-the-united-states-bureau-of.</E>
                </P>
                <P>
                    <E T="03">Opioid or other substance use disorder treatment</E>
                     is defined as the interactive communication between medical or educational professionals and opioid users or their families, other treatment professionals or those who interact with opioid or other substance users.
                </P>
                <P>
                    <E T="03">Rural Area</E>
                     refers to any area, as confirmed by the most recent decennial Census of the United States, which is not located within a city, town, or incorporated area that has a population of greater than 20,000 inhabitants; or an urbanized area contiguous to a city or town that has a population of greater than 50,000 inhabitants; and which excludes certain populations pursuant to 7 U.S.C. 1991(a)(13)(H) and (I). For purposes of the definition of Rural 
                    <E T="03">A</E>
                    rea, the Agency has determined to recognize any census-designated “urban area” in place of an “urbanized area,” given that the Census Bureau no longer tracks or uses the term urbanized area.
                </P>
                <P>
                    4. 
                    <E T="03">Application of Awards.</E>
                </P>
                <P>(a) The Agency will review, evaluate, and score applications received in response to this notice based on 7 CFR 1734.26. Awards under the DLT program will be made on a competitive basis using specific selection criteria provided in 7 CFR 1734.27. The Agency advises all interested parties that the applicant bears the full burden in preparing and submitting an application in response to this notice regardless of whether or not funding is appropriated for the DLT program in FY 2025.</P>
                <P>(b) For this application window, applicants may, but are not required to, submit an application competing for residual Coronavirus Aid, Relief, and Economic Security Act funding (CARES) funds. An estimated $5 million is available to prevent, prepare for, and respond to coronavirus, domestically or internationally, for telemedicine and distance learning services in rural areas. Interested applicants are encouraged to identify specific ways in which their application addresses COVID-19.</P>
                <HD SOURCE="HD2">B. Federal Award Information</HD>
                <P>
                    <E T="03">Type of Award:</E>
                     Grants.
                </P>
                <P>
                    <E T="03">Fiscal Year Funds:</E>
                     FY 2025.
                </P>
                <P>
                    <E T="03">Available Funds:</E>
                     Based on FY 2024 appropriated funding, the Agency estimates that approximately $40 million will be available for FY 2025.
                </P>
                <P>To combat a key threat to economic prosperity, rural workforce and quality of life, the Agency is directed to set aside 20 percent of the total available funds for FY 2025 for projects that seek to reduce the morbidity and mortality associated with substance use disorder (including opioid misuse) in rural communities by strengthening the capacity to address prevention, treatment and/or recovery at the community level.</P>
                <P>For this application window, applicants may, but are not required to, submit an application competing for CARES Act funding as detailed in section A(4)(b) of this notice.</P>
                <P>The total appropriated amount minus the determined set aside amount will be available for all eligible projects. RUS may at its discretion, increase the total level of funding available in this funding round from any available source provided the awards meet the requirements of the statute which made the funding available to the Agency.</P>
                <P>
                    <E T="03">Award Amounts:</E>
                     Pursuant to 7 CFR 1734.24, the Administrator has established that the minimum grant amount of $50,000 and the maximum grant amount of $1,000,000 will be applied to this grant opportunity, if funds are appropriated.
                </P>
                <P>
                    <E T="03">Anticipated Award Date:</E>
                     September 30, 2025.
                </P>
                <P>
                    <E T="03">Performance Period:</E>
                     Three-year period, beginning the date funds are released.
                </P>
                <P>
                    <E T="03">Renewal or Supplemental Awards:</E>
                     Although prior DLT grants cannot be renewed, existing DLT awardees can submit applications for new projects that are distinct (clearly separate and different) from previously funded projects, either because they are for a completely separate purpose and technology or because they propose to serve a new service area, unassociated with prior funded service areas. Grant applications must be submitted during the application window.
                </P>
                <P>
                    <E T="03">Type of Assistance Instrument:</E>
                     Grant Agreement.
                </P>
                <HD SOURCE="HD2">C. Eligibility Information</HD>
                <P>
                    1. 
                    <E T="03">Eligible Applicants.</E>
                     Eligible applicants must meet the eligibility requirements of 7 CFR 1734.4.
                </P>
                <P>
                    (a) Applicants must have a Unique Entity Identifier (UEI) and an active registration that includes the Financial Assistance Representations and Certifications and has current information in the System for Award Management (SAM) at: 
                    <E T="03">www.sam.gov.</E>
                     Further information regarding UEI acquisition and SAM registration can be found in Section D.3 of this document.
                </P>
                <P>(b) Corporations that have been convicted of a federal felony within the past 24 months are not eligible. Any corporation that has been assessed to have any unpaid federal tax liability, for which all judicial and administrative remedies have been exhausted or have lapsed and is not being paid in a timely manner pursuant to an agreement with the authority responsible for collecting the tax liability, is not eligible for financial assistance.</P>
                <P>
                    (c) Applicants are required to provide evidence of their ability to contract with RUS to obtain the grant and comply with all applicable requirements, in accordance with 7 CFR 1734.4(a). It is incumbent on applicants to determine the appropriate entity to apply for the grant. Entities created by educational or medical institutions for the purpose of applying for and managing grants, such as university or hospital foundations, should not be applicants unless they can own and manage grant-funded equipment as required by the Grant Agreement and applicable regulations, including 2 CFR part 200. Accordingly, RUS will not transfer awards to another entity because the applicant has later determined that it cannot close the award, execute the standard Grant Agreement, which is publicly available, nor hold the grant assets in its name. Similarly, if there will be shared ownership of assets, this must be fully 
                    <PRTPAGE P="591"/>
                    addressed in the application, including all related co-awardee entity information necessary to prepare legal documents. The agency will not add co-awardees to the grant agreements if the information was not clearly presented in the application.
                </P>
                <P>
                    2. 
                    <E T="03">Cost Sharing or Matching.</E>
                     The DLT program requires matching contributions for grants as outlined in 7 CFR 1734.22. The Application Guide located on the DLT website at 
                    <E T="03">www.rd.usda.gov/programs-services/telecommunications-programs/distance-learning-telemedicine-grants</E>
                     provides additional guidance for matching contributions.
                </P>
                <P>
                    (a) 
                    <E T="03">Match Documentation.</E>
                     Grant applicants must demonstrate matching contributions, in cash or in kind (new or non-depreciated items), of at least 15 percent of the grant amount requested. Matching contributions must be used for approved purposes for grants (see 7 CFR 1734.21 and Section D.6 of this notice). Applications that do not provide sufficient documentation of the required 15 percent match will be deemed ineligible.
                </P>
                <P>
                    (b) 
                    <E T="03">Discounts and Donations.</E>
                     A review of applications submitted in the past determined that vendor-donated matches did not have value without a required subsequent purchase of vendor equipment or licenses with grant funds. For example, in many grant applications, software licenses were donated in satisfaction of the matching requirement. However, such licenses only worked with, and thus only had value with, the same vendor's equipment. Additionally, by side agreement, grant applicants were required to purchase the vendor's equipment once the grant was made with grant funds. The Agency determined that such a practice violated federal procurement standards found at 2 CFR 200.317 through 200.327, because the grant applicant did not put the purchase out for bid, either because no other equipment would work with the “donated” licenses, or because they were contractually obligated to buy the equipment before the grant was made. As such, the Agency has determined that vendor matches requiring subsequent purchases, either by necessity or contract, are not permitted.
                </P>
                <P>
                    3. 
                    <E T="03">Other Eligibility Requirements.</E>
                </P>
                <P>(a) The Application Guide provides additional information regarding eligible and ineligible items for equipment and facilities.</P>
                <P>(b) Grant applications that are written by vendors who are mentioned in the application as vendors to be used on the project to be funded by the DLT award are ineligible as a violation of the competition rules in 2 CFR 200.319. Such vendors are also prohibited from bidding on the project because of conflict of interest. Additionally, applicants must fully understand the procurement requirements of 2 CFR part 200, subpart D and 7 CFR part 1734 when compiling an application for submission and must avoid the use of predetermined equipment as a violation of the bidding requirements unless they have adequately demonstrated in the application that no other equipment is available for the intended purpose.</P>
                <P>
                    (c) Projects located in areas covered by the Coastal Barrier Resources Act (16 U.S.C. 3501 
                    <E T="03">et seq.</E>
                    ) are not eligible for financial assistance from the DLT program. See 7 CFR 1734.23(a)(11).
                </P>
                <P>(d) If a DLT project proposes service on or over Tribal Lands and the applicant is non-Tribal, then a letter of consent is required from each Tribal Council with jurisdiction over the Tribal Lands included in the project. However, if a DLT project proposes infrastructure construction or deployment on or over Tribal Lands, then a Tribal Resolution is required from each Tribal Government with jurisdiction over the Tribal Lands included in the project.</P>
                <HD SOURCE="HD2">D. Application and Submission Information</HD>
                <P>
                    1. 
                    <E T="03">Address to Request Application Package.</E>
                     The Application Guide, copies of necessary forms, and resources are available at 
                    <E T="03">www.rd.usda.gov/programs-services/telecommunications-programs/distance-learning-telemedicine-grants.</E>
                     Application information is also available at 
                    <E T="03">www.grants.gov.</E>
                     If you require alternative means of communication of program information (
                    <E T="03">e.g.,</E>
                     Braille, large print, audiotape, etc.) please contact the 711 Relay Service.
                </P>
                <P>
                    2. 
                    <E T="03">Content and Form of Application Submission.</E>
                </P>
                <P>
                    (a) 
                    <E T="03">Application Completion.</E>
                     Carefully review 7 CFR part 1734, subparts A and B. A list of items for a complete application can be found at 7 CFR 1734.25. The Application Guide provides specific, detailed instructions for each item of a complete application. The Agency emphasizes the importance of including every item and strongly encourages applicants to follow the instructions carefully, using the examples and illustrations in the Application Guide.
                </P>
                <P>
                    (b) 
                    <E T="03">Description of Project Sites.</E>
                     Most DLT grant projects contain several project sites. The Agency provides a sample worksheet that is located on the DLT website (found here: 
                    <E T="03">www.rd.usda.gov/programs-services/telecommunications-programs/distance-learning-telemedicine-grants</E>
                    ) to help applicants clearly identify hub, hub/end-user, and end-user sites. As in prior DLT funding windows, site information must be consistent throughout the application. Applications without consistent site information will be returned as ineligible.
                </P>
                <P>
                    (c) 
                    <E T="03">Submission of Application Items.</E>
                     Given the high volume of program interest, applicants should submit the application items in the order as indicated in the table below. Applications that are not assembled in the specified order prevent timely determination of eligibility.
                </P>
                <GPOTABLE COLS="3" OPTS="L2,tp0,i1" CDEF="s50,17,r50">
                    <TTITLE> </TTITLE>
                    <BOXHD>
                        <CHED H="1">Application item</CHED>
                        <CHED H="1">Regulation</CHED>
                        <CHED H="1">Comments</CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">SF-424 (Application for Federal Assistance Form)</ENT>
                        <ENT>7 CFR 1734.25(a)</ENT>
                        <ENT>
                            Form provided through 
                            <LI>
                                <E T="03">www.grants.gov.</E>
                            </LI>
                        </ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Executive Summary of the Project</ENT>
                        <ENT>7 CFR 1734.25(b)</ENT>
                        <ENT>Narrative, including a publicly releasable section that describes the population served.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Non-Duplication of Services</ENT>
                        <ENT>7 CFR 1734.25(b)(8)</ENT>
                        <ENT>Guidance provided in the Application Guide.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Scoring Criteria Documentation</ENT>
                        <ENT>7 CFR 1734.25(c)</ENT>
                        <ENT>Provide documentation on how applicant meets each of the scoring criteria (see 7 CFR 1734.26).</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Scope of Work</ENT>
                        <ENT>7 CFR 1734.25(d)</ENT>
                        <ENT>Narrative and documentation, including the budget.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Financial Information and Sustainability</ENT>
                        <ENT>7 CFR 1734.25(e)</ENT>
                        <ENT>Narrative.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Statement of Experience</ENT>
                        <ENT>7 CFR 1734.25(f)</ENT>
                        <ENT>Narrative.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Funding Commitments from All Sources</ENT>
                        <ENT>7 CFR 1734.25(g) </ENT>
                        <ENT>Worksheet and match documentation letters with authorized signatures.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Telecommunications System Plan</ENT>
                        <ENT>7 CFR 1734.25(h)</ENT>
                        <ENT>Documentation.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Compliance with other Federal Statutes</ENT>
                        <ENT>7 CFR 1734.25(i)</ENT>
                        <ENT>
                            Addressed by providing Financial Assistance Representations and Certifications in 
                            <E T="03">www.SAM.gov.</E>
                        </ENT>
                    </ROW>
                    <ROW>
                        <PRTPAGE P="592"/>
                        <ENT I="01">Assurance Regarding Felony Conviction or Tax Delinquent Status for Corporate Applicants</ENT>
                        <ENT>7 CFR 1734.25(i)</ENT>
                        <ENT>
                            Addressed by providing Financial Assistance Representations and Certifications in 
                            <E T="03">sam.gov/content/home.</E>
                        </ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Environmental Review Requirements</ENT>
                        <ENT>7 CFR 1734.25(j)</ENT>
                        <ENT>Guidance provided in the Application Guide.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Evidence of Legal Authority and Existence</ENT>
                        <ENT>7 CFR 1734.25(k)</ENT>
                        <ENT>Guidance provided in the Application Guide.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Federal Debt Certification</ENT>
                        <ENT>7 CFR 1734.25(l)</ENT>
                        <ENT>SF-424, Application for Federal Assistance.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Consultation with USDA State Director</ENT>
                        <ENT>7 CFR 1734.25(m)</ENT>
                        <ENT>Documentation.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Supplemental Information</ENT>
                        <ENT>7 CFR 1734.25(n)</ENT>
                        <ENT>Documentation.</ENT>
                    </ROW>
                </GPOTABLE>
                <P>
                    3. 
                    <E T="03">System for Award Management and Unique Entity Identifier.</E>
                </P>
                <P>
                    (a) At the time of application, each applicant must have an active registration in the SAM before submitting its application in accordance with 2 CFR part 25. To register in the SAM, entities will be required to obtain a UEI. Instructions for obtaining the UEI are available at 
                    <E T="03">sam.gov/content/entity-registration.</E>
                </P>
                <P>(b) Applicants must maintain an active SAM registration, with current, accurate and complete information, at all times during which it has an active federal award or an application under consideration by a federal awarding agency.</P>
                <P>(c) Applicants must ensure they complete the Financial Assistance General Certifications and Representations in the SAM.</P>
                <P>(d) Applicants must provide a valid UEI in its application, unless determined exempt under 2 CFR 25.110.</P>
                <P>(e) The Agency will not make an award until the applicant has complied with all the SAM requirements including providing the UEI. If an applicant has not fully complied with the requirements by the time the Agency is ready to make an award, the Agency may determine that the applicant is not qualified to receive a federal award and use that determination as a basis for making a federal award to another applicant.</P>
                <P>
                    4. 
                    <E T="03">Submission Dates and Times.</E>
                </P>
                <P>
                    (a) 
                    <E T="03">Application Technical Assistance.</E>
                     Prior to official submission of applications, applicants may request technical assistance or other application guidance from the Agency, if such requests are made prior to February 21, 2024. Agency contact information can be found in the 
                    <E T="02">FOR FURTHER INFORMATION CONTACT</E>
                     section of this notice.
                </P>
                <P>
                    (b) 
                    <E T="03">Application Deadline Date.</E>
                     Applications must be submitted through 
                    <E T="03">www.grants.gov</E>
                     and received no later than March 6, 2024 to be eligible for funding under this grant opportunity.
                </P>
                <P>
                    (c) 
                    <E T="03">Applications Received After Deadline Date.</E>
                     Late or incomplete applications will not be eligible for funding under this grant opportunity.
                </P>
                <P>The Agency will not solicit or consider new scoring information that is submitted after the application deadline. The Agency reserves the right to contact applicants to seek clarification on materials contained in the submitted application.</P>
                <P>
                    5. 
                    <E T="03">Intergovernmental Review.</E>
                     Executive Order (E.O.) 12372, Intergovernmental Review of Federal Programs, applies to this program. This E.O. requires that federal agencies provide opportunities for consultation on proposed assistance with State and local governments. Applicants should use the USDA Office of the Chief Financial Officer (OCFO), Intergovernmental Review website (
                    <E T="03">www.usda.gov/ocfo/federal-financial-assistance-policy/intergovernmental-review</E>
                    ) instructions to contact the State Points of Contact (SPOC). Any comments obtained through the SPOC must be provided as part of the application process. Applications from federally recognized Indian Tribes are not subject to this requirement.
                </P>
                <P>
                    6. 
                    <E T="03">Funding Restrictions.</E>
                </P>
                <P>(a) Ineligible grant purposes are outlined in 7 CFR 1734.23. Applicants should exclude ineligible items and ineligible matching contributions from the budget. If an ineligible item or matching contribution is included in the budget, the item will be removed and may result in an application being deemed ineligible. See the Application Guide for more details on funding restrictions, matching contributions, a recommended budget format, and detailed budget compilation instructions.</P>
                <P>(1) If an application includes both eligible and ineligible grant purposes on a single line of the application budget, and the cost of the ineligible item can be determined, the ineligible item will be removed from the approved budget. However, the entire line item will be deemed ineligible if the cost of the ineligible item cannot be determined.</P>
                <P>(b) Hub sites located in non-rural areas are not eligible for grant assistance unless they are necessary to provide DLT services to rural residents at end user sites. See 7 CFR 1734.2(h).</P>
                <P>(c) For the purposes of this NOFO, the cost of video conferencing platform licenses is considered an eligible cost if:</P>
                <P>(1) The video conferencing platform is an integral component in a project delivering distance learning or telemedicine services to an end user through the use of eligible equipment;</P>
                <P>(2) The cost does not exceed ten percent of the grant amount;</P>
                <P>(3) The application demonstrates that the predominant use (50 percent or more) of the video conferencing platform will be for the distance learning or telemedicine project;</P>
                <P>(4) The license is new and not a renewal of an existing license; and</P>
                <P>(5) The number of licenses requested does not exceed the number of end-user devices requested in the application.</P>
                <P>The duration of funding for video conferencing platform licenses is limited to three years from the date funds are made available.</P>
                <P>(d) If an application includes multiple costs on a single line of the application budget, one of which is subject to a cost limitation, as outlined in 7 CFR 1734.21, the items that are not subject to the cost limitation will be deducted when calculating the cost limitation percentage. However, the entire line item will be applied against the cost limitation if each cost cannot be determined.</P>
                <P>(e) Grantees may not subaward any part of a DLT grant without the express, prior written approval of RUS.</P>
                <P>
                    7. 
                    <E T="03">Other Submission Requirements.</E>
                </P>
                <P>(a) Applications will not be accepted via paper, fax or electronic mail.</P>
                <P>
                    (b) Submit the electronic application through 
                    <E T="03">www.grants.gov.</E>
                     Do not send a paper copy to RUS. To increase the range of applicants that will be successful in FY 2025, only ONE application per applicant is eligible for approval.
                </P>
                <P>
                    (c) For duplicate applications submitted through 
                    <E T="03">www.grants.gov,</E>
                     the Agency will base its evaluation on the last copy of the application submitted. If an applicant submits multiple applications for different projects, then the Agency will only consider the application with the highest score.
                </P>
                <P>
                    (d) 
                    <E T="03">Grants.gov</E>
                     requires some credentialing and online authentication 
                    <PRTPAGE P="593"/>
                    procedures. These procedures may take several business days to complete. Therefore, the applicant should complete the registration, credentialing, and authorization procedures at 
                    <E T="03">www.grants.gov</E>
                     before submitting an application. Instructions on all required passwords, credentialing, and software are available on 
                    <E T="03">www.grants.gov.</E>
                     If system errors or technical difficulties occur, use the customer support resources available at the 
                    <E T="03">Grants.gov</E>
                     website.
                </P>
                <HD SOURCE="HD2">E. Application Review Information</HD>
                <P>
                    1. 
                    <E T="03">Criteria.</E>
                     Grant applications are scored competitively and are subject to the criteria provided in 7 CFR 1734.26 and this notice, and further guidance on these criteria is provided in the Application Guide.
                </P>
                <P>
                    (a) 
                    <E T="03">Rurality Category (up to 40 points).</E>
                     The rurality score is based on two factors:
                </P>
                <P>(1) The population size of each community where an end-user site is located, and</P>
                <P>(2) Whether an end-user site lies within an urbanized area adjacent to a city or town having a population more than 50,000 inhabitants.</P>
                <P>For non-fixed site projects and projects which contain non-fixed components, the rurality score will be based on the hub site.</P>
                <P>
                    Applicants should use 2020 census data from the census website (
                    <E T="03">data.census.gov/cedsci/</E>
                    ) as their source for population data. To determine if a site lies in any incorporated or unincorporated city, village, or borough having a population in excess of 20,000 inhabitants or an urbanized area contiguous to a city or town having a population in excess of 50,000 inhabitants, applicants should check the site address, using the DLT mapping tool available at 
                    <E T="03">www.rd.usda.gov/programs-services/telecommunications-programs/distance-learning-telemedicine-grants.</E>
                     The Application Guide provides additional guidance for this category, including a worksheet to assist applicants in the calculation of their rurality scores.
                </P>
                <P>
                    (b) 
                    <E T="03">Economic Need Category (up to 30 points).</E>
                     Economic need is based on the county poverty percentage of the end-user sites proposed in the application. The percentages must be determined by utilizing the United States Census Small Area Income and Poverty Estimates (SAIPE) program. Applicants can use the spreadsheet posted to the DLT program website to look up current SAIPE county-level data. End-user sites located in geographic areas, for which no SAIPE data exist, will be determined to have an average SAIPE poverty percentage of 30 percent. Such geographic areas may include territories of the United States or other locations eligible for funding through the DLT program.
                </P>
                <P>
                    (c) 
                    <E T="03">Service Needs and Benefits Category (up to 30 points).</E>
                     This category measures the extent to which the proposed project meets the need for distance learning or telemedicine services in Rural Areas, the benefits derived from the proposed services, and the local community involvement in the planning, implementation, and financial assistance of the project. RUS will also consider the extent to which the applicant's documentation identifies the local economic, education, or health care challenges. The applicant must explain how the project proposes to address these issues and why the applicant cannot complete the project without a grant.
                </P>
                <P>
                    (d) 
                    <E T="03">Special Consideration (up to 10 points).</E>
                     Special consideration points will be awarded for projects with at least one end-user site in the following areas. Applicants may only receive special consideration points in one area (up to 10 points):
                </P>
                <P>
                    (1) 
                    <E T="03">Creating More and Better Markets (10 points).</E>
                     Projects that enable and improve distance learning and telemedicine services in Rural Areas to the most distressed tier of the Distressed Communities index are eligible for 10 points. The most distressed tier of the index are those communities with a score over 80. A list of Distressed Communities can be found at: 
                    <E T="03">www.rd.usda.gov/media/file/download/fy24distressedcommunityindexlist-.xlsx.</E>
                </P>
                <P>
                    (2) 
                    <E T="03">Projects advancing Racial Justice, Place-Based Equity, and Opportunity. (10 points).</E>
                     Projects that meet one of the criteria below will receive 10 points.
                </P>
                <P>
                    (i) Projects proposing to serve rural communities with a Social Vulnerability Index (SVI) with a score of 0.75 or higher are eligible. For the purposes of this NOFO, Puerto Rico, Guam, America Samoa, the Northern Mariana Islands, Palau, the Marshall Islands, the Federated States of Micronesia, the U.S. Virgin Islands, and Hawaiian Census Tribal areas are considered Socially Vulnerable Communities. A GIS layer identifying the Socially Vulnerable Communities can be found using the DLT mapping tool available at: 
                    <E T="03">www.rd.usda.gov/programs-services/telecommunications-programs/distance-learning-telemedicine-grants.</E>
                </P>
                <P>
                    (ii) Projects that enable and improve distance learning and telemedicine services on Tribal Lands. Tribal Lands will be identified in GIS layers included in the DLT mapping tool available at: 
                    <E T="03">www.rd.usda.gov/programs-services/telecommunications-programs/distance-learning-telemedicine-grants.</E>
                </P>
                <P>(iii) Projects proposed by a federally recognized Tribe, including Tribal instrumentalities and entities that are wholly owned by Tribes.</P>
                <P>
                    2. 
                    <E T="03">Review and Selection Process.</E>
                     Grant applications are ranked by the final score. RUS selects applications based on those rankings, subject to the availability of funds. As noted in Section D.7. of this announcement, RUS will approve no more than one application per applicant. If an applicant submits more than one application for different projects, then the Agency will only consider the application with the highest score. If an applicant submits more than one application for the same project, then the Agency will only consider the latest submission. In addition, the Agency has the authority to limit the number of applications selected in any one state or for any one project during a fiscal year. See 7 CFR 1734.27 for a description of the grant application selection process. An application receiving fewer points can be selected over a higher scoring application if there are insufficient funds available to cover the costs of the higher scoring application, as stated in 7 CFR 1734.27(b)(3).
                </P>
                <P>The Agency evaluates grant applications in accordance with 7 CFR 1734.27(c). The Agency reserves the right to offer the applicant less than the grant funding requested.</P>
                <HD SOURCE="HD2">F. Federal Award Administration Information</HD>
                <P>
                    1. 
                    <E T="03">Federal Award Notices.</E>
                     The Agency notifies applicants whose projects are selected for awards by mailing or emailing a copy of an award letter. The receipt of an award letter does not authorize the applicant to commence performance under the award. After sending the award letter, the Agency will send an agreement that contains all the terms and conditions for the grant. An applicant must execute and return the grant agreement, accompanied by any additional items required by the agreement, within the number of days specified in the selection notice letter. The standard agreement is available on the 
                    <E T="03">www.rd.usda.gov/programs-services/telecommunications-programs/distance-learning-telemedicine-grants.</E>
                </P>
                <P>
                    2. 
                    <E T="03">Administrative and National Policy Requirements.</E>
                     The items listed in 7 CFR part 1734, this announcement, the Application Guide, and program resources implement the appropriate administrative and national policy requirements, which include but are not limited to:
                </P>
                <P>
                    (a) Executing a DLT Grant Agreement.
                    <PRTPAGE P="594"/>
                </P>
                <P>(b) Using Form SF 270, Request for Advance or Reimbursement, to request reimbursements (along with the submission of receipts for expenditures and any other documentation to support the request for reimbursement).</P>
                <P>(c) Submitting an annual Project Performance Activity Report, no later than January 31st of the year following the year in which all or any portion of the grant is first advanced and continuing in subsequent years until completion of the project.</P>
                <P>(d) Ensuring that records are maintained to document all activities and expenditures utilizing DLT grant funds and matching funds (receipts for expenditures are to be included in this documentation).</P>
                <P>(e) Providing a final project performance report, no later than one hundred twenty (120) days after the expiration date, termination of the grant, the project completion, or the final disbursement of the grant by the grantee, whichever event occurs last.</P>
                <P>(f) Complying with policies, guidance, and requirements as described in the following applicable Code of Federal Regulations, and any successor regulations:</P>
                <P>(1) 2 CFR parts 200 and 400 (Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards).</P>
                <P>(2) 2 CFR parts 417 and 180 (Government-wide Nonprocurement Debarment and Suspension).</P>
                <P>
                    (g) Complying with Executive Order 13166, Improving Access to Services for Persons with Limited English Proficiency. For information on limited English proficiency and agency-specific guidance, go to 
                    <E T="03">www.LEP.gov.</E>
                </P>
                <P>(h) Accountability and Compliance with Civil Rights Laws. The regulation found at 7 CFR part 1901, subpart E contains policies and procedures for implementing the regulations of the Department of Agriculture issued pursuant to Title VI of the Civil Rights Act of 1964, Title VIII of the Civil Rights Act of 1968, Title IX, Section 504 of the Rehabilitation Act of 1973, Executive Order 13166, Executive Order 11246, and the Equal Credit Opportunity Act of 1974, as they relate to RD. Nothing herein shall be interpreted to prohibit preference to American Indians on Indian Reservations.</P>
                <P>The policies contained in this subpart apply to recipients. As recipients of federal financial assistance, awardees are required to comply with the applicable federal, tribal, state, and local laws. Title VI of the Civil Rights Act of 1964 and Section 504 of the Rehabilitation Act prohibits discrimination by recipients of federal financial assistance. Recipients are required to adhere to specific outreach activities. These outreach activities include contacting community organizations and leaders that include minority leaders; advertising in local newspapers and other media throughout the entire service area; and including the nondiscrimination slogan, “This is an Equal Opportunity Program. Discrimination is prohibited by Federal Law,” in methods that may include, but not be limited to, advertisements, electronic media, public broadcasts, and printed materials, such as brochures and pamphlets.</P>
                <P>
                    By completing the Financial Assistance Representations and Certifications on 
                    <E T="03">SAM.gov,</E>
                     recipients affirm that they will operate the program free from discrimination. The recipient will maintain the race and ethnic data on the board members and beneficiaries of the program. The recipient will provide alternative forms of communication to persons with limited English proficiency. The Agency will conduct Civil Rights Compliance Reviews on recipients to identify the collection of racial and ethnic data on program beneficiaries. In addition, the compliance review will ensure that equal access to the program benefits and activities are provided for persons with disabilities and language barriers.
                </P>
                <P>
                    (i) Build America, Buy America Act (BABAA). With respect to any construction under the DLT project, Awardees that are Non-Federal Entities, defined pursuant to 2 CFR 200.1 as any State, local government, Indian tribe, Institution of Higher Education, or nonprofit organization, shall be governed by the requirements of Section 70914 of the Build America, Buy America Act (BABAA) within the Infrastructure Investment and Jobs Act (Pub. L. 117-58), and its implementing regulations at 2 CFR part 184. Any requests for waiver of these requirements must be submitted pursuant to USDA's guidance available online at 
                    <E T="03">www.usda.gov/ocfo/federal-financial-assistance-policy/USDABuyAmericaWaiver.</E>
                </P>
                <P>
                    (j) Geospatial Data. Awardee, and any and all contracts entered into by the Awardee with respect to the Award, shall ensure that geospatial data required to be collected and provided to the agency, conforms with the requirements of USDA Department Regulation DR-3465-001 and the Geospatial Metadata Standards set forth in DM 3465-001, which can be obtained online at 
                    <E T="03">usda.gov/directives/dr-3465-001</E>
                     and 
                    <E T="03">usda.gov/directives/dm-3465-001.</E>
                </P>
                <P>
                    3. 
                    <E T="03">Reporting.</E>
                </P>
                <P>
                    (a) 
                    <E T="03">Performance Reporting.</E>
                     All recipients of DLT financial assistance must provide annual performance activity reports to RUS until the project is complete and the funds are expended. A final performance report is also required; the final report may serve as the last annual report. The final report must include an evaluation of the success of the project in meeting the DLT program objectives. See 7 CFR 1734.7 for additional information on these reporting requirements.
                </P>
                <P>
                    (b) 
                    <E T="03">Annual Audit.</E>
                     All recipients of DLT financial assistance must provide an annual audit as follows:
                </P>
                <P>(1) Non-Federal Entities, which include recipients that are states, local governments, Indian tribes, institutions of higher education, or nonprofit organizations, shall provide RUS with an audit pursuant to 2 CFR part 200, subpart F (Audit Requirements). The recipient must follow subsection 2 CFR 200.502 in determining federal awards expended. All RUS loans impose an ongoing compliance requirement for the purpose of determining federal awards expended during a fiscal year. In addition, the recipient must include the value of new federal loans made along with any grant expenditures from all federal sources during the recipient's fiscal year. Therefore, the audit submission requirement for this program begins in the recipient's fiscal year that the loan is made and thereafter, based on the balance of federal loan(s) at the beginning of the audit period. All required audits must be submitted within the earlier of: (i) 30 calendar days after receipt of the auditor's report; or (ii) nine months after the end of the recipient's audit period.</P>
                <P>(2) For all other entities, recipients shall provide RUS with an audit within 120 days after the as of audit date in accordance with 7 CFR part 1773. With respect to grant funds, the audit is required until all grant funds have been expended or rescinded. While an audit is required, recipients must also submit the reports on internal control; compliance with provisions of laws, regulations, contracts and grant agreements; and instances of fraud.</P>
                <P>
                    (c) 
                    <E T="03">Recipient and Sub-recipient Reporting.</E>
                     The applicant must have the necessary processes and systems in place to comply with the reporting requirements for first-tier sub-awards, if approved by the agency, and executive compensation under the Federal Funding Accountability and Transparency Act of 2006 in the event the applicant receives funding unless such applicant is exempt from such reporting requirements pursuant to 2 CFR 170.105. The reporting 
                    <PRTPAGE P="595"/>
                    requirements under the Transparency Act pursuant to 2 CFR part 170 are as follows:
                </P>
                <P>
                    (1) If approved by the agency, first Tier Sub-Awards of $30,000 or more (unless they are exempt under 2 CFR part 170) must be reported by the recipient to 
                    <E T="03">www.fsrs.gov</E>
                     no later than the end of the month following the month the sub-award was made. Please note that currently underway is a consolidation of eight federal procurement systems, including the Federal Sub-award Reporting System (FSRS), into one system, SAM. As a result, the FSRS will soon be consolidated into and accessed through 
                    <E T="03">www.sam.gov.</E>
                </P>
                <P>
                    (2) The total compensation of the recipient's executives (the five most highly compensated executives) must be reported by the recipient (if the recipient meets the criteria under 2 CFR part 170) to 
                    <E T="03">www.sam.gov</E>
                     by the end of the month following the month in which the award was made.
                </P>
                <P>(3) If sub-awards are approved by the agency, the total compensation of the sub-recipient's executives (the five most highly compensated executives) must be reported by the sub-recipient (if the sub-recipient meets the criteria under 2 CFR part 170) to the recipient by the end of the month following the month in which the sub-award was made.</P>
                <P>
                    (d) 
                    <E T="03">Record Keeping and Accounting.</E>
                     The agreement will contain provisions related to record keeping and accounting requirements.
                </P>
                <HD SOURCE="HD2">G. Federal Awarding Agency Contacts</HD>
                <P>
                    For general questions about this announcement, please contact the point of contact provided in the 
                    <E T="02">FOR FURTHER INFORMATION CONTACT</E>
                     section of this notice.
                </P>
                <HD SOURCE="HD2">H. Other Information</HD>
                <P>
                    (1) 
                    <E T="03">Paperwork Reduction Act.</E>
                     In accordance with the Paperwork Reduction Act of 1995 (44 U.S.C. chapter 35), the information collection requirements associated with the programs, as covered in this notice, have been approved by the Office of Management and Budget (OMB) under OMB Control Number 0572-0096.
                </P>
                <P>
                    (2) 
                    <E T="03">National Environmental Policy Act.</E>
                     All recipients under this notice are subject to the requirements of 7 CFR part 1970.
                </P>
                <P>
                    (3) 
                    <E T="03">Federal Funding Accountability and Transparency Act.</E>
                     All applicants, in accordance with 2 CFR part 25, must be registered in the SAM and have a UEI number as stated in Section D.3 of this notice. All recipients of Federal financial assistance are required to report information about first-tier sub-awards and executive total compensation in accordance with 2 CFR part 170.
                </P>
                <P>
                    (4) 
                    <E T="03">Civil Rights Act.</E>
                     All grants made under this notice are subject to Title VI of the Civil Rights Act of 1964 as required by the USDA 7 CFR part 15, subpart A and Section 504 of the Rehabilitation Act of 1973, Title VIII of the Civil Rights Act of 1968, Title IX, Executive Order 13166 (Limited English Proficiency), Executive Order 11246, and the Equal Credit Opportunity Act of 1974.
                </P>
                <P>
                    (5) 
                    <E T="03">Equal Opportunity for Religious Organizations.</E>
                </P>
                <P>
                    (a) Faith-based organizations may apply for this award on the same basis as any other organization, as set forth at, and subject to the protections and requirements of, this part and any applicable constitutional and statutory requirements, including 42 U.S.C. 2000bb 
                    <E T="03">et seq.</E>
                     USDA will not, in the selection of recipients, discriminate for or against an organization on the basis of the organization's religious character, motives, or affiliation, or lack thereof, or on the basis of conduct that would not be considered grounds to favor or disfavor a similarly situated secular organization.
                </P>
                <P>(b) A faith-based organization that participates in this program will retain its independence from the Government and may continue to carry out its mission consistent with religious freedom and conscience protections in Federal law. Religious accommodations may also be sought under many of these religious freedom and conscience protection laws.</P>
                <P>(c) A faith-based organization may not use direct Federal financial assistance from USDA to support or engage in any explicitly religious activities except when consistent with the Establishment Clause of the First Amendment and any other applicable requirements. An organization receiving Federal financial assistance also may not, in providing services funded by USDA, or in their outreach activities related to such services, discriminate against a program beneficiary or prospective program beneficiary on the basis of religion, a religious belief, a refusal to hold a religious belief, or a refusal to attend or participate in a religious practice.</P>
                <P>
                    (6) 
                    <E T="03">Nondiscrimination Statement.</E>
                     In accordance with Federal civil rights laws and USDA civil rights regulations and policies, the USDA, its Mission Areas, agencies, staff offices, employees, and institutions participating in or administering USDA programs are prohibited from discriminating based on race, color, national origin, religion, sex, gender identity (including gender expression), sexual orientation, disability, age, marital status, family/parental status, income derived from a public assistance program, political beliefs, or reprisal or retaliation for prior civil rights activity, in any program or activity conducted or funded by USDA (not all bases apply to all programs). Remedies and complaint filing deadlines vary by program or incident.
                </P>
                <P>
                    Program information may be made available in languages other than English. Persons with disabilities who require alternative means of communication to obtain program information (
                    <E T="03">e.g.,</E>
                     Braille, large print, audiotape, American Sign Language) should contact the responsible Mission Area, agency, or staff office; or the 711 Relay Service.
                </P>
                <P>
                    To file a program discrimination complaint, a complainant should complete a Form AD-3027, 
                    <E T="03">USDA Program Discrimination Complaint Form,</E>
                     which can be obtained online at 
                    <E T="03">www.usda.gov/sites/default/files/documents/ad-3027.pdf,</E>
                     or from any USDA office, by calling (866) 632-9992, or by writing a letter addressed to USDA. The letter must contain the complainant's name, address, telephone number, and a written description of the alleged discriminatory action in sufficient detail to inform the Assistant Secretary for Civil Rights (ASCR) about the nature and date of an alleged civil rights violation. The completed AD-3027 form or letter must be submitted to USDA by:
                </P>
                <P>
                    (1) 
                    <E T="03">Mail:</E>
                     U.S. Department of Agriculture, Office of the Assistant Secretary for Civil Rights, 1400 Independence Avenue SW, Washington, DC 20250-9410; or
                </P>
                <P>
                    (2) 
                    <E T="03">Fax:</E>
                     (833) 256-1665 or (202) 690-7442; or
                </P>
                <P>
                    (3) 
                    <E T="03">Email: program.intake@usda.gov.</E>
                </P>
                <P>USDA is an equal opportunity provider, employer, and lender.</P>
                <SIG>
                    <NAME>Andrew Berke,</NAME>
                    <TITLE>Administrator, Rural Utilities Service, USDA Rural Development.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-30465 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 3410-15-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF AGRICULTURE</AGENCY>
                <SUBAGY>Rural Utilities Service</SUBAGY>
                <DEPDOC>[DOCKET #: RUS-24-ELECTRIC-0032]</DEPDOC>
                <SUBJECT>Notice of Extension of the Application Deadline for Section 313A Guarantees for Bonds and Notes Issued for Utility Infrastructure Purposes for Fiscal Year 2025</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Rural Utilities Service, USDA.</P>
                </AGY>
                <ACT>
                    <PRTPAGE P="596"/>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Rural Utilities Service (RUS or the Agency), a Rural Development agency of the United States Department of Agriculture (USDA), is announcing the extension and reopening of the Guarantees for Bonds and Notes Issued for Utility Infrastructure Purposes Program (the 313A Program) for Fiscal Year (FY) 2025 application window through January 31, 2025.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>The application period for the funding opportunity published October 25, 2024 at 89 FR 85148 is reopened. Completed applications must be electronically received by RUS no later than 5 p.m. eastern time (ET) on January 31, 2025. Applicants intending to submit applications must have their applications received by the closing deadline.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        Completed applications must be submitted electronically to Amy McWilliams, Branch Chief, Policy and Outreach Branch, Office of Customer Service and Technical Assistance, Electric Program, RUS at 
                        <E T="03">amy.mcwilliams@usda.gov.</E>
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Amy McWilliams, Branch Chief, Policy and Outreach Branch, Office of Customer Service and Technical Assistance, Electric Program, Rural Utilities Service, USDA, 1400 Independence Avenue SW, Mail Stop 1560, Room 4121-South, Washington, DC 20250-1560, by email at 
                        <E T="03">amy.mcwilliams@usda.gov,</E>
                         or call (202) 205-8663.
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">Background</HD>
                <P>
                    The 313A Program guarantees loans to selected applicants and the proceeds of those loans are to be used for the purpose of making utility infrastructure loans and for refinancing bonds or notes issued for such purposes to a borrower that has at any time received, or is eligible to receive, a loan under the Rural Electrification Act of 1936, as amended. The FY 2025 funding opportunity for the 313A Program was announced by a Notice of Funding Opportunity (NOFO) published in the 
                    <E T="04">Federal Register</E>
                     on October 25, 2024, at 89 FR 85148. Applicants should refer to this NOFO for all details on this funding opportunity.
                </P>
                <P>With this notice, RUS is reopening the December 24, 2024, application deadline and extending it until 5 p.m. ET on January 31, 2025.</P>
                <SIG>
                    <NAME>Andrew Berke,</NAME>
                    <TITLE>Administrator, Rural Utilities Service, USDA Rural Development.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31668 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 3410-15-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">CIVIL RIGHTS COLD CASE RECORDS REVIEW BOARD</AGENCY>
                <DEPDOC>[Agency Docket Number: CRCCRRB-2025-0006-N]</DEPDOC>
                <SUBJECT>Notice of Formal Determination on Records Release</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Civil Rights Cold Case Records Review Board.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        The Civil Rights Cold Case Records Review Board received 195 pages of records from the National Archives and Records Administration (NARA) related to seven civil rights cold case incidents to which the Review Board assigned the unique identifiers 2024-003-018, 2024-003-023, 2024-003-035, 2024-003-038, 2024-003-051, 2024-003-067, and 2024-003-068. NARA did not propose any postponements of disclosure. On December 20, 2024, the Review Board determined that the records should be publicly disclosed in the Civil Rights Cold Case Records Collection. By issuing this notice, the Review Board complies with section 7(c)(4) of the Civil Rights Cold Case Records Collection Act of 2018 that requires the Review Board to publish in the 
                        <E T="04">Federal Register</E>
                         its determinations on the disclosure or postponement of records in the Collection no more than 14 days after the date of its decision.
                    </P>
                </SUM>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Stephannie Oriabure, Chief of Staff, Civil Rights Cold Case Records Review Board, 1800 F Street NW, Washington, DC 20405, (771) 221-0014, 
                        <E T="03">info@coldcaserecords.gov</E>
                        .
                    </P>
                    <P>
                        <E T="03">Authority:</E>
                         Pub. L. 115-426, 132 Stat. 5489 (44 U.S.C. 2107).
                    </P>
                    <SIG>
                        <DATED>Dated: December 30, 2024.</DATED>
                        <NAME>Stephannie Oriabure,</NAME>
                        <TITLE>Chief of Staff.</TITLE>
                    </SIG>
                </FURINF>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31618 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6820-SY-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF COMMERCE</AGENCY>
                <SUBAGY>Foreign-Trade Zones Board</SUBAGY>
                <DEPDOC>[B-62-2024]</DEPDOC>
                <SUBJECT>Foreign-Trade Zone (FTZ) 49, Notification of Proposed Production Activity; Sanofi US Services Inc.; (Pharmaceutical Products); Ridgefield, New Jersey</SUBJECT>
                <P>Sanofi US Services Inc. submitted a notification of proposed production activity to the FTZ Board (the Board) for its facilities in Ridgefield, New Jersey within FTZ 49. The notification conforming to the requirements of the Board's regulations (15 CFR 400.22) was received on December 18, 2024.</P>
                <P>
                    Pursuant to 15 CFR 400.14(b), FTZ production activity would be limited to the specific foreign-status material(s)/component(s) and specific finished product(s) described in the submitted notification (summarized below) and subsequently authorized by the Board. The benefits that may stem from conducting production activity under FTZ procedures are explained in the background section of the Board's website—accessible via 
                    <E T="03">www.trade.gov/ftz.</E>
                </P>
                <P>The proposed finished product is Beyfortus® (Nirsevimab)—dosage form vaccine (duty-free).</P>
                <P>The proposed foreign-status materials/components include Beyfortus® (Nirsevimab monoclonal antibody active pharmaceutical ingredient)—unmixed and mixed drug substance (duty-free).</P>
                <P>
                    Public comment is invited from interested parties. Submissions shall be addressed to the Board's Executive Secretary and sent to: 
                    <E T="03">ftz@trade.gov.</E>
                     The closing period for their receipt is February 18, 2025.
                </P>
                <P>A copy of the notification will be available for public inspection in the “Online FTZ Information System” section of the Board's website.</P>
                <P>
                    For further information, contact Diane Finver at 
                    <E T="03">Diane.Finver@trade.gov.</E>
                </P>
                <SIG>
                    <DATED>Dated: December 31, 2024.</DATED>
                    <NAME>Elizabeth Whiteman,</NAME>
                    <TITLE>Executive Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31702 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 3510-DS-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <PRTPAGE P="597"/>
                <AGENCY TYPE="S">DEPARTMENT OF COMMERCE</AGENCY>
                <SUBAGY>Bureau of Industry and Security</SUBAGY>
                <SUBJECT>In the Matter of Joel Alejandro Garza-Corona, Inmate Number: 26658-510, FCI Ashland, P.O. Box 6001, Ashland, KY 41105; Order Denying Export Privileges</SUBJECT>
                <P>On February 16, 2023, in the U.S. District Court for the Southern District of Texas, Joel Alejandro Garza-Corona (“Garza-Corona”) was convicted of violating 18 U.S.C. 554(a). Specifically, Garza-Corona was convicted of smuggling 2,399 rounds of assorted ammunition from the United States to Mexico without the required authorization from the U.S. Department of Commerce. As a result of his conviction, the court sentenced him to 40 months in prison.</P>
                <P>
                    Pursuant to section 1760(e) of the Export Control Reform Act (“ECRA”),
                    <SU>1</SU>
                    <FTREF/>
                     the export privileges of any person who has been convicted of certain offenses, including, but not limited to 18 U.S.C. 554(a), may be denied for a period of up to ten (10) years from the date of his/her conviction. 50 U.S.C. 4819(e). In addition, any Bureau of Industry and Security (“BIS”) licenses or other authorizations issued under ECRA, in which the person had an interest at the time of the conviction, may be revoked. 
                    <E T="03">Id.</E>
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         ECRA was enacted on August 13, 2018, as part of the John S. McCain National Defense Authorization Act for Fiscal Year 2019, and as amended is codified at 50 U.S.C. 4801-4852.
                    </P>
                </FTNT>
                <P>
                    BIS received notice of Garza-Corona's conviction for violating 18 U.S.C. 554(a). As provided in section 766.25 of the Export Administration Regulations (“EAR” or the “Regulations”), BIS provided notice and opportunity for Garza-Corona to make a written submission to BIS. 15 CFR 766.25.
                    <SU>2</SU>
                    <FTREF/>
                     BIS has not received a written submission from Garza-Corona.
                </P>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         The Regulations are currently codified in the Code of Federal Regulations at 15 CFR parts 730 through 774 (2024).
                    </P>
                </FTNT>
                <P>
                    Based upon my review of the record and consultations with BIS's Office of Exporter Services, including its Director, and the facts available to BIS, I have decided to deny Garza-Corona's export privileges under the Regulations for a period of eight years from the date of Garza-Corona's conviction. The Office of Exporter Services has also decided to revoke any BIS-issued licenses in which Garza-Corona had an interest at the time of his conviction.
                    <SU>3</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         The Director, Office of Export Enforcement, is the authorizing official for issuance of denial orders pursuant to amendments to the Regulations (85 FR 73411, November 18, 2020).
                    </P>
                </FTNT>
                <P>
                    Accordingly, it is hereby 
                    <E T="03">ordered</E>
                    :
                </P>
                <P>
                    <E T="03">First,</E>
                     from the date of this Order until February16, 2031, Joel Alejandro Garza-Corona, with a last known address of: Inmate Number: 26658-510, FCI Ashland, P.O. Box 6001, Ashland, KY 41105 and when acting for or on his behalf, his successors, assigns, employees, agents or representatives (“the Denied Person”), may not directly or indirectly participate in any way in any transaction involving any commodity, software or technology (hereinafter collectively referred to as “item”) exported or to be exported from the United States that is subject to the Regulations, including, but not limited to:
                </P>
                <P>A. Applying for, obtaining, or using any license, license exception, or export control document;</P>
                <P>B. Carrying on negotiations concerning, or ordering, buying, receiving, using, selling, delivering, storing, disposing of, forwarding, transporting, financing, or otherwise servicing in any way, any transaction involving any item exported or to be exported from the United States that is subject to the Regulations, or engaging in any other activity subject to the Regulations; or</P>
                <P>C. Benefitting in any way from any transaction involving any item exported or to be exported from the United States that is subject to the Regulations, or from any other activity subject to the Regulations.</P>
                <P>
                    <E T="03">Second,</E>
                     no person may, directly or indirectly, do any of the following:
                </P>
                <P>A. Export, reexport, or transfer (in-country) to or on behalf of the Denied Person any item subject to the Regulations;</P>
                <P>B. Take any action that facilitates the acquisition or attempted acquisition by the Denied Person of the ownership, possession, or control of any item subject to the Regulations that has been or will be exported from the United States, including financing or other support activities related to a transaction whereby the Denied Person acquires or attempts to acquire such ownership, possession or control;</P>
                <P>C. Take any action to acquire from or to facilitate the acquisition or attempted acquisition from the Denied Person of any item subject to the Regulations that has been exported from the United States;</P>
                <P>D. Obtain from the Denied Person in the United States any item subject to the Regulations with knowledge or reason to know that the item will be, or is intended to be, exported from the United States; or</P>
                <P>E. Engage in any transaction to service any item subject to the Regulations that has been or will be exported from the United States and which is owned, possessed or controlled by the Denied Person, or service any item, of whatever origin, that is owned, possessed or controlled by the Denied Person if such service involves the use of any item subject to the Regulations that has been or will be exported from the United States. For purposes of this paragraph, servicing means installation, maintenance, repair, modification or testing.</P>
                <P>
                    <E T="03">Third,</E>
                     pursuant to section 1760(e) of ECRA and sections 766.23 and 766.25 of the Regulations, any other person, firm, corporation, or business organization related to Garza-Corona by ownership, control, position of responsibility, affiliation, or other connection in the conduct of trade or business may also be made subject to the provisions of this Order in order to prevent evasion of this Order.
                </P>
                <P>
                    <E T="03">Fourth,</E>
                     in accordance with part 756 of the Regulations, Garza-Corona may file an appeal of this Order with the Under Secretary of Commerce for Industry and Security. The appeal must be filed within 45 days from the date of this Order and must comply with the provisions of part 756 of the Regulations.
                </P>
                <P>
                    <E T="03">Fifth,</E>
                     a copy of this Order shall be delivered to Garza-Corona and shall be published in the 
                    <E T="04">Federal Register</E>
                    .
                </P>
                <P>
                    <E T="03">Sixth,</E>
                     this Order is effective immediately and shall remain in effect until February 16, 2031.
                </P>
                <SIG>
                    <DATED>Issued this 31st day of December, 2024.</DATED>
                    <NAME>Dan Clutch,</NAME>
                    <TITLE>Acting Director, Office of Export Enforcement. </TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31669 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 3510-DT-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF COMMERCE</AGENCY>
                <SUBAGY>Bureau of Industry and Security</SUBAGY>
                <SUBJECT>In the Matter of Eric Nana Kofi Ampong-Coker, Inmate Number: 16722-510, FCI Cumberland, P.O. Box 1000, Cumberland, MD 21501; Order Denying Export Privileges</SUBJECT>
                <P>
                    On September 6, 2023, in the U.S. District Court for the District of Maryland, Eric Nana Kofi Ampong-Coker (“Ampong-Coker”) was convicted of violating 50 U.S.C. 4819. Specifically, Ampong-Coker was convicted of knowingly and willfully attempting to export one (1) SCCY Industries LL.C., Model CPX-2 9mm handgun; one (1) Mossberg 9mm handgun; one (1) Smith &amp; Wesson 9mm handgun; one (1) FIS Product, Model XD-9 9mm handgun; and one (1) Sarsilmaz (Sar Arms), 9mm 
                    <PRTPAGE P="598"/>
                    handgun, which weapons were designated under ECCN 0A501 from the United States to Ghana without the required licenses. As a result of his conviction, the court sentenced Among-Coker to 30 months in prison and two years of supervised release.
                </P>
                <P>
                    Pursuant to section 1760(e) of the Export Control Reform Act (“ECRA”),
                    <SU>1</SU>
                    <FTREF/>
                     the export privileges of any person who has been convicted of certain offenses, including, but not limited to, 50 U.S.C. 4819, may be denied for a period of up to ten (10) years from the date of his/her conviction. 50 U.S.C. 4819(e). In addition, any Bureau of Industry and Security (“BIS”) licenses or other authorizations issued under ECRA, in which the person had an interest at the time of the conviction, may be revoked. 
                    <E T="03">Id.</E>
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         ECRA was enacted on August 13, 2018, as part of the John S. McCain National Defense Authorization Act for Fiscal Year 2019, and as amended is codified at 50 U.S.C. 4801-4852.
                    </P>
                </FTNT>
                <P>
                    BIS received notice of Ampong-Coker's conviction for violating 50 U.S.C. 4819. As provided in section 766.25 of the Export Administration Regulations (“EAR” or the “Regulations”), BIS provided notice and opportunity for Ampong-Coker to make a written submission to BIS. 15 CFR 766.25.
                    <SU>2</SU>
                    <FTREF/>
                     BIS received and considered a written submission from Ampong-Coker.
                </P>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         The Regulations are currently codified in the Code of Federal Regulations at 15 CFR parts 730 through 774 (2024).
                    </P>
                </FTNT>
                <P>
                    Based upon my review of the record and consultations with BIS's Office of Exporter Services, including its Director, and the facts available to BIS, I have decided to deny Ampong-Coker's export privileges under the Regulations for a period of 10 years from the date of Ampong-Coker's conviction. The Office of Exporter Services has also decided to revoke any BIS-issued licenses in which Ampong-Coker had an interest at the time of his conviction.
                    <SU>3</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         The Director, Office of Export Enforcement, is the authorizing official for issuance of denial orders pursuant to amendments to the Regulations (85 FR 73411, November 18, 2020).
                    </P>
                </FTNT>
                <P>
                    Accordingly, it is hereby 
                    <E T="03">ordered:</E>
                </P>
                <P>
                    <E T="03">First,</E>
                     from the date of this Order until September 6, 2033, Eric Nana Kofi Ampong-Coker, with last known addresses of: Inmate Number: 16722-510, FCI Cumberland, P.O. Box 1000, Cumberland, MD 21501, and when acting for or on his behalf, his successors, assigns, employees, agents or representatives (“the Denied Person”), may not directly or indirectly participate in any way in any transaction involving any commodity, software or technology (hereinafter collectively referred to as “item”) exported or to be exported from the United States that is subject to the Regulations, including, but not limited to:
                </P>
                <P>A. Applying for, obtaining, or using any license, license exception, or export control document;</P>
                <P>B. Carrying on negotiations concerning, or ordering, buying, receiving, using, selling, delivering, storing, disposing of, forwarding, transporting, financing, or otherwise servicing in any way, any transaction involving any item exported or to be exported from the United States that is subject to the Regulations, or engaging in any other activity subject to the Regulations; or</P>
                <P>C. Benefitting in any way from any transaction involving any item exported or to be exported from the United States that is subject to the Regulations, or from any other activity subject to the Regulations.</P>
                <P>
                    <E T="03">Second,</E>
                     no person may, directly or indirectly, do any of the following:
                </P>
                <P>A. Export, reexport, or transfer (in-country) to or on behalf of the Denied Person any item subject to the Regulations;</P>
                <P>B. Take any action that facilitates the acquisition or attempted acquisition by the Denied Person of the ownership, possession, or control of any item subject to the Regulations that has been or will be exported from the United States, including financing or other support activities related to a transaction whereby the Denied Person acquires or attempts to acquire such ownership, possession or control;</P>
                <P>C. Take any action to acquire from or to facilitate the acquisition or attempted acquisition from the Denied Person of any item subject to the Regulations that has been exported from the United States;</P>
                <P>D. Obtain from the Denied Person in the United States any item subject to the Regulations with knowledge or reason to know that the item will be, or is intended to be, exported from the United States; or</P>
                <P>E. Engage in any transaction to service any item subject to the Regulations that has been or will be exported from the United States and which is owned, possessed or controlled by the Denied Person, or service any item, of whatever origin, that is owned, possessed or controlled by the Denied Person if such service involves the use of any item subject to the Regulations that has been or will be exported from the United States. For purposes of this paragraph, servicing means installation, maintenance, repair, modification or testing.</P>
                <P>
                    <E T="03">Third,</E>
                     pursuant to section 1760(e) of ECRA and sections 766.23 and 766.25 of the Regulations, any other person, firm, corporation, or business organization related to Ampong-Coker by ownership, control, position of responsibility, affiliation, or other connection in the conduct of trade or business may also be made subject to the provisions of this Order in order to prevent evasion of this Order.
                </P>
                <P>
                    <E T="03">Fourth,</E>
                     in accordance with part 756 of the Regulations, Ampong-Coker may file an appeal of this Order with the Under Secretary of Commerce for Industry and Security. The appeal must be filed within 45 days from the date of this Order and must comply with the provisions of part 756 of the Regulations.
                </P>
                <P>
                    <E T="03">Fifth,</E>
                     a copy of this Order shall be delivered to Ampong-Coker and shall be published in the 
                    <E T="04">Federal Register</E>
                    .
                </P>
                <P>
                    <E T="03">Sixth,</E>
                     this Order is effective immediately and shall remain in effect until September 6, 2033.
                </P>
                <SIG>
                    <DATED>Issued this 31st day of December, 2024.</DATED>
                    <NAME>Dan Clutch,</NAME>
                    <TITLE>Acting Director, Office of Export Enforcement.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31667 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 3510-DT-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <PRTPAGE P="599"/>
                <AGENCY TYPE="S">DEPARTMENT OF COMMERCE</AGENCY>
                <SUBAGY>Bureau of Industry and Security</SUBAGY>
                <SUBJECT>In the Matter of Derby Clerfe, 9 Garden Terrace, Pittsburgh, PA 15521; Order Denying Export Privileges</SUBJECT>
                <P>On May 30, 2024, in the U.S. District Court for the Western District of Pennsylvania, Derby Clerfe (“Clerfe”) was convicted of violating 18 U.S.C. 371. Specifically, Clerfe pled guilty to conspiring with others to export from the United States to Haiti nine handguns without the required licenses and without filing Electronic Export Information in the Automated Export System. As a result of his conviction, the Court sentenced Clerfe to one year of probation.</P>
                <P>
                    Pursuant to section 1760(e) of the Export Control Reform Act (“ECRA”),
                    <SU>1</SU>
                    <FTREF/>
                     the export privileges of any person who has been convicted of certain offenses, including, but not limited to, 18 U.S.C. 371, may be denied for a period of up to ten (10) years from the date of his/her conviction. 50 U.S.C. 4819(e). In addition, any Bureau of Industry and Security (“BIS”) licenses or other authorizations issued under ECRA, in which the person had an interest at the time of the conviction, may be revoked. 
                    <E T="03">Id.</E>
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         ECRA was enacted on August 13, 2018, as part of the John S. McCain National Defense Authorization Act for Fiscal Year 2019, and as amended is codified at 50 U.S.C. 4801-4852.
                    </P>
                </FTNT>
                <P>
                    BIS received notice of Clerfe's conviction for violating 18 U.S.C. 371. As provided in section 766.25 of the Export Administration Regulations (“EAR” or the “Regulations”), BIS provided notice and opportunity for Clerfe to make a written submission to BIS. 15 CFR 766.25.
                    <SU>2</SU>
                    <FTREF/>
                     BIS has not received a written submission from Clerfe.
                </P>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         The Regulations are currently codified in the Code of Federal Regulations at 15 CFR parts 730 through 774 (2024).
                    </P>
                </FTNT>
                <P>
                    Based upon my review of the record and consultations with BIS's Office of Exporter Services, including its Director, and the facts available to BIS, I have decided to deny Clerfe's export privileges under the Regulations for a period of two years from the date of Clerfe's conviction. The Office of Exporter Services has also decided to revoke any BIS-issued licenses in which Clerfe had an interest at the time of his conviction.
                    <SU>3</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         The Director, Office of Export Enforcement, is the authorizing official for issuance of denial orders pursuant to amendments to the Regulations (85 FR 73411, November 18, 2020).
                    </P>
                </FTNT>
                <P>
                    Accordingly, it is hereby 
                    <E T="03">ordered:</E>
                </P>
                <P>
                    <E T="03">First,</E>
                     from the date of this Order until May 30, 2026, Derby Clerfe, with a last known address of 9 Garden Terrace, Pittsburgh, PA 15521, and when acting for or on his behalf, his successors, assigns, employees, agents or representatives (” the Denied Person”), may not directly or indirectly participate in any way in any transaction involving any commodity, software or technology (hereinafter collectively referred to as “item”) exported or to be exported from the United States that is subject to the Regulations, including, but not limited to:
                </P>
                <P>A. Applying for, obtaining, or using any license, license exception, or export control document;</P>
                <P>B. Carrying on negotiations concerning, or ordering, buying, receiving, using, selling, delivering, storing, disposing of, forwarding, transporting, financing, or otherwise servicing in any way, any transaction involving any item exported or to be exported from the United States that is subject to the Regulations, or engaging in any other activity subject to the Regulations; or</P>
                <P>C. Benefitting in any way from any transaction involving any item exported or to be exported from the United States that is subject to the Regulations, or from any other activity subject to the Regulations.</P>
                <P>
                    <E T="03">Second,</E>
                     no person may, directly or indirectly, do any of the following:
                </P>
                <P>A. Export, reexport, or transfer (in-country) to or on behalf of the Denied Person any item subject to the Regulations;</P>
                <P>B. Take any action that facilitates the acquisition or attempted acquisition by the Denied Person of the ownership, possession, or control of any item subject to the Regulations that has been or will be exported from the United States, including financing or other support activities related to a transaction whereby the Denied Person acquires or attempts to acquire such ownership, possession or control;</P>
                <P>C. Take any action to acquire from or to facilitate the acquisition or attempted acquisition from the Denied Person of any item subject to the Regulations that has been exported from the United States;</P>
                <P>D. Obtain from the Denied Person in the United States any item subject to the Regulations with knowledge or reason to know that the item will be, or is intended to be, exported from the United States; or</P>
                <P>E. Engage in any transaction to service any item subject to the Regulations that has been or will be exported from the United States and which is owned, possessed or controlled by the Denied Person, or service any item, of whatever origin, that is owned, possessed or controlled by the Denied Person if such service involves the use of any item subject to the Regulations that has been or will be exported from the United States. For purposes of this paragraph, servicing means installation, maintenance, repair, modification or testing.</P>
                <P>
                    <E T="03">Third,</E>
                     pursuant to section 1760(e) of ECRA and sections 766.23 and 766.25 of the Regulations, any other person, firm, corporation, or business organization related to Clerfe by ownership, control, position of responsibility, affiliation, or other connection in the conduct of trade or business may also be made subject to the provisions of this Order in order to prevent evasion of this Order.
                </P>
                <P>
                    <E T="03">Fourth,</E>
                     in accordance with part 756 of the Regulations, Clerfe may file an appeal of this Order with the Under Secretary of Commerce for Industry and Security. The appeal must be filed within 45 days from the date of this Order and must comply with the provisions of part 756 of the Regulations.
                </P>
                <P>
                    <E T="03">Fifth,</E>
                     a copy of this Order shall be delivered to Clerfe and shall be published in the 
                    <E T="04">Federal Register</E>
                    .
                </P>
                <P>
                    <E T="03">Sixth,</E>
                     this Order is effective immediately and shall remain in effect until May 30, 2026.
                </P>
                <SIG>
                    <P>Issued this 31st day of December, 2024.</P>
                    <NAME>Dan Clutch,</NAME>
                    <TITLE>Acting Director, Office of Export Enforcement.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31656 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 3510-DT-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF COMMERCE</AGENCY>
                <SUBAGY>Bureau of Industry and Security</SUBAGY>
                <SUBJECT>In the Matter of Daniel Ray Lane, Inmate Number: 60019-177, FCI Texarkana, Federal Correctional Institution, P.O. Box 7000, Texarkana, TX 75505; Order Denying Export Privileges</SUBJECT>
                <PRTPAGE P="600"/>
                <P>
                    On June 11, 2024, in the U.S. District Court for the Eastern District of Pennsylvania, Daniel Ray Lane (“Lane”), was convicted of violating 18 U.S.C. 371 and the International Emergency Economic Powers Act (50 U.S.C 1701, 
                    <E T="03">et seq.</E>
                    ) (“IEEPA”). Specifically, Lane was convicted of conspiring to sell sanctioned Iranian petroleum/crude oil to a refinery in China. As a result of his conviction, the Court sentenced Lane to 45 months of imprisonment and three years of supervised release.
                </P>
                <P>
                    Pursuant to section 1760(e) of the Export Control Reform Act (“ECRA”),
                    <SU>1</SU>
                    <FTREF/>
                     the export privileges of any person who has been convicted of certain offenses, including, but not limited to, 18 U.S.C. 371 and IEEPA, may be denied for a period of up to ten (10) years from the date of his/her conviction. 50 U.S.C. 4819(e) (Prior Convictions). In addition, any Bureau of Industry and Security (BIS) licenses or other authorizations issued under ECRA, in which the person had an interest at the time of the conviction, may be revoked. 
                    <E T="03">Id.</E>
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         ECRA was enacted on August 13, 2018, as part of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 and, as amended, is codified at 50 U.S.C. 4801-4852.
                    </P>
                </FTNT>
                <P>
                    BIS received notice of Lane's conviction for violating 18 U.S.C. 371 and IEEPA, and has provided notice and opportunity for Lane to make a written submission to BIS, as provided in section 766.25 of the Export Administration Regulations (“EAR” or the “Regulations”). 15 CFR 766.25.
                    <SU>2</SU>
                    <FTREF/>
                     BIS has not received a written submission from Lane.
                </P>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         The Regulations are currently codified in the Code of Federal Regulations at 15 CFR parts 730 through 774 (2024).
                    </P>
                </FTNT>
                <P>
                    Based upon my review of the record and consultations with BIS's Office of Exporter Services, including its Director, and the facts available to BIS, I have decided to deny Lane's export privileges under the Regulations for a period of 10 years from the date of Lane's conviction. The Office of Exporter Services has also decided to revoke any BIS-issued licenses in which Lane had an interest at the time of his conviction.
                    <SU>3</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         The Director, Office of Export Enforcement, is the authorizing official for issuance of denial orders, pursuant to amendments to the Regulations (85 FR 73411, November 18, 2020).
                    </P>
                </FTNT>
                <P>
                    Accordingly, it is hereby 
                    <E T="03">ordered</E>
                    :
                </P>
                <P>
                    <E T="03">First</E>
                    , from the date of this Order until June 11, 2034, Daniel Ray Lane, with a last known address of Inmate Number: 60019-117, FCI Texarkana, Federal Correctional Institution, P.O. Box 7000, Texarkana, TX 75505, and when acting for or on his behalf, his successors, assigns, employees, agents or representatives (“the Denied Person”), may not directly or indirectly participate in any way in any transaction involving any commodity, software or technology (hereinafter collectively referred to as “item”) exported or to be exported from the United States that is subject to the Regulations, including, but not limited to:
                </P>
                <P>A. Applying for, obtaining, or using any license, license exception, or export control document;</P>
                <P>B. Carrying on negotiations concerning, or ordering, buying, receiving, using, selling, delivering, storing, disposing of, forwarding, transporting, financing, or otherwise servicing in any way, any transaction involving any item exported or to be exported from the United States that is subject to the Regulations, or engaging in any other activity subject to the Regulations; or</P>
                <P>C. Benefitting in any way from any transaction involving any item exported or to be exported from the United States that is subject to the Regulations, or from any other activity subject to the Regulations.</P>
                <P>
                    <E T="03">Second</E>
                    , no person may, directly or indirectly, do any of the following:
                </P>
                <P>A. Export, reexport, or transfer (in-country) to or on behalf of the Denied Person any item subject to the Regulations;</P>
                <P>B. Take any action that facilitates the acquisition or attempted acquisition by the Denied Person of the ownership, possession, or control of any item subject to the Regulations that has been or will be exported from the United States, including financing or other support activities related to a transaction whereby the Denied Person acquires or attempts to acquire such ownership, possession or control;</P>
                <P>C. Take any action to acquire from or to facilitate the acquisition or attempted acquisition from the Denied Person of any item subject to the Regulations that has been exported from the United States;</P>
                <P>D. Obtain from the Denied Person in the United States any item subject to the Regulations with knowledge or reason to know that the item will be, or is intended to be, exported from the United States; or</P>
                <P>E. Engage in any transaction to service any item subject to the Regulations that has been or will be exported from the United States and which is owned, possessed or controlled by the Denied Person, or service any item, of whatever origin, that is owned, possessed or controlled by the Denied Person if such service involves the use of any item subject to the Regulations that has been or will be exported from the United States. For purposes of this paragraph, servicing means installation, maintenance, repair, modification or testing.</P>
                <P>
                    <E T="03">Third</E>
                    , pursuant to section 1760(e) of the Export Control Reform Act (50 U.S.C. 4819(e)) and sections 766.23 and 766.25 of the Regulations, any other person, firm, corporation, or business organization related to Lane by ownership, control, position of responsibility, affiliation, or other connection in the conduct of trade or business may also be made subject to the provisions of this Order in order to prevent evasion of this Order.
                </P>
                <P>
                    <E T="03">Fourth</E>
                    , in accordance with part 756 of the Regulations, Lane may file an appeal of this Order with the Under Secretary of Commerce for Industry and Security. The appeal must be filed within 45 days from the date of this Order and must comply with the provisions of part 756 of the Regulations.
                </P>
                <P>
                    <E T="03">Fifth</E>
                    , a copy of this Order shall be delivered to Lane and shall be published in the 
                    <E T="04">Federal Register</E>
                    .
                </P>
                <P>
                    <E T="03">Sixth</E>
                    , this Order is effective immediately and shall remain in effect until June 11, 2034.
                </P>
                <SIG>
                    <DATED>Issued this 31st day of December, 2024.</DATED>
                    <NAME>Dan Clutch,</NAME>
                    <TITLE>Acting Director, Office of Export Enforcement.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31654 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 3510-DT-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <PRTPAGE P="601"/>
                <AGENCY TYPE="S">DEPARTMENT OF COMMERCE</AGENCY>
                <SUBAGY>International Trade Administration</SUBAGY>
                <DEPDOC>[A-557-830]</DEPDOC>
                <SUBJECT>Crystalline Silicon Photovoltaic Cells, Whether or Not Assembled Into Modules, From Malaysia: Amended Preliminary Determination of Less-Than-Fair-Value Investigation</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Enforcement and Compliance, International Trade Administration, Department of Commerce.</P>
                </AGY>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The U.S. Department of Commerce (Commerce) is amending its preliminary affirmative determination in the less-than-fair-value (LTFV) investigation of crystalline silicon photovoltaic cells, whether or not assembled into modules (solar cells), from Malaysia to correct two significant ministerial errors. The period of investigation (POI) is April 1, 2023, through March 31, 2024.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Applicable January 6, 2025.</P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Patrick Barton or Elizabeth Talbot Russ, AD/CVD Operations, Office III, Enforcement and Compliance, International Trade Administration, U.S. Department of Commerce, 1401 Constitution Avenue NW, Washington, DC 20230; telephone: (202) 482-0012 or (202) 482-5516 respectively.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">Background</HD>
                <P>
                    On December 4, 2024, Commerce published in the 
                    <E T="04">Federal Register</E>
                     its preliminary affirmative determination in the LTFV investigation of solar cells from Malaysia.
                    <SU>1</SU>
                    <FTREF/>
                     On December 9, 2024, a mandatory respondent, Jinko Solar Technology Sdn. Bhd. (Jinko Solar), timely alleged that Commerce made a significant ministerial error in calculating its estimated weighted-average dumping margin.
                    <SU>2</SU>
                    <FTREF/>
                     On December 9, 2024, the American Alliance for Solar Manufacturing Trade Committee (the petitioner) timely alleged that Commerce made ministerial errors in calculating Jinko Solar's estimated weighted-average dumping margin.
                    <SU>3</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         
                        <E T="03">See Crystalline Silicon Photovoltaic Cells, Whether or Not Assembled Into Modules, From Malaysia: Affirmative Preliminary Determination of Sales at Less Than Fair Value, Postponement of Final Determination, and Extension of Provisional Measures,</E>
                         89 FR 96207 (December 4, 2024) (
                        <E T="03">Preliminary Determination</E>
                        ), and accompanying Preliminary Decision Memorandum.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         
                        <E T="03">See</E>
                         Jinko Solar's Letter, “Jinko Request to Correct Ministerial Error,” dated December 9, 2024.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         
                        <E T="03">See</E>
                         Petitioner's Letter, “Ministerial Error Allegation,” dated December 9, 2024.
                    </P>
                </FTNT>
                <HD SOURCE="HD1">Scope of the Investigation</HD>
                <P>
                    The products covered by this investigation are solar cells from Malaysia. For a complete description of the scope of this investigation, 
                    <E T="03">see</E>
                     the 
                    <E T="03">Preliminary Determination.</E>
                </P>
                <HD SOURCE="HD1">Legal Framework</HD>
                <P>
                    A ministerial error is defined as including errors “in addition, subtraction, or other arithmetic function, clerical error resulting from inaccurate copying, duplication, or the like, and any other similar type of unintentional error which {Commerce} considers ministerial.” 
                    <SU>4</SU>
                    <FTREF/>
                     A ministerial error is considered to be “significant” if its correction, either singly or in combination with other errors, would result in: (1) a change of at least five absolute percentage points in, but not less than 25 percent of, the weighted-average dumping margin calculated in the preliminary determination; or (2) a difference between a weighted-average dumping margin of zero (or 
                    <E T="03">de minimis</E>
                    ) and a weighted-average dumping margin of greater than 
                    <E T="03">de minimis</E>
                     or vice versa.
                    <SU>5</SU>
                    <FTREF/>
                     Pursuant to 19 CFR 351.224(e), Commerce “will analyze any comments received and, if appropriate, correct any significant ministerial error by amending the preliminary determination.”
                </P>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         
                        <E T="03">See</E>
                         section 735(e) of the Tariff Act of 1930, as amended (the Act); 
                        <E T="03">see also</E>
                         19 CFR 351.224(f).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         
                        <E T="03">See</E>
                         19 CFR 351.224(g).
                    </P>
                </FTNT>
                <HD SOURCE="HD1">Analysis of Significant Ministerial Errors</HD>
                <P>
                    In the 
                    <E T="03">Preliminary Determination,</E>
                     Commerce made significant ministerial errors within the meaning of section 735(e) of the Act and 19 CFR 351.224(f) and (g) in calculating the weighted-average dumping margin for Jinko Solar. Specifically, Commerce failed to convert certain Malaysian ringgit (MYR)-denominated expense fields to U.S. dollars (USD) for the purposes of its dumping margin calculations.
                    <SU>6</SU>
                    <FTREF/>
                     Moreover, Commerce did not correctly implement its decision to consolidate certain of Jinko Solar's U.S. customer codes (CUSCODU) in the dumping margin calculations.
                    <SU>7</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         
                        <E T="03">See</E>
                         Petitioner's Letter “Ministerial Error Allegation,” dated December 9, 2024.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>7</SU>
                         See Jinko Solar's Letter “Jinko Request to Correct Ministerial Error,” dated December 9, 2024.
                    </P>
                </FTNT>
                <P>
                    We find that these errors meet the definition of “ministerial errors,” and that the corrections of the errors for Jinko Solar results in a change that is at least five absolute percentage points in, and not less than 25 percent of, the margin calculated for Jinko Solar in the 
                    <E T="03">Preliminary Determination.</E>
                     As such, they constitute significant errors within the meaning of 19 CFR 351.224(g). Accordingly, pursuant to 19 CFR 351.224(e), Commerce is amending the 
                    <E T="03">Preliminary Determination</E>
                     to correct these significant ministerial errors by revising the rates for Jinko Solar and all other producers and/or exporters.
                    <SU>8</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>8</SU>
                         
                        <E T="03">See</E>
                         Memorandum, “Analysis of Ministerial Error Allegations,” dated concurrently with, and hereby adopted by, this notice (Ministerial Error Memorandum).
                    </P>
                </FTNT>
                <P>
                    For a complete discussion of the alleged ministerial errors, 
                    <E T="03">see</E>
                     the Ministerial Error Memorandum.
                </P>
                <HD SOURCE="HD1">Amended Preliminary Determination</HD>
                <P>As a result of correcting the significant ministerial errors for Jinko Solar, Commerce determines the following estimated weighted-average dumping margins exist:</P>
                <PRTPAGE P="602"/>
                <GPOTABLE COLS="3" OPTS="L2,i1" CDEF="s100,16,18">
                    <BOXHD>
                        <CHED H="1">Exporter/producer</CHED>
                        <CHED H="1">
                            Weighted-average
                            <LI>dumping margin</LI>
                            <LI>(percent)</LI>
                        </CHED>
                        <CHED H="1">
                            Cash deposit rate
                            <LI>(adjusted for</LI>
                            <LI>subsidy offsets(s))</LI>
                            <LI>(percent)</LI>
                        </CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">Hanwha Q Cells Malaysia Sdn. Bhd</ENT>
                        <ENT>0.00</ENT>
                        <ENT>0.00</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Jinko Solar Technology Sdn. Bhd</ENT>
                        <ENT>9.90</ENT>
                        <ENT>
                            <SU>9</SU>
                             6.43
                        </ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Baojia New Energy Manufacturing Sdn</ENT>
                        <ENT>* 81.24</ENT>
                        <ENT>* 81.24</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">CRC Solar Cell Joint Stock Company</ENT>
                        <ENT>* 81.24</ENT>
                        <ENT>* 81.24</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Lynter Enterprise</ENT>
                        <ENT>* 81.24</ENT>
                        <ENT>* 81.24</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Mega PP Sdn. Bhd</ENT>
                        <ENT>* 81.24</ENT>
                        <ENT>* 81.24</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">All Others</ENT>
                        <ENT>9.90</ENT>
                        <ENT>6.43</ENT>
                    </ROW>
                    <TNOTE>* Rates based on facts available with adverse inferences.</TNOTE>
                </GPOTABLE>
                <HD SOURCE="HD1">Disclosure</HD>
                <P>
                    We intend to disclose the calculations performed for this amended preliminary determination to parties within five days after public announcement or, if there is no public announcement, within five days of the date of publication of this notice, in accordance with 19 CFR 351.224.
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>9</SU>
                         
                        <E T="03">See</E>
                         Memorandum, “Countervailing Duty Investigation of Crystalline Silicon Photovoltaic Cells, Whether or Not Assembled into Modules, from Malaysia: Amended Preliminary Determination Calculations for Jinko Solar Technology Sdn. Bhd.,” dated October 31, 2024.
                    </P>
                </FTNT>
                <HD SOURCE="HD1">Amended Cash Deposits and Suspension of Liquidation</HD>
                <P>
                    The collection of cash deposits and suspension of liquidation will be revised according to the rates calculated in this amended preliminary determination, in accordance with section 733(d) of the Act. Because the amended rate for Jinko Solar and all other producers and/or exporters result in decreased cash deposit rates, the amended rates will be effective retroactively to December 4, 2024, the date of publication of the 
                    <E T="03">Preliminary Determination.</E>
                     We will also instruct U.S. Customs and Border Protection to issue instructions for requesting a refund of the difference between the amount of cash deposits paid as a result of the application of the 
                    <E T="03">Preliminary Determination</E>
                     rates and the amount due as a result of the amended preliminary determination rates.
                </P>
                <HD SOURCE="HD1">Notification of U.S. International Trade Commission</HD>
                <P>In accordance with section 733(f) of the Act, we intend to notify the U.S. International Trade Commission of our amended preliminary determination.</P>
                <HD SOURCE="HD1">Notification to Interested Parties</HD>
                <P>This notice is issued and published pursuant to sections 733(d) and 777(i) of the Act, and 19 CFR 351.224(e).</P>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>Abdelali Elouaradia,</NAME>
                    <TITLE>Deputy Assistant Secretary for Enforcement and Compliance.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31764 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 3510-DS-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF COMMERCE</AGENCY>
                <SUBAGY>International Trade Administration</SUBAGY>
                <DEPDOC>[A-570-922, A-583-842, C-570-923]</DEPDOC>
                <SUBJECT>Raw Flexible Magnets From the People's Republic of China and Taiwan: Continuation of Antidumping Duty Orders and Countervailing Duty Order</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Enforcement and Compliance, International Trade Administration, Department of Commerce.</P>
                </AGY>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>As a result of the determinations by the U.S. Department of Commerce (Commerce) and the U.S. International Trade Commission (ITC) that revocation of the antidumping duty (AD) orders on raw flexible magnets from the People's Republic of China (China) and Taiwan, and revocation of the countervailing duty (CVD) order on raw flexible magnets from China would likely lead to the continuation or recurrence of dumping, countervailable subsidies, and material injury to an industry in the United States, Commerce is publishing a notice of continuation of the AD orders and the CVD order.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Applicable December 27, 2024.</P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Garry Kasparov, AD/CVD Operations, Office I, Enforcement and Compliance, International Trade Administration, U.S. Department of Commerce, 1401 Constitution Avenue NW, Washington, DC 20230; telephone: (202) 482-1397.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">Background</HD>
                <P>
                    On September 17, 2008, Commerce published in the 
                    <E T="04">Federal Register</E>
                     the AD orders on raw flexible magnets from China and Taiwan and the CVD order on raw flexible magnets China.
                    <SU>1</SU>
                    <FTREF/>
                     On June 3, 2024, the ITC instituted,
                    <SU>2</SU>
                    <FTREF/>
                     and Commerce initiated,
                    <SU>3</SU>
                    <FTREF/>
                     the third sunset review of the 
                    <E T="03">Orders,</E>
                     pursuant to section 751(c) of the Tariff Act of 1930, as amended (the Act). As a result of its reviews, Commerce determined that revocation of the 
                    <E T="03">Orders</E>
                     would likely lead to the continuation or recurrence of dumping and countervailable subsidies, and therefore, notified the ITC of the magnitude of the margins of dumping and subsidy rates likely to prevail should the 
                    <E T="03">Orders</E>
                     be revoked.
                    <SU>4</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         
                        <E T="03">See Antidumping Duty Order: Raw Flexible Magnets from the People's Republic of China,</E>
                         73 FR 53847 (September 17, 2008); 
                        <E T="03">Antidumping Duty Order: Raw Flexible Magnets from Taiwan,</E>
                         73 FR 53848 (September 17, 2008); 
                        <E T="03">and Raw Flexible Magnets from the People's Republic of China: Countervailing Duty Order,</E>
                         73 FR 53849 (September 17, 2008) (collectively, 
                        <E T="03">Orders</E>
                        ).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         
                        <E T="03">See Raw Flexible Magnets from China and Taiwan; Institution of Five-Year Reviews,</E>
                         89 FR 47607 (June 3, 2024).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         
                        <E T="03">See Initiation of Five-Year (Sunset) Reviews,</E>
                         89 FR 47525 (June 3, 2024).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         
                        <E T="03">See Raw Flexible Magnets from the People's Republic of China and Taiwan: Final Results of the Expedited Third Sunset Review of the Antidumping Duty Orders,</E>
                         89 FR 79242 (September 27, 2024), and accompanying Issues and Decision Memorandum (IDM); 
                        <E T="03">see also Raw Flexible Magnets from the People's Republic of China: Final Results of the Expedited Third Sunset Review of the Countervailing Duty Order,</E>
                         89 FR 82565 (October 11, 2024), and accompanying IDM.
                    </P>
                </FTNT>
                <P>
                    On December 27, 2024, the ITC published its determination, pursuant to sections 751(c) and 752(a) of the Act, that revocation of the 
                    <E T="03">Orders</E>
                     would likely lead to continuation or recurrence of material injury to an industry in the United States within a reasonably foreseeable time.
                    <SU>5</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         
                        <E T="03">See Raw Flexible Magnets from China and Taiwan; Determination,</E>
                         89 FR 105627 (December 27, 2024) (
                        <E T="03">ITC Final Determination</E>
                        ); 
                        <E T="03">see also Raw Flexible Magnets from China and Taiwan:</E>
                         Investigation Nos. 701-TA-452 and 731-TA-1129-1130 (Third Review).
                    </P>
                </FTNT>
                <HD SOURCE="HD1">Scope of the Orders</HD>
                <P>
                    The products covered by the 
                    <E T="03">Orders</E>
                     are certain flexible magnets regardless of 
                    <PRTPAGE P="603"/>
                    shape,
                    <SU>6</SU>
                    <FTREF/>
                     color, or packaging.
                    <SU>7</SU>
                    <FTREF/>
                     Subject flexible magnets are bonded magnets composed (not necessarily exclusively) of (i) any one or combination of various flexible binders (such as polymers or co-polymers, or rubber) and (ii) a magnetic element, which may consist of a ferrite permanent magnet material (commonly, strontium or barium ferrite, or a combination of the two), a metal alloy (such as NdFeB or Alnico), any combination of the foregoing with each other or any other material, or any other material capable of being permanently magnetized. Subject flexible magnets may be in either magnetized or unmagnetized (including demagnetized) condition, and may or may not be fully or partially laminated or fully or partially bonded with paper, plastic, or other material, of any composition and/or color. Subject flexible magnets may be uncoated or may be coated with an adhesive or any other coating or combination of coatings.
                </P>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         The term “shape” includes, but is not limited to profiles, which are flexible magnets with a non-rectangular cross-section.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>7</SU>
                         Packaging includes retail or specialty packaging such as digital printer cartridges.
                    </P>
                </FTNT>
                <P>
                    Specifically excluded from the scope of these 
                    <E T="03">Orders</E>
                     are printed flexible magnets, defined as flexible magnets (including individual magnets) that are laminated or bonded with paper, plastic, or other material if such paper, plastic, or other material bears printed text and/or images, including but not limited to business cards, calendars, poetry, sports event schedules, business promotions, decorative motifs, and the like. This exclusion does not apply to such printed flexible magnets if the printing concerned consists of only the following: a trade mark or trade name; country of origin; border, stripes, or lines; any printing that is removed in the course of cutting and/or printing magnets for retail sale or other disposition from the flexible magnet; manufacturing or use instructions (
                    <E T="03">e.g.,</E>
                     “print this side up,” “this side up,” “laminate here”); printing on adhesive backing (that is, material to be removed in order to expose adhesive for use such as application of laminate) or on any other covering that is removed from the flexible magnet prior or subsequent to final printing and before use; non-permanent printing (that is, printing in a medium that facilitates easy removal, permitting the flexible magnet to be re-printed); printing on the back (magnetic) side; or any combination of the above.
                </P>
                <P>
                    All products meeting the physical description of subject merchandise that are not specifically excluded are within the scope of these 
                    <E T="03">Orders.</E>
                     The products subject to the 
                    <E T="03">Orders</E>
                     are currently classifiable principally under subheadings 8505.19.10 and 8505.19.20 of the Harmonized Tariff Schedule of the United States (HTSUS). The HTSUS subheadings are provided only for convenience and customs purposes; the written description of the scope of the 
                    <E T="03">Orders</E>
                     is dispositive.
                </P>
                <HD SOURCE="HD1">Continuation of the Orders</HD>
                <P>
                    As a result of the determinations by Commerce and the ITC that revocation of the 
                    <E T="03">Orders</E>
                     would likely lead to continuation or recurrence of dumping, countervailable subsidies, and material injury to an industry in the United States, pursuant to section 751(d)(2) of the Act, Commerce hereby orders the continuation of the 
                    <E T="03">Orders.</E>
                     U.S. Customs and Border Protection will continue to collect AD and CVD cash deposits at the rates in effect at the time of entry for all imports of subject merchandise.
                </P>
                <P>
                    The effective date of the continuation of the 
                    <E T="03">Orders</E>
                     is December 27, 2024.
                    <SU>8</SU>
                    <FTREF/>
                     Pursuant to section 751(c)(2) of the Act and 19 CFR 351.218(c)(2), Commerce intends to initiate the next five-year reviews of the 
                    <E T="03">Orders</E>
                     not later than 30 days prior to fifth anniversary of the date of the last determination by the ITC.
                </P>
                <FTNT>
                    <P>
                        <SU>8</SU>
                         
                        <E T="03">See ITC Final Determination.</E>
                    </P>
                </FTNT>
                <HD SOURCE="HD1">Administrative Protective Order (APO)</HD>
                <P>This notice also serves as a final reminder to parties subject to an APO of their responsibility concerning the return or destruction of proprietary information disclosed under APO in accordance with 19 CFR 351.305(a)(3), which continues to govern business proprietary information in this segment of the proceeding. Timely written notification of the return or destruction of APO materials, or conversion to judicial protective order, is hereby requested. Failure to comply with the regulations and terms of an APO is a violation which is subject to sanction.</P>
                <HD SOURCE="HD1">Notification to Interested Parties</HD>
                <P>These five-year (sunset) reviews and this notice are in accordance with sections 751(c) and 751(d)(2) of the Act and published in accordance with section 777(i) of the Act, and 19 CFR 351.218(f)(4).</P>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>Abdelali Elouaradia,</NAME>
                    <TITLE>Deputy Assistant Secretary for Enforcement and Compliance.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31724 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 3510-DS-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF COMMERCE</AGENCY>
                <SUBAGY>National Oceanic and Atmospheric Administration</SUBAGY>
                <DEPDOC>[RTID 0648-XE545]</DEPDOC>
                <SUBJECT>Taking and Importing Marine Mammals; Taking Marine Mammals Incidental to Geophysical Surveys Related to Oil and Gas Activities in the Gulf of Mexico</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>National Marine Fisheries Service (NMFS), National Oceanic and Atmospheric Administration (NOAA), Commerce.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of issuance of letter of authorization.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>In accordance with the Marine Mammal Protection Act (MMPA), as amended, its implementing regulations, and NMFS' MMPA Regulations for Taking Marine Mammals Incidental to Geophysical Surveys Related to Oil and Gas Activities in the Gulf of Mexico, notification is hereby given that NMFS has issued a Letter of Authorization (LOA) to LLOG Exploration Offshore, L.L.C. (LLOG) for the take of marine mammals incidental to geophysical survey activity in the Gulf of Mexico (GOM).</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>The LOA is effective from December 31, 2024 through April 19, 2026.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        The LOA, LOA request, and supporting documentation are available online at: 
                        <E T="03">https://www.fisheries.noaa.gov/action/incidental-take-authorization-oil-and-gas-industry-geophysical-survey-activity-gulf-mexico.</E>
                         In case of problems accessing these documents, please call the contact listed below (see 
                        <E T="02">FOR FURTHER INFORMATION CONTACT</E>
                         section).
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Jenna Harlacher, Office of Protected Resources, NMFS, (301) 427-8401.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">Background</HD>
                <P>
                    Sections 101(a)(5)(A) and (D) of the MMPA (16 U.S.C. 1361 
                    <E T="03">et seq.</E>
                    ) direct the Secretary of Commerce to allow, upon request, the incidental, but not intentional, taking of small numbers of marine mammals by U.S. citizens who engage in a specified activity (other than commercial fishing) within a specified geographical region if certain findings are made and either regulations are issued or, if the taking is limited to harassment, a notice of a proposed authorization is provided to the public for review.
                    <PRTPAGE P="604"/>
                </P>
                <P>An authorization for incidental takings shall be granted if NMFS finds that the taking will have a negligible impact on the species or stock(s), will not have an unmitigable adverse impact on the availability of the species or stock(s) for subsistence uses (where relevant), and if the permissible methods of taking and requirements pertaining to the mitigation, monitoring and reporting of such takings are set forth. NMFS has defined “negligible impact” in 50 CFR 216.103 as an impact resulting from the specified activity that cannot be reasonably expected to, and is not reasonably likely to, adversely affect the species or stock through effects on annual rates of recruitment or survival.</P>
                <P>Except with respect to certain activities not pertinent here, the MMPA defines “harassment” as: any act of pursuit, torment, or annoyance which (i) has the potential to injure a marine mammal or marine mammal stock in the wild (Level A harassment); or (ii) has the potential to disturb a marine mammal or marine mammal stock in the wild by causing disruption of behavioral patterns, including, but not limited to, migration, breathing, nursing, breeding, feeding, or sheltering (Level B harassment).</P>
                <P>On January 19, 2021, we issued a final rule with regulations to govern the unintentional taking of marine mammals incidental to geophysical survey activities conducted by oil and gas industry operators, and those persons authorized to conduct activities on their behalf (collectively “industry operators”), in U.S. waters of the GOM over the course of 5 years (86 FR 5322, January 19, 2021). The rule was based on our findings that the total taking from the specified activities over the 5-year period will have a negligible impact on the affected species or stock(s) of marine mammals and will not have an unmitigable adverse impact on the availability of those species or stocks for subsistence uses, and became effective on April 19, 2021.</P>
                <P>
                    The regulations at 50 CFR 217.180 
                    <E T="03">et seq.</E>
                     allow for the issuance of LOAs to industry operators for the incidental take of marine mammals during geophysical survey activities and prescribe the permissible methods of taking and other means of effecting the least practicable adverse impact on marine mammal species or stocks and their habitat (often referred to as mitigation), as well as requirements pertaining to the monitoring and reporting of such taking. Under § 217.186 (e), issuance of an LOA shall be based on a determination that the level of taking will be consistent with the findings made for the total taking allowable under these regulations and a determination that the amount of take authorized under the LOA is of no more than small numbers.
                </P>
                <P>NMFS subsequently discovered that the 2021 rule was based on erroneous take estimates. We conducted another rulemaking using correct take estimates and other newly available and pertinent information relevant to the analyses supporting some of the findings in the 2021 final rule and the taking allowable under the regulations. We issued a final rule in April 2024, effective May 24, 2024 (89 FR 31488, April 24, 2024).</P>
                <P>The 2024 final rule made no changes to the specified activities or the specified geographical region in which those activities would be conducted, nor to the original 5-year period of effectiveness. In consideration of the new information, the 2024 rule presented new analyses supporting affirmance of the negligible impact determinations for all species, and affirmed that the existing regulations, which contain mitigation, monitoring, and reporting requirements, are consistent with the “least practicable adverse impact” standard of the MMPA.</P>
                <HD SOURCE="HD1">Summary of Request and Analysis</HD>
                <P>
                    LLOG's new survey plans include conducting survey effort at multiple platform locations in the GOM. Survey effort could be conducted as Zero Offset, Offset, or Walkaway vertical seismic profile (VSP), Salt Proximity Survey, and/or Checkshot survey. Water depths at the locations where LLOG plans to conduct survey effort range from approximately 366 to 2,300 meters (m). LLOG plans to use either a 12-element, 2,400 cubic inch (in
                    <SU>3</SU>
                    ) airgun array, or a 6-element, 1,500 in
                    <SU>3</SU>
                     airgun array.
                </P>
                <P>LLOG currently has 7 active LOAs associated with similar survey activities as described above: 3 in zone 7, effective January 1, 2023 through December 31, 2024 (87 FR 78652, December 22, 2022), effective May 12, 2023 through December 31, 2024 (88 FR 31715, May 18, 2023), and effective March 1, 2022 through April 19, 2026 (89 FR 751, January 5, 2024); 2 in zone 5, effective September 21, 2023 through December 31, 2025 (88 FR 66409, September 27, 2023) and effective March 1, 2022 through April 19, 2026 (89 FR 14056, February 26, 2024); and 2 in zone 6, effective July 1, 2023 through July 5, 2025 (88 FR 41909, June 28, 2023) and effective September 16, 2024 through April 19, 2026 (89 FR 77475, September 23, 2024).</P>
                <P>The purpose of the newly issued LOA is to combine all LLOG survey activities, including remaining survey activity associated with the seven existing LOAs as well as newly planned survey activity, under a single LOA. This newly issued LOA would reduce workload for both LLOG and NMFS and streamline reporting. The new activity includes additional areas not covered under any active LLOG survey LOAs. As such, the seven active LOAs will expire to coincide with this new LOA that covers all of LLOGs survey activity. All currently active LOAs issued to LLOG were superseded by this new LOA, and all survey activity covered under previously active LOAs is now covered under this LOA.</P>
                <P>
                    Consistent with the preamble to the final rule, the new survey effort proposed by LLOG in its LOA request was used to develop LOA-specific take estimates based on the acoustic exposure modeling results described in the preamble (89 FR 31488, April 24, 2024). In order to generate the appropriate take number for authorization, the following information was considered: (1) survey type; (2) location (by modeling zone 
                    <SU>1</SU>
                    <FTREF/>
                    ); (3) number of days; (4) source; and (5) month.
                    <SU>2</SU>
                    <FTREF/>
                     In this case, the 4,130 in
                    <SU>3</SU>
                     airgun array was selected. This proxy selection represents the least impactful modeled airgun array, but remains conservative for purposes of evaluating LLOG's planned survey effort (
                    <E T="03">i.e.,</E>
                     maximum 12-element, 2,400 in
                    <SU>3</SU>
                     array). The acoustic exposure modeling performed in support of the rule provides 24-hour exposure estimates for each species, specific to each modeled source and survey type in each zone and month.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         For purposes of acoustic exposure modeling, the GOM was divided into seven zones. Zone 1 is not included in the geographic scope of the rule.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         Acoustic propagation modeling was performed for two seasons: winter (December-March) and summer (April-November). Marine mammal density data is generally available on a monthly basis, and therefore further refines take estimates temporally.
                    </P>
                </FTNT>
                <P>
                    No VSP surveys were included in the modeled survey types, and use of existing proxies (
                    <E T="03">i.e.,</E>
                     two-dimensional (2D), three-dimensional (3D) (narrow-azimuth) NAZ, 3D (wide-azimuth) WAZ, Coil) is generally conservative for use in evaluation of VSP survey effort, largely due to the greater area covered by the modeled proxies. Summary descriptions of these modeled survey geometries are available in the preamble to the 2018 proposed rule (83 FR 29212, 29220, June 22, 2018). Coil was selected as the best available proxy survey type in this case because the spatial coverage of the new survey activity is most similar to the coil survey pattern.
                </P>
                <P>
                    For the new survey activity, the seismic source array will be deployed in 
                    <PRTPAGE P="605"/>
                    one of the following forms: Zero Offset VSP—deployed from a drilling rig at or near the borehole, with the seismic receivers (
                    <E T="03">i.e.,</E>
                     geophones) deployed in the borehole on wireline at specified depth intervals; Offset VSP—in a fixed position deployed from a supply vessel on an offset position; Walkaway VSP—attached to a line, or a series of lines, towed by a supply vessel; 3D VSP—source moves along a spiral or line swaths towed by a supply vessel; Salt-Proximity—consists typically of a combination of both Zero Offset VSP plus a fixed Offset VSP; or Checkshot—similar to Zero Offset VSP, typically hung from a platform and a sensor placed at a few depths in the well, where only the first energy arrival is recorded. The coil survey pattern in the model was assumed to cover approximately 144 kilometers squared (km
                    <SU>2</SU>
                    ) per day (compared with approximately 795 km
                    <SU>2</SU>
                    , 199 km
                    <SU>2</SU>
                    , and 845 km
                    <SU>2</SU>
                     per day for the 2D, 3D NAZ, and 3D WAZ survey patterns, respectively). Among the different parameters of the modeled survey patterns (
                    <E T="03">e.g.,</E>
                     area covered, line spacing, number of sources, shot interval, total simulated pulses), NMFS considers area covered per day to be most influential on daily modeled exposures exceeding Level B harassment criteria. Because LLOG's planned survey is expected to cover no additional area as a stationary source, the coil proxy is most representative of the effort planned by LLOG in terms of predicted Level B harassment.
                </P>
                <P>The survey will take place over approximately 61 days total, including 19 days in zone 5, 19 days in zone 6, and 23 days in zone 7. The monthly distribution of survey days is not known in advance. Take estimates for each species are based on the month that produces the greatest value.</P>
                <P>
                    For the Rice's whale, take estimates based on the modeling yielded results that are not realistically likely to occur when considered in light of other relevant information concerning Rice's whale habitat preferences considered during the rulemaking process. NMFS' 2024 final rule provided detailed discussion regarding Rice's whale habitat (see, 
                    <E T="03">e.g.,</E>
                     89 FR 31508, 31519). In summary, recent survey data, sightings, and acoustic data support Rice's whale occurrence in waters throughout the GOM between approximately 100 m and 400 m depth along the continental shelf break, and associated habitat-based density modeling has identified similar habitat (
                    <E T="03">i.e.,</E>
                     approximately 100 to 400 m water depths along the continental shelf break) as being Rice's whale habitat (Garrison 
                    <E T="03">et al.,</E>
                     2023; Soldevilla 
                    <E T="03">et al.,</E>
                     2022, 2024).
                </P>
                <P>Although Rice's whales may occur outside of the general depth range expected to provide suitable habitat, we expect that any such occurrence would be rare. LLOG's planned activities will occur in water depths of approximately 366 to 2,300 m in the central GOM. Although there is some minimal habitat depth overlap, the majority of LLOG's survey would occur in deeper water, and the modeling results indicate only 1 take of Rice's whale (even without considering whether there is overlap with Rice's whale habitat). Thus, NMFS does not expect there to be the reasonable potential for take of Rice's whale in association with this survey and, accordingly, does not authorize take of Rice's whale through the LOA.</P>
                <P>Based on the results of our analysis here and in the other previously issued LOAs, NMFS has determined that the level of taking expected for the newly combined survey activities and authorized through the LOA is consistent with the findings made for the total taking allowable under the regulations. See table 1 in this notice and table 6 of the rule (89 FR 31488, April 24, 2024).</P>
                <HD SOURCE="HD1">Small Numbers Determination</HD>
                <P>Under the GOM rule, NMFS may not authorize incidental take of marine mammals in an LOA if it will exceed “small numbers.” In short, when an acceptable estimate of the individual marine mammals taken is available, if the estimated number of individual animals taken is up to, but not greater than, one-third of the best available abundance estimate, NMFS will determine that the numbers of marine mammals taken of a species or stock are small (89 FR 31535, May 24, 2024). For more information please see NMFS' discussion of small numbers in the 2021 final rule (86 FR 5438, January 19, 2021).</P>
                <P>The take numbers for authorization are determined as described above in the Summary of Request and Analysis section. In addition, we are adding the previously analyzed take from LLOG's 7 active LOAs. Subsequently, the total incidents of harassment for each species are multiplied by scalar ratios to produce a derived product that better reflects the number of individuals likely to be taken within a survey (as compared to the total number of instances of take), accounting for the likelihood that some individual marine mammals may be taken on more than 1 day (86 FR 5404, January 19, 2021; 89 FR 31535, May 24, 2024). The output of this scaling, where appropriate, is incorporated into adjusted total take estimates that are the basis for NMFS' small numbers determinations, as depicted in table 1.</P>
                <P>
                    This product is used by NMFS in making the necessary small numbers determinations through comparison with the best available abundance estimates (see discussion at 86 FR 5391, January 19, 2021). For this comparison, NMFS' approach is to use the maximum theoretical population, determined through review of current stock assessment reports (SAR; 
                    <E T="03">https://www.fisheries.noaa.gov/national/marine-mammal-protection/marine-mammal-stock-assessments</E>
                    ) and model-predicted abundance information (
                    <E T="03">https://seamap.env.duke.edu/models/Duke/GOM/</E>
                    ). Information supporting the small numbers determinations is provided in table 1.
                </P>
                <GPOTABLE COLS="5" OPTS="L2,i1" CDEF="s50,12,12,12,12">
                    <TTITLE>
                        Table 1—Take Analysis 
                        <SU>1</SU>
                    </TTITLE>
                    <BOXHD>
                        <CHED H="1">Species</CHED>
                        <CHED H="1">
                            Authorized
                            <LI>take</LI>
                        </CHED>
                        <CHED H="1">Scaled take</CHED>
                        <CHED H="1">
                            Abundance 
                            <SU>2</SU>
                        </CHED>
                        <CHED H="1">
                            Percent
                            <LI>abundance</LI>
                        </CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">Rice's whale</ENT>
                        <ENT>0</ENT>
                        <ENT>n/a</ENT>
                        <ENT>51</ENT>
                        <ENT>n/a</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Sperm whale</ENT>
                        <ENT>443</ENT>
                        <ENT>187</ENT>
                        <ENT>3,007</ENT>
                        <ENT>6.2</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">
                            <E T="03">Kogia</E>
                             spp
                        </ENT>
                        <ENT>
                            <SU>3</SU>
                             207
                        </ENT>
                        <ENT>62.3</ENT>
                        <ENT>980</ENT>
                        <ENT>7.7</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Beaked whales</ENT>
                        <ENT>743</ENT>
                        <ENT>75</ENT>
                        <ENT>803</ENT>
                        <ENT>9.3</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Rough-toothed dolphin</ENT>
                        <ENT>1,134</ENT>
                        <ENT>325</ENT>
                        <ENT>4,853</ENT>
                        <ENT>6.7</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Bottlenose dolphin</ENT>
                        <ENT>1,156</ENT>
                        <ENT>332</ENT>
                        <ENT>165,125</ENT>
                        <ENT>0.2</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Clymene dolphin</ENT>
                        <ENT>1,674</ENT>
                        <ENT>480</ENT>
                        <ENT>4,619</ENT>
                        <ENT>10.4</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Atlantic spotted dolphin</ENT>
                        <ENT>1,111</ENT>
                        <ENT>319</ENT>
                        <ENT>21,506</ENT>
                        <ENT>1.5</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Pantropical spotted dolphin</ENT>
                        <ENT>11,871</ENT>
                        <ENT>3407</ENT>
                        <ENT>67,225</ENT>
                        <ENT>5.1</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Spinner dolphin</ENT>
                        <ENT>156</ENT>
                        <ENT>45</ENT>
                        <ENT>5,548</ENT>
                        <ENT>0.8</ENT>
                    </ROW>
                    <ROW>
                        <PRTPAGE P="606"/>
                        <ENT I="01">Striped dolphin</ENT>
                        <ENT>3,185</ENT>
                        <ENT>914</ENT>
                        <ENT>5,634</ENT>
                        <ENT>16.2</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Fraser's dolphin</ENT>
                        <ENT>457</ENT>
                        <ENT>131</ENT>
                        <ENT>1,665</ENT>
                        <ENT>7.9</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Risso's dolphin</ENT>
                        <ENT>315</ENT>
                        <ENT>93</ENT>
                        <ENT>1,974</ENT>
                        <ENT>4.7</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">
                            Blackfish 
                            <SU>4</SU>
                        </ENT>
                        <ENT>3,233</ENT>
                        <ENT>954</ENT>
                        <ENT>6,113</ENT>
                        <ENT>15.6</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Short-finned pilot whale</ENT>
                        <ENT>803</ENT>
                        <ENT>237</ENT>
                        <ENT>2,741</ENT>
                        <ENT>8.6</ENT>
                    </ROW>
                    <TNOTE>
                        <SU>1</SU>
                         Scalar ratios were applied to “Authorized Take” values as described at 86 FR 5322, 5404 (January 19, 2021) to derive scaled take numbers shown here.
                    </TNOTE>
                    <TNOTE>
                        <SU>2</SU>
                         Best abundance estimate. For most taxa, the best abundance estimate for purposes of comparison with take estimates is considered here to be the model-predicted abundance (Garrison 
                        <E T="03">et al.,</E>
                         2023). For Rice's whale, Atlantic spotted dolphin, and Risso's dolphin, the larger estimated SAR abundance estimate is used.
                    </TNOTE>
                    <TNOTE>
                        <SU>3</SU>
                         Includes 13 take by Level A harassment and 194 takes by Level B harassment. Small numbers determination made on basis of scaled Level B harassment take plus authorized Level A harassment take.
                    </TNOTE>
                    <TNOTE>
                        <SU>4</SU>
                         The “blackfish” guild includes melon-headed whales, false killer whales, pygmy killer whales, and killer whales.
                    </TNOTE>
                </GPOTABLE>
                <P>
                    Based on the analysis contained herein of LLOG's proposed survey activity described in its LOA application, the previous analysis from the 7 active LOAs, and the anticipated take of marine mammals, NMFS finds that small numbers of marine mammals will be taken relative to the affected species or stock sizes (
                    <E T="03">i.e.,</E>
                     less than one-third of the best available abundance estimate) and therefore the taking is of no more than small numbers.
                </P>
                <HD SOURCE="HD1">Authorization</HD>
                <P>NMFS has determined that the level of taking for this LOA request is consistent with the findings made for the total taking allowable under the incidental take regulations and that the amount of take authorized under the LOA is of no more than small numbers. Accordingly, we have issued an LOA to LLOG authorizing the take of marine mammals incidental to its geophysical survey activity, as described above.</P>
                <SIG>
                    <DATED>Dated: December 31, 2024.</DATED>
                    <NAME>Catherine Marzin, </NAME>
                    <TITLE>Acting Director, Office of Protected Resources, National Marine Fisheries Service.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31750 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 3510-22-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF COMMERCE</AGENCY>
                <SUBAGY>National Oceanic and Atmospheric Administration</SUBAGY>
                <SUBJECT>Notice of Cashes Ledge Site Added to the Inventory of Areas for Possible Designation as National Marine Sanctuaries</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Office of National Marine Sanctuaries (ONMS), National Ocean Service (NOS), National Oceanic and Atmospheric Administration (NOAA), Department of Commerce.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        On June 13, 2014, NOAA published a final rule establishing the Sanctuary Nomination Process, allowing communities to submit nominations to NOAA for consideration as new national marine sanctuaries. The rule outlined the review process, national significance criteria, and management considerations that NOAA uses to evaluate nominations for inclusion in the inventory of areas that could eventually be considered for designation. The rule also states that NOAA will publish a 
                        <E T="04">Federal Register</E>
                         notice when areas have been added to the inventory of successful nominations. This notice announces that NOAA has added the Cashes Ledge area to the inventory; the agency is not moving forward with a designation at this time.
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Applicable January 3, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        Matt Brookhart, Eastern Regional Director, NOAA Office of National Marine Sanctuaries, 1315 East-West Highway, Silver Spring, Maryland 20910, and at 
                        <E T="03">https://nominate.noaa.gov/nominations/.</E>
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Matt Brookhart, Eastern Regional Director, NOAA Office of National Marine Sanctuaries, 
                        <E T="03">matt.brookhart@noaa.gov,</E>
                         or at 301-452-4177.
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">I. Background</HD>
                <P>
                    The National Marine Sanctuaries Act (NMSA) (16 U.S.C. 1431 
                    <E T="03">et seq.</E>
                    ) authorizes the Secretary of Commerce to identify and designate as national marine sanctuaries areas of the marine environment, including the Great Lakes, which are of special national significance; to manage these areas as the National Marine Sanctuary System; and to provide for the comprehensive and coordinated conservation and management of these areas and the activities affecting them in a manner which complements existing regulatory authorities. Section 303 of the NMSA, 16 U.S.C. 1433, provides national marine sanctuary designation standards and factors required in determining whether an area qualifies for consideration as a potential national marine sanctuary, and section 304, 16 U.S.C. 1434, establishes procedures for national marine sanctuary designation and implementation. Regulations implementing the NMSA and each national marine sanctuary are codified in part 922 of title 15 of the Code of Federal Regulations.
                </P>
                <P>
                    On June 13, 2014, NOAA issued a final rule that established the Sanctuary Nomination Process and finalized the national significance criteria and management considerations it will use to review new national marine sanctuary nominations (79 FR 33851). If NOAA determines a nomination adequately meets the final criteria and considerations, it may place that nomination in an inventory of areas to consider for designation as a national marine sanctuary. NOAA also stated that it would send a letter of notification to the nominator and publish a 
                    <E T="04">Federal Register</E>
                     notice identifying areas that have been added to the inventory of successful nominations. This notice documents that NOAA is adding the Cashes Ledge area to the inventory.
                </P>
                <P>
                    NOAA is not designating any new national marine sanctuaries with this action. Any proposed designations of areas on the inventory would be conducted by NOAA as a separate process under the NMSA, Administrative Procedure Act (5 U.S.C. Subchapter II), National Environmental Policy Act (42 U.S.C. 4321 
                    <E T="03">et seq.</E>
                    ), and other applicable authorities.
                </P>
                <HD SOURCE="HD1">II. Cashes Ledge Sanctuary Nomination Added to the Inventory</HD>
                <P>
                    Conservation Law Foundation (CLF) nominated the Cashes Ledge area to be considered for designation as a national marine sanctuary on July 29, 2024. CLF identified a 766 mi
                    <SU>2</SU>
                     area around Cashes 
                    <PRTPAGE P="607"/>
                    Ledge, which is located 90 miles east of Portsmouth, New Hampshire in the Gulf of Maine. This area includes not just Cashes Ledge, but also Parker Ridge and Sigsbee Ridge, which collectively form a 32 mile long granite ridge that rises sharply from the sea floor and runs parallel to the coastline. CLF nominated the Cashes Ledge area for consideration as a national marine sanctuary to protect its nationally significant ecological resources. These include dense kelp forests, habitat for species such as cod, Atlantic wolffish, halibut, and flounder, and globally significant populations of marine mammals, such as North Atlantic right whales, and seabirds, such as Atlantic puffins. CLF also nominated the Cashes Ledge area for consideration in order to better protect the Gulf of Maine ecosystem, which New England's coastal communities depend on economically for tourism, shipping, offshore energy, and recreational and commercial fishing.
                </P>
                <P>Based on information included in the nomination, including the comment letters submitted with the nomination, as well as NOAA's internal analysis, NOAA has determined that the nomination is responsive to the 11 national significance criteria and management considerations it uses to review nominations. Therefore, this notice serves to inform the public of the agency's decision to add the Cashes Ledge area to the inventory of successful nominations.</P>
                <P>At this time, NOAA is not initiating a sanctuary designation process. In adding the Cashes Ledge area to the inventory, NOAA does not endorse or imply endorsement of any specific boundaries, regulations or management measures in the Cashes Ledge nomination. Should NOAA decide to initiate a sanctuary designation process for Cashes Ledge in the future, it would establish a highly public, multi-year process for exploring possibilities for sanctuary boundaries, regulations and programs in partnership with other Federal agencies, Tribal Nations, State governments, stakeholders and the public.</P>
                <HD SOURCE="HD1">III. Classification</HD>
                <HD SOURCE="HD2">A. National Environmental Policy Act (NEPA)</HD>
                <P>
                    NOAA has concluded that the action of adding the Cashes Ledge area to the inventory of successful nominations will not have a significant effect, individually or cumulatively, on the human environment because this action is administrative in nature and does not designate or propose to designate any new national marine sanctuaries. NOAA has further determined that this action is not connected to a larger action, and does not involve extraordinary circumstances precluding the use of a categorical exclusion in accordance with NEPA (42 U.S.C. 4321 
                    <E T="03">et seq.</E>
                    ). Therefore, this action is categorically excluded from the requirement to prepare an environmental assessment or environmental impact statement, in accordance with NOAA Administrative Order 216-6A Environmental Review Procedures, and the NOAA NEPA Companion Manual. As defined in the NOAA NEPA Companion Manual, Appendix E, categorical exclusion category G7, the proposed action is a notice of administrative and procedural nature and for which any environmental effects are too broad and speculative to lend themselves to meaningful analysis at this time and will be subject later to the NEPA process, as applicable. Should NOAA decide to propose the designation of a national marine sanctuary, each individual national marine sanctuary designation process will be subject to case-by-case analysis, as required under NEPA and as outlined in section 304(a)(2)(A) of the NMSA.
                </P>
                <P>
                    <E T="03">Authority:</E>
                     16 U.S.C. 1431 
                    <E T="03">et seq.</E>
                </P>
                <SIG>
                    <NAME>John Armor,</NAME>
                    <TITLE>Director, Office of National Marine Sanctuaries, National Ocean Service, National Oceanic and Atmospheric Administration.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-30702 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 3510-NK-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">CONSUMER FINANCIAL PROTECTION BUREAU</AGENCY>
                <SUBJECT>Supervisory Highlights, Issue 37 (Winter 2024)</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Consumer Financial Protection Bureau.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Supervisory Highlights.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        The Consumer Financial Protection Bureau (CFPB) is issuing its thirty seventh edition of 
                        <E T="03">Supervisory Highlights.</E>
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        This edition of 
                        <E T="03">Supervisory Highlights</E>
                         covers recent supervisory findings in the areas of deposits, furnishing, and short-term small dollar lending. The findings in this edition of 
                        <E T="03">Supervisory Highlights</E>
                         cover select examinations that were generally completed between January 1, 2024, to October 1, 2024.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Jaclyn Sellers, Senior Counsel, at (202) 435-7449. If you require this document in an alternative electronic format, please contact 
                        <E T="03">CFPB_Accessibility@cfpb.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">1. Introduction</HD>
                <P>
                    The Consumer Financial Protection Bureau's (CFPB) Supervision program assesses supervised institutions' compliance with Federal consumer financial law including unfair, deceptive, or abusive acts or practices (UDAAPs) prohibited by the Consumer Financial Protection Act of 2010 (the CFPA).
                    <SU>1</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         12 U.S.C. 5531, 5536.
                    </P>
                </FTNT>
                <P>
                    This edition of 
                    <E T="03">Supervisory Highlights</E>
                     covers recent supervisory findings in the areas of deposits, furnishing, and short-term small dollar lending. In connection with deposits, Supervision continues to find that supervised institutions are charging consumers unfair overdraft and non-sufficient funds fees, and this edition provides an update on Supervision's work in this space. Aside from the refunds discussed in the context of deposits accounts below, mortgage originators and servicers have also recently reported issuing refunds related to unfair, deceptive, or otherwise unlawful fees and charges, which the CFPB anticipates reporting on in an upcoming edition of 
                    <E T="03">Supervisory Highlights.</E>
                     In short, mortgage servicers have reported issuing $4,251,815 in refunds for 91,931 affected loans. Mortgage originators reported issuing $115,605,024 in refunds for 134,912 affected loans. In connection with furnishing, examiners continue to find violations of the Fair Credit Reporting Act (FCRA) 
                    <SU>2</SU>
                    <FTREF/>
                     and its implementing regulation, Regulation V.
                    <SU>3</SU>
                    <FTREF/>
                     These violations include failing to maintain policies and procedures regarding identify theft and the accuracy and integrity of information. Additionally, examiners continue to find that furnishers are not investigating indirect disputes. This edition of 
                    <E T="03">Supervisory Highlights</E>
                     also includes, for the first time, supervisory findings in connection with Buy Now, Pay Later and paycheck advance products. More specifically examiners identified multiple violations of law including UDAAPs in connection with both Buy Now Pay Later and paycheck advance products. This edition also highlights how weak technology controls can cause or contribute to violations of Federal consumer financial law. For example, Supervision found that the way that core processors configured their platforms caused violations of Federal consumer financial law. 
                    <PRTPAGE P="608"/>
                    Additionally, an institution violated the law by rolling out a dysfunctional online banking platform that made it difficult for credit union members to perform basic banking functions for weeks, with some features unavailable for more than six months. One area of particular concern associated with technology that the CFPB expects to highlight in future publications is the risk associated with “Bring Your Own Device” (BYOD) policies, which refers to being able to conduct business on a personally owned device, rather than a company issued device. BYOD policies may increase security risks including, for example, data breaches, malware, and unauthorized access to sensitive data. Institutions that permit BYOD should ensure that they take steps to mitigate the risks associated with these policies.
                </P>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         15 U.S.C. 1681 
                        <E T="03">et seq.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         12 CFR part 1022.
                    </P>
                </FTNT>
                <P>
                    The findings in this edition of 
                    <E T="03">Supervisory Highlights</E>
                     cover select examinations that were generally completed between January 1, 2024, to October 1, 2024. To maintain the anonymity of the supervised institutions discussed in 
                    <E T="03">Supervisory Highlights,</E>
                     references to institutions generally are in the plural and the related findings may pertain to one or more institutions.
                    <SU>4</SU>
                    <FTREF/>
                     We invite readers with questions or comments about 
                    <E T="03">Supervisory Highlights</E>
                     to contact us at 
                    <E T="03">CFPB_Supervision@cfpb.gov.</E>
                </P>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         If a supervisory matter is referred to the Office of Enforcement, Enforcement may cite additional violations based on these facts or uncover additional information that could impact the conclusion as to what violations may exist.
                    </P>
                </FTNT>
                <HD SOURCE="HD1">2. Supervisory Observations</HD>
                <HD SOURCE="HD2">2.1 Deposits</HD>
                <P>
                    Supervision examined the deposit operations of supervised institutions to assess whether they engaged in any UDAAPs prohibited by the CFPA.
                    <SU>5</SU>
                    <FTREF/>
                     In these examinations, Supervision identified unfair overdraft and non-sufficient funds (NSF) fees as well as unfair acts or practices related to consumer requests to stop payment of preauthorized debit card transactions.
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         12 U.S.C. 5531, 5536.
                    </P>
                </FTNT>
                <HD SOURCE="HD3">2.1.1 Unanticipated Overdraft Fees and Re-Presentment NSF Fees</HD>
                <P>
                    In recent examinations of depository institutions and service providers, Supervision continued to cite unfair acts or practices at institutions that charged consumers for unfair unanticipated overdraft fees, such as Authorize-Positive Settle-Negative (APSN) overdraft fees, during this time period.
                    <SU>6</SU>
                    <FTREF/>
                     Supervision also continued to cite institutions in connection with charging consumers NSF fees on the transaction that already incurred an NSF fee when it was previously declined.
                    <SU>7</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         APSN overdraft fees are overdraft fees that financial institutions assess for debit card or ATM transactions for which the consumer had a sufficient available balance at the time the consumer authorized the transaction, but which, given the delay between authorization and settlement, the consumer's account balance is insufficient to cover at the time of settlement. 
                        <E T="03">See Supervisory Highlights: Junk Fees Update Special Edition, Issue</E>
                         31, 4-7 (March 2023) 
                        <E T="03">https://www.consumerfinance.gov/data-research/research-reports/supervisory-highlights-junk-fees-update-special-edition-issue-31-fall-2023</E>
                         ; 
                        <E T="03">Supervisory Highlights: Junk Fees Special Edition, Issue 29,</E>
                         3-6 (March 2023), 
                        <E T="03">https://www.consumerfinance.gov/data-research/research-reports/supervisory-highlights-junk-fees-special-edition-issue-29-winter-2023/; Consumer Financial Protection Circular 2022-06, Unanticipated Overdraft Fee Assessment Practices,</E>
                         at 8-12 (Oct. 26, 2022), 
                        <E T="03">https://www.consumerfinance.gov/compliance/circulars/consumer-financial-protection-circular-2022-06-unanticipated-overdraft-fee-assessment-practices/.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>7</SU>
                         These transactions, called re-presentments, occur when, after declining a transaction because of insufficient funds and assessing an NSF fee for the transaction, the consumer's account-holding institution returns the transaction to the merchant's depository institution, and the merchant presents the same transaction to the consumer's account-holding institution for payment again. In some instances, when the consumer's account remains insufficient to pay for the transaction upon re-presentment, the consumer's account-holding institution again returns the transaction to the merchant and assesses another NSF fee for the transaction, without providing consumers a reasonable opportunity to prevent another fee after the first failed presentment attempt. Absent restrictions on the assessment of NSF fees by the consumer's account-holding institution, this cycle can occur multiple times, and consumers may be charged multiple fees for a single transaction.
                    </P>
                </FTNT>
                <P>Since the CFPB heightened its supervisory attention on overdraft and NSF fees in 2022, financial institutions have agreed to refund nearly $250 million to consumers—approximately $184 million in unfair unanticipated overdraft fees charged on transactions that were authorized when the consumer had sufficient funds, and approximately $66 million in unfair NSF fees charged on the same transaction that already incurred an NSF fee when it was previously declined. This $250 million reflects $240 million that the CFPB previously announced in October 2023 and April 2024, and an additional $10 million that financial institutions have agreed to refund since the period covered by those announcements.</P>
                <HD SOURCE="HD3">2.1.2 Core Processor Practices</HD>
                <P>Supervision continued to examine core processors in their capacity as service providers to large depository institutions. Core processors provide critical deposit, payment, and data processing services to many supervised institutions, and the system functionality that these entities develop drives many fee practices, including overdraft and NSF fee practices. </P>
                <P>
                    In examinations of core processors, examiners found that core processors had enhanced their core platforms during the review periods to enable client institutions to avoid assessing re-presentment NSF fees and APSN overdraft fees. However, examiners also found that the core processors configured their platforms so that the platforms would continue to assess the fees by default unless the client institutions took affirmative action to avoid assessing these fees. Examiners concluded that, in the offering and providing of core service platforms, core processors engaged in an unfair act or practice by assessing APSN overdraft fees and re-presentment NSF fees through their core platforms. An act or practice is unfair when: (1) it causes or is likely to cause substantial injury to consumers; (2) the injury is not reasonably avoidable by consumers; and (3) the injury is not outweighed by countervailing benefits to consumers or to competition.
                    <SU>8</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>8</SU>
                         12 U.S.C. 5531 and 5536.
                    </P>
                </FTNT>
                <P>The assessment of re-presentment NSF fees and APSN fees results in substantial injury to consumers. These fees also increased the risk of consumers incurring additional fees on subsequent transactions caused by the fees, which lowered consumers' account balances. The core processors caused these injuries because they were a predictable and foreseeable consequence of their core platforms' limitations and configuration. Where the platforms were configured to assess the fees by default, it was foreseeable to the core processors that their clients would fail to take affirmative action to cease charging these fees and thus continue to assess these fees. As with the fees themselves, the relevant system limitations and configurations were not reasonably avoidable by consumers and not outweighed by any countervailing benefits to consumers or competition.</P>
                <P>In response to these findings, the core processors enhanced their core platforms to not only enable their client institutions to prevent the assessment of these fees but also to ensure that clients would not assess these fees by default if the clients did not take action to prevent their assessment.</P>
                <HD SOURCE="HD3">2.1.3 Improper Re-Presentment Processing Practices</HD>
                <P>
                    Supervision has reviewed depository institutions' practices in processing automated clearinghouse (ACH) transactions to ensure that they are taking adequate steps to prevent the 
                    <PRTPAGE P="609"/>
                    origination of improper re-presentment transactions by their merchant and business clients. When a consumer pays for goods or services, the consumer may authorize the merchant to debit their bank account by submitting an ACH transaction to the consumer's bank. The merchant will originate the ACH transaction by passing an ACH debit entry along to its bank, referred to as an “originating depository financial institution” (ODFI), which will then send the entry to the consumer's bank, referred to as a “receiving depository financial institution” (RDFI). The RDFI then may either post the transaction and debit the consumer's bank account or return the transaction to the ODFI because of insufficient funds in the consumer's account. The network rules governing ACH transactions impose certain formatting and processing requirements to identify re-presentment transactions. As explained above, in response to supervisory findings, core processors have enhanced their platforms to enable institutions to avoid charging NSF fees on readily identifiable re-presentment transactions. Accordingly, when an ODFI does not ensure that its clients comply with these formatting and processing requirements or otherwise do not originate improper re-presentment transactions, ACH transactions may not be readily identifiable as re-presentments by the RDFI and, by extension, the RDFI's core platform may fail to prevent charging NSF fees on re-presentment transactions.
                </P>
                <P>
                    The ACH network rules also generally limit the number of permissible re-presentments for a single transaction by limiting an ODFI and its clients to a maximum of two re-presentment attempts after the initial presentment is returned for insufficient funds. However, as the CFPB has previously observed, an ODFI's clients may, in an attempt to obtain payment from consumers, seek to improperly re-present transactions to circumvent this limit on the number of permissible representments.
                    <SU>9</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>9</SU>
                         CFPB, 
                        <E T="03">Online Payday Loan Payments</E>
                         (2016), at 14 (explaining that, according to CFPB analysis of online ACH payments, 50 percent of failed payments are re-presented after three failed payment attempts), 
                        <E T="03">https://www.consumerfinance.gov/data-research/research-reports/online-payday-loan-payments/.</E>
                    </P>
                </FTNT>
                <P>Supervision found that depository institutions engaged in an unfair act or practice in their capacity as ODFIs by processing transactions for payment as initial presentments when the transactions were in fact re-presentments without taking steps to address indicia of inaccuracy. Examiners found that these institutions, in their capacity as ODFIs, did not monitor their originator clients' use of their ACH processing services to identify or prevent them from improperly re-presenting transactions. These depository institutions possessed information that strongly suggested that a percentage of ACH transactions that they processed as ODFIs were re-presented items that were improperly formatted and submitted by their originator clients as new transactions. These indicia included ACH entries reflecting transactions from the same payee, in the same amount, made close in time, which lacked indications that the transactions were recurring payments or otherwise reflected separate transactions.</P>
                <P>By failing to monitor originators to identify and prevent improper re-presentment practices, these depository institutions caused or were likely to cause substantial injury to consumers in the form of NSF fees that could otherwise have been avoided. These fees would not have been assessed had the transaction been properly re-presented because the transaction would then either be identifiable as a re-presentment and the NSF fee would have been waived by the bank's core platform or would have not been submitted at all to the extent that the business client had already submitted the maximum number of re-presentment attempts. Although the supervised depository institutions, as ODFIs, did not actually assess these NSF fees, examiners found they caused the injury because the assessment of these fees was a probable and foreseeable consequence of their processing transactions for payment as initial presentments when the transactions were in fact re-presentments.</P>
                <P>Even if a consumer's bank did not assess NSF fees, consumers still suffered injury in the form of improper debiting of funds. When an originator obtains payment for a previously returned transaction by submitting the transaction as initial presentment, rather than a re-presentment, without the consumer's authorization, the consumer suffers monetary harm by their account being debited without their authorization. These injuries were not reasonably avoidable and were also not outweighed by countervailing benefits to consumers or competition. In response to these findings, depository institutions implemented processes to prevent the origination of improper re-presentment transactions by their clients, including regularly monitoring and auditing ACH transactions to identify any re-presented items that are miscoded as initial presentments and any other indicia of inaccuracy.</P>
                <HD SOURCE="HD3">2.1.4 Stop Payment Services of Debit Card Network Operators</HD>
                <P>
                    Consumers frequently complain that they face challenges in stopping payment of preauthorized debit card transactions, which they have a right to do under the Electronic Fund Transfer Act (EFTA) and its implementing Regulation E.
                    <SU>10</SU>
                    <FTREF/>
                     Supervision has found in examinations that depository institutions likewise face difficulties in executing stop payment requests for recurring debit card transactions for various reasons. 
                </P>
                <FTNT>
                    <P>
                        <SU>10</SU>
                         15 U.S.C. 1693e(a); 12 CFR 1005.10(c).
                    </P>
                </FTNT>
                <P>
                    Unlike other types of recurring payment transactions, depository institutions' core platforms generally do not offer the capability to stop payment of preauthorized debit card transactions. Regulation E recognizes that, in the case of a preauthorized debit made through a debit card network, a depository institution may not have the capability to block a preauthorized debit from being posted to the consumer's account given the manner in which preauthorized debit card transactions are processed.
                    <SU>11</SU>
                    <FTREF/>
                     Accordingly, it allows banks to comply with the stop-payment requirements by using a third party, such as a debit card network, to block the transfer, as long as the consumer's account is not debited for the payment.
                    <SU>12</SU>
                    <FTREF/>
                     To that end, some debit card networks offer stop payment capabilities that network members may use to stop payment of recurring debit card transactions routed through the network. Supervision recently conducted examinations of debit card network operators in their capacity as service providers to large depository institutions. Examiners found that, in some debit card networks, these network operators did not offer a network-based stop payment service that their members may use to stop payment of a recurring debit card transaction. Examiners also found that, in other debit card networks, the network operators did offer such a service but very few of its members elected to use the service.
                </P>
                <FTNT>
                    <P>
                        <SU>11</SU>
                         
                        <E T="03">See</E>
                         comment 1005.10(c)-3.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>12</SU>
                         
                        <E T="03">See Id.</E>
                    </P>
                </FTNT>
                <P>
                    Examiners concluded that these network operators engaged in an unfair act or practice by processing preauthorized debit card payments subject to consumer's valid stop payment requests due to the manner in which they operated their networks. By processing such transactions, the network operators caused substantial 
                    <PRTPAGE P="610"/>
                    monetary injury to consumers who were charged for preauthorized debit card transactions that they requested to be and were entitled to have stopped. Even though the consumer's financial institution could likely recover the amount debited through standard dispute resolution and chargeback processes for debit card transactions, consumers would still be deprived of their funds while the dispute was processed. In any event, these processes are not an adequate substitute for a consumer's right to stop payment of preauthorized debit card transactions.
                </P>
                <P>Operators of networks that did not offer a stop payment service caused this injury because it was foreseeable to them that not offering such a capability in the network would result in network members lacking the capability to stop payment of the transactions and, by extension, consumers being charged for such transactions after they submit a valid stop payment order. Even where network operators offered a network-based stop payment capability, these operators still caused this injury to consumers, because, given that very few network members elected to use the capability, it was foreseeable to them that consumers would be charged for preauthorized debits that they are entitled to have stopped.</P>
                <P>The substantial injury identified in these exams was not reasonably avoidable by consumers. When entering a recurring transaction, consumers have little reason to anticipate potential injury, and if they did, few means to avoid it. Consumers have a reasonable expectation that their issuing bank will comply with the requirements of Regulation E and stop payment if a valid request is entered. Consumers also have little to no control over which debit card networks their transactions are routed through, and no control over whether the network offers a stop payment service or whether their bank has voluntarily enrolled in such a service. Lastly, in considering countervailing benefits to consumers and competition from processing preauthorized debit card transactions subject to a consumer's valid stop payment request, Supervision found this practice to be injurious in its net effects. </P>
                <P>In response to these findings, the network operators revised and implemented relevant network processes and capabilities to ensure that they cease to process preauthorized debit card payments routed through their networks that are subject to consumers' valid stop payment requests.</P>
                <HD SOURCE="HD2">2.2 Furnishing</HD>
                <P>
                    Entities—such as banks, loan servicers, and others (to which we refer herein collectively as furnishers)—that furnish information to consumer reporting companies (CRCs) 
                    <SU>13</SU>
                    <FTREF/>
                     for inclusion in consumer reports play a vital role in availability of credit and have a significant role to play in the fair and accurate reporting of credit information. Furnishers are subject to several requirements under the FCRA 
                    <SU>14</SU>
                    <FTREF/>
                     and its implementing regulation, Regulation V,
                    <SU>15</SU>
                    <FTREF/>
                     including obligations to reasonably investigate disputes and to furnish data subject to the relevant accuracy requirements. In recent reviews, examiners continued to find deficiencies in furnishers' compliance with FCRA and Regulation V requirements.
                </P>
                <FTNT>
                    <P>
                        <SU>13</SU>
                         The term “consumer reporting company” means the same as “consumer reporting agency,” as defined in the Fair Credit Reporting Act, 15 U.S.C. 1681a(f), including nationwide consumer reporting agencies as defined in 15 U.S.C. 1681a(p) and nationwide specialty consumer reporting agencies as defined in 15 U.S.C. 1681a(x).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>14</SU>
                         15 U.S.C. 1681 
                        <E T="03">et seq.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>15</SU>
                         12 CFR part 1022.
                    </P>
                </FTNT>
                <HD SOURCE="HD3">2.2.1 Duty To Maintain Reasonable Procedures To Respond To Identify Theft Block Requests Notifications From CRCs</HD>
                <P>
                    The FCRA requires furnishers to have reasonable procedures in place to respond to certain notifications they receive from CRCs related to information resulting from identity theft (
                    <E T="03">i.e.,</E>
                     identity theft block request notifications) to prevent the refurnishing of such information.
                    <SU>16</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>16</SU>
                         15 U.S.C. 1681s-2(a)(6)(A).
                    </P>
                </FTNT>
                <P>Examiners found that furnishers did not have reasonable procedures in place to respond to identity theft block request notifications from CRCs. Specifically, in recent reviews of installment loan furnishers, examiners identified that the furnishers did not have any procedures in place to respond to identity theft block request notifications received from CRCs. Consequently, the furnishers did not process the requests and repeatedly refurnished information that consumers asserted had resulted from identity theft and, thus, that should have been blocked. In response to these findings, furnishers are establishing and implementing procedures to respond to identity theft block request notifications received from CRCs.</P>
                <HD SOURCE="HD3">2.2.2 Duty To Conduct Reasonable Investigations of Indirect Disputes</HD>
                <P>
                    After receiving notice of a dispute of the completeness or accuracy of any information from a CRC, furnishers are required to conduct a reasonable investigation with respect to the disputed information.
                    <SU>17</SU>
                    <FTREF/>
                     The furnisher must review all relevant information provided by the CRC and must complete the investigation and report the results to the CRC within a certain requisite timeframe (typically 30 days).
                    <SU>18</SU>
                    <FTREF/>
                     Conducting a reasonable investigation that is responsive to the specific allegations in a dispute often requires furnishers to at least review information relevant to the dispute in its own possession and, in some cases, may necessarily entail accessing or requesting third-party documents and other information relevant to the dispute to which the furnisher reasonably has access.
                </P>
                <FTNT>
                    <P>
                        <SU>17</SU>
                         15 U.S.C. 1681s-2(b)(1)(A).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>18</SU>
                         15 U.S.C. 1681s-2(b)(1)(B), (C).
                    </P>
                </FTNT>
                <P>
                    Examiners are continuing to find that furnishers are violating the FCRA duty to conduct reasonable investigations of indirect disputes.
                    <SU>19</SU>
                    <FTREF/>
                     In recent reviews of debt collector furnishers, examiners found that the furnishers failed to conduct reasonable investigations of certain indirect disputes in circumstances in which the furnishers utilized automated dispute response systems that reviewed only their own systems of record to assess the accuracy of the disputed information. Examiners identified instances in which the furnishers, through their automated systems, responded to CRCs verifying the information subject to the dispute even though the furnishers' records were insufficient to confirm the information in a reliable manner. In each instance, the furnishers' automated systems did not consider any records of the furnishers' clients—
                    <E T="03">i.e.,</E>
                     the entities, such as creditors, on behalf of which the furnishers were collecting debts—relevant to the dispute.
                </P>
                <FTNT>
                    <P>
                        <SU>19</SU>
                         
                        <E T="03">See</E>
                         for example, 
                        <E T="03">Supervisory Highlights Consumer Reporting Special Edition,</E>
                          
                        <E T="03">cfpb_supervisory-highlights_issue-20_122019.pdf.</E>
                    </P>
                </FTNT>
                <P>
                    In addition, examiners found that debt collector furnishers failed to reasonably investigate certain indirect disputes in circumstances in which the furnishers' agents responded to CRCs regarding the dispute without investigating any relevant information on their clients' systems of record despite the agents having access to those systems of record. Rather than reviewing their clients' records to which they had access to assess the accuracy of the disputed information, the furnishers' agents forwarded the disputes to the clients for investigation and, when the clients failed to respond, instructed CRCs to delete the related 
                    <PRTPAGE P="611"/>
                    consumer tradelines. Examiners found that the furnishers in these circumstances failed to conduct reasonable investigations of indirect disputes.
                </P>
                <HD SOURCE="HD3">2.2.3 Duty To Establish and Implement Reasonable Policies and Procedures Concerning the Accuracy and Integrity of Furnished Information</HD>
                <P>
                    Examiners are continuing to find 
                    <SU>20</SU>
                    <FTREF/>
                     that furnishers are violating the Regulation V duty to establish and implement reasonable written policies and procedures regarding the accuracy and integrity of the information furnished to a CRC and to consider and incorporate, as appropriate, the guidelines of appendix E to Regulation V.
                    <SU>21</SU>
                    <FTREF/>
                     Recent supervisory reviews identifying violations of this Regulation V requirement include:
                </P>
                <FTNT>
                    <P>
                        <SU>20</SU>
                         
                        <E T="03">Id.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>21</SU>
                         12 CFR 1022.42(a), (b).
                    </P>
                </FTNT>
                <P> In reviews of student loan furnishers, examiners found that the furnishers relied solely on external procedures regarding the technical steps for creating and transmitting consumer reporting files, but maintained no internal policies or procedures with respect to complying with the applicable requirements of the FCRA and Regulation V. Examiners found that the furnishers' failure to establish and implement reasonable written policies and procedures regarding the accuracy and integrity of information furnished to CRCs contributed to multiple systemic accuracy issues identified at the furnishers, including, for example, continuing to report accounts that had been discharged in bankruptcy, reporting inaccurate term durations for certain loans, and reporting inaccurate special comment codes regarding the status of certain accounts.</P>
                <P>• In reviews of installment loan furnishers, examiners found that furnishers lacked reasonable policies and procedures for identifying practices or activities that can compromise the accuracy or integrity of furnished information. Specifically, examiners found weaknesses in furnishers' policies and procedures with respect to considering feedback received from CRCs—resulting in the furnishers failing to identify that furnishing files were rejected by CRCs—and processing identity theft block requests received from CRCs. Deficiencies in the furnishers' internal controls regarding the accuracy and integrity of furnished information led to failures in identifying, and promptly remediating, accounts that were furnished inaccurately. Examiners also found that furnishers failed to design means of communication with CRCs to prevent erroneous association of information with the wrong consumers, which resulted in the furnishing of mismatched personal information for thousands of consumers.</P>
                <P> In reviews of credit card furnishers, examiners found that the furnishers failed to maintain and implement reasonable written furnishing policies and procedures, including by failing to adequately provide for, among other things: the identification and handling of frivolous or irrelevant disputes, the replacement of dispute codes following resolution of disputes, and quality assurance with respect to the accuracy and integrity of information furnished to CRCs. Examiners also identified deficiencies in furnishers' policies and procedures for correcting information after determining it to be inaccurate, finding that, for example, such deficiencies allowed inaccuracies to persist for over a year on average before being remediated.</P>
                <P>In response to these findings, furnishers are implementing and/or enhancing written policies and procedures to address the identified procedural deficiencies.</P>
                <HD SOURCE="HD2">2.3 Short-Term Small Dollar Lending</HD>
                <P>The short-term small dollar lending market continues to evolve, and as part of this market, the Buy Now, Pay Later market, where lenders advertise buying products over four payments, has expanded rapidly over the past few years. The paycheck advance market, where lenders tie funding amounts to accrued or estimated wages and those amounts are repayable on the next payday or withheld from the next paycheck, also has expanded rapidly in recent years. Firms sometimes market these products as “earned wage” products. Certain Buy Now, Pay Later firms and certain paycheck advance firms consented to CFPB's examination authority. Across these examinations, examiners identified a number of unfair, deceptive, or abusive acts or practices. In addition to the examinations giving rise to the findings discussed in this section, CFPB staff worked with certain State regulators on their examinations of Buy Now Pay Later firms.</P>
                <HD SOURCE="HD3">2.3.1 Failing To Timely Resolve Consumer Disputes</HD>
                <P>Consumers who used Buy Now, Pay Later loans to purchase products or services frequently alleged that the merchants did not provide the items or services as agreed or communicated other disputes to the lender. Lenders engaged in unfair acts or practices by failing to timely resolve consumer disputes in which consumers alleged they were owed refunds for various reasons, such as where the delay was contrary to the dispute policy on its website regarding dispute resolution timelines. These delays were long, with hundreds of consumers deprived of funds for months at a time. Consumers incurred substantial injury in the form of deprivation of funds that should have been refunded in a timely manner. Additionally, consumers whose claims were denied may have been required to make full payments at unpredictable times after delayed investigations during which they were not permitted to make payments. The injuries were not reasonably avoidable as consumers lacked control over the dispute resolution process. The substantial injuries to consumers were not outweighed by any countervailing benefits to consumers or competition. In response to these findings, the Buy Now, Pay Later lenders refunded the amounts at issue and implemented monitoring to eliminate delayed resolutions.</P>
                <HD SOURCE="HD3">2.3.2 Misrepresenting Loan Costs or Terms</HD>
                <P>Buy Now, Pay Later lenders worked with merchant partners to advertise their loans, and in certain instances, the merchant partner websites advertised incorrect loan costs or terms. The lenders exercised control and approval rights over these advertisements. Thus, the lenders engaged in a deceptive act or practice when its merchant partners ran advertisements on their behalf that included false representations. These advertisements misled or were likely to mislead reasonable consumers, and the deceptive representations were material because they related to the cost and terms of the loans as payment methods. In response to these findings, the lenders contacted the relevant merchants to ensure they updated their websites and refunded overcharges to customers. They also enhanced the marketing review process across merchant partners.</P>
                <HD SOURCE="HD3">2.3.3 Denying Credit Based On Payment Processing Deficiencies on Earlier Loans</HD>
                <P>
                    Buy Now, Pay Later lenders' payment platforms prevented consumers with loan balances below $1 from making payments. Subsequently, the lenders denied those consumers' loan applications on the basis that consumers had not paid those balances. The lenders engaged in an unfair act or practice by preventing consumers with loan balances below $1 from making 
                    <PRTPAGE P="612"/>
                    payments, while denying those consumers' loan applications because of those same balances. This conduct caused or was likely to cause substantial injury, as it resulted in the lenders denying additional credit for consumers with outstanding balances of less than $1. In addition, consumers may have incurred costs attempting to secure alternative credit. Consumers also may have spent time contacting the lenders to resolve these outstanding balances. This practice was not reasonably avoidable, as the lenders did not allow consumers to make payments to cure an outstanding balance of less than $1. The substantial injury to consumers was not outweighed by any countervailing benefits to consumers or competition. In response to these findings, Supervision directed the lenders to enhance system capabilities to allow consumers to pay off or automatically remove loan balances of less than $1 and refrain from preventing consumers from obtaining additional loans if they have balances of less than $1.
                </P>
                <HD SOURCE="HD3">2.3.4 Designing Consumer Interfaces To Include Misrepresentations About Uses and Benefits of Tips and Tipping</HD>
                <P>Examiners found that lenders designed consumer interfaces for paycheck advance products—sometimes marketed as “earned wage” products—to include statements and illustrations representing that if consumers paid tips, the tips would help specific numbers of customers and were a way to help other borrowers. In fact, lenders added tips to general revenues.</P>
                <P>
                    A representation, omission, act, or practice is deceptive when: (1) the representation, omission, act or practice misleads or is likely to mislead the consumer; (2) the consumer's interpretation of the representation, omission, act or practice is reasonable under the circumstances; and (3) the misleading representation, omission, act or practice is material.
                    <SU>22</SU>
                    <FTREF/>
                     Examiners found lenders engaged in deceptive acts and practices when they misled or were likely to mislead reasonable consumers through written and graphic references that correlated amounts of tips provided to numbers of people helped. They also misled or were likely to mislead reasonable consumers into believing tips directly benefited other customers, although in reality they added tips to general revenue. These representations were material because they were likely to affect customers' choices regarding tipping, including whether to tip and how much.
                </P>
                <FTNT>
                    <P>
                        <SU>22</SU>
                         12 U.S.C. 5531.
                    </P>
                </FTNT>
                <P>
                    An abusive act or practice: (1) materially interferes with the ability of a consumer to understand a term or condition of a consumer financial product or service; or (2) takes unreasonable advantage of: a lack of understanding on the part of the consumer of the material risks, costs or conditions of the product or service; the ability of the consumer to protect the interest of the consumer in selecting or using a financial product or service; or the reasonable reliance by the consumer on a covered person to act in the interest of the consumer.
                    <SU>23</SU>
                    <FTREF/>
                     Examiners found that lenders engaged in abusive acts or practices when they took unreasonable advantage of consumers' inability to protect their interests in selecting or using consumer financial products or services. Lenders took unreasonable advantage of superior information in knowing that tips went to general revenue. Under the circumstances and given the misrepresentations, customers lacked the ability to make fully informed choices about whether and how much to tip, which affected the ability to protect their monetary interests. Lenders gained unreasonable advantages when they designed interfaces to take advantage of consumers' misimpressions, based on specific consumer research they conducted, and profited from tips that would not have been made or were higher than if customers had known tips went to general revenue.
                </P>
                <FTNT>
                    <P>
                        <SU>23</SU>
                         12 U.S.C. 5535(a)(1)(B). 
                        <E T="03">See also</E>
                         CFPB, 
                        <E T="03">Policy on Abusive Acts or Practices,</E>
                         (Apr. 3, 2023), 
                        <E T="03">https://www.consumerfinance.gov/compliance/supervisory-guidance/policy-statement-on-abusiveness/#1.</E>
                    </P>
                </FTNT>
                <HD SOURCE="HD3">2.3.5 Blocking Loan Account Closure and Continuing to Debit Deposit Accounts</HD>
                <P>Examiners found that lenders engaged in deceptive acts and practices when they prevented paycheck advance product consumers from closing their loan accounts until they resolved pending debits, and continued debiting consumer deposit accounts, despite representations that accounts could be closed at any time and that lenders would not engage in collection activity. Lenders misled or were likely to mislead consumers through confusing and conflicting representations about how to close loan accounts and that consumers could cancel agreements and use of services at any time, the only consequences of nonpayment being placing loan accounts on hold. Consumers could reasonably interpret lenders' statements to mean that they could cancel agreements and services at any time, along with pending debits, and would not be blocked from closing their loan accounts until pending debits were processed. Lenders' representations were material because they were likely to affect consumer choice regarding whether to use the service in the first place and how they might employ funds differently if consumers understood debits continued after attempted account closure.</P>
                <P>Examiners also found that lenders engaged in abusive acts or practices when they took unreasonable advantage of consumers' inability to protect their interests when they blocked consumers from closing their loan accounts and continued to attempt to debit their deposit accounts, despite statements that consumers could close their accounts any time and that lenders would not engage in collection activity. Consumers could not protect their interests in selecting or using paycheck advance products because they were blocked from closing their loan accounts and were subject to repeated debits, despite representations that they could close their loan accounts at any time and lenders would not take repayment actions against them. At account opening, lenders led consumers to believe they could close their accounts anytime and avoid repeated debits. But after attempting account closure, consumers were subject to repeated debits and potentially to third-party fees. Lenders gained unreasonable advantage by inducing consumers to take out paycheck advance products under false premises, gaining more loan accounts than they otherwise would have.</P>
                <HD SOURCE="HD3">2.3.6 Blocking Funds Transfers</HD>
                <P>
                    Examiners found that lenders engaged in unfair acts or practices when technology failures resulted in consumer having certain transfers blocked from linked deposit accounts to other personal accounts. Specifically, lenders offered a payment card linked to a particular deposit account in concert with the paycheck advance product, and during a specific time period, consumers who had not repaid the paycheck advances timely and had balances in these linked accounts were unable to access their funds in a timely manner. Lenders caused substantial injury because consumers were unable to access their funds in a timely manner and were denied access to funds. Other injury included time spent and trouble and aggravation caused when consumers tried to cure the problem. Consumers could not reasonably avoid or anticipate the injury because they were not warned of the error and could not resolve it themselves. The 
                    <PRTPAGE P="613"/>
                    underlying technology failures and their consequences provided no discernible benefit to consumers or competition.
                </P>
                <HD SOURCE="HD1">3. Supervisory Developments</HD>
                <P>
                    Set forth below are select supervision program developments including final rules and orders that have been issued since the last edition of 
                    <E T="03">Supervisory Highlights.</E>
                </P>
                <HD SOURCE="HD3">3.1.1 CFPB Issues Final Rule Governing Overdraft Lending at Very Large Financial Institutions</HD>
                <P>
                    On December 12, 2024, the CFPB issued a final rule related to overdraft lending.
                    <SU>24</SU>
                    <FTREF/>
                     The final rule updates the Federal regulations governing overdraft fees for financial institutions with more than $10 billion in assets. Extensions of overdraft credit provided by these institutions will now adhere to the consumer protections required of similarly situated products, unless the overdraft fee is $5 or less, or otherwise only recovers estimated costs and losses. The rule will allow consumers to better comparison shop across credit products and provides substantive protections that apply to other consumer credit.
                </P>
                <FTNT>
                    <P>
                        <SU>24</SU>
                         The final rule is available at: 
                        <E T="03">cfpb_overdraft-regulatory-text-and-commentary_2024-12.pdf.</E>
                    </P>
                </FTNT>
                <HD SOURCE="HD3">3.1.2 CFPB Orders Federal Supervision of Google Following Contested Designation</HD>
                <P>
                    On December 6, 2024, the CFPB published an order establishing supervisory authority over Google Payment Corp.
                    <SU>25</SU>
                    <FTREF/>
                     This was the CFPB's second supervisory designation order in a contested matter. While Google Payment Corp. is already subject to CFPB's enforcement jurisdiction, the CFPB determined that Google Payment Corp. met the legal requirements for supervision.
                </P>
                <FTNT>
                    <P>
                        <SU>25</SU>
                         The Decision and Order is available at: 
                        <E T="03">cfpb_Publication-Redacted-Decision-and-Order-Designating-Google-Payment-for-Su_6EZQyMz.pdf.</E>
                    </P>
                </FTNT>
                <HD SOURCE="HD3">3.1.3 CFPB Issues Final Rule Defining Larger Participants of a Market For General-Use Digital Consumer Payment Applications</HD>
                <P>
                    On November 21, 2024, the CFPB issued a final rule to establish authority over nonbank covered persons that are larger participants of a market for providing general-use digital consumer payment applications.
                    <SU>26</SU>
                    <FTREF/>
                     The rule, which takes effect January 9, 2025, will allow the CFPB to supervise these firms, which provide widely-used payment wallet and funds transfer apps. Nonbank firms qualify as larger participants if their general-use digital consumer payment applications facilitate more than 50 million consumer payment transactions denominated in U.S. dollars per year and they are not small business concerns as defined by Small Business Administration regulations. The CFPB estimates that nonbank larger participants in this market collectively facilitated over 13 billion such consumer payment transactions annually. The rule will help the CFPB to ensure that these companies follow Federal consumer financial law just like large banks and credit unions already supervised by the CFPB. The rule also will help the CFPB to detect and assess risks to consumers and markets including emerging risks.
                </P>
                <FTNT>
                    <P>
                        <SU>26</SU>
                         The final rule, as published in the 
                        <E T="04">Federal Register</E>
                        , 89 FR 99582 (Dec. 10, 2024).
                    </P>
                </FTNT>
                <SIG>
                    <NAME>Rohit Chopra,</NAME>
                    <TITLE>Director, Consumer Financial Protection Bureau.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31670 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4810-AM-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">CONSUMER PRODUCT SAFETY COMMISSION</AGENCY>
                <DEPDOC>[Docket No. CPSC-2024-0045]</DEPDOC>
                <SUBJECT>Agency Information Collection Activities; Proposed Collection; Comment Request; Bathtub Slip Resistance Study</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Consumer Product Safety Commission.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of information collection; request for comment.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>As required by the Paperwork Reduction Act of 1995, the Consumer Product Safety Commission (CPSC or Commission) requests comments on a request for approval from the Office of Management and Budget (OMB) for a new information collection. The proposed collection is a bathtub slip resistance study to support work on a voluntary Safety Standard for Bathtub and Shower Structure. Before CPSC can collect this information from the public, it must solicit public comment on this proposed collection of information and receive OMB approval. This notice describes the collection of information for which CPSC intends to seek OMB approval.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Submit comments on the collection of information by March 7, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may submit comments, identified by Docket No. CPSC-2024-0045, within 60 days of publication of this notice by any of the following methods:</P>
                    <P>
                        <E T="03">Electronic Submissions:</E>
                         Submit electronic comments to the Federal eRulemaking Portal at: 
                        <E T="03">http://www.regulations.gov.</E>
                         Follow the instructions for submitting comments. Do not submit through this website: confidential business information, trade secret information, or other sensitive or protected information that you do not want to be available to the public. The Commission typically does not accept comments submitted by email, except as described below.
                    </P>
                    <P>
                        <E T="03">Mail/hand delivery/courier/written submissions:</E>
                         CPSC encourages you to submit electronic comments by using the Federal eRulemaking Portal. You may, however, submit comments by mail/hand delivery/courier to: Office of the Secretary, Consumer Product Safety Commission, 4330 East West Highway, Bethesda, MD 20814; telephone (301) 504-7923.
                    </P>
                    <P>
                        <E T="03">Instructions:</E>
                         All submissions received must include the agency name and docket number for this notice. CPSC may post all comments without change, including any personal identifiers, contact information, or other personal information provided, to: 
                        <E T="03">http://www.regulations.gov.</E>
                         If you wish to submit confidential business information, trade secret information, or other sensitive or protected information that you do not want to be available to the public, you may submit such comments by mail, hand delivery, or courier, or you may email them to 
                        <E T="03">cpsc-os@cpsc.gov.</E>
                    </P>
                    <P>
                        <E T="03">Docket:</E>
                         For access to the docket to read background documents or comments received, go to: 
                        <E T="03">https://www.regulations.gov,</E>
                         insert docket number CPSC-2024-0045 into the “Search” box, and follow the prompts.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Cynthia Gillham, Consumer Product Safety Commission, 4330 East West Highway, Bethesda, MD 20814; (301) 504-7791, or by email to: 
                        <E T="03">pra@cpsc.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    Under the Paperwork Reduction Act of 1995 (44 U.S.C. 3501-3521), before an agency submits a proposed collection of information to OMB for approval, it must first publish a document in the 
                    <E T="04">Federal Register</E>
                     providing a 60-day comment period and otherwise consult with members of the public and affected agencies concerning the proposed collection of information. In this notice we provide the estimated burden associated with a bathtub slip resistance study necessary to update information to support work on a voluntary Safety Standard for Bathtub and Shower Structure to replace ASTM F462, 
                    <E T="03">
                        Standard Consumer Safety 
                        <PRTPAGE P="614"/>
                        Specification for Slip-Resistant Bathing Facilities,
                    </E>
                     which ASTM withdrew in 2016.
                    <SU>1</SU>
                    <FTREF/>
                     Under the PRA, an agency must publish the following information:
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         ASTM F462-79 
                        <E T="03">Standard Consumer Safety Specification for Slip-Resistant Bathing Facilities</E>
                         (2007) (withdrawn 2016), 
                        <E T="03">available at https://www.astm.org/f0462-79r07.html.</E>
                    </P>
                </FTNT>
                <P>• A title for the collection of information;</P>
                <P>• A summary of the collection of information;</P>
                <P>• A brief description of the need for the information and the proposed use of the information;</P>
                <P>• A description of the likely respondents and proposed frequency of response to the collection of information;</P>
                <P>• An estimate of the burden that will result from the collection of information; and</P>
                <P>• Notice that comments may be submitted to the agency and OMB.</P>
                <P>
                    44 U.S.C. 3507(a)(1)(D). In accordance with this requirement, the Commission provides the following information: 
                    <SU>2</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         On December 26, 2024, the Commission voted (5-0) to publish this notice.
                    </P>
                </FTNT>
                <P>
                    <E T="03">Title:</E>
                     Bathtub Slip Resistance Study.
                </P>
                <P>
                    <E T="03">OMB Number:</E>
                     New.
                </P>
                <P>
                    <E T="03">Type of Request:</E>
                     New information collection requirement.
                </P>
                <P>
                    <E T="03">Type of Review Requested:</E>
                     Regular.
                </P>
                <P>
                    <E T="03">Requested Expiration Date of Approval:</E>
                     Three years from date of approval.
                </P>
                <P>
                    <E T="03">Summary of the Collection of Information:</E>
                     The objective of this study is to conduct human slip research on three bathtubs on the market and to measure the friction demand of participants stepping into and out of the bathtubs when dry and wet. CPSC contracted with Arizona State University (ASU) to conduct this study. Participants will be recruited from the Phoenix, Arizona metro area. The experiments will be conducted at ASU's Locomotion Research Laboratory. The study will involve a total of three sessions to test three bathtub surfaces, where participants will walk into the tub and step out, while wearing fall arresting harness systems for safety. During these sessions, resistance forces under the foot and motion of the foot movements will be measured. The study will quantify the minimum frictional performance required for a bathing surface to reduce slips and falls. CPSC staff will share the results of the study with the ASTM F15.03 Committee on Safety Standards for Bathtub and Shower Structure working on replacing ASTM F462.
                </P>
                <P>
                    <E T="03">Description of the Need for the Information and Proposed Use of the Information:</E>
                     Falls are the leading cause of injury and death for older adults 65 and older.
                    <SU>3</SU>
                    <FTREF/>
                     Information collected as part of the bathtub slip resistance study is needed initially to support CPSC staff in efforts to work with the ASTM F15.03 Committee on Safety Standards for Bathtub and Shower Structures to replace the obsolete ASTM F462 standard for bathing surface friction that ASTM withdrew in 2016. This study will be used to inform CPSC staff of major requirements needed to achieve an efficient and effective slip-resistance standard.
                </P>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         Chowdhury et al., U.S. Consumer Prod. Safety Comm'n., 
                        <E T="03">Consumer Product-related Injuries and Deaths Among Adults 65 Years of Age and Older,</E>
                         67-68 (2021), 
                        <E T="03">available at https://tinyurl.com/2t88v33m.</E>
                    </P>
                </FTNT>
                <P>
                    <E T="03">Affected Public:</E>
                     Adults between ages 18 and 95 years old.
                </P>
                <P>
                    <E T="03">Estimated Number of Respondents:</E>
                     We expect up to 200 respondents annually. Over the full authorized period of the study, which is three years, up to 600 respondents may participate.
                </P>
                <P>
                    <E T="03">Frequency:</E>
                     One.
                </P>
                <P>
                    <E T="03">Total Estimated Annual Burden:</E>
                     Though response times will vary, on average, it will take 2.5 hours for respondents to fully participate in the study. Therefore, the annual estimated response burden is 500 hours (200 responses × 2.5 hours per response).
                </P>
                <P>
                    <E T="03">Total Estimated Annual Burden Cost:</E>
                     There are no costs to respondents and no respondent recordkeeping requirements associated with the study. There are no operating, maintenance, or capital costs associated with the collection. Participants will receive $100 for participation in the study.
                </P>
                <P>
                    <E T="03">Request for Comments:</E>
                </P>
                <P>
                    CPSC requests that interested parties submit comments regarding this proposed information collection (see the 
                    <E T="02">ADDRESSES</E>
                     section at the beginning of this notice). Pursuant to 44 U.S.C. 3506(c)(2)(A), the Commission specifically invites comments on:
                </P>
                <P>• Whether the proposed collection of information is necessary for the proper performance of CPSC's functions, including whether the information will have practical utility;</P>
                <P>• The accuracy of CPSC's estimate of the burden of the proposed collection of information;</P>
                <P>• Ways to enhance the quality, utility, and clarity of the information the Commission proposes to collect; and</P>
                <P>• Ways to minimize the burden of the collection of information on respondents, including through the use of automated collection techniques when appropriate, and other forms of information technology.</P>
                <SIG>
                    <NAME>Alberta E. Mills,</NAME>
                    <TITLE>Secretary, Consumer Product Safety Commission.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31623 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6355-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF DEFENSE</AGENCY>
                <SUBAGY>Office of the Secretary</SUBAGY>
                <DEPDOC>[Transmittal No. 23-73]</DEPDOC>
                <SUBJECT>Arms Sales Notification</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Defense Security Cooperation Agency, Department of Defense(DoD).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Arms sales notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The DoD is publishing the unclassified text of an arms sales notification.</P>
                </SUM>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Pamela Young at (703) 953-6092, 
                        <E T="03">pamela.a.young14.civ@mail.mil,</E>
                         or 
                        <E T="03">dsca.ncr.rsrcmgmt.list.cns-mbx@mail.mil.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>This 36(b)(1) arms sales notification is published to fulfill the requirements of section 155 of Public Law 104-164 dated July 21, 1996. The following is a copy of a letter to the Speaker of the House of Representatives with attached Transmittal 23-73, Policy Justification, and Sensitivity of Technology.</P>
                <SIG>
                    <DATED>Dated: December 31, 2024.</DATED>
                    <NAME>Stephanie J. Bost,</NAME>
                    <TITLE>Alternate OSD Federal Register Liaison Officer, Department of Defense.</TITLE>
                </SIG>
                <BILCOD>BILLING CODE 6001-FR-P</BILCOD>
                <GPH SPAN="3" DEEP="522">
                    <PRTPAGE P="615"/>
                    <GID>EN06JA25.009</GID>
                </GPH>
                <BILCOD>BILLING CODE 6001-FR-C</BILCOD>
                <HD SOURCE="HD3">Transmittal No. 23-73</HD>
                <HD SOURCE="HD3">Notice of Proposed Issuance of Letter of Offer Pursuant to Section 36(b)(1) of the Arms Export Control Act, as amended</HD>
                <P>
                    (i) 
                    <E T="03">Prospective Purchaser:</E>
                     Government of the Netherlands
                </P>
                <P>
                    (ii) 
                    <E T="03">Total Estimated Value:</E>
                </P>
                <GPOTABLE COLS="2" OPTS="L0,tp0,p0,8/9,g1,t1,i1" CDEF="s30,xs56">
                    <TTITLE> </TTITLE>
                    <BOXHD>
                        <CHED H="1"> </CHED>
                        <CHED H="1"> </CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">Major Defense Equipment * </ENT>
                        <ENT>$140 million</ENT>
                    </ROW>
                    <ROW RUL="n,s">
                        <ENT I="01">Other </ENT>
                        <ENT>$ 10 million</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="02">TOTAL </ENT>
                        <ENT>$150 million</ENT>
                    </ROW>
                </GPOTABLE>
                <P>
                    (iii) 
                    <E T="03">Description and Quantity or Quantities of Articles or Services under Consideration for Purchase:</E>
                </P>
                <FP SOURCE="FP-2">
                    <E T="03">Major Defense Equipment (MDE):</E>
                </FP>
                <FP SOURCE="FP1-2">Up to three hundred eighty-six (386) Hellfire Air-to-Ground Missiles, AGM-114R2</FP>
                <FP SOURCE="FP-2">
                    <E T="03">Non-MDE:</E>
                </FP>
                <FP SOURCE="FP1-2">Also included is U.S. Army Aviation and Missile Command (AMCOM) Security Assistance Management Directorate (SAMD) technical assistance; Tactical Aviation and Ground Munitions (TAGM) Project Office technical assistance; non-standard books, publications, and other Hellfire publications; integration support; and other related elements of logistics and program support.</FP>
                <P>
                    (iv) 
                    <E T="03">Military Department:</E>
                     Army (NE-B-YAY, NE-B-YAZ)
                </P>
                <P>
                    (v) 
                    <E T="03">Prior Related Cases, if any:</E>
                     NE-B-WFV
                </P>
                <P>
                    (vi) 
                    <E T="03">Sales Commission, Fee, etc., Paid, Offered, or Agreed to be Paid:</E>
                     None known at this time
                    <PRTPAGE P="616"/>
                </P>
                <P>
                    (vii) 
                    <E T="03">Sensitivity of Technology Contained in the Defense Article or Defense Services Proposed to be Sold:</E>
                     See Attached Annex
                </P>
                <P>
                    (viii) 
                    <E T="03">Date Report Delivered to Congress:</E>
                     February 2, 2024
                </P>
                <P>* As defined in Section 47(6) of the Arms Export Control Act.</P>
                <HD SOURCE="HD2">POLICY JUSTIFICATION</HD>
                <HD SOURCE="HD2">The Netherlands—Hellfire Missiles</HD>
                <P>The Government of the Netherlands has requested to buy up to three hundred eighty-six (386) Hellfire Air-to-Ground Missiles, AGM-114R2. Also included is U.S. Army Aviation and Missile Command (AMCOM) Security Assistance Management Directorate (SAMD) technical assistance; Tactical Aviation and Ground Munitions (TAGM) Project Office technical assistance; non-standard books, publications, and other Hellfire publications; integration support; and other related elements of logistics and program support. The estimated total cost is $150 million.</P>
                <P>This proposed sale will support the foreign policy goals and national security objectives of the United States (U.S.) by improving the security of a NATO Ally that is a force for political stability and economic progress in Europe.</P>
                <P>The proposed sale will improve the Netherlands' capability to strengthen its homeland defense and deter regional threats. This will contribute to its military goals of updating capability while further enhancing interoperability with the U.S. and other allies. The Netherlands will have no difficulty absorbing this equipment into its armed forces.</P>
                <P>The proposed sale of this equipment and support will not alter the basic military balance in the region.</P>
                <P>The principal contractor will be Lockheed Martin Corporation in Orlando, FL. The purchaser typically requests offsets. Any offset agreement will be defined in negotiations between the purchaser and the contractor(s).</P>
                <P>Implementation of this proposed sale will require U.S. Government or contractor representatives to travel to the Netherlands for program management reviews to support the program.</P>
                <P>There will be no adverse impact on U.S. defense readiness as a result of this proposed sale.</P>
                <HD SOURCE="HD3">Transmittal No. 23-73</HD>
                <HD SOURCE="HD3">Notice of Proposed Issuance of Letter of Offer Pursuant to Section 36(b)(1) of the Arms Export Control Act, as amended</HD>
                <HD SOURCE="HD3">Annex</HD>
                <HD SOURCE="HD3">Item No. vii</HD>
                <P>
                    (vii) 
                    <E T="03">Sensitivity of Technology:</E>
                </P>
                <P>1. The AGM-114R2 Hellfire Missile is used against heavy and light armored targets, thin skinned vehicles, urban structures, bunkers, caves, and personnel. The missile is Inertial Measurement Unit (IMU) based, with a variable delay fuse, and improved safety and reliability.</P>
                <P>2. The highest level of classification of defense articles, components, and services included in this potential sale is SECRET.</P>
                <P>3. If a technologically advanced adversary were to obtain knowledge of the specific hardware and software elements, the information could be used to develop countermeasures that might reduce weapon system effectiveness or be used in the development of a system with similar or advanced capabilities.</P>
                <P>4. A determination has been made that the Government of the Netherlands can provide substantially the same degree of protection for the sensitive technology being released as the U.S. Government. This sale is necessary in furtherance of the U.S. foreign policy and national security objectives outlined in the Policy Justification.</P>
                <P>5. All defense articles and services listed in this transmittal have been authorized for release and export to the Government of the Netherlands.</P>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31698 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6001-FR-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF DEFENSE</AGENCY>
                <SUBAGY>Office of the Secretary</SUBAGY>
                <DEPDOC>[Transmittal No. 24-23]</DEPDOC>
                <SUBJECT>Arms Sales Notification</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Defense Security Cooperation Agency, Department of Defense (DoD).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Arms sales notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The DoD is publishing the unclassified text of an arms sales notification.</P>
                </SUM>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Pamela Young at (703) 953-6092, 
                        <E T="03">pamela.a.young14.civ@mail.mil,</E>
                         or 
                        <E T="03">dsca.ncr.rsrcmgmt.list.cns-mbx@mail.mil.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>This 36(b)(1) arms sales notification is published to fulfill the requirements of section 155 of Public Law 104-164 dated July 21, 1996. The following is a copy of a letter to the Speaker of the House of Representatives with attached Transmittal 24-23, Policy Justification, and Sensitivity of Technology.</P>
                <SIG>
                    <DATED>Dated: December 31, 2024.</DATED>
                    <NAME>Stephanie J. Bost,</NAME>
                    <TITLE>Alternate OSD Federal Register Liaison Officer, Department of Defense.</TITLE>
                </SIG>
                <BILCOD>BILLING CODE 6001-FR-P</BILCOD>
                <GPH SPAN="3" DEEP="547">
                    <PRTPAGE P="617"/>
                    <GID>EN06JA25.010</GID>
                </GPH>
                <BILCOD>BILLING CODE 6001-FR-C</BILCOD>
                <HD SOURCE="HD3">Transmittal No. 24-23</HD>
                <HD SOURCE="HD3">Notice of Proposed Issuance of Letter of Offer Pursuant to Section 36(b)(1) of the Arms Export Control Act, as amended</HD>
                <P>
                    (i) 
                    <E T="03">Prospective Purchaser:</E>
                     Government of Croatia
                </P>
                <P>
                    (ii) 
                    <E T="03">Total Estimated Value:</E>
                </P>
                <GPOTABLE COLS="2" OPTS="L0,tp0,p0,8/9,g1,t1,i1" CDEF="s30,xs56">
                    <TTITLE> </TTITLE>
                    <BOXHD>
                        <CHED H="1"> </CHED>
                        <CHED H="1"> </CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">Major Defense Equipment * </ENT>
                        <ENT>$250 million</ENT>
                    </ROW>
                    <ROW RUL="n,s">
                        <ENT I="01">Other</ENT>
                        <ENT>$250 million</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="02">TOTAL</ENT>
                        <ENT>$500 million</ENT>
                    </ROW>
                </GPOTABLE>
                <P>Funding Source: Foreign Military Financing and National Funds</P>
                <P>
                    (iii) 
                    <E T="03">Description and Quantity or Quantities of Articles or Services under Consideration for Purchase:</E>
                </P>
                <FP SOURCE="FP-2">
                    <E T="03">Major Defense Equipment (MDE):</E>
                </FP>
                <FP SOURCE="FP1-2">Eight (8) UH-60M Black Hawk helicopters</FP>
                <FP SOURCE="FP1-2">Nineteen (19) T700-GE 701D engines (16 installed, 3 spares)</FP>
                <FP SOURCE="FP1-2">Twenty (20) AN/ARC-231A RT-1987 very high frequency (VHF)/ultra high frequency (UHF)/Line of Sight (LOS) satellite communications (SATCOM) radios</FP>
                <FP SOURCE="FP1-2">Ten (10) AN/AAR-57 Counter Missile Warning Systems (CMWS)</FP>
                <FP SOURCE="FP1-2">
                    Twenty (20) H-764U Embedded Global Position Systems with 
                    <PRTPAGE P="618"/>
                    Inertial Navigation (EGI) and Selective Availability Anti-Spoofing Module (SAASM) (or future replacement)
                </FP>
                <FP SOURCE="FP1-2">Eighteen (18) M240H machine guns</FP>
                <FP SOURCE="FP-2">
                    <E T="03">Non-MDE:</E>
                </FP>
                <FP SOURCE="FP1-2">Also included are: AN/ARC-231 RT-1808A (or future replacement) VHF/UHF/LOS SATCOM radios; APR-39C(V)1/4 radar warning receivers; AVR-2B laser detecting sets; APX-123A Identification Friend or Foe (IFF) transponders (or future replacement); ARC-220 high frequency (HF) radio with KY-100M; VRC-100 ground stations; AN/PYQ-10 Simple Key Loader (SKL); KIV-77 Common Identification Friend or Foe (IFF) crypto applique computers; KY-100M; communications security (COMSEC) encryption devices AN/ARN-147(V) VHF Omni-Directional Range (VOR)/instrument landing system (ILS) receiver radio; AN/ARN-149(V) low frequency (LF)/automatic direction finder (ADF) radio receiver; AN/ARN-153 tactical air navigation system (TACAN) receiver-transmitter; AN/APN-209 radar altimeter; AN/ARC-210 radios; EBC-406HM emergency locator transmitter (ELT); Encrypted Aircraft Wireless Intercommunications Systems (EAWIS); Improved Heads-Up Display (IHUD); signal data converters for IHUD; signal data converters for heads-up display (HUD); forward-looking infrared (FLIR) with electro-optical and infrared (E.O./IR) capabilities; E.O./IR cabin monitoring systems; E.O./IR digital video recorder; AN/ARC-201D RT-1478D (or future replacement); Enhanced Ballistic Armor Protection Systems (EBAPS); Internal Auxiliary Fuel Tank Systems (IAFTS); Fast Rope Insertion &amp; Extraction System (FRIES); External Rescue Hoist (ERH); rescue hoist equipment sets; Dual Patient Litter System (DPLS) Sets; Martin Baker palletized Crew Chief/Gunner seats with crashworthy floor structural modifications; External Stores Support System (ESSS); Integrated Tow Plates Production Assets; universal software loading kits; 60k volt-ampere (VA) generator kits; instrument panel sets; external gun mount systems; Black Hawk Aircrew Trainer (BAT); Black Hawk Maintenance Trainer (BHMT-M); Black Hawk Avionics Trainer; Maintenance Blended Reconfigurable Avionics Trainer (MBRAT); training devices; helmets; transportation; organizational equipment; spare and repair parts; support equipment; tools and test equipment; technical data and publications; personnel training and training equipment; United States (U.S.) government and contractor engineering, technical, and logistics support services; and other related elements of logistics and program support.</FP>
                <P>
                    (iv) 
                    <E T="03">Military Department:</E>
                     Army (HR-B-UCH)
                </P>
                <P>
                    (v) 
                    <E T="03">Prior Related Cases, if any:</E>
                     7L-B-UGK, HR-B-UBQ, HR-B-UBT
                </P>
                <P>
                    (vi) 
                    <E T="03">Sales Commission, Fee, etc., Paid, Offered, or Agreed to be Paid:</E>
                     None
                </P>
                <P>
                    (vii) 
                    <E T="03">Sensitivity of Technology Contained in the Defense Article or Defense Services Proposed to be Sold:</E>
                     See Attached Annex
                </P>
                <P>
                    (viii) 
                    <E T="03">Date Report Delivered to Congress:</E>
                     January 26, 2024
                </P>
                <P>*As defined in Section 47(6) of the Arms Export Control Act.</P>
                <HD SOURCE="HD2">POLICY JUSTIFICATION</HD>
                <HD SOURCE="HD2">Croatia—UH-60M Black Hawk Helicopters</HD>
                <P>The Government of Croatia has requested to buy eight (8) UH-60M Black Hawk helicopters; nineteen (19) T700-GE 701D engines (16 installed, 3 spares); twenty (20) AN/ARC-231A RT-1987 very high frequency (VHF)/ultra high frequency (UHF)/Line of Sight (LOS) satellite communications (SATCOM) radios; ten (10) AN/AAR-57 Counter Missile Warning Systems (CMWS); twenty (20) H-764U Embedded Global Position Systems with Inertial Navigation (EGI) and Selective Availability Anti-Spoofing Module (SAASM) (or future replacement); and eighteen (18) M240H machine guns. Also included are: AN/ARC-231 RT-1808A (or future replacement) VHF/UHF/LOS SATCOM radios; APR-39C(V)1/4 radar warning receivers; AVR-2B laser detecting sets; APX-123A Identification Friend or Foe (IFF) transponders (or future replacement); ARC-220 high frequency (HF) radio with KY-100M; VRC-100 ground stations; AN/PYQ-10 Simple Key Loader (SKL); KIV-77 Common Identification Friend or Foe (IFF) crypto applique computers; KY-100M; communications security (COMSEC) encryption devices AN/ARN-147(V) VHF Omni-Directional Range (VOR)/instrument landing system (ILS) receiver radio; AN/ARN-149(V) low frequency (LF)/automatic direction finder (ADF) radio receiver; AN/ARN-153 tactical air navigation system (TACAN) receiver-transmitter; AN/APN-209 radar altimeter; AN/ARC-210 radios; EBC-406HM emergency locator transmitter (ELT); Encrypted Aircraft Wireless Intercommunications Systems (EAWIS); Improved Heads-Up Display (IHUD); signal data converters for IHUD; signal data converters for heads-up display (HUD); forward-looking infrared (FLIR) with electro-optical and infrared (E.O./IR) capabilities; E.O./IR cabin monitoring systems; E.O./IR digital video recorder; AN/ARC-201D RT-1478D (or future replacement); Enhanced Ballistic Armor Protection Systems (EBAPS); Internal Auxiliary Fuel Tank Systems (IAFTS); Fast Rope Insertion &amp; Extraction System (FRIES); External Rescue Hoist (ERH); rescue hoist equipment sets; Dual Patient Litter System (DPLS) Sets; Martin Baker palletized Crew Chief/Gunner seats with crashworthy floor structural modifications; External Stores Support System (ESSS); Integrated Tow Plates Production Assets; universal software loading kits; 60k volt-ampere (VA) generator kits; instrument panel sets; external gun mount systems; Black Hawk Aircrew Trainer (BAT); Black Hawk Maintenance Trainer (BHMT-M); Black Hawk Avionics Trainer; Maintenance Blended Reconfigurable Avionics Trainer (MBRAT); training devices; helmets; transportation; organizational equipment; spare and repair parts; support equipment; tools and test equipment; technical data and publications; personnel training and training equipment; U.S. government and contractor engineering, technical, and logistics support services; and other related elements of logistics and program support. The estimated total cost is $500 million.</P>
                <P>This proposed sale will support the foreign policy and national security of the U.S. by improving the security of a NATO Ally that continues to be an important force for political stability and economic progress in Europe.</P>
                <P>The proposed sale will improve Croatia's capability to deter current and future threats and support coalition operations as well as promote interoperability with the U.S. and other NATO forces. Croatia will have no difficulty absorbing this equipment into its armed forces.</P>
                <P>The principal contractor will be Lockheed Martin/Sikorsky, in Stratford, CT. There are no known offset agreements in connection with this potential sale.</P>
                <P>
                    Implementation of this proposed sale will require approximately fifteen (15) U.S. Government and/or fifteen (15) contractor representatives to travel to Croatia for an extended period for equipment de-processing/fielding, 
                    <PRTPAGE P="619"/>
                    system checkout, training, and technical and logistics support.
                </P>
                <P>There will be no adverse impact on U.S. defense readiness as a result of this proposed sale.</P>
                <HD SOURCE="HD3">Transmittal No. 24-23</HD>
                <HD SOURCE="HD3">Notice of Proposed Issuance of Letter of Offer Pursuant to Section 36(b)(1) of the Arms Export Control Act</HD>
                <HD SOURCE="HD3">Annex</HD>
                <HD SOURCE="HD3">Item No. vii</HD>
                <P>
                    (vii) 
                    <E T="03">Sensitivity of Technology:</E>
                </P>
                <P>1. The UH-60M aircraft is a medium lift four bladed aircraft which includes two (2) T-701D engines. The aircraft has four (4) Multifunction Displays (MFD), which provides aircraft system, flight, mission, and communication management systems. The instrumentation panel includes four (4) Multifunction Displays (MFDs), two (2) Pilot and Co-Pilot Flight Director Panels, and two (2) Data Concentrator Units (DCUs). The Navigation System will have Embedded Global Positioning System (GPS)/Inertial Navigation System (INS) (EGIs), and two (2) Advanced Flight Control Computer Systems (AFCC), which provide 4 axis aircraft control:</P>
                <P>a. The AN/ARC-201 very high frequency (VHF)—frequency modulation (FM) (VHF-FM) Single Channel Ground and Airborne Radio System (SINCGARS) is a reliable, field-proven voice and data communication system used with the UH-60. A non-communications security (COMSEC) export variant of this radio that meets these requirements will be provided.</P>
                <P>b. AN/ARC-231 RT-1808A (or future replacement) VHF/UHF/LOS satellite communications (SATCOM) Radios. The AN/ARC-231 is a software-definable radio for military aircraft that provides two-way, multi-mode voice and data communications over a 30 Hz to 512 MHz frequency range. It covers both line-of-sight ultra-high frequency (UHF) and VHF bands with amplitude modulation (AM), FM, and SATCOM capabilities.</P>
                <P>c. The AN/ARC-231A is a software-definable radio for military aircraft that provides two-way, multi-mode voice and data communications over a 30 Hz to 512 MHz frequency range. No designated exportable, non-COMSEC capable version is planned. The AN/ARC-231A supports both line-of-sight UHF and VHF bands with AM, FM, and SATCOM capabilities. It also includes embedded frequency agile modes, Electronic Counter-Countermeasures (ECCM), anti-jam waveforms including Have Quick and Single Channel Ground and Airborne Radio System (SINCGARS), Demand Assigned Multiple Access (DAMA), and Integrated Waveform (IW). It provides simultaneous, real-time participation in tactical voice and data communications networks. The RT-1987 will provide National Security Agency (NSA) Tactical Secure Voice Cryptographic Interoperability Specification (TSVCIS) 3.1.1 crypto modernization compliance. Operator selectable air traffic control channel spacing of 5, 8.33, 12.5, and 25 kHz steps, and other data link and secure communications features, provide battlefield interoperability.</P>
                <P>d. The AN/ARC-210 is a family of radios for military aircraft that provides two-way, multi-mode voice and data communications over a 30 to 512+ MHz frequency range. It covers both UHF and VHF bands with AM, FM, and SATCOM capabilities. The ARC-210 radio also includes embedded anti-jam waveforms, including Have Quick and SINCGARS, and other data link and secure communications features, providing total battlefield interoperability and high-performance capabilities in the transfer of data, voice, and imagery. The software-programmable encryption is under the NSA Cryptographic Modernization Initiative.</P>
                <P>e. The AN/ARC-220 High Frequency (HF) Airborne Communication System provides rotary-wing aircraft with advanced voice and data capabilities for short-and long-distance communications. The system is software programmable with a frequency range of 2.0000-29.9999 MHz, in 100 Hz steps and provides for providing embedded automatic Link establishment (ALE), serial tone data modem, text messaging, GPS position reporting, and anti-jam (ECCM) functions.</P>
                <P>f. The AN/APX-123A (or future replacement) Identification Friend or Foe (IFF) Transponder is a space diversity transponder and is installed on various military platforms. When installed in conjunction with platform antennas and the remote-control unit (or other appropriate control unit), the transponder provides identification, altitude, and surveillance reporting in response to interrogations from airborne, ground-based, and surface interrogators. The transponder will be classified SECRET if MODE IV, MODE 5, or MODE S fill is installed in the equipment with a crypto device. This item contains sensitive technology.</P>
                <P>g. The VRC-100 HF Communication System is the ground station version of the AN/ARC-220 for use in Aviation Operation Centers. It provides for advanced voice and data capabilities for short-and long-distance communications. The system is software programmable with a frequency range of 2.0000-29.9999 MHz in 100 Hz steps and provides embedded Automatic Link Establishment (ALE), serial tone data modem, text messaging, GPS position reporting, and anti-jam (ECCM) functions. The system is purchased with all required mounts, amplifiers, antennas, power supplies, and accessories.</P>
                <P>h. The AN/PYQ-10 Simple Key Loader (SKL) is a ruggedized, portable, hand-held fill device for securely receiving, storing, and transferring data between compatible cryptographic and communications equipment. The AN/PYQ-10(C) Simple Key Loader (SKL) will contain the KOV-21 COMSEC card, which is a Controlled Cryptographic Item (CCI). Cryptographic functions are performed by an embedded KOV-21 card developed by the NSA.</P>
                <P>i. The KIV-77 Identification Friend or Foe (IFF) Crypto Applique provides cryptographic and time-of-day services for a Combined Interrogator/Transponder (CIT) or individual interrogator or transponder Mark XIIA (Mode 4 and Mode 5) IFF system deployed to identify cooperative, friendly systems. The KIV-77 contains embedded security, and when keys are loaded is classified up to Secret.</P>
                <P>j. The KY-100M is a self-contained terminal including COMSEC that provides for secure voice and data communications in tactical airborne and ground environments. It is an integral part of U.S. Forces' and Federal law enforcement agencies' networks and provides half-duplex, narrowband, and wideband communications. Its flexible interfaces increase compatibility with a wide range of voice, data, radio, and satellite equipment. The KY can support Tier 1 crypto.</P>
                <P>k. The AN/APR-39C(V)1/4 Radar Warning System detects radar-based rangefinders, target designators, and beam rider systems targeting an aircraft or vehicle. The APR-39 is a detection component of the suite of countermeasures designed to increase survivability of current generation combat aircraft and specialized special operations aircraft against the threat posed by laser designated or guided weapons. This item contains sensitive technology.</P>
                <P>
                    l. The AN/AVR-2B Laser Warning Receiver detects laser rangefinders, target designators, and beam rider laser-aided systems targeting an aircraft or vehicle. The AVR-2B is a detection component of the suite of countermeasures designed to increase survivability of current generation combat aircraft and specialized special operations aircraft against the threat 
                    <PRTPAGE P="620"/>
                    posed by laser designated or guided weapons. This item contains sensitive technology.
                </P>
                <P>m. The AAR-57 Common Missile Warning System (CMWS) is an integrated infrared (IR) countermeasures suite utilizing ultraviolet (UV) sensors to display accurate threat location and dispense countermeasures either automatically or under pilot or crew control to defeat incoming missile threats.</P>
                <P>n. Embedded GPS/Inertial Navigation System INS (EGI) provides GPS and INS capabilities to the aircraft. The EGI will include Selective Availability Anti-Spoofing Module (SAASM) security modules to be used for secure GPS Precise Positioning Service (PPS) if required. The Embedded GPS/INS within the SAASM contains sensitive technology.</P>
                <P>2. The highest level of classification of defense articles, components, and services included in this potential sale is SECRET.</P>
                <P>3. If a technologically advanced adversary were to obtain knowledge of the specific hardware and software elements, the information could be used to develop countermeasures that might reduce weapon system effectiveness or be used in the development of a system with similar or advanced capabilities.</P>
                <P>4. A determination has been made that Croatia can provide substantially the same degree of protection for the sensitive technology being released as the U.S. Government. This sale is necessary in furtherance of the U.S. foreign policy and national security objectives outlined in the Policy Justification.</P>
                <P>5. All defense articles and services listed in this transmittal are authorized for release and export to Croatia.</P>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31700 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6001-FR-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF DEFENSE</AGENCY>
                <SUBAGY>Office of the Secretary</SUBAGY>
                <DEPDOC>[Docket ID: DoD-2024-OS-0150]</DEPDOC>
                <SUBJECT>Proposed Collection; Comment Request</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Chief Information Officer (CIO), Department of Defense (DoD).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>60-Day information collection notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        In compliance with the 
                        <E T="03">Paperwork Reduction Act of 1995,</E>
                         the CIO announces a proposed public information collection and seeks public comment on the provisions thereof. Comments are invited on: whether the proposed collection of information is necessary for the proper performance of the functions of the agency, including whether the information shall have practical utility; the accuracy of the agency's estimate of the burden of the proposed information collection; ways to enhance the quality, utility, and clarity of the information to be collected; and ways to minimize the burden of the information collection on respondents, including through the use of automated collection techniques or other forms of information technology.
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Consideration will be given to all comments received by March 7, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may submit comments, identified by docket number and title, by any of the following methods:</P>
                    <P>
                        <E T="03">Federal eRulemaking Portal:</E>
                          
                        <E T="03">http://www.regulations.gov.</E>
                         Follow the instructions for submitting comments.
                    </P>
                    <P>
                        <E T="03">Mail:</E>
                         Department of Defense, Office of the Assistant to the Secretary of Defense for Privacy, Civil Liberties, and Transparency, Regulatory Directorate, 4800 Mark Center Drive, Mailbox #24 Suite 05F16, Alexandria, VA 22350-1700.
                    </P>
                    <P>
                        <E T="03">Instructions:</E>
                         All submissions received must include the agency name, docket number and title for this 
                        <E T="04">Federal Register</E>
                         document. The general policy for comments and other submissions from members of the public is to make these submissions available for public viewing at 
                        <E T="03">http://www.regulations.gov</E>
                         as they are received without change, including any personal identifiers or contact information.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>To request more information on this proposed information collection or to obtain a copy of the proposal and associated collection instruments, please write to Office of the Department of Defense Chief Information Officer, 6000 Defense Pentagon, Washington, DC 20301-6000 ATTN: Mr. Rodney McCall, or call (703) 697-5936.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P/>
                <P>
                    <E T="03">Title; Associated Form; and OMB Number:</E>
                     System Authorization Access Request Form; DD 2875; OMB Control Number 0704-0630.
                </P>
                <P>
                    <E T="03">Needs and Uses:</E>
                     The information collection is necessary for validating the trustworthiness of individuals who request access to DoD systems and information. When an individual requires access to a DoD information system, application, or database, he/she retrieves the DD Form 2875. Executive Order 10450 “Security Requirements for Government Employment” establishes the security requirements for government employment. The requestor's security requirements (background investigation and clearance information) are identified on the DD Form 2875 and validated by the cognizant Security Manager. Collection of the requestor's information ensures that any system access granted is consistent with the interests of the national security.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Individuals or households.
                </P>
                <P>
                    <E T="03">Annual Burden Hours:</E>
                     600,000.
                </P>
                <P>
                    <E T="03">Number of Respondents:</E>
                     900,000.
                </P>
                <P>
                    <E T="03">Responses per Respondent:</E>
                     8.
                </P>
                <P>
                    <E T="03">Annual Responses:</E>
                     7,200,000.
                </P>
                <P>
                    <E T="03">Average Burden per Response:</E>
                     5 minutes.
                </P>
                <P>
                    <E T="03">Frequency:</E>
                     As needed.
                </P>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>Stephanie J. Bost,</NAME>
                    <TITLE>Alternate OSD Federal Register Liaison Officer, Department of Defense. </TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31664 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6001-FR-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF DEFENSE</AGENCY>
                <SUBAGY>Office of the Secretary</SUBAGY>
                <DEPDOC>[Docket ID: DoD-2024-OS-0149]</DEPDOC>
                <SUBJECT>Proposed Collection; Comment Request</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Washington Headquarters Services (WHS), Department of Defense (DoD).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>60-Day information collection notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        In compliance with the 
                        <E T="03">Paperwork Reduction Act of 1995,</E>
                         the WHS announces a proposed public information collection and seeks public comment on the provisions thereof. Comments are invited on: whether the proposed collection of information is necessary for the proper performance of the functions of the agency, including whether the information shall have practical utility; the accuracy of the agency's estimate of the burden of the proposed information collection; ways to enhance the quality, utility, and clarity of the information to be collected; and ways to minimize the burden of the information collection on respondents, including through the use of automated collection techniques or other forms of information technology.
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Consideration will be given to all comments received by March 7, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may submit comments, identified by docket number and title, by any of the following methods:</P>
                    <P>
                        <E T="03">Federal eRulemaking Portal:</E>
                          
                        <E T="03">http://www.regulations.gov.</E>
                         Follow the instructions for submitting comments.
                    </P>
                    <P>
                        <E T="03">Mail:</E>
                         Department of Defense, Office of the Assistant to the Secretary of Defense 
                        <PRTPAGE P="621"/>
                        for Privacy, Civil Liberties, and Transparency, Regulatory Directorate, 4800 Mark Center Drive, Mailbox #24 Suite 05F16, Alexandria, VA 22350-1700.
                    </P>
                    <P>
                        <E T="03">Instructions:</E>
                         All submissions received must include the agency name, docket number and title for this 
                        <E T="04">Federal Register</E>
                         document. The general policy for comments and other submissions from members of the public is to make these submissions available for public viewing at 
                        <E T="03">http://www.regulations.gov</E>
                         as they are received without change, including any personal identifiers or contact information.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        To request more information on this proposed information collection or to obtain a copy of the proposal and associated collection instruments, please write to Washington Headquarters Services, the Director of Administration and Management, ATTN: Reginald Lucas, 4800 Mark Center Drive, Alexandria, VA 22350, Suite 03F09, (571) 372-7574, or email 
                        <E T="03">reginald.t.lucas2.civ@mail.mil.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P/>
                <P>
                    <E T="03">Title; Associated Form; and OMB Number:</E>
                     Fast Track Generic Clearance for the Collection of Qualitative Feedback on Agency Service Delivery; OMB Control Number 0704-0553.
                </P>
                <P>
                    <E T="03">Needs and Uses:</E>
                     The information collection activity provides a means to garner qualitative customer and stakeholder feedback in an efficient, timely manner, in accordance with the Administration's commitment to improving service delivery. By qualitative feedback, we mean information that provides useful insights on perceptions and opinions but are not statistical surveys that yield quantitative results that can be generalized to the population of study. This feedback will provide insights into customer or stakeholder perceptions, experiences, expectations, provide an early warning of issues with service, or focus attention on areas where communication, training or changes in operations might improve delivery of products or services. These collections will allow for ongoing, collaborative, and actionable communications between the Agency and its customers and stakeholders. It will also allow feedback to contribute directly to the improvement of program management.
                </P>
                <P>The solicitation of feedback will target areas such as: Timeliness, appropriateness, accuracy of information, courtesy, efficiency of service delivery, and resolution of issues with service delivery. Responses will be assessed to plan and inform efforts to improve or maintain the quality of service offered to the public. If this information is not collected, vital feedback from customers and stakeholders on the Agency's services will be unavailable.</P>
                <P>The Agency will only submit a collection for approval under this generic clearance if it meets the following conditions:</P>
                <P>• The collections are voluntary;</P>
                <P>• The collections are low-burden for respondents (based on considerations of total burden hours, total number of respondents, or burden-hours per respondent) and are low-cost for both the respondents and the Federal Government;</P>
                <P>• The collections are noncontroversial and do not raise issues of concern to other Federal agencies;</P>
                <P>• Any collection is targeted to the solicitation of opinions from respondents who have experience with the program or may have experience with the program in the near future;</P>
                <P>• Personally identifiable information is collected only to the extent necessary and is not retained;</P>
                <P>• Information gathered will be used only internally for general service improvement and program management purposes and is not intended for release outside of the agency;</P>
                <P>• Information gathered will not be used for the purpose of substantially informing influential policy decisions; and</P>
                <P>• Information gathered will yield qualitative information; the collections will not be designed or expected to yield statistically reliable results or used as though the results are generalizable to the population of study.</P>
                <P>Feedback collected under this generic clearance provides useful information, but it does not yield data that can be generalized to the overall population. This type of generic clearance for qualitative information will not be used for quantitative information collections that are designed to yield reliably actionable results, such as monitoring trends over time or documenting program performance. Such data uses require more rigorous designs that address: The target population to which generalizations will be made, the sampling frame, the sample design (including stratification and clustering), the precision requirements or power calculations that justify the proposed sample size, the expected response rate, methods for assessing potential nonresponse bias, the protocols for data collection, and any testing procedures that were or will be undertaken prior to fielding the study. Depending on the degree of influence the results are likely to have, such collections may still be eligible for submission for other generic mechanisms that are designed to yield quantitative results.</P>
                <P>As a general matter, information collections will not result in any new system of records containing privacy information and will not ask questions of a sensitive nature, such as sexual behavior and attitudes, religious beliefs, and other matters that are commonly considered private.</P>
                <P>
                    <E T="03">Affected Public:</E>
                     Individuals or households; Businesses or other for-profits; Not-for-profit institutions; Farms; Federal Government; State, Local, or Tribal Governments.
                </P>
                <P>
                    <E T="03">Annual Burden Hours:</E>
                     50,000.
                </P>
                <P>
                    <E T="03">Number of Respondents:</E>
                     300,000.
                </P>
                <P>
                    <E T="03">Responses per Respondent:</E>
                     1.
                </P>
                <P>
                    <E T="03">Annual Responses:</E>
                     300,000.
                </P>
                <P>
                    <E T="03">Average Burden per Response:</E>
                     10 minutes.
                </P>
                <P>
                    <E T="03">Frequency:</E>
                     On occasion.
                </P>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>Stephanie J. Bost,</NAME>
                    <TITLE>Alternate OSD Federal Register Liaison Officer, Department of Defense. </TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31663 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6001-FR-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF DEFENSE</AGENCY>
                <SUBAGY>Office of the Secretary</SUBAGY>
                <DEPDOC>[Docket ID: DoD-2024-OS-0030]</DEPDOC>
                <SUBJECT>Submission for OMB Review; Comment Request</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Office of the Under Secretary of Defense for Personnel and Readiness (OUSD (P&amp;R)), Department of Defense (DoD).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>30-Day information collection notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The DoD has submitted to the Office of Management and Budget (OMB) for clearance the following proposal for collection of information under the provisions of the Paperwork Reduction Act.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Consideration will be given to all comments received by February 5, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        Written comments and recommendations for the proposed information collection should be sent within 30 days of publication of this notice to 
                        <E T="03">www.reginfo.gov/public/do/PRAMain.</E>
                         Find this particular information collection by selecting “Currently under 30-day Review—Open for Public Comments” or by using the search function.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Reginald Lucas, (571) 372-7574, 
                        <E T="03">whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <PRTPAGE P="622"/>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P/>
                <P>
                    <E T="03">Title; Associated Form; and OMB Number:</E>
                     Family Member Travel Screening; Form Number DD 3040, 3040-1, 3040-2, 3040-3, 3040-4; OMB Control Number 0704-0560.
                </P>
                <P>
                    <E T="03">Type of Request:</E>
                     Reinstatement.
                </P>
                <P>
                    <E T="03">Number of Respondents:</E>
                     302,205.
                </P>
                <P>
                    <E T="03">Responses per Respondent:</E>
                     1.
                </P>
                <P>
                    <E T="03">Annual Responses:</E>
                     302,205.
                </P>
                <P>
                    <E T="03">Average Burden per Response:</E>
                     18.026 minutes.
                </P>
                <P>
                    <E T="03">Annual Burden Hours:</E>
                     90,793.
                </P>
                <P>
                    <E T="03">Needs and Uses:</E>
                     The DD Forms 3040, 3040-1, 3040-2, 3040-3, and 3040-4 are used during the Family Member Travel Screening process when active-duty Service members with Permanent Change of Station order request Command sponsorship for accompanied travel to remote or outside continental United States installations. These forms document any special medical, dental, and/or educational needs of dependents accompanying the Service member to assist in determining the availability of care at a gaining installation. This standardized collection of information is required by the National Defense Authorization Act (NDAA) of 2010, 10 United States Code 136 `Under Secretary of Defense for Personnel and Readiness,' and the DoD Instruction (DoDI) 1315.19, “The Exceptional Family Member Program (EFMP).” The NDAA 2010 established the Office of Special Needs (OSN) and tasked OSN with developing, implementing, and overseeing comprehensive policies surrounding assignment and support for these military families. Additionally, per DoDI 1315.19, military departments are required to screen family members of active duty Service members for special needs and to coordinate assignments for Service members enrolled in the EFMP to verify if necessary medical and/or educational services are available at the next assignment.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Individuals or households.
                </P>
                <P>
                    <E T="03">Frequency:</E>
                     On occasion.
                </P>
                <P>
                    <E T="03">Respondent's Obligation:</E>
                     Voluntary.
                </P>
                <P>
                    <E T="03">DoD Clearance Officer:</E>
                     Mr. Reginald Lucas.
                </P>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>Stephanie J. Bost,</NAME>
                    <TITLE>Alternate OSD Federal Register Liaison Officer, Department of Defense.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31661 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6001-FR-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF DEFENSE</AGENCY>
                <SUBAGY>Office of the Secretary</SUBAGY>
                <DEPDOC>[Docket ID: DOD-2024-OS-0152]</DEPDOC>
                <SUBJECT>Proposed Collection; Comment Request</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Office of the Under Secretary of Defense for Personnel and Readiness (OUSD (P&amp;R)), Department of Defense (DoD).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>60-day information collection notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        In compliance with the 
                        <E T="03">Paperwork Reduction Act of 1995,</E>
                         the OUSD P&amp;R, announces a proposed public information collection and seeks public comment on the provisions thereof. Comments are invited on: whether the proposed collection of information is necessary for the proper performance of the functions of the agency, including whether the information shall have practical utility; the accuracy of the agency's estimate of the burden of the proposed information collection; ways to enhance the quality, utility, and clarity of the information to be collected; and ways to minimize the burden of the information collection on respondents, including the use of automated collection techniques or other forms of information technology.
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Consideration will be given to all comments received by March 7, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may submit comments, identified by docket number and title, by any of the following methods:</P>
                    <P>
                        <E T="03">Federal eRulemaking Portal: http://www.regulations.gov.</E>
                         Follow the instructions for submitting comments.
                    </P>
                    <P>
                        <E T="03">Mail:</E>
                         Department of Defense, Office of the Assistant to the Secretary of Defense for Privacy, Civil Liberties, and Transparency, Regulatory Directorate, 4800 Mark Center Drive, Mailbox #24 Suite 05F16, Alexandria, VA 22350-1700.
                    </P>
                    <P>
                        <E T="03">Instructions:</E>
                         All submissions received must include the agency name, docket number and title for this 
                        <E T="04">Federal Register</E>
                         document. The general policy for comments and other submissions from members of the public is to make these submissions available for public viewing at 
                        <E T="03">http://www.regulations.gov</E>
                         as they are received without change, including any personal identifiers or contact information.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>To request more information on this proposed information collection or to obtain a copy of the proposal and associated collection instruments, please write to OEPM, Voluntary Education, 4000 Pentagon, Room 3C1063 Washington, DC 20301-4000, Mark Phelan, (571) 372-5355.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P/>
                <P>
                    <E T="03">Title; Associated Form; And Omb Number:</E>
                     Department of Defense (DoD) Voluntary Education Partnership Memorandum of Understanding (MOU) Institutional Compliance Program (ICP); OMB Control Number 0704-VEPP.
                </P>
                <P>
                    <E T="03">Needs And Uses:</E>
                     The DoD Voluntary Education Partnership MOU ICP is a full-scale, risk-based compliance program that assesses institutional compliance to reduce risks associated with non-compliance. Each year, the ICP team considers the entire population of MOU signatories, leveraging over 24,000 pieces of data to narrow the population from over 2,700 to 250, and then conducts an in-depth assessment on those 250 institutions. The team then provided critical feedback to those institutions to enable them to implement Corrective Action Plans to improve their individual level of compliance with the tenets of their MOUs.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Educational Institutions.
                </P>
                <P>
                    <E T="03">Annual Burden Hours:</E>
                     3,000.
                </P>
                <P>
                    <E T="03">Number of Respondents:</E>
                     250.
                </P>
                <P>
                    <E T="03">Responses per Respondent:</E>
                     1.
                </P>
                <P>
                    <E T="03">Annual Responses:</E>
                     250.
                </P>
                <P>
                    <E T="03">Average Burden per Response:</E>
                     12 hours.
                </P>
                <P>
                    <E T="03">Frequency:</E>
                     On occasion.
                </P>
                <P>The information reviewed is not the same for all the selected educational institutions. The basic information is associated with the review process is as follows:</P>
                <P>(a) Recruiting, Marketing, and Advertising</P>
                <P>The data examined in Recruiting, Marketing, &amp; Advertising were focused on the content used to attract prospective Service members as students, and whether this content complied with the legal and ethical requirements in the MOU.</P>
                <P>(b) Financial Matters</P>
                <P>Financial Matters data pertain to the cost of attendance, pre and post-enrollment tools and processes, and the ease with which prospective Service members can access information. MOU compliance requires that Service members have easy access to clear and accurate information regarding financial aid options. This includes access to trained and qualified counseling staff who can provide accurate and up-to-date information regarding the costs of attending an institution, and recommendations regarding individual financial choices.</P>
                <P>(c) Accreditation</P>
                <P>
                    To be able to sign a DoD MOU, all institutions must be accredited by a 
                    <PRTPAGE P="623"/>
                    national or regional accrediting body recognized by the ED. Also, the institution may only conduct programs from among those offered or authorized by the main administrative and academic office, in accordance with standard procedures for authorization of degree programs by the educational institution. These programs are reviewed to ensure that the educational institution is compliant with the signed DoD MOU.
                </P>
                <P>(d) Post-graduate Opportunities</P>
                <P>Information reviewed should include the unchanging degree plans and requirements needed, guidance available for professional opportunities upon completion of the degree program, and processes regarding readmission policies for Service members fulfilling military obligations while attending the institution.</P>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>Stephanie J. Bost,</NAME>
                    <TITLE>Alternate OSD Federal Register Liaison Officer, Department of Defense. </TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31666 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6001-FR-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF DEFENSE</AGENCY>
                <SUBAGY>Office of the Secretary</SUBAGY>
                <DEPDOC>[Transmittal No. 24-07]</DEPDOC>
                <SUBJECT>Arms Sales Notification</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Defense Security Cooperation Agency, Department of Defense (DoD).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Arms sales notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The DoD is publishing the unclassified text of an arms sales notification.</P>
                </SUM>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Pamela Young at (703) 953-6092, 
                        <E T="03">pamela.a.young14.civ@mail.mil,</E>
                         or 
                        <E T="03">dsca.ncr.rsrcmgmt.list.cns-mbx@mail.mil.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>This 36(b)(1) arms sales notification is published to fulfill the requirements of section 155 of Public Law 104-164 dated July 21, 1996. The following is a copy of a letter to the Speaker of the House of Representatives with attached Transmittal 24-07, Policy Justification, and Sensitivity of Technology.</P>
                <SIG>
                    <DATED>Dated: December 31, 2024.</DATED>
                    <NAME>Stephanie J. Bost,</NAME>
                    <TITLE>Alternate OSD Federal Register Liaison Officer, Department of Defense.</TITLE>
                </SIG>
                <BILCOD>BILLING CODE 6001-FR-P</BILCOD>
                <GPH SPAN="3" DEEP="512">
                    <PRTPAGE P="624"/>
                    <GID>EN06JA25.011</GID>
                </GPH>
                <BILCOD>BILLING CODE 6001-FR-C</BILCOD>
                <HD SOURCE="HD3">Transmittal No. 24-07</HD>
                <HD SOURCE="HD3">Notice of Proposed Issuance of Letter of Offer Pursuant to Section 36(b)(1) of the Arms Export Control Act, as amended</HD>
                <P>
                    (i) 
                    <E T="03">Prospective Purchaser:</E>
                     Government of India
                </P>
                <P>
                    (ii) 
                    <E T="03">Total Estimated Value:</E>
                </P>
                <GPOTABLE COLS="2" OPTS="L0,tp0,p0,8/9,g1,t1,i1" CDEF="s30,xs56">
                    <TTITLE> </TTITLE>
                    <BOXHD>
                        <CHED H="1"/>
                        <CHED H="1"/>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">Major Defense Equipment * </ENT>
                        <ENT>$1.70 billion</ENT>
                    </ROW>
                    <ROW RUL="n,s">
                        <ENT I="01">Other </ENT>
                        <ENT>$2.29 billion</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="02">TOTAL </ENT>
                        <ENT>$3.99 billion</ENT>
                    </ROW>
                </GPOTABLE>
                <P>Funding Source: National Funds</P>
                <P>
                    (iii) 
                    <E T="03">Description and Quantity or Quantities of Articles or Services under Consideration for Purchase:</E>
                </P>
                <FP SOURCE="FP-2">
                    <E T="03">Major Defense Equipment (MDE):</E>
                </FP>
                <FP SOURCE="FP1-2">Thirty-one (31) MQ-9B Sky Guardian Aircraft</FP>
                <FP SOURCE="FP1-2">One hundred sixty-one (161) Embedded Global Positioning &amp; Inertial Navigation Systems (EGIs)</FP>
                <FP SOURCE="FP1-2">Thirty-five (35) L3 Rio Grande Communications Intelligence Sensor Suites</FP>
                <FP SOURCE="FP1-2">One hundred seventy (170) AGM-114R Hellfire Missiles</FP>
                <FP SOURCE="FP1-2">Sixteen (16) M36E9 Hellfire Captive Air Training Missiles (CATM)</FP>
                <FP SOURCE="FP1-2">Three hundred ten (310) GBU-39B/B Laser Small Diameter Bombs (LSDB)</FP>
                <FP SOURCE="FP1-2">Eight (8) GBU-39B/B LSDB Guided Test Vehicles (GTVs) with live fuzes</FP>
                <FP SOURCE="FP-2">
                    <E T="03">Non-MDE:</E>
                </FP>
                <FP SOURCE="FP1-2">
                    Also included are Certifiable Ground Control Stations; TPE-331-10-GD engines; M299 Hellfire missile launchers; KIV-77 cryptographic appliques and other Identification Friend or Foe (IFF) equipment; KOR-24A Small Tactical Terminals 
                    <PRTPAGE P="625"/>
                    (STT); AN/SSQ-62F, AN/SSQ-53G, and AN/SSQ-36 sonobuoys; ADU-891/E Adapter Group Test Sets; Common Munitions Built-In-Test (BIT) Reprogramming Equipment (CMBRE); GBU-39B/B tactical training rounds, Weapons Load Crew Trainers, and Reliability Assessment Vehicles-Instrumented; Portable Pre-flight/Post-flight Equipment (P3E); CCM-700A encryption devices; KY-100M narrowband/wideband terminals; KI-133 cryptographic units; AN/PYQ-10 Simple Key Loaders; Automatic Identification System (AIS) transponders; ROVER 6Si and TNR2x transceivers; MR6000 ultra high frequency (UHF) and very high frequency (VHF) radios; Selex SeaSpray Active Electronically Scanned Array (AESA) surveillance radars; HISAR-300 radars; SNC 4500 Auto Electronic Surveillance Measures (ESM) Systems; SAGE 750 ESM systems; Due Regard Radars (DRR); MX-20 Electro-Optical Infrared (E.O.-IR) Laser Target Designators (LTDs); Ku-Band SATCOM GAASI Transportable Earth Stations (GATES); C-Band Line-of-Sight (LOS) Ground Data Terminals; AN/DPX-7 IFF transponders; Compact Multi-band Data Links (CMDL); initial spare and repair parts, consumables, accessories, and repair and return support; secure communications, precision navigation, and cryptographic equipment; munitions support and support equipment; testing and integration support and equipment; classified and unclassified software delivery and support; classified and unclassified publications and technical documentation; personnel training and training equipment; transportation support; warranties; studies and surveys; U.S. Government and contractor engineering, technical, and logistics support services; and other related elements of logistics and program support.
                </FP>
                <P>
                    (iv) 
                    <E T="03">Military Department:</E>
                     Air Force (IN-D-SAF)
                </P>
                <P>
                    (v) 
                    <E T="03">Prior Related Cases, if any:</E>
                     None
                </P>
                <P>
                    (vi) 
                    <E T="03">Sales Commission, Fee, etc., Paid, Offered, or Agreed to be Paid:</E>
                     None known at this time
                </P>
                <P>
                    (vii) 
                    <E T="03">Sensitivity of Technology Contained in the Defense Article or Defense Services Proposed to be Sold:</E>
                     See Attached Annex
                </P>
                <P>
                    (viii) 
                    <E T="03">Date Report Delivered to Congress:</E>
                     February 1, 2024
                </P>
                <P>*As defined in Section 47(6) of the Arms Export Control Act.</P>
                <HD SOURCE="HD3">POLICY JUSTIFICATION</HD>
                <HD SOURCE="HD2">India—MQ-9B Remotely Piloted Aircraft</HD>
                <P>The Government of India has requested to buy thirty-one (31) MQ-9B Sky Guardian aircraft; one hundred sixty-one (161) Embedded Global Positioning &amp; Inertial Navigation Systems (EGIs); thirty-five (35) L3 Rio Grande Communications Intelligence Sensor Suites; one hundred seventy (170) AGM-114R Hellfire missiles; sixteen (16) M36E9 Hellfire Captive Air Training Missiles (CATM); three hundred ten (310) GBU-39B/B Laser Small Diameter Bombs (LSDB); and eight (8) GBU-39B/B LSDB Guided Test Vehicles (GTVs) with live fuzes. Also included are Certifiable Ground Control Stations; TPE-331-10-GD engines; M299 Hellfire missile launchers; KIV-77 cryptographic appliques and other Identification Friend or Foe (IFF) equipment; KOR-24A Small Tactical Terminals (STT); AN/SSQ-62F, AN/SSQ-53G, and AN/SSQ-36 sonobuoys; ADU-891/E Adapter Group Test Sets; Common Munitions Built-In-Test (BIT) Reprogramming Equipment (CMBRE); GBU-39B/B tactical training rounds, Weapons Load Crew Trainers, and Reliability Assessment Vehicles-Instrumented; Portable Pre-flight/Post-flight Equipment (P3E); CCM-700A encryption devices; KY-100M Narrowband/wideband terminals; KI-133 cryptographic units; AN/PYQ-10 Simple Key Loaders; Automatic Identification System (AIS) transponders; ROVER 6Si and TNR2x transceivers; MR6000 ultra high frequency (UHF) and very high frequency (VHF) radios; Selex SeaSpray Active Electronically Scanned Array (AESA) surveillance radars; HISAR-300 Radars; SNC 4500 Auto Electronic Surveillance Measures (ESM) Systems; SAGE 750 ESM systems; Due Regard Radars (DRR); MX-20 Electro-Optical Infrared (E.O.-IR) Laser Target Designators (LTDs); Ku-Band SATCOM GAASI Transportable Earth Stations (GATES); C-Band Line-of-Sight (LOS) Ground Data Terminals; AN/DPX-7 IFF transponders; Compact Multi-band Data Links (CMDL); initial spare and repair parts, consumables, accessories, and repair and return support; secure communications, precision navigation, and cryptographic equipment; munitions support and support equipment; testing and integration support and equipment; classified and unclassified software delivery and support; classified and unclassified publications and technical documentation; personnel training and training equipment; transportation support; warranties; studies and surveys; United States (U.S.) Government and contractor engineering, technical, and logistics support services; and other related elements of logistics and program support. The estimated total cost is $3.99 billion.</P>
                <P>This proposed sale will support the foreign policy and national security objectives of the U.S. by helping to strengthen the U.S.-Indian strategic relationship and to improve the security of a major defensive partner which continues to be an important force for political stability, peace, and economic progress in the Indo-Pacific and South Asia region.</P>
                <P>The proposed sale will improve India's capability to meet current and future threats by enabling unmanned surveillance and reconnaissance patrols in sea lanes of operation. India has demonstrated a commitment to modernizing its military and will have no difficulty absorbing these articles and services into its armed forces.</P>
                <P>The proposed sale of this equipment and support will not alter the basic military balance in the region. The principal contractor will be General Atomics Aeronautical Systems, Poway, CA. The purchaser typically requests offsets. Any offset agreement will be defined in negotiations between the purchaser and the contractor.</P>
                <P>Implementation of this proposed sale will not require the assignment of any additional U.S. Government or contractor representatives to India.</P>
                <P>There will be no adverse impact on U.S. defense readiness as a result of this proposed sale.</P>
                <HD SOURCE="HD3">Transmittal No. 24-07</HD>
                <HD SOURCE="HD3">Notice of Proposed Issuance of Letter of Offer Pursuant to Section 36(b)(1) of the Arms Export Control Act</HD>
                <HD SOURCE="HD3">Annex</HD>
                <HD SOURCE="HD3">Item No. vii</HD>
                <P>
                    (vii) 
                    <E T="03">Sensitivity of Technology:</E>
                </P>
                <P>
                    1. The MQ-9B Remotely Piloted Aircraft (RPA) is a weapons-ready aircraft designed for Medium-Altitude Long-Endurance (MALE); Intelligence, Surveillance, and Reconnaissance (ISR); Target Acquisition; and Strike Missions. The MQ-9B RPA is not a USAF program of record, but has close ties to, and builds upon, the proven success of the MQ-9A Reaper. The MQ-9B is a highly modular, easily configurable aircraft that contains the necessary hard points, power, and data connections to accommodate a variety of payloads and munitions to meet multiple missions—
                    <PRTPAGE P="626"/>
                    including counter-land, counter-sea, and anti-submarine strike operations. The system is designed to be controlled by two operators within a Certifiable Ground Control Station (CGCS). The MQ-9B is able to operate using a direct Line-of-Sight (LOS) datalink or Beyond Line-of-Sight (BLOS) through satellite communications (SATCOM). The MQ-9B system can be deployed from a single site that supports launch, recovery, mission control, and maintenance. The system also supports remote-split operations where launch, recovery, and maintenance occur at a Forward Operating Base and mission control is conducted from another location or Main Operating Base (MOB).
                </P>
                <P>a. The Honeywell TPE-331-10-GD is a turboprop engine with power output ranging from 429 to 1,230 kW.</P>
                <P>b. The M-Code capable Embedded Global Positioning System/Inertial Navigation System (GPS/INS) (EGI), with an embedded GPS Precise Positioning Service (PPS) Receiver Application Module-Standard Electronic Module (GRAM-S/M), is a self-contained navigation system that provides acceleration, velocity, position, attitude, platform azimuth, magnetic and true heading, altitude, body angular rates, time tags, and coordinated universal time (UTC) synchronized time. The embedded GRAM-S/M enables access to both the encrypted P(Y) and M-Code signals, providing protection against active spoofing attacks, enhanced military exclusivity, integrity, and anti-jam.</P>
                <P>c. The MX-20HD is a gyro-stabilized, multi-spectral, multi-field-of-view (FOV) Electro-Optical/Infrared (E.O./IR) targeting system. The system provides surveillance laser illumination and laser designation through use of an externally mounted turret sensor unit and internally mounted master control. Sensor video imagery is displayed in the aircraft in real time and may be recorded for subsequent analysis.</P>
                <P>2. The Ground Control Station (GCS) can be either fixed or mobile. The fixed GCS is enclosed in a customer-specified shelter. It incorporates workstations that allow operators to control and monitor the aircraft, as well as record and exploit downlinked payload data. The mobile GCS allows operators to perform the same functions and is contained on a mobile trailer. Workstations in either GCS can be tailored to meet customer requirements.</P>
                <P>3. L3 Rio Grande capabilities meet rigorous mission requirements for small, manned and unmanned intelligence, surveillance, and reconnaissance (ISR) platforms. Rio Grande intercepts, locates, monitors, and records communications signals using a common set of software applications. Rio Grande operates open architecture design, supports third-party special signals applications, real-time audio recording and playback, and a three-dimensional display of the area of interest.</P>
                <P>4. The AGM-114R Hellfire is a missile equipped with a Semi-Active Laser (SAL) seeker that homes-in on the reflected light of a laser designator. The AGM-114R can be launched from higher altitudes than previous variants because of its enhanced guidance and navigation capabilities, which include a Height-of-Burst (HOB) proximity sensor. With its multi-purpose warhead, the missile can destroy hard, soft, and enclosed targets. The sale will include Captive Air Flight Training Missiles (CATM), which are inert devices used for training to handle Hellfire missiles.</P>
                <P>5. The GBU-39B/B Laser Small Diameter Bomb (LSDB) All Up Round (AUR) is a 250-pound GPS and semi-active laser guided, small autonomous, day or night, adverse weather, conventional, air-to-ground precision glide weapon able to strike fixed and stationary, re-locatable, non-hardened targets from standoff ranges. The LSDB's laser guidance set enables the weapon to strike moving targets. It is intended to provide aircraft with an ability to carry a high number of bombs. Aircraft are able to carry four SDBs in place of one 2,000-pound bomb. The Guided Test Vehicle, Reliability Assessment Vehicle-Instrumented, Tactical Training Round (TTR), and Weapons Load Crew Trainer are LSDB configurations with telemetry kits or inert fills in place of the warhead and are used to test the LSDB weapon system or for flight and ground crew training.</P>
                <P>6. The M299 launcher provides a mechanical and electrical interface between the Hellfire missile and aircraft.</P>
                <P>7. The KIV-77 is a cryptographic applique for IFF. It can be loaded with Mode 5 classified elements.</P>
                <P>8. The KOR-24A Small Tactical Terminal is a command, control, communications, and intelligence (C3I) system incorporating high-capacity, jam-resistant, digital communication links for exchange of near real-time tactical information, including both data and voice, among air, ground, and sea elements.</P>
                <P>9. AN/SSQ-62F is a sixth-generation, Directional Command Active Sonobuoy System (DICASS) sonobuoy used for detecting and localizing submarines. The DICASS sonobuoy can provide both range and bearing to the target for accurate position fixing. Like the AN/SSQ-62E, the AN/SSQ-62F sonobuoy can support any of the four acoustic frequencies as selected via the Electronic Function Select.</P>
                <P>10. AN/SSQ-53G is a sonobuoy which combines a passive directional and calibrated wide-band omni capability into a single multi-functional sonobuoy. It features both Electronic Function Select (EFS) for use prior to loading and launching and Command Function Select (CFS) to allow the operator to modify the sonobuoy's modes of operation after it has been deployed in the water.</P>
                <P>11. AN/SSQ-36 is a sonobuoy which provides vertical temperature profiles for Anti-Submarine Warfare (ASW) applications to evaluate local effects of seawater temperature on sonar propagation and acoustic range prediction.</P>
                <P>12. The Portable Pre-flight/Post-flight Equipment (P3E) is used by the ground crew at the MQ-9B operating sites to interface with the aircraft for performing maintenance functions. The P3E is a ruggedized computer assembly that interfaces directly with the aircraft via a cable and provides functionality for conducting pre and post-flight checks, and to establish the aircraft on the SATCOM datalink for handover to the flight crew in the Ground Control Station. The ADU-891 Adapter Group Test Set provides the physical and electrical interface between the Common Munitions Built-in-Test Reprogramming Equipment (CMBRE) and the missile.</P>
                <P>13. Common Munitions Built-In-Test (BIT)/Reprogramming Equipment (CMBRE) is support equipment used to interface with weapon systems to initiate and report BIT results and upload and download flight software. CMBRE supports multiple munitions platforms with a range of applications that perform preflight checks, periodic maintenance checks, loading of Operational Flight Program (OFP) data, loading of munitions mission planning data, loading of Global Positioning System (GPS) cryptographic keys, and declassification of munitions memory.</P>
                <P>14. The KY-100M is a cryptographic-modernized lightweight terminal for secure voice and data communications. The KY-100M provides wideband and narrowband half-duplex communication. Operating in tactical ground, marine, and airborne applications, the KY-100M enables secure communication with a broad range of radio and satellite equipment.</P>
                <P>
                    15. The KI-133 is used with a MQ-9B unique radio implementation, specifically using X Band. The KI-133 does not operate with a modem and is 
                    <PRTPAGE P="627"/>
                    not a radio, rather it is an inline encryptor utilizing the KIV 700A for encryption and decryption.
                </P>
                <P>16. The AN/PYQ-10 Simple Key Loader is a handheld device used for securely receiving, storing, and transferring data between compatible cryptographic and communications equipment.</P>
                <P>17. The Automatic Identification System (AIS) transponder provides maritime patrol and Search and Rescue (SAR) aircraft with the ability to track and identify AIS-equipped vessels over a dedicated very high frequency (VHF) data link. AIS is a key component of any maritime ISR network and offers maritime authorities with the ability to better coordinate air and sea search, rescue, surveillance, and interdiction operations.</P>
                <P>18. The L3Harris ROVER 6Si and TNR2x transceivers provide real-time, full-motion video (FMV) and other network data for situational awareness, targeting, battle damage assessment, surveillance, relay, convoy over-watch operations, and other situations where eyes-on-target are required. It provides expanded frequencies and additional processing resources from previous ROVER versions, allowing increased levels of collaboration and interoperability with numerous manned and unmanned airborne platforms.</P>
                <P>19. The SAGE 750 Electronic Surveillance Measures (ESM) System is a UK-produced, digital electronic intelligence (ELINT) sensor which analyzes the electromagnetic spectrum to map the source of active emissions. Using highly accurate Direction Finding (DF) antennas, SAGE builds target locations and provides situational awareness, advance warning of threats, and the ability to cue other sensors.</P>
                <P>20. The Selex SeaSpray is an Active Electronically Scanned Array (AESA) surveillance radar suitable for a range of capabilities from long-range search to small target detection.</P>
                <P>21. HISAR-300 radar provides superior long range, real-time, high-resolution imaging and wide area search capability for overland and maritime surveillance missions, day or night and in all weather conditions.</P>
                <P>22. The SNC 4500 Auto Electronic Surveillance Measures (ESM) System is a digital electronic intelligence (ELINT) sensor which analyzes the electromagnetic spectrum to map the source of active emissions. Using highly accurate Direction Finding (DF) antennas, the SNC 4500 builds target locations and provides situational awareness, advance warning of threats, and the ability to cue other sensors.</P>
                <P>23. Due Regard Radar (DRR) is a collision avoidance air-to-air radar. DRR is a key component of GA-ASI's overall airborne Detect and Avoid System (DAAS) architecture for the MQ-9B. By tracking non-cooperative aircraft, DRR enables a collision avoidance capability onboard the RPA and allows the pilot to separate the aircraft from other air traffic in cooperation with Air Traffic Control (ATC).</P>
                <P>24. The AN/DPX-7 is an Identification Friend or Foe (IFF) transponder used to identify and track aircraft, ships, and some ground forces to reduce friendly fire incidents.</P>
                <P>25. The MR6000 ultra high frequency (UHF) and very high frequency radio (VHF) is a multi-band, portable, two-way communication radio.</P>
                <P>26. The C-Band Line-of-Sight (LOS) Ground Data Terminals and Ku-Band SATCOM GA-ASI Transportable Earth Stations (GATES) provide command, control, and data acquisition for the MQ-9B.</P>
                <P>27. The Compact Multi-band Data Link (CMDL) is a miniaturized, high-performance, wide-band data links operating in Ku, C, L, or S-band, with both analog and digital waveforms. It is interoperable with military and commercial products including Tactical Common Data Link (TCDL) terminals, the complete line of ROVER systems, and coded orthogonal frequency-division multiplexing (COFDM) receivers.</P>
                <P>28. The highest level of classification of defense articles, components, and services included in this potential sale is SECRET.</P>
                <P>29. If a technologically advanced adversary were to obtain knowledge of the specific hardware and software elements, the information could be used to develop countermeasures that might reduce weapon system effectiveness or be used in the development of a system with similar or advanced capabilities.</P>
                <P>30. A determination has been made that India can provide substantially the same degree of protection for the sensitive technology being released as the U.S. Government. This sale is necessary in furtherance of the U.S. foreign policy and national security objectives outlined in the Policy Justification.</P>
                <P>31. All defense articles and services listed in this transmittal have been authorized for release and export to India.</P>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31699 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6001-FR-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF DEFENSE</AGENCY>
                <SUBAGY>Office of the Secretary</SUBAGY>
                <DEPDOC>[Docket ID: DoD-2024-OS-0148]</DEPDOC>
                <SUBJECT>Proposed Collection; Comment Request</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Washington Headquarter Services (WHS), Department of Defense (DoD).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>60-Day information collection notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        In compliance with the 
                        <E T="03">Paperwork Reduction Act of 1995,</E>
                         the WHS announces a proposed public information collection and seeks public comment on the provisions thereof. Comments are invited on: whether the proposed collection of information is necessary for the proper performance of the functions of the agency, including whether the information shall have practical utility; the accuracy of the agency's estimate of the burden of the proposed information collection; ways to enhance the quality, utility, and clarity of the information to be collected; and ways to minimize the burden of the information collection on respondents, including through the use of automated collection techniques or other forms of information technology.
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Consideration will be given to all comments received by March 7, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may submit comments, identified by docket number and title, by any of the following methods:</P>
                    <P>
                        <E T="03">Federal eRulemaking Portal: http://www.regulations.gov.</E>
                         Follow the instructions for submitting comments.
                    </P>
                    <P>
                        <E T="03">Mail:</E>
                         Department of Defense, Office of the Assistant to the Secretary of Defense for Privacy, Civil Liberties, and Transparency, Regulatory Directorate, 4800 Mark Center Drive, Mailbox #24 Suite 05F16, Alexandria, VA 22350-1700.
                    </P>
                    <P>
                        <E T="03">Instructions:</E>
                         All submissions received must include the agency name, docket number and title for this 
                        <E T="04">Federal Register</E>
                         document. The general policy for comments and other submissions from members of the public is to make these submissions available for public viewing at 
                        <E T="03">http://www.regulations.gov</E>
                         as they are received without change, including any personal identifiers or contact information.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        To request more information on this proposed information collection or to obtain a copy of the proposal and associated collection instruments, please write to WHS Parking Management Office, Pentagon, Room 2D1039, 9000 Defense Pentagon, 
                        <PRTPAGE P="628"/>
                        Washington, DC 20301-9000, Myrna Merced, 703-697-9864.
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P/>
                <P>
                    <E T="03">Title; Associated Form; and OMB Number:</E>
                     Pentagon Reservation Parking Permit Application; DD Form 1199; OMB Control Number 0704-0395.
                </P>
                <P>
                    <E T="03">Needs and Uses:</E>
                     WHS requires the collection of information from members of the public assigned to the Pentagon, Mark Center, and Suffolk buildings to obtain an authorized parking permit to park in a controlled parking facility without being enrolled in the Mass Transit Benefit Program. The authority is promulgated in 10 United States Code 2674 Operation and Control of Pentagon Reservation and Defense Facilities in National Capital Region; Administrative Instruction Number 88, Pentagon Reservation Vehicle Parking Program, and Executive Order 9397 (Social Security Number, as amended.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Individuals or households.
                </P>
                <P>
                    <E T="03">Annual Burden Hours:</E>
                     350.
                </P>
                <P>
                    <E T="03">Number of Respondents:</E>
                     4,200.
                </P>
                <P>
                    <E T="03">Responses per Respondent:</E>
                     1.
                </P>
                <P>
                    <E T="03">Annual Responses:</E>
                     4,200.
                </P>
                <P>
                    <E T="03">Average Burden per Response:</E>
                     5 minutes.
                </P>
                <P>
                    <E T="03">Frequency:</E>
                     On occasion.
                </P>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>Stephanie J. Bost,</NAME>
                    <TITLE>Alternate OSD Federal Register Liaison Officer, Department of Defense. </TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31662 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6001-FR-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF DEFENSE</AGENCY>
                <SUBAGY>Office of the Secretary</SUBAGY>
                <DEPDOC>[Transmittal No. 23-07]</DEPDOC>
                <SUBJECT>Arms Sales Notification</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Defense Security Cooperation Agency, Department of Defense (DoD).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Arms sales notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The DoD is publishing the unclassified text of an arms sales notification.</P>
                </SUM>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Pamela Young at (703) 953-6092, 
                        <E T="03">pamela.a.young14.civ@mail.mil,</E>
                         or 
                        <E T="03">dsca.ncr.rsrcmgmt.list.cns-mbx@mail.mil.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>This 36(b)(1) arms sales notification is published to fulfill the requirements of section 155 of Public Law 104-164 dated July 21, 1996. The following is a copy of a letter to the Speaker of the House of Representatives with attached Transmittal 23-07, Policy Justification, and Sensitivity of Technology.</P>
                <SIG>
                    <DATED>Dated: December 31, 2024.</DATED>
                    <NAME>Stephanie J. Bost,</NAME>
                    <TITLE>Alternate OSD Federal Register Liaison Officer, Department of Defense.</TITLE>
                </SIG>
                <BILCOD>BILLING CODE 6001-FR-P</BILCOD>
                <GPH SPAN="3" DEEP="556">
                    <PRTPAGE P="629"/>
                    <GID>EN06JA25.008</GID>
                </GPH>
                <BILCOD>BILLING CODE 6001-FR-C</BILCOD>
                <HD SOURCE="HD3">Transmittal No. 23-07</HD>
                <HD SOURCE="HD3">Notice of Proposed Issuance of Letter of Offer Pursuant to Section 36(b)(1) of the Arms Export Control Act, as amended</HD>
                <P>
                    (i) 
                    <E T="03">Prospective Purchaser:</E>
                     Republic of Türkiye
                </P>
                <P>
                    (ii) 
                    <E T="03">Total Estimated Value:</E>
                </P>
                <GPOTABLE COLS="2" OPTS="L0,tp0,p0,8/9,g1,t1,i1" CDEF="s30,xs56">
                    <TTITLE> </TTITLE>
                    <BOXHD>
                        <CHED H="1"> </CHED>
                        <CHED H="1"> </CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">Major Defense Equipment *</ENT>
                        <ENT>$15.3 billion</ENT>
                    </ROW>
                    <ROW RUL="n,s">
                        <ENT I="01">Other</ENT>
                        <ENT>$ 7.7 billion</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="02">TOTAL</ENT>
                        <ENT>$23.0 billion</ENT>
                    </ROW>
                </GPOTABLE>
                <P>Funding Source: National Funds</P>
                <P>
                    (iii) 
                    <E T="03">Description and Quantity or Quantities of Articles or Services under Consideration for Purchase:</E>
                     The Republic of Türkiye has requested to buy 40 new F-16 Block 70 aircraft and to modernize 79 existing F-16 aircraft to V-Configuration. The request includes:
                </P>
                <FP SOURCE="FP-2">
                    <E T="03">Major Defense Equipment (MDE):</E>
                </FP>
                <FP SOURCE="FP1-2">Thirty-two (32) F-16 C Block 70 Aircraft</FP>
                <FP SOURCE="FP1-2">Eight (8) F-16 D Block 70 Aircraft</FP>
                <FP SOURCE="FP1-2">Forty-eight (48) F110-GE-129D Engines (40 installed, 8 spares)</FP>
                <FP SOURCE="FP1-2">
                    One hundred forty-nine (149) Improved Programmable Display 
                    <PRTPAGE P="630"/>
                    Generators (iPDG) (40 installed, 10 spares, 99 for modernization program (79 installed, 20 spares))
                </FP>
                <FP SOURCE="FP1-2">One hundred forty-nine (149) AN/APG-83 Active Electronically Scanned Array (AESA) Scalable Agile Beam Radars (SABR) (40 installed, 10 spares, 99 for modernization program (79 installed, 20 spares))</FP>
                <FP SOURCE="FP1-2">One hundred sixty-nine (169) Modular Mission Computers (MMC) 7000AHC (or available mission computer) (40 installed, 10 spares, 119 for modernization program (79 installed, 40 spares))</FP>
                <FP SOURCE="FP1-2">One hundred fifty-nine (159) Embedded Global Positioning System (GPS) Inertial Navigation Systems (INS) (EGI) with Selective Availability Anti-Spoofing Module (SAASM) or M-Code capability and Precise Positioning Service (PPS) (40 installed, 8 spares, 111 for modernization program (79 installed, 32 spares))</FP>
                <FP SOURCE="FP1-2">One hundred sixty-eight (168) Integrated Viper Electronic Warfare Suite (IVEWS) or equivalent Electronic Warfare (EW) systems (40 installed, 10 spares, 118 for modernization program (79 installed, 39 spares))</FP>
                <FP SOURCE="FP1-2">Eight hundred fifty-eight (858) LAU-129 Guided Missile Launchers</FP>
                <FP SOURCE="FP1-2">Forty-four (44) M61 Vulcan cannons (40 installed, 4 spares)</FP>
                <FP SOURCE="FP1-2">Sixteen (16) AN/AAQ-33 Sniper Advanced Targeting Pods (ATP)</FP>
                <FP SOURCE="FP1-2">One hundred fifty-one (151) Multifunctional Information Distribution System-Joint Tactical Radio Systems (MIDS-JTRS) (40 installed and 4 ground terminals, 8 spares, and 99 for modernization program (79 installed and 4 ground terminals, 16 spares))</FP>
                <FP SOURCE="FP1-2">Nine hundred fifty-two (952) Advanced Medium Range Air-to-Air Missiles (AMRAAM) AIM-120C-8 or equivalent missiles</FP>
                <FP SOURCE="FP1-2">Ninety-six (96) AMRAAM Guidance Sections</FP>
                <FP SOURCE="FP1-2">Eight hundred sixty-four (864) GBU-39/B Small Diameter Bombs Increment 1 (SDB-1)</FP>
                <FP SOURCE="FP1-2">Two (2) GBU-39(T-1)/B SDB-1 Guided Test Vehicles</FP>
                <FP SOURCE="FP1-2">Two (2) GBU-39(T-1)/B SDB-1 Practice Bombs</FP>
                <FP SOURCE="FP1-2">Ninety-six (96) AGM-88B High-Speed Anti-Radiation Missiles (HARM)</FP>
                <FP SOURCE="FP1-2">Ninety-six (96) AGM-88E Advanced Anti-Radiation Guided Missiles (AARGM)</FP>
                <FP SOURCE="FP1-2">Ten (10) AARGM Captive Air Training Missiles (CATM)</FP>
                <FP SOURCE="FP1-2">Eleven (11) AARGM Control Sections</FP>
                <FP SOURCE="FP1-2">Twelve (12) AARGM Guidance Sections</FP>
                <FP SOURCE="FP1-2">Four hundred one (401) AIM-9X Block II Sidewinder Missiles</FP>
                <FP SOURCE="FP1-2">Twelve (12) AIM-9X Block II Sidewinder Captive Air Training Missiles (CATMs)</FP>
                <FP SOURCE="FP1-2">Forty (40) AIM-9X Block II Sidewinder Tactical Guidance Units</FP>
                <FP SOURCE="FP1-2">Twelve (12) AIM-9X Block II Sidewinder CATM Guidance Units</FP>
                <FP SOURCE="FP1-2">Twelve (12) MK82 Inert Filled General-Purpose Bombs</FP>
                <FP SOURCE="FP1-2">Eight hundred fifty (850) Joint Direct Attack Munition (JDAM) KMU-556 Tail Kits for GBU-31</FP>
                <FP SOURCE="FP1-2">Two hundred (200) JDAM KMU-557 Tail Kits for GBU-31v3</FP>
                <FP SOURCE="FP1-2">Three hundred eighty-four (384) JDAM KMU-559 Tail Kits for GBU-32</FP>
                <FP SOURCE="FP1-2">Three (3) JDAM KMU-572 Tail Kits for GBU-38 or Laser JDAM GBU-54</FP>
                <FP SOURCE="FP1-2">One thousand fifty (1,050) FMU-152 Fuzes</FP>
                <FP SOURCE="FP-2">
                    <E T="03">Non-MDE:</E>
                </FP>
                <FP SOURCE="FP1-2">Also included are AMRAAM CATMs; AIM-9X Sidewinder training missiles and Active Optical Target Detectors (AOTD); HARM control sections, rocket motors, and warhead spares; FMU-139 Joint Programmable Fuzes; DSU-38 Laser Guidance Sets for GBU-54; missile containers; AN/ARC-238 radios; AN/APX-127 or equivalent Advanced Identification Friend or Foe (AIFF) Combined Interrogator Transponders (CIT) with mode 5; Joint Helmet Mounted Cueing Systems (JHMCS) II or Scorpion Hybrid Optical-based Inertial Tracker (HObIT) helmet mounted displays; Infrared Search and Track (IRST) pods; AN/ALE-47 Countermeasure Dispenser Systems (CMDS); KY-58 and KIV-78 cryptographic devices; Simple Key Loaders (SKLs); additional secure communications, precision navigation, and cryptographic equipment; Flight Mission Planning Systems (FMPS); Remote Operated Video Enhanced Receivers (ROVER) 6i/6Sis; Tactical Network ROVER kits, and STINGER Multi Bi-Directional (MBI) antennas; SNIPER pod pylons; impulse cartridges, chaff, flares, and ammunition; other bomb components; Common Munitions Built-in-Test (BIT) Reprogramming Equipment (CMBRE); Rackmount Improved Avionics Intermediate Shop (RIAIS); Cartridge Actuated Devices/Propellant Actuated Devices (CAD/PAD); Triple Missile Launcher Adapters (TMLA); aircraft, avionics, and weapons integration, test support, and equipment; major modernization upgrade kits for F-16 Block 40 and Block 50+ aircraft and Service Life Extension Program (SLEP) modifications; aircraft and engine repair and refurbishment after maintenance; spare and repair parts, consumables, and accessories and repair and return support; aircraft, engine, ground, and pilot support equipment; Classified/Unclassified Computer Program Identification Number (CPIN) systems; electronic warfare database support; pylons, launcher adaptors, weapon interfaces, bomb and ejection racks, conformal fuel tanks, and travel pods; precision measurement equipment laboratory and calibration support; Classified/Unclassified software and software support; Classified/Unclassified publications, manuals, and technical documentation; maps and mapping data; facilities and construction support; simulators and training devices; personnel training and training equipment; United States (U.S.) Government and contractor engineering, technical and logistics support services, studies and surveys; and other related elements of logistical and program support.</FP>
                <P>
                    (iv) 
                    <E T="03">Military Department:</E>
                     Air Force (TK-D-SAE, TK-D-QCV)
                </P>
                <P>
                    (v) 
                    <E T="03">Prior Related Cases, if any:</E>
                     TK-D-SFA, TK-D-SLA, TK-D-NCU, TK-D-SMB, TK-D-YAC, TK-D-YAE, TK-D-YAH, TK-P-AHX
                </P>
                <P>
                    (vi) 
                    <E T="03">Sales Commission, Fee, etc., Paid, Offered, or Agreed to be Paid:</E>
                     None known at this time
                </P>
                <P>
                    (vii) 
                    <E T="03">Sensitivity of Technology Contained in the Defense Article or Defense Services Proposed to be Sold:</E>
                     See Attached Annex
                </P>
                <P>
                    (viii) 
                    <E T="03">Date Report Delivered to Congress:</E>
                     January 26, 2024
                </P>
                <P>* As defined in Section 47(6) of the Arms Export Control Act.</P>
                <HD SOURCE="HD2">POLICY JUSTIFICATION</HD>
                <HD SOURCE="HD2">Republic of Türkiye—F-16 Aircraft Acquisition and Modernization</HD>
                <P>
                    The Republic of Türkiye has requested to buy 40 new F-16 aircraft and to modernize 79 existing F-16 aircraft to V-Configuration. The request includes: thirty-two (32) F-16 C Block 70 aircraft; eight (8) F-16 D Block 70 aircraft; forty-eight (48) F110-GE-129D engines (40 installed, 8 spares); one hundred forty-nine (149) Improved Programmable Display Generators (iPDG) (40 installed, 10 spares, 99 for modernization program (79 installed, 20 
                    <PRTPAGE P="631"/>
                    spares)); one hundred forty-nine (149) AN/APG-83 Active Electronically Scanned Array (AESA) Scalable Agile Beam Radars (SABR) (40 installed, 10 spares, 99 for modernization program (79 installed, 20 spares)); one hundred sixty-nine (169) Modular Mission Computers (MMC) 7000AHC (or available mission computer) (40 installed, 10 spares, 119 for modernization program (79 installed, 40 spares)); one hundred fifty-nine (159) Embedded Global Positioning System (GPS) Inertial Navigation Systems (INS) (EGI) with Selective Availability Anti-Spoofing Module (SAASM) or M-Code capability and Precise Positioning Service (PPS) (40 installed, 8 spares, 111 for modernization program (79 installed, 32 spares)); one hundred sixty-eight (168) Integrated Viper Electronic Warfare Suite (IVEWS) or equivalent Electronic Warfare (EW) systems (40 installed, 10 spares, 118 for modernization program (79 installed, 39 spares)); eight hundred fifty-eight (858) LAU-129 guided missile launchers; forty-four (44) M61 Vulcan cannons (40 installed, 4 spares); sixteen (16) AN/AAQ-33 Sniper Advanced Targeting Pods (ATP); one hundred fifty-one (151) Multifunctional Information Distribution System-Joint Tactical Radio Systems (MIDS-JTRS) (40 installed and 4 ground terminals, 8 spares, and 99 for modernization program (79 installed and 4 ground terminals, 16 spares)); nine hundred fifty-two (952) Advanced Medium Range Air-to-Air Missiles (AMRAAM) AIM-120C-8 or equivalent missiles; ninety-six (96) AMRAAM guidance sections; eight hundred sixty-four (864) GBU-39/B Small Diameter Bombs Increment 1 (SDB-1); two (2) GBU-39(T-1)/B SDB-1 guided test vehicles; two (2) GBU-39(T-1)/B SDB-1 practice bombs; ninety-six (96) AGM-88B High-Speed Anti-Radiation Missiles (HARM); ninety-six (96) AGM-88E Advanced Anti-Radiation Guided Missiles (AARGM); ten (10) AARGM Captive Air Training Missiles (CATM); eleven (11) AARGM control sections; twelve (12) AARGM guidance sections; four hundred one (401) AIM-9X Block II Sidewinder missiles; twelve (12) AIM-9X Block II Sidewinder Captive Air Training Missiles (CATMs); forty (40) AIM-9X Block II Sidewinder tactical guidance units; twelve (12) AIM-9X Block II Sidewinder CATM guidance units; twelve (12) MK82 Inert Filled general purpose bombs; eight hundred fifty (850) Joint Direct Attack Munition (JDAM) KMU-556 tail kits for GBU-31; two hundred (200) JDAM KMU-557 tail kits for GBU-31v3; three hundred eighty-four (384) JDAM KMU-559 tail kits for GBU-32; three (3) JDAM KMU-572 tail kits for GBU-38 or Laser JDAM GBU-54; one thousand fifty (1,050) FMU-152 fuzes. Also included are AMRAAM CATMs; AIM-9X Sidewinder training missiles and Active Optical Target Detectors (AOTD); HARM control sections, rocket motors, and warhead spares; FMU-139 Joint Programmable Fuzes; DSU-38 Laser Guidance Sets for GBU-54; missile containers; AN/ARC-238 radios; AN/APX-127 or equivalent Advanced Identification Friend or Foe (AIFF) Combined Interrogator Transponders (CIT) with mode 5; Joint Helmet Mounted Cueing Systems (JHMCS) II or Scorpion Hybrid Optical-based Inertial Tracker (HObIT) helmet mounted displays; Infrared Search and Track (IRST) pods; AN/ALE-47 Countermeasure Dispenser Systems (CMDS); KY-58 and KIV-78 cryptographic devices; Simple Key Loaders (SKLs); additional secure communications, precision navigation, and cryptographic equipment; Flight Mission Planning Systems (FMPS); Remote Operated Video Enhanced Receivers (ROVER) 6i/6Sis; Tactical Network ROVER kits, and STINGER Multi Bi-Directional (MBI) antennas; SNIPER pod pylons; impulse cartridges, chaff, flares, and ammunition; bomb components and Common Munitions Built-in-Test Reprogramming Equipment (CMBRE); Rackmount Improved Avionics Intermediate Shop (RIAIS); Cartridge Actuated Devices/Propellant Actuated Devices (CAD/PAD); Triple Missile Launcher Adapters (TMLA); aircraft, avionics, and weapons integration, test support, and equipment; major modernization upgrade kits for F-16 Block 40 and Block 50+ aircraft and Service Life Extension Program (SLEP) modifications; aircraft and engine repair and refurbishment after maintenance; engine and aircraft spare and repair parts, consumables, and accessories and repair and return support; aircraft, engine, ground, and pilot support equipment; Classified/Unclassified Computer Program Identification Number (CPIN) systems; electronic warfare database support; pylons, launcher adaptors, weapon interfaces, bomb and ejection racks, conformal fuel tanks, and travel pods; precision measurement equipment laboratory and calibration support; Classified/Unclassified software and software support; Classified/Unclassified publications, manuals, and technical documentation; maps and mapping data; facilities and construction support; simulators and training devices; personnel training and training equipment; U.S. Government and contractor engineering, technical and logistics support services, studies and surveys; and other related elements of logistical and program support. The estimated total cost is $23.0 billion.
                </P>
                <P>This proposed sale will support the foreign policy goals and national security of the U.S. by improving the air capabilities and interoperability of a North Atlantic Treaty Organization (NATO) Ally that is a force for political and economic stability in Europe.</P>
                <P>The proposed sale will allow Türkiye to expand and modernize its fleet of F-16 aircraft as older F-16 aircraft approach the end of their service life. These new and refurbished aircraft will provide Türkiye with a fleet of modernized multi-role combat aircraft to enable it to provide for the defense of its airspace, contribute to NATO missions to preserve regional security and defend NATO Allies, and maintain interoperability with U.S. and NATO forces. Türkiye has F-16 aircraft in its inventory and will have no difficulty absorbing these aircraft and services into its armed forces.</P>
                <P>The proposed sale of this equipment and support will not alter the basic military balance in the region.</P>
                <P>The principal contractor will be Lockheed Martin, Greenville, SC. The purchaser typically requests offsets. Any offset agreement will be defined in negotiations between the purchaser and the contractor.</P>
                <P>Implementation of this proposed sale will not require the assignment of any additional U.S. Government or contractor representatives to Türkiye.</P>
                <P>There will be no adverse impact on U.S. defense readiness as a result of this proposed sale.</P>
                <HD SOURCE="HD3">Transmittal No. 23-07</HD>
                <HD SOURCE="HD3">Notice of Proposed Issuance of Letter of Offer Pursuant to Section 36(b)(1) of the Arms Export Control Act</HD>
                <HD SOURCE="HD3">Annex</HD>
                <HD SOURCE="HD3">Item No. vii</HD>
                <P>
                    (vii) 
                    <E T="03">Sensitivity of Technology:</E>
                </P>
                <P>
                    1. The F-16 Block 70 weapon system is a fourth generation single-engine supersonic all-weather multirole fighter aircraft and features advanced avionics and systems. It contains the General Electric F110-129D engine, AN/APG-83 radar, digital flight control system, embedded internal global navigation system, Joint Helmet Mounted Cueing Systems (JHMCS) II or Scorpion Hybrid Optical-based Inertial Tracker (HObIT) with Night Vision Device (NVD) compatibility, internal and external Electronic Warfare (EW) equipment, 
                    <PRTPAGE P="632"/>
                    Advanced IFF, Link-16 datalink, operational flight trainer, and software and computer systems.
                </P>
                <P>(a) General Electric F110-GE-129D engines are afterburning turbofan jet engines that power the F-16.</P>
                <P>(b) General Electric F110-GE-129D engine spare modules are kits made up of spare engine components including the following modules: inlet fan, core engine, fan drive turbine, augmenter duct and nozzle, and gear box.</P>
                <P>(c) The Modular Mission Computer (MMC) 7000AHC is the central aircraft computer of the F-16. It serves as the hub for all aircraft subsystems and avionics data transfer.</P>
                <P>(d) The Improved Programmable Display Generator (iPDG) and color multifunction displays utilize ruggedized commercial liquid crystal display technology that is designed to withstand the harsh environment found in modern fighter cockpits. The display generator is the fifth-generation graphics processor for the F-16. Through the use of state-of-the-art microprocessors and graphics engines, it provided orders of magnitude increases in throughput, memory, and graphics capabilities.</P>
                <P>
                    (e) The APG-83 Scalable Agile Beam Radar (SABR) is an Active Electronically Scanned Array (AESA) radar upgrade for the F-16. It includes higher processor power, higher transmission power, more sensitive receiver electronics, and Synthetic Aperture Radar (SAR), which creates higher-resolution ground maps from a greater distance than existing mechanically scanned array radars (
                    <E T="03">e.g.,</E>
                     APG-68). The upgrade features an increase in detection range of air targets, increases in processing speed and memory, and significant improvements in all modes.
                </P>
                <P>(f) The Embedded Global Positioning System/Inertial Navigation System (GPS/INS) (EGI) with Selective Availability Anti-Spoofing Module (SAASM)—or M-Code receiver when available—and Precise Positioning Service (PPS) is a self-contained navigation system that provides the following: acceleration, velocity, position, attitude, platform azimuth, magnetic and true heading, altitude, body angular rates, time tags, and coordinated universal time (UTC) synchronized time. SAASM or M-Code enables the GPS receiver access to the encrypted P(Y or M) signal, providing protection against active spoofing attacks.</P>
                <P>(g) The Joint Helmet Mounted Cueing System II (JHMCS II) or Scorpion Hybrid Optical-based Inertial Tracker (HObIT) is a device used in aircraft to project information to the pilot's eyes and aids in tasks such as cueing weapons and aircraft sensors to air and ground targets. This system projects visual targeting and aircraft performance information on the back of the helmet's visor, enabling the pilot to monitor this information without interrupting their field of view through the cockpit canopy. This provides improvement for close combat targeting and engagement.</P>
                <P>(h) The Integrated Electronic (EW) Warfare Suite provides passive radar warning, wide spectrum Radio Frequency (RF) jamming, and control and management of the entire EW system. This system is anticipated to be internal to the aircraft, although mounted pod variants are used in certain circumstances.</P>
                <P>(i) The Advanced Identification Friend or Foe (AIFF) Combined Interrogator Transponder (CIT) is a system capable of transmitting and interrogating Mode V. Mode IV and Mode V anti-jam performance specifications, data, software source code, algorithms, and tempest plans or reports will not be offered, released, discussed, or demonstrated.</P>
                <P>(j) The Multifunction Information Distribution System (MIDS) Joint Tactical Radio System (JTRS) is a four-channel software programmable radio for Link-16 digital voice communications and datalink, Tactical Air Navigation (TACAN), and advanced waveforms. Link-16 is a command, control, communications, and intelligence (C3I) system incorporating high-capacity and jam-resistant digital communication links for exchange of near real-time tactical information, including both data and voice, among air, ground, and sea elements.</P>
                <P>2. The LAU-129 Guided Missile Launcher is capable of launching the AIM-9 family of missiles or AIM-120 AMRAAM. The LAU-129 launcher serves as the mechanical and electrical interface between missile and aircraft.</P>
                <P>3. The Triple Missile Launcher Adapter (TMLA) carries three (3) missile launchers and missiles from a single standard wing pylon.</P>
                <P>4. The M61 Vulcan Cannon is a six-barreled automatic 20mm cannon with a cyclic rate of fire from 2,500-6,000 shots per minute. This weapon is a hydraulically powered air-cooled Gatling gun used to damage and destroy aerial targets, suppress and incapacitate personnel targets, and damage and destroy moving and stationary light material targets.</P>
                <P>5. The AN/AAQ-33 Sniper Advanced Targeting Pod (ATP) is a single, lightweight targeting pod for military aircraft that provides positive target identification, autonomous tracking, Global Positioning System (GPS) coordinate generation, and precise weapons guidance from extended standoff ranges. It incorporates a high-definition mid-wave forward-looking infrared (FLIR) dual-mode laser, visible-light High-Definition television (HDTV), laser spot tracker, video data link (VDL), and a digital data recorder.</P>
                <P>6. The L3Harris ROVER 6i/6Si transceiver provides real-time full-motion video (FMV) and other network data for situational awareness, targeting, battle damage assessment, and surveillance for relay and convoy over-watch operations and other situations where eyes-on-target are required. This potential sale includes Tactical Network kits and Stinger MBI antennas. It provides expanded frequencies and additional processing resources from previous ROVER versions, allowing increased levels of collaboration and interoperability with numerous manned and unmanned airborne platforms.</P>
                <P>7. The Infrared Search and Track (IRST) system detects and tracks threats that have infrared signatures at long ranges. It can act without emitting any radiation of its own and enables aircrews to detect adversaries before those adversaries see or sense them.</P>
                <P>8. The AN/ARC-238 radio with HAVE QUICK II is a voice communications radio system that employs cryptographic technology. Other waveforms may be included as needed.</P>
                <P>9. The AN/APX-126/127 Advanced Identification Friend or Foe (IFF) Combined Interrogator Transponder (CIT) is a system capable of transmitting and interrogating Mode 5. The AN/APX-127 is a form, fit, and function refresh of the AN/APX-126 and is the next generation to be produced.</P>
                <P>10. The AN/ALE-47 Countermeasure Dispenser Set (CMDS) provides an integrated threat-adaptive computer-controlled capability for dispensing chaff, flares, and active radio frequency expendables. The AN/ALE-47 uses threat data received over the aircraft interfaces to assess the threat situation and determine a response.</P>
                <P>11. The KY-58 is a secure voice module primarily used to encrypt radio communication to and from military aircraft and other tactical vehicles.</P>
                <P>12. The KIV-78 is a cryptographic applique for IFF. It can be loaded with Mode 5 classified elements.</P>
                <P>13. The AN/PYQ-10 Simple Key Loader is a handheld device used for securely receiving, storing, and transferring data between compatible cryptographic and communications equipment.</P>
                <P>
                    14. The Flight Mission Planning System (FMPS) is a multi-platform, PC-
                    <PRTPAGE P="633"/>
                    based mission planning system. FMPS is the Turkish-designed equivalent to the Joint Mission Planning System (JMPS).
                </P>
                <P>15. The AIM-9X Block II Sidewinder Missile is a short-range air-to-air missile providing a high off-boresight seeker, enhanced countermeasure rejection capability, low drag/high angle of attack airframe, and the ability to integrate a Helmet Mounted Cueing System. This potential sale will include AIM-9X guidance section spares, Active Optical Target Detectors, Captive Air Training Missiles (CATM), and CATM guidance units.</P>
                <P>16. The AIM-120C-8 Advanced Medium Range Air-to-Air Missile (AMRAAM) is a supersonic, air-launched, aerial intercept guided missile featuring digital technology and micro-miniature solid-state electronics. AMRAAM capabilities include look-down/shoot-down, multiple launches against multiple targets, resistance to electronic countermeasures, and interception of high- and low-flying and maneuvering targets. This potential sale will include Captive Air Training Missiles (CATM) as well as AMRAAM guidance section and control section spares.</P>
                <P>17. The GBU-39 Small Diameter Bomb Increment 1 (SDB-I) is a 250-lb GPS-aided inertial navigation system with small autonomous, day or night, adverse weather, conventional, air-to-ground precision glide weapon capabilities able to strike fixed and stationary re-locatable non-hardened targets from standoff ranges. It is intended to provide aircraft with an ability to carry a high number of bombs. Aircraft are able to carry four SDBs in place of one 2,000-lb bomb. This potential sale includes SDB-I Guided Test Vehicles and GBU-39/B Tactical Training Rounds.</P>
                <P>18. The AGM-88 High-Speed Anti-Radiation Missile (HARM) is a tactical air-to-surface missile designed to inhibit or destroy surface-to-air missile radars, early warning radars, and radar-directed air defense artillery systems. This potential sale includes HARM guidance section, control section, warhead, and rocket motor spares.</P>
                <P>19. The AGM-88E Advanced Anti-Radiation Guided Missile (AARGM) weapon system is an air-to-ground missile intended for Suppression of Enemy Air Defenses (SEAD) and Destruction of Enemy Air Defenses (DEAD) missions. The AARGM provides suppression or destruction of enemy RADAR and denies the enemy the use of air defense systems, thereby improving the survivability of tactical aircraft. This potential sale will include CATMs as well as guidance section, control section, propulsion section, GPS cards, and warhead spares.</P>
                <P>
                    20. Joint Direct-Attack Munitions (JDAM) consist of a bomb body paired with a warhead-specific tail kit containing an Inertial Navigation System (INS)/Global Positioning System (GPS) guidance capability that converts unguided free-fall bombs into accurate, adverse weather “smart” munitions. The JDAM weapon can be delivered from modest standoff ranges at high or low altitudes against a variety of land and surface targets during the day or night. The JDAM is capable of receiving target coordinates via preplanned mission data from the delivery aircraft, by onboard aircraft sensors (
                    <E T="03">i.e.,</E>
                     FLIR, Radar, etc.) during captive carry, or from a third-party source via manual or automated aircrew cockpit entry.
                </P>
                <P>(a) The GBU-31 is a 2,000-pound JDAM consisting of a KMU-556 tail kit and BLU-109 or MK-84 bomb body.</P>
                <P>(b) The GBU-31v3 is a 2,000-pound JDAM consisting of a KMU-557 tail kit and BLU-109 bomb body.</P>
                <P>(c) The GBU-32 is a 1,000-pound JDAM consisting of a KMU-559 tail kit and BLU-110 or MK-83 bomb body.</P>
                <P>(d) The GBU-54 Laser Joint Direct Attack Munition (LJDAM) is a 500-pound JDAM which incorporates all the capabilities of the JDAM guidance tail kit and adds a precision laser guidance set. The LJDAM gives the weapon system an optional semi-active laser guidance in addition to the INS/GPS guidance. This provides the optional capability to strike moving targets. The GBU-54 consists of a DSU-38 laser guidance set, KMU-572 tail kit, and MK-82 or BLU-111 bomb body.</P>
                <P>(e) This potential sale includes inert bombs, which have no explosive fill and are used for integration testing.</P>
                <P>21. The FMU-152 or FMU-139 Joint Programmable Fuze (JPF) is a multi-delay, multi-arm, and proximity sensor compatible with general purpose blast, frag, and hardened-target penetrator weapons. The JPF settings are cockpit selectable in flight when used with numerous precision-guided weapons.</P>
                <P>22. The Common Munitions Built-In-Test/Reprogramming Equipment (CMBRE) is support equipment used to interface with weapon systems to initiate and report BIT results and to upload and download flight software. CMBRE supports multiple munitions platforms with a range of applications that perform preflight checks, periodic maintenance checks, loading of Operational Flight Program (OFP) data, loading of munitions mission planning data, loading of Global Positioning System (GPS) cryptographic keys, and declassification of munitions memory.</P>
                <P>23. The Electronic Warfare Integrated Reprogramming Database (EWIRDB) is used by U.S. Government engineers in the reprogramming and creation of shareable Mission Data Files for the AN/ALQ-131 electronic countermeasures pod on the F-16 aircraft. The source product is not releasable to the customer.</P>
                <P>24. The highest level of classification of defense articles, components, and services included in this potential sale is SECRET.</P>
                <P>25. If a technologically advanced adversary were to obtain knowledge of the specific hardware and software elements, the information could be used to develop countermeasures that might reduce weapon system effectiveness or be used in the development of a system with similar or advanced capabilities.</P>
                <P>26. A determination has been made that Türkiye can provide substantially the same degree of protection for the sensitive technology being released as the U.S. Government. This sale is necessary in furtherance of the U.S. foreign policy and national security objectives outlined in the Policy Justification.</P>
                <P>27. All defense articles and services listed in this transmittal have been authorized for release and export to Türkiye.</P>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31697 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6001-FR-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF DEFENSE</AGENCY>
                <SUBAGY>Office of the Secretary</SUBAGY>
                <DEPDOC>[Docket ID: DOD-2024-OS-0151]</DEPDOC>
                <SUBJECT>Proposed Collection; Comment Request</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Office of the Under Secretary of Defense for Personnel and Readiness (OUSD (P&amp;R)), Department of Defense (DoD).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>60-Day information collection notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        In compliance with the 
                        <E T="03">Paperwork Reduction Act of 1995,</E>
                         the OUSD P&amp;R announces a proposed public information collection and seeks public comment on the provisions thereof. Comments are invited on: whether the proposed collection of information is necessary for the proper performance of the functions of the agency, including whether the information shall have practical utility; the accuracy of the agency's estimate of the burden of the proposed information collection; ways to enhance the quality, 
                        <PRTPAGE P="634"/>
                        utility, and clarity of the information to be collected; and ways to minimize the burden of the information collection on respondents, including through the use of automated collection techniques or other forms of information technology.
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Consideration will be given to all comments received by March 7, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may submit comments, identified by docket number and title, by any of the following methods:</P>
                    <P>
                        <E T="03">Federal eRulemaking Portal: http://www.regulations.gov.</E>
                         Follow the instructions for submitting comments.
                    </P>
                    <P>
                        <E T="03">Mail:</E>
                         Department of Defense, Office of the Assistant to the Secretary of Defense for Privacy, Civil Liberties, and Transparency, Regulatory Directorate, 4800 Mark Center Drive, Mailbox #24 Suite 05F16, Alexandria, VA 22350-1700.
                    </P>
                    <P>
                        <E T="03">Instructions:</E>
                         All submissions received must include the agency name, docket number and title for this 
                        <E T="04">Federal Register</E>
                         document. The general policy for comments and other submissions from members of the public is to make these submissions available for public viewing at 
                        <E T="03">http://www.regulations.gov</E>
                         as they are received without change, including any personal identifiers or contact information.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>To request more information on this proposed information collection or to obtain a copy of the proposal and associated collection instruments, please write to Office of the Under Secretary of Defense, Military Personnel Policy, 1500 Defense Pentagon, Washington, DC 20301-4000, Ronald Garner (703) 693-1059.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P/>
                <P>
                    <E T="03">Title; Associated Form; and OMB Number:</E>
                     Combat Related Special Compensation and Reconsideration Forms; DD 2860, DD3210; OMB Control Number 0704-CRSC.
                </P>
                <P>
                    <E T="03">Needs and Uses:</E>
                     This information collection requirement is necessary for both the initial review of information and determination of eligibility benefits for the CRSC Program, and to obtain and record additional information for reconsideration into the CRSC Program if the Service Member has been previously denied entry due to failure to meet program criteria. The reconsideration form is used to gain and collect new and substantive documentation that supports the request of the Service Members qualifications for the CRSC Program.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Individuals or households.
                </P>
                <P>
                    <E T="03">Annual Burden Hours:</E>
                     5,625.
                </P>
                <P>
                    <E T="03">Number of Respondents:</E>
                     22,500.
                </P>
                <P>
                    <E T="03">Responses per Respondent:</E>
                     1.
                </P>
                <P>
                    <E T="03">Annual Responses:</E>
                     22,500.
                </P>
                <P>
                    <E T="03">Average Burden per Response:</E>
                     15 minutes.
                </P>
                <P>
                    <E T="03">Frequency:</E>
                     As required.
                </P>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>Stephanie J. Bost,</NAME>
                    <TITLE>Alternate OSD Federal Register Liaison Officer, Department of Defense. </TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31665 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6001-FR-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF DEFENSE</AGENCY>
                <SUBAGY>Office of the Secretary</SUBAGY>
                <DEPDOC>[Docket ID: DoD-2024-OS-0107]</DEPDOC>
                <SUBJECT>Submission for OMB Review; Comment Request</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Office of the Under Secretary of Defense for Personnel and Readiness (OUSD (P&amp;R)), Department of Defense (DoD).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>30-Day information collection notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The DoD has submitted to the Office of Management and Budget (OMB) for clearance the following proposal for collection of information under the provisions of the Paperwork Reduction Act.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Consideration will be given to all comments received by February 5, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        Written comments and recommendations for the proposed information collection should be sent within 30 days of publication of this notice to 
                        <E T="03">www.reginfo.gov/public/do/PRAMain.</E>
                         Find this particular information collection by selecting “Currently under 30-day Review—Open for Public Comments” or by using the search function.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Reginald Lucas, 
                        <E T="03">whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil</E>
                         or (571) 372-7574.
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P/>
                <P>
                    <E T="03">Title; Associated Form; and OMB Number:</E>
                     Defense Sexual Assault Incident Reporting; DD Form 2965, 2910, 2910-1, 2910-2, 2910-3, 2910-4; OMB Control Number 0704-0482.
                </P>
                <P>
                    <E T="03">Type of Request:</E>
                     Extension.
                </P>
                <P>
                    <E T="03">Number of Respondents:</E>
                     8,247.
                </P>
                <P>
                    <E T="03">Responses per Respondent:</E>
                     1.
                </P>
                <P>
                    <E T="03">Annual Responses:</E>
                     8,247.
                </P>
                <P>
                    <E T="03">Average Burden per Response:</E>
                     2.1 hours.
                </P>
                <P>
                    <E T="03">Annual Burden Hours:</E>
                     17,318.
                </P>
                <P>
                    <E T="03">Needs and Uses:</E>
                     Section 563 of Public Law (Pub. L.) 110-417, the National Defense Authorization Act (NDAA) for Fiscal Year (FY) 2009, directs the Secretary of Defense to implement a centralized case-level database for the collection and maintenance of information regarding sexual assaults involving members of the armed forces.
                </P>
                <P>This includes information, if available, about the nature of the assault, victim, alleged offender, investigative information, case outcomes in connection with the assault, and other information necessary to fulfill reporting requirements. Section 543 of Public Law 114-328, the NDAA for FY 2017, further directed the Secretary of Defense to include information on each claim of retaliation in connection with a report of sexual assault in the Armed Force made by or against a member of such Armed Force in the Annual Report on Sexual Assault in the Military. This includes the narrative description and nature of each complaint, information on the complainant and alleged retaliator, and summary and determination of the investigation. Section 536 of Public Law 116-92 of the NDAA for FY 2020 directs the Secretary to prescribe procedures under which a victim who files a restricted report on an incident of sexual assault may request, at any time, the return of any personal property of the victim obtained as part of the sexual assault forensic examination.</P>
                <P>
                    <E T="03">Affected Public:</E>
                     Individuals or households.
                </P>
                <P>
                    <E T="03">Frequency:</E>
                     On occasion.
                </P>
                <P>
                    <E T="03">Respondent's Obligation:</E>
                     Voluntary.
                </P>
                <P>
                    <E T="03">DoD Clearance Officer:</E>
                     Mr. Reginald Lucas.
                </P>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>Stephanie J. Bost,</NAME>
                    <TITLE>Alternate OSD Federal Register Liaison Officer, Department of Defense.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31660 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6001-FR-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF ENERGY</AGENCY>
                <SUBAGY>Federal Energy Regulatory Commission</SUBAGY>
                <SUBJECT>Combined Notice of Filings #1</SUBJECT>
                <P>Take notice that the Commission received the following exempt wholesale generator filings:</P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     EG25-69-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Painter Energy Storage, LLC.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Painter Energy Storage, LLC submits Notice of Self-Certification of Exempt Wholesale Generator Status.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5060.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/21/25.
                </P>
                <P>Take notice that the Commission received the following Complaints and Compliance filings in EL Dockets:</P>
                <PRTPAGE P="635"/>
                <P>
                    <E T="03">Docket Numbers:</E>
                     EL25-46-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Commonwealth of Pennsylvania v. PJM Interconnection, L.L.C.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Complaint of Commonwealth of Pennsylvania v. PJM Interconnection, L.L.C.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5225.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/21/25.
                </P>
                <P>Take notice that the Commission received the following electric rate filings:</P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER10-1107-011.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Pacific Gas and Electric Company.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Triennial Market Power Analysis for Southwest Region of Pacific Gas and Electric Company.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/26/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241226-5393.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 2/24/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER10-1585-027; ER10-1594-027; ER10-1597-011; ER10-1617-027; ER10-1624-012; ER10-1628-027; ER10-1632-029; ER12-60-029; ER16-733-018; ER16-1148-018.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Tenaska Energía de Mexico, S. de R. L. de C.V., LQA, LLC, Tenaska Power Management, LLC, Tenaska Power Services Co., Texas Electric Marketing, LLC, Tenaska Gateway Partners, Ltd., New Mexico Electric Marketing, LLC, Kiowa Power Partners, LLC, California Electric Marketing, LLC, Alabama Electric Marketing, LLC.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Triennial Market Power Analysis for Southwest Power Pool Inc. Region of Alabama Electric Marketing, LLC et al.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5148.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 2/28/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER10-2794-037.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     EDF Trading North America, LLC.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Triennial Market Power Analysis for Southwest Power Pool Inc. Region of EDF Trading North America, LLC.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5067.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 2/28/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER10-2818-012; ER10-2806-012; ER23-2750-003; ER23-2751-003; ER23-2752-003.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     White Rock Wind West, LLC, White Rock Wind East, LLC, Horizon Hill Wind, LLC, TransAlta Energy Marketing (U.S.) Inc., TransAlta Energy Marketing Corporation.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Triennial Market Power Analysis for Southwest Power Pool Inc. Region of TransAlta Energy Marketing Corp., et al.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/26/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241226-5397.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 2/24/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER10-2835-012.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Google Energy LLC.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Triennial Market Power Analysis for Southwest Power Pool Inc. Region of Google Energy LLC.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/27/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241227-5232.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 2/25/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER10-2984-069.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Merrill Lynch Commodities, Inc.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Triennial Market Power Analysis for Southwest Power Pool Inc. Region of Merrill Lynch Commodities, Inc.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5066.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 2/28/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER10-3063-004.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Green Country Energy, LLC.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Triennial Market Power Analysis for Southwest Power Pool Inc. Region of Green Country Energy, LLC.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/27/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241227-5233.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 2/25/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER16-1258-007; ER10-1520-019; ER10-1521-019; ER13-1266-053; ER15-2211-050; ER16-438-010; ER22-1385-013; ER23-674-009; ER23-676-009; ER24-1587-002.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     AlbertaEx, L.P., BHE Power Watch, LLC, BHE Wind Watch, LLC, BHER Market Operations, LLC., Marshall Wind Energy LLC, MidAmerican Energy Services, LLC, CalEnergy, LLC, Occidental Power Marketing, L.P., Occidental Power Services, Inc., Grande Prairie Wind, LLC.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Triennial Market Power Analysis for Southwest Region of Grande Prairie Wind, LLC et al.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/26/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241226-5395.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 2/24/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER25-386-001.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Midcontinent Independent System Operator, Inc., Ameren Illinois Company.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Tariff Amendment: Ameren Illinois Company submits tariff filing per 35.17(b): 2024-12-30_SA 4385 and SA 4386_Ameren IL-Mt. Carmel Sub WCA and UCA to be effective 12/31/9998.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5238.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/21/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER25-438-001.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Midcontinent Independent System Operator, Inc., Ameren Illinois Company.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Tariff Amendment: Ameren Illinois Company submits tariff filing per 35.17(b): 2024-12-30_SA 4393 and SA 4394_Ameren IL-Newton Sub WCA and UCA to be effective 12/31/9998.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5242.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/21/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER25-814-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Evergy Kansas Central, Inc.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Request for Waiver of Tariff Provisions of Evergy Kansas Central, Inc.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/26/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241226-5380.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/16/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER25-822-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Big Rivers Electric Corporation.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Request for Limited Waiver and Expedited Action of Big Rivers Electric Corporation.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/23/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241223-5467.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/13/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER25-823-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Painter Energy Storage, LLC.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Initial Rate Filing: Baseline new to be effective 1/15/2025.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5000.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/21/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER25-825-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     PJM Interconnection, L.L.C.
                </P>
                <P>
                    <E T="03">Description:</E>
                     § 205(d) Rate Filing: Amendment to ISA, Service Agreement No. 6736; Queue No. AE2-226 to be effective 3/1/2025.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5069.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/21/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER25-826-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     West Deptford Energy, LLC.
                </P>
                <P>
                    <E T="03">Description:</E>
                     West Deptford Energy, LLC requests a one-time, limited waiver of the 90-day prior notice requirement set forth in Schedule 2 to the PJM Interconnection, L.L.C. Open Access Transmission Tariff.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/27/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241227-5236.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/17/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER25-827-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     PJM Interconnection, L.L.C.
                </P>
                <P>
                    <E T="03">Description:</E>
                     § 205(d) Rate Filing: Amendment to WMPA, SA No. 7025; Queue No. AG1-193 to be effective 3/4/2025.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5116.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/21/25.
                </P>
                <PRTPAGE P="636"/>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER25-828-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Ringer Hill Wind, LLC.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Compliance filing: Updated Market Power Analysis for the NE Region &amp; Non-Material Change in Status to be effective 12/31/2024.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5181.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/21/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     ER25-829-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Smith Creek Hydro, LLC.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Initial Rate Filing: Baseline new to be effective 12/31/2024.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5209.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/21/25.
                </P>
                <P>
                    The filings are accessible in the Commission's eLibrary system (
                    <E T="03">https://elibrary.ferc.gov/idmws/search/fercgensearch.asp</E>
                    ) by querying the docket number.
                </P>
                <P>Any person desiring to intervene, to protest, or to answer a complaint in any of the above proceedings must file in accordance with Rules 211, 214, or 206 of the Commission's Regulations (18 CFR 385.211, 385.214, or 385.206) on or before 5:00 p.m. Eastern time on the specified comment date. Protests may be considered, but intervention is necessary to become a party to the proceeding.</P>
                <P>
                    eFiling is encouraged. More detailed information relating to filing requirements, interventions, protests, service, and qualifying facilities filings can be found at: 
                    <E T="03">https://www.ferc.gov/docs-filing/efiling/filing-req.pdf</E>
                    . For other information, call (866) 208-3676 (toll free). For TTY, call (202) 502-8659.
                </P>
                <P>
                    The Commission's Office of Public Participation (OPP) supports meaningful public engagement and participation in Commission proceedings. OPP can help members of the public, including landowners, environmental justice communities, Tribal members and others, access publicly available information and navigate Commission processes. For public inquiries and assistance with making filings such as interventions, comments, or requests for rehearing, the public is encouraged to contact OPP at (202) 502-6595 or 
                    <E T="03">OPP@ferc.gov</E>
                    . 
                </P>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>Debbie-Anne A. Reese,</NAME>
                    <TITLE>Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31653 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6717-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF ENERGY</AGENCY>
                <SUBAGY>Federal Energy Regulatory Commission</SUBAGY>
                <DEPDOC>[Project No. P-14581-002]</DEPDOC>
                <SUBJECT>Turlock &amp; Modesto Irrigation District; Notice of Reasonable Period of Time for Water Quality Certification Application</SUBJECT>
                <P>
                    On December 13, 2024, the Turlock &amp; Modesto Irrigation District submitted to the Federal Energy Regulatory Commission (Commission) a copy of its application for Clean Water Act section 401(a)(1) water quality certification filed with the California State Water Resources Control Board (Water Board), in conjunction with the above captioned project. The submittal also included a response from the Water Board stating that it received the application on the same day. Pursuant to section 5.23(b) of the Commission's regulations,
                    <SU>1</SU>
                    <FTREF/>
                     we hereby notify the Water Board of the following:
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         18 CFR 5.23(b).
                    </P>
                </FTNT>
                <P>
                    <E T="03">Date of Receipt of the Certification Request:</E>
                     December 13, 2024
                </P>
                <P>
                    <E T="03">Reasonable Period of Time to Act on the Certification Request:</E>
                     December 13, 2025.
                </P>
                <P>If the Water Board fails or refuses to act on the water quality certification request on or before the above date, then the certifying authority is deemed waived pursuant to section 401(a)(1) of the Clean Water Act, 33 U.S.C. 1341(a)(1).</P>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>Debbie-Anne A. Reese,</NAME>
                    <TITLE>Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31650 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6717-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF ENERGY</AGENCY>
                <SUBAGY>Federal Energy Regulatory Commission</SUBAGY>
                <DEPDOC>[Docket No. CP25-12-000]</DEPDOC>
                <SUBJECT>Rover Pipeline LLC; Notice of Schedule for the Preparation of an Environmental Assessment for the Rover—Bulger Delivery Meter Station Project</SUBJECT>
                <P>On October 31, 2024, Rover Pipeline LLC (Rover), filed an application in Docket No. CP25-12-000 requesting a Certificate of Public Convenience and Necessity pursuant to section 7(c) of the Natural Gas Act to construct, own, and operate certain natural gas pipeline facilities necessary to expand its existing Bulger Compressor Station in Washington County, Pennsylvania. The proposed project is known as the Rover—Bulger Compressor Station and Harmon Creek Meter Station Expansion Project (Project).</P>
                <P>On November 14, 2024, the Federal Energy Regulatory Commission (Commission or FERC) issued its Notice of Application for the Project. Among other things, that notice alerted agencies issuing Federal authorizations of the requirement to complete all necessary reviews and to reach a final decision on a request for a Federal authorization within 90 days of the date of issuance of the Commission staff's environmental document for the Project.</P>
                <P>
                    This notice identifies Commission staff's intention to prepare an environmental assessment (EA) for the Project and the planned schedule for the completion of the environmental review.
                    <SU>1</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         40 CFR 1501.10 (2024).
                    </P>
                </FTNT>
                <HD SOURCE="HD1">Schedule for Environmental Review</HD>
                <P>Issuance of EA May 5, 2025</P>
                <P>
                    90-day Federal Authorization Decision Deadline 
                    <SU>2</SU>
                    <FTREF/>
                     August 4, 2025
                </P>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         The Commission's deadline applies to the decisions of other Federal agencies, and State agencies acting under federally delegated authority, that are responsible for Federal authorizations, permits, and other approvals necessary for proposed projects under the Natural Gas Act. Per 18 CFR 157.22(a), the Commission's deadline for other agency's decisions applies unless a schedule is otherwise established by Federal law.
                    </P>
                </FTNT>
                <P>If a schedule change becomes necessary, additional notice will be provided so that the relevant agencies are kept informed of the Project's progress.</P>
                <HD SOURCE="HD1">Project Description</HD>
                <P>
                    Rover proposes to construct, own, and operate certain facilities necessary to expand its existing Harmon Creek Receipt Meter Station and Bulger Compressor Station, within its existing Bulger Compressor Station in Washington County, Pennsylvania. The Rover-Bulger Compressor Station and Harmon Creek Meter Station Expansion Project would allow Rover to ensure delivery of Range Resources—Appalachia LLC's (Range) requested transportation quantities at the required pressures. According to Rover, the Project is designed to receive up to an additional 400,000 dekatherms of natural gas assets per day to Rover. Rover does not have the authority to construct facilities pursuant to blanket certificate authority under Part 157, Subpart F of the Commission's regulations, therefore, Rover was required to file an application under part 157 of the Commission's regulations.
                    <PRTPAGE P="637"/>
                </P>
                <HD SOURCE="HD1">Background</HD>
                <P>
                    On December 11, 2024, the Commission issued a 
                    <E T="03">Notice of Scoping Period Requesting Comments on Environmental Issues for the Proposed Rover—Bulger Delivery Meter Station Project</E>
                     (Notice of Scoping). The Notice of Scoping was sent to affected landowners; Federal, State, and local government agencies; elected officials; environmental and public interest groups; Native American Tribes; other interested parties; and local libraries and newspapers. All substantive comments will be addressed in the EA.
                </P>
                <HD SOURCE="HD1">Additional Information</HD>
                <P>
                    In order to receive notification of the issuance of the EA and to keep track of formal issuances and submittals in specific dockets, the Commission offers a free service called eSubscription. This service provides automatic notification of filings made to subscribed dockets, document summaries, and direct links to the documents. Go to 
                    <E T="03">https://www.ferc.gov/ferc-online/overview</E>
                     to register for eSubscription.
                </P>
                <P>
                    The Commission's Office of Public Participation (OPP) supports meaningful public engagement and participation in Commission proceedings. OPP can help members of the public, including landowners, environmental justice communities, Tribal members and others, access publicly available information and navigate Commission processes. For public inquiries and assistance with making filings such as interventions, comments, or requests for rehearing, the public is encouraged to contact OPP at (202) 502-6595 or 
                    <E T="03">OPP@ferc.gov.</E>
                </P>
                <P>
                    Additional information about the Project is available from the Commission's Office of External Affairs at (866) 208-FERC or on the FERC website (
                    <E T="03">www.ferc.gov</E>
                    ). Using the “eLibrary” link, select “General Search” from the eLibrary menu, enter the selected date range and “Docket Number” excluding the last three digits (
                    <E T="03">i.e.,</E>
                     CP24-88-000), and follow the instructions. For assistance with access to eLibrary, the helpline can be reached at (866) 208-3676, TTY (202) 502-8659, or at 
                    <E T="03">FERCOnlineSupport@ferc.gov.</E>
                     The eLibrary link on the FERC website also provides access to the texts of formal documents issued by the Commission, such as orders, notices, and rulemakings.
                </P>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>Debbie-Anne A. Reese,</NAME>
                    <TITLE>Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31649 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6717-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF ENERGY</AGENCY>
                <SUBAGY>Federal Energy Regulatory Commission</SUBAGY>
                <SUBJECT>Combined Notice of Filings</SUBJECT>
                <P>Take notice that the Commission has received the following Natural Gas Pipeline Rate and Refund Report filings:</P>
                <HD SOURCE="HD1">Filings Instituting Proceedings</HD>
                <P>
                    <E T="03">Docket Numbers:</E>
                     OR25-6-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Buckeye Pipe Line Company, L.P.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Petition for Declaratory Order of Buckeye Pipe Line Company, L.P.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/20/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241220-5518.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/21/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     RP25-309-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     ETC Tiger Pipeline, LLC.
                </P>
                <P>
                    <E T="03">Description:</E>
                     § 4(d) Rate Filing: Assignment of Chesapeake NRA to SWN to be effective 1/1/2025.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5059.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/13/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     RP25-310-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Gulf Run Transmission, LLC.
                </P>
                <P>
                    <E T="03">Description:</E>
                     § 4(d) Rate Filing: Assignment of Chesapeake NRA to SWN to be effective 1/1/2025.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5064.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/13/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     RP25-311-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Enable Gas Transmission, LLC.
                </P>
                <P>
                    <E T="03">Description:</E>
                     § 4(d) Rate Filing: NRA Filing—SWEPCO &amp; Comanche to be effective 1/1/2025.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5080.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/13/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     RP25-312-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Enable Gas Transmission, LLC.
                </P>
                <P>
                    <E T="03">Description:</E>
                     § 4(d) Rate Filing: Cancel SWEPCO Agreement_2 to be effective 1/1/2025.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5081.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/13/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     RP25-313-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Transcontinental Gas Pipe Line Company, LLC.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Compliance filing: Cash Out Surcharge True Up Filing 2025 to be effective 2/1/2025.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5085.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/13/25.
                </P>
                <P>
                    <E T="03">Docket Numbers:</E>
                     RP25-314-000.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Texas Eastern Transmission, LP.
                </P>
                <P>
                    <E T="03">Description:</E>
                     § 4(d) Rate Filing: TETLP EPC FEB 2025 FILING to be effective 2/1/2025.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5108.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/13/25.
                </P>
                <P>Any person desiring to intervene, to protest, or to answer a complaint in any of the above proceedings must file in accordance with Rules 211, 214, or 206 of the Commission's Regulations (18 CFR 385.211, 385.214, or 385.206) on or before 5:00 p.m. Eastern time on the specified comment date. Protests may be considered, but intervention is necessary to become a party to the proceeding.</P>
                <HD SOURCE="HD1">Filings in Existing Proceedings</HD>
                <P>
                    <E T="03">Docket Numbers:</E>
                     RP23-466-003.
                </P>
                <P>
                    <E T="03">Applicants:</E>
                     Florida Gas Transmission Company, LLC.
                </P>
                <P>
                    <E T="03">Description:</E>
                     Compliance filing: RP23-466-002 Settlement Compliance Filing to be effective 1/1/2025.
                </P>
                <P>
                    <E T="03">Filed Date:</E>
                     12/30/24.
                </P>
                <P>
                    <E T="03">Accession Number:</E>
                     20241230-5141.
                </P>
                <P>
                    <E T="03">Comment Date:</E>
                     5 p.m. ET 1/13/25.
                </P>
                <P>Any person desiring to protest in any the above proceedings must file in accordance with Rule 211 of the Commission's Regulations (18 CFR 385.211) on or before 5:00 p.m. Eastern time on the specified comment date.</P>
                <P>
                    The filings are accessible in the Commission's eLibrary system (
                    <E T="03">https://elibrary.ferc.gov/idmws/search/fercgensearch.asp</E>
                    ) by querying the docket number.
                </P>
                <P>
                    eFiling is encouraged. More detailed information relating to filing requirements, interventions, protests, service, and qualifying facilities filings can be found at: 
                    <E T="03">https://www.ferc.gov/docs-filing/efiling/filing-req.pdf.</E>
                     For other information, call (866) 208-3676 (toll free). For TTY, call (202) 502-8659.
                </P>
                <P>
                    The Commission's Office of Public Participation (OPP) supports meaningful public engagement and participation in Commission proceedings. OPP can help members of the public, including landowners, environmental justice communities, Tribal members and others, access publicly available information and navigate Commission processes. For public inquiries and assistance with making filings such as interventions, comments, or requests for rehearing, the public is encouraged to contact OPP at (202) 502-6595 or 
                    <E T="03">OPP@ferc.gov.</E>
                </P>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>Debbie-Anne A. Reese,</NAME>
                    <TITLE>Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31652 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6717-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <PRTPAGE P="638"/>
                <AGENCY TYPE="S">DEPARTMENT OF ENERGY</AGENCY>
                <SUBAGY>Federal Energy Regulatory Commission</SUBAGY>
                <DEPDOC>[Project No. P-2299-082]</DEPDOC>
                <SUBJECT>Turlock &amp; Modesto Irrigation District; Notice of Reasonable Period of Time for Water Quality Certification Application</SUBJECT>
                <P>
                    On December 13, 2024, the Turlock &amp; Modesto Irrigation District submitted to the Federal Energy Regulatory Commission (Commission) a copy of its application for Clean Water Act section 401(a)(1) water quality certification filed with the California State Water Resources Control Board (Water Board), in conjunction with the above captioned project. The submittal also included a response from the Water Board stating that it received the application on the same day. Pursuant to section 5.23(b) of the Commission's regulations,
                    <SU>1</SU>
                    <FTREF/>
                     we hereby notify the Water Board of the following:
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         18 CFR 5.23(b).
                    </P>
                </FTNT>
                <P>
                    <E T="03">Date of Receipt of the Certification Request:</E>
                     December 13, 2024.
                </P>
                <P>
                    <E T="03">Reasonable Period of Time to Act on the Certification Request:</E>
                     December 13, 2025.
                </P>
                <P>If the Water Board fails or refuses to act on the water quality certification request on or before the above date, then the certifying authority is deemed waived pursuant to section 401(a)(1) of the Clean Water Act, 33 U.S.C. 1341(a)(1).</P>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>Debbie-Anne A. Reese,</NAME>
                    <TITLE>Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31651 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6717-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">ENVIRONMENTAL PROTECTION AGENCY</AGENCY>
                <DEPDOC>[EPA-HQ-OPP-2017-0751; FRL-12478-01-OCSPP]</DEPDOC>
                <SUBJECT>Pesticide Registration Review; Decisions and Case Closures for Several Pesticides; Notice of Availability</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Environmental Protection Agency (EPA).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>This notice announces the availability of EPA's interim registration review decisions for the following chemicals: 1,3-PAD, chlorothalonil, thiophanate-methy/carbendazim, and TCMTB.</P>
                </SUM>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P/>
                    <P>
                        <E T="03">For pesticide specific information, contact:</E>
                         The Chemical Review Manager for the pesticide of interest identified in table 1 of unit I.
                    </P>
                    <P>
                        <E T="03">For general information on the registration review program, contact:</E>
                         Melanie Biscoe, Pesticide Re-Evaluation Division (7508P), Office of Pesticide Programs, Environmental Protection Agency, 1200 Pennsylvania Ave. NW, Washington, DC 20460-0001; telephone number: (202) 566-0701; email address: 
                        <E T="03">biscoe.melanie@epa.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">I. Purpose of This Notice</HD>
                <P>Pursuant to 40 CFR 155.58(c), this notice announces the availability of EPA's interim or final registration review decisions for the pesticides shown in table 1. The interim registration review decisions are supported by rationales included in the docket established for each chemical.</P>
                <GPOTABLE COLS="3" OPTS="L2,nj,i1" CDEF="s50,xls110,r50">
                    <TTITLE>Table 1—Interim Registration Review Decisions Being Issued</TTITLE>
                    <BOXHD>
                        <CHED H="1">Registration review case name and No.</CHED>
                        <CHED H="1">Docket ID No.</CHED>
                        <CHED H="1">Chemical review manager and contact information</CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">1,3-PAD; Case Number 5109</ENT>
                        <ENT>EPA-HQ-OPP-2014-0406</ENT>
                        <ENT>
                            Areej Jahangir, 
                            <E T="03">jahangir.areej@epa.gov</E>
                            , (202) 566-1577.
                        </ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">2-(thiocyanomethylthio) benzothiazole (TCMTB); Case Number 2625</ENT>
                        <ENT>EPA-HQ-OPP-2014-0405</ENT>
                        <ENT>
                            Erin Dandridge, 
                            <E T="03">dandridge.erin@epa.gov</E>
                            , (202) 566-0635.
                        </ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Chlorothalonil; Case Number 0097</ENT>
                        <ENT>EPA-HQ-OPP-2011-0840</ENT>
                        <ENT>
                            Rachel Blatnick, 
                            <E T="03">blatnick.rachel@epa.gov</E>
                            , (202) 566-2223.
                        </ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Thiophanate-methyl and carbendazim; Case Number 2680</ENT>
                        <ENT>EPA-HQ-OPP-2014-0004</ENT>
                        <ENT>
                            Alex McKee, 
                            <E T="03">mckee.alex@epa.gov</E>
                            , (202) 566-1939. 
                            <LI>
                                Megan Snyderman, 
                                <E T="03">snyderman.megan@epa.gov</E>
                                , (202) 566-0639.
                            </LI>
                        </ENT>
                    </ROW>
                </GPOTABLE>
                <HD SOURCE="HD1">II. Background</HD>
                <P>EPA is conducting its registration review of the chemicals listed in table 1 of unit I pursuant to the Federal Insecticide, Fungicide, and Rodenticide Act (FIFRA) section 3(g) (7 U.S.C. 136a(g)) and the Procedural Regulations for Registration Review at 40 CFR part 155, subpart C. FIFRA section 3(g) provides, among other things, that pesticide registrations are to be reviewed every 15 years. Consistent with 40 CFR 155.57, in its final registration review decision, EPA will ultimately determine whether a pesticide continues to meet the registration standard in FIFRA section 3(c)(5) (7 U.S.C. 136a(c)(5)). As part of the registration review process, the Agency has completed interim registration review decisions for the pesticides in table 1 of unit I.</P>
                <P>Prior to completing the interim review decisions in table 1 of unit I, EPA posted proposed interim decisions or proposed registration review decisions for these chemicals and invited the public to submit any comments or new information, consistent with 40 CFR 155.58(a). EPA considered and responded to any comments or information received during these public comment periods in the respective interim decision or final registration review decisions.</P>
                <P>
                    For additional background on the registration review program, see: 
                    <E T="03">https://www.epa.gov/pesticide-reevaluation.</E>
                </P>
                <P>
                    <E T="03">Authority:</E>
                     7 U.S.C. 136 
                    <E T="03">et seq.</E>
                </P>
                <SIG>
                    <DATED>Dated: December 31, 2024.</DATED>
                    <NAME>Jean Anne Overstreet,</NAME>
                    <TITLE>Director, Pesticide Re-Evaluation Division, Office of Pesticide Programs.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31644 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6560-50-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">ENVIRONMENTAL PROTECTION AGENCY</AGENCY>
                <DEPDOC>[EPA-HQ-OPPT-2018-0435]; FRL-8807-03-OCSPP]</DEPDOC>
                <SUBJECT>Diisodecyl Phthalate (DIDP); Risk Evaluation Under the Toxic Substances Control Act (TSCA); Notice of Availability</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Environmental Protection Agency (EPA).</P>
                </AGY>
                <ACT>
                    <PRTPAGE P="639"/>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Environmental Protection Agency (EPA or Agency) is announcing the availability of the final risk evaluation under the Toxic Substances Control Act (TSCA) for diisodecyl phthalate (DIDP). The purpose of risk evaluations under TSCA is to determine whether a chemical substance presents an unreasonable risk of injury to health or the environment, without consideration of costs or non-risk factors, including unreasonable risk to potentially exposed or susceptible subpopulations identified as relevant to the risk evaluation by EPA, under the conditions of use. EPA used the best available science to prepare this final risk evaluation and determined, based on the weight of scientific evidence, that DIDP poses unreasonable risk to human health. Under TSCA, EPA must initiate risk management actions to address the unreasonable risk.</P>
                </SUM>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        The docket for this action, identified by docket identification (ID) number EPA-HQ-OPPT-2018-0435, is available online at 
                        <E T="03">https://www.regulations.gov.</E>
                         Additional information about dockets generally, along with instructions for visiting the docket in-person, is available at 
                        <E T="03">https://www.epa.gov/dockets.</E>
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P/>
                    <P>
                        <E T="03">For technical information:</E>
                         Brianne Raccor, Existing Chemical Risk Management Division (7404M), Office of Pollution Prevention and Toxics, Environmental Protection Agency, 1200 Pennsylvania Ave. NW, Washington, DC 20460-0001; telephone number: (202) 564-0303; email address: 
                        <E T="03">raccor.brianne@epa.gov.</E>
                    </P>
                    <P>
                        <E T="03">For general information:</E>
                         The TSCA-Hotline, ABVI-Goodwill, 422 South Clinton Ave., Rochester, NY 14620; telephone number: (202) 554-1404; email address: 
                        <E T="03">TSCA-Hotline@epa.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">I. Executive Summary</HD>
                <HD SOURCE="HD2">A. Does this action apply to me?</HD>
                <P>
                    This action is directed to the public in general and may be of particular interest to those involved in the manufacture, processing, distribution, use, and disposal of DIDP, related industry trade organizations, non-governmental organizations with an interest in human and environmental health, State and local governments, Tribal Nations, and/or those interested in the assessment of risks involving chemical substances and mixtures regulated under TSCA. As such, the Agency has not attempted to describe all the specific entities that this action might apply to. If you need help determining applicability, consult the technical contact listed under 
                    <E T="02">FOR FURTHER INFORMATION CONTACT</E>
                    .
                </P>
                <HD SOURCE="HD2">B. What is the Agency's authority for taking this action?</HD>
                <P>The Agency conducted this risk evaluation under TSCA section 6, 15 U.S.C. 2605, which requires that EPA conduct risk evaluations on chemical substances and identifies the minimum components EPA must include in all chemical substance risk evaluations. Each risk evaluation must be conducted consistent with the best available science, be based on the weight of the scientific evidence, and consider reasonably available information. 15 U.S.C. 2625(h), (i), and (k). See also the implementing procedural regulations at 40 CFR part 702.</P>
                <HD SOURCE="HD2">C. What action is the Agency taking?</HD>
                <P>EPA is announcing the availability of the final risk evaluation under TSCA for DIDP. The purpose of risk evaluations under TSCA is to determine whether a chemical substance presents an unreasonable risk of injury to health or the environment, without consideration of costs or non-risk factors, including unreasonable risk to potentially exposed or susceptible subpopulations identified as relevant to the risk evaluation by EPA, under the conditions of use. EPA has used the best available science to prepare this final risk evaluation and based on the weight of scientific evidence, determined that DIDP poses unreasonable risk to human health. Upon a determination of unreasonable risk, EPA must initiate risk management action as required pursuant to TSCA section 6(a), 15 U.S.C 2605(a), to address the unreasonable risk.</P>
                <HD SOURCE="HD1">II. Background</HD>
                <HD SOURCE="HD2">A. What is DIDP?</HD>
                <P>DIDP is a common chemical name for the category of chemical substances that includes the following substances: 1,2- benzenedicarboxylic acid, 1,2-diisodecyl ester (CASRN 26761-40-0) and 1,2-benzenedicarboxylic acid, di-C9-11-branched alkyl esters, C10-rich (CASRN 68515-49-1). Both CASRNs contain mainly C10 dialkyl phthalate esters. DIDP is manufactured (including imported), processed, distributed, and disposed as part of industrial, commercial, and consumer conditions of use. DIDP is used primarily as a plasticizer to make flexible polyvinyl chloride (PVC). It is also used to make building and construction materials; automotive articles; and other commercial and consumer products including adhesives and sealants, paints and coatings, and electrical and electronic products. The production volume of DIDP has increased significantly over the past decade from between 100 and 250 million pounds in 2015 to between 100 million and 1 billion pounds in 2019.</P>
                <HD SOURCE="HD2">B. Risk Evaluation of DIDP</HD>
                <P>In May 2019, EPA received a request to conduct a risk evaluation DIDP from ExxonMobil Chemical Company, Evonik Corporation, and Teknor Apex, through the American Chemistry Council's High Phthalates Panel (ACC HPP). In December 2019, EPA notified ACC HPP that the Agency had granted the manufacturer requested risk evaluation. See EPA-HQ-OPPT-2018-0435 (Ref. 1). In November 2020, EPA released the draft scope of the DIDP risk evaluation (Ref. 2) and, after considering public comments, issued the final problem formulation in August 2021 (Ref. 3). On February 29, 2024, EPA released a draft risk evaluation for public comment and peer review by the Science Advisory Committee on Chemicals (SACC). (Ref. 4). The draft documents and public comments are in docket ID number EPA-HQ-OPPT-2024-0073. A non-technical summary is also available (Ref. 5). Given the shared peer review and chemical similarities with DINP, a shared set of responses to peer review and public comments will be available in January 2025 when the final Diisononyl Phthalate (DINP) risk evaluation is released (Ref. 6).</P>
                <HD SOURCE="HD1">III. Unreasonable Risk Determination</HD>
                <P>
                    EPA has determined that DIDP presents an unreasonable risk of injury to human health under the conditions of use. EPA did not identify risk of injury to the environment that would contribute to the unreasonable risk determination for DIDP. EPA has determined that the unreasonable risk to human health presented by DIDP is due to non-cancer effects (
                    <E T="03">i.e.,</E>
                     reduced offspring survival) in female workers of reproductive age from acute inhalation exposures and acute aggregated exposures. The unreasonable risk determination is based on the information within the risk evaluation, the appendices, and technical support documents of the risk evaluation in accordance with TSCA section 6(b). It is also based on TSCA's best available science (TSCA section 26(h)), weight of scientific evidence standards (TSCA section 26(i)), and relevant implementing regulations in 40 CFR part 702, including, to the extent practicable, the amendments to the procedures for chemical risk evaluation 
                    <PRTPAGE P="640"/>
                    under TSCA finalized in May 2024 (89 FR 37028; May 3, 2024).
                </P>
                <P>Between release of the draft risk evaluation and finalization of the DIDP risk evaluation, EPA updated the risk determination to find that six COUs contribute to unreasonable risk of DIDP based on new information identified by EPA, information provided by public commenters, and recommendations of the SACC. These changes stem from consideration of 1) multiple factors impacting occupational exposure during spray application, 2) applicability of developmental effects to average adult workers, and 3) identification of DIDP-containing products that could be spray applied. The COUs that EPA identified as presenting unreasonable risk were for acute exposure scenarios in which unprotected female workers of reproductive age were to spray adhesives and sealants; paints and coatings; lacquers, stains, varnishes, and floor finishes; or penetrants and inspection fluids that contain DIDP, because doing so could create high concentrations of DIDP in mist that an unprotected worker could inhale. The human health hazard that EPA identified as having the strongest evidence to support this risk evaluation is developmental toxicity, which means that laboratory animals dosed with DIDP had litters where more rodent offspring died than was the case with the litters of rodents that were not dosed with DIDP. As the most sensitive health effects of concern relate to exposure of the developing fetus during gestation, the population to which this risk determination is most relevant is female workers of reproductive age.</P>
                <P>
                    Consistent with the statutory requirements of TSCA section 6(a), EPA will propose a risk management regulatory action to the extent necessary so that DIDP no longer presents an unreasonable risk. EPA expects to focus its risk management action on the conditions of use that significantly contribute to the unreasonable risk. However, it should be noted that, under TSCA section 6(a), EPA is not limited to regulating the specific activities found to drive unreasonable risk and may select from among a suite of risk management requirements in section 6(a) related to manufacture (including import), processing, distribution in commerce, commercial use, and disposal as part of its regulatory options to address the unreasonable risk. As a general example, EPA may regulate upstream activities (
                    <E T="03">e.g.,</E>
                     processing, distribution in commerce) to address downstream activities (
                    <E T="03">e.g.,</E>
                     industrial and commercial uses) driving unreasonable risk, even if the upstream activities do not drive the unreasonable risk. Like the prioritization and risk evaluation processes, there is an opportunity for public comment on any proposed risk management actions.
                </P>
                <P>
                    For more information about the TSCA risk evaluation process for existing chemicals, go to 
                    <E T="03">https://www.epa.gov/assessing-and-managing-chemicals-under-tsca.</E>
                </P>
                <HD SOURCE="HD1">IV. References</HD>
                <P>
                    The following is a listing of the documents that are specifically referenced in this document. The docket includes these documents and other information considered by EPA, including documents that are referenced within the documents that are included in the docket, even if the referenced document is not physically located in the docket. For assistance in locating these other documents, please consult the person listed under 
                    <E T="02">FOR FURTHER INFORMATION CONTACT</E>
                    .
                </P>
                <EXTRACT>
                    <FP SOURCE="FP-2">
                        1. EPA. Di-isodecyl Phthalate (DIDP); Manufacturer Request for Risk Evaluation Under the Toxic Substances Control Act (TSCA); Notice of Availability and Request for Comments. 
                        <E T="04">Federal Register</E>
                        . 84 FR 42914, August 19, 2019 (FRL-9998-26).
                    </FP>
                    <FP SOURCE="FP-2">
                        2. EPA. Di-isodecyl Phthalate (DIDP); Draft Scope of the Risk Evaluation to be Conducted Under the Toxic Substances Control Act (TSCA); Notice of Availability and Request for Comments. 
                        <E T="04">Federal Register</E>
                        . 85 FR 76077, November 27, 2020 (FRL-10017-14).
                    </FP>
                    <FP SOURCE="FP-2">
                        3. EPA. Di-isodecyl Phthalate (DIDP); Final Scope of the Risk Evaluation To Be Conducted Under the Toxic Substances Control Act (TSCA); Notice of Availability. 
                        <E T="04">Federal Register</E>
                        . 86 FR 48695, August 31, 2021 (FRL-8807-01-OCSPP).
                    </FP>
                    <FP SOURCE="FP-2">
                        4. EPA. Di-isodecyl Phthalate (DIDP) and Di-isononyl Phthalate (DINP); Science Advisory Committee on Chemicals (SACC) Peer Review of Draft Documents; Notice of SACC Meeting; Availability; and Request for Comment. 
                        <E T="04">Federal Register</E>
                        . 89 FR 43847, May 20, 2024 (FRL-11760-02-OCSPP).
                    </FP>
                    <FP SOURCE="FP-2">5. EPA. Nontechnical Summary of the TSCA Risk Evaluation for Diisodecyl Phthalate (DIDP). December 2024. (EPA Document ID No. EPA-740-S-24-008).</FP>
                    <FP SOURCE="FP-2">6. EPA. Comment Summary and Responses for Diisodecyl Phthalate (DIDP) and Diisononyl Phthalate (DINP). December 2024.</FP>
                </EXTRACT>
                <P>
                    <E T="03">Authority:</E>
                     15 U.S.C. 2601 
                    <E T="03">et seq.</E>
                </P>
                <SIG>
                    <DATED>Dated: December 20, 2024.</DATED>
                    <NAME>Michal Freedhoff,</NAME>
                    <TITLE>Assistant Administrator, Office of Chemical Safety and Pollution Prevention.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31280 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6560-50-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">ENVIRONMENTAL PROTECTION AGENCY</AGENCY>
                <DEPDOC>[EPA-HQ-OAR-2023-0151; FRL-10890-02-OAR]</DEPDOC>
                <SUBJECT>California State Nonroad Engine Pollution Control Standards; Small Off-Road Engines Regulations; Notice of Decision</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Environmental Protection Agency (EPA).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of decision.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Environmental Protection Agency (“EPA”) is providing notice of its decision granting the California Air Resources Board's (“CARB's”) request for an authorization of amendments to its small off-road engine (“SORE”) regulations. CARB's amendments covered by this authorization include those adopted by CARB in 2016 and 2021. EPA's decision was issued under the authority of section 209 of the Clean Air Act (“CAA” or “Act”).</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Petitions for review must be filed by March 7, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        EPA has established a docket for this action under Docket ID EPA-HQ-OAR-2023-0151. All documents relied upon in making this decision, including those submitted to EPA by CARB, are contained in the public docket. Publicly available docket materials are available either electronically through 
                        <E T="03">www.regulations.gov</E>
                         or in hard copy at the EPA Docket Center, WJC West Building, Room 3334, 1301 Constitution Avenue NW, Washington, DC 20004. The Docket Center's hours of operation are 8:30 a.m. to 4:30 p.m.; generally, it is open Monday through Friday, except Federal holidays. The electronic mail (email) address for the EPA Docket is: 
                        <E T="03">a-and-r-Docket@epa.gov.</E>
                         An electronic version of the public docket is available through the Federal government's electronic public docket and comment system. You may access EPA dockets at 
                        <E T="03">http://www.regulations.gov.</E>
                         After opening the 
                        <E T="03">www.regulations.gov</E>
                         website, enter EPA-HQ-OAR-2023-0151 in the “Enter Keyword or ID” fill-in box to view documents in the record. Although a part of the official docket, the public docket does not include Confidential Business Information (“CBI”) or other information whose disclosure is restricted by statute.
                    </P>
                    <P>
                        EPA's Office of Transportation and Air Quality (“OTAQ”) maintains a web page that contains general information on its review of California waiver and authorization requests. Included on that page are links to prior waiver 
                        <E T="04">Federal Register</E>
                         notices, some of which are 
                        <PRTPAGE P="641"/>
                        cited in this notice; the page can be accessed at: 
                        <E T="03">https://www.epa.gov/state-and-local-transportation/vehicle-emissions-california-waivers-and-authorizations.</E>
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Michael Olechiw, Office of Transportation and Air Quality, U.S. Environmental Protection Agency, 2000 Traverwood Drive, Ann Arbor, Michigan 48105. Telephone: 734-214-4297. Email: 
                        <E T="03">California-Waivers-and-Authorizations@epa.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    On May 23, 2023, EPA published a 
                    <E T="04">Federal Register</E>
                     notice announcing its receipt of CARB's authorization request. In that notice, EPA invited public comment on California's authorization request and an opportunity to present testimony at a public hearing.
                    <SU>1</SU>
                    <FTREF/>
                     EPA held a public hearing on June 27, 2023, and the written comment period closed on July 28, 2023.
                    <SU>2</SU>
                    <FTREF/>
                     EPA has considered all comments submitted to the public docket on this matter.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         88 FR 33143 (May 23, 2023).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         A transcript of the public hearing is located at EPA-HQ-OAR-2023-0151-0007 and all written comments are also located at 
                        <E T="03">regulations.gov</E>
                         at EPA-HQ-OAR-2023-0151.
                    </P>
                </FTNT>
                <P>
                    On December 19, 2024, I signed a Decision Document granting California an authorization pursuant to section 209(e)(2)(A) of the CAA, as amended, 42 U.S.C. 7543(e)(2)(A), for CARB's 2016 and 2021 amendments to CARB's SORE regulations (the “2016 SORE Amendments” and “2021 SORE Amendments” respectively).
                    <SU>3</SU>
                    <FTREF/>
                     The 2016 SORE Amendments incorporate improvements to evaporative emissions certification procedures, revise the compliance testing procedure, update the evaporative emissions certification test fuel to represent commercially available gasoline, and align aspects of the SORE requirements with the corresponding federal requirements, while retaining elements of the evaporative emission standards previously adopted by CARB. The 2021 SORE Amendments primarily establish exhaust and evaporative emission standards and associated test procedures for 2024 and subsequent model year engines and equipment. The 2021 SORE Amendments establish SORE emission standards in two phases. First, the exhaust emission standards for most 2024 and subsequent model year (“MY”) SORE are zero (0.00 grams per kilowatt-hour) for hydrocarbons and oxides of nitrogen. The evaporative emission standards for most 2024 and subsequent MY SORE are zero (0.00 grams per test). The above-mentioned emission standards apply for all categories of SORE except pressure washer engines with displacements greater than or equal to 225 cubic centimeters (cc) and portable generator engines. The emission standards for these latter categories of engines are amended and start in MY 2024; they are not zero but are numerically lower (more stringent) than the pre-MY 2024 CARB emission standards. The second phase of the emissions standards will be implemented beginning in MY 2028, when the exhaust and evaporative emission standards for engines used in pressure washers with displacements greater than or equal to 225 cc and portable generators will be aligned with the zero emission standards for other categories of SORE. A comprehensive description of California's SORE amendments can be found in the Decision Document for this authorization and in materials submitted to the Docket by CARB.
                    <SU>4</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         EPA's Decision Document can be found at EPA-HQ-OAR-2023-0151. EPA's authorization decision includes the entire 2016 amendment and 2021 amendment regulatory text that can be found in CARB's December 20, 2022, authorization request (the SORE Authorization Support Document) found at EPA-HQ-OAR-2023-0151-0003. (CARB's entire authorization submission to EPA is found at EPA-HQ-OAR-2023-0151). The specific regulatory provisions under EPA's authorization consideration and included in this decision can be found at footnotes 1 and 2 to the SORE Authorization Support Document.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         The Decision Document can be found at EPA-HQ-OAR-2023-0151.
                    </P>
                </FTNT>
                <P>
                    CAA section 209(e)(1) permanently preempts any state, or political subdivision thereof, from adopting or attempting to enforce any standard or other requirement relating to the control of emissions for certain new nonroad engines or vehicles.
                    <SU>5</SU>
                    <FTREF/>
                     For all other nonroad engines (including “non-new” engines), states generally are preempted from adopting and enforcing standards and other requirements relating to the control of emissions, except that CAA section 209(e)(2)(A) requires EPA, after notice and opportunity for public hearing, to authorize California to adopt and enforce such regulations unless EPA makes one of three enumerated findings. Specifically, EPA must deny the authorization if the Administrator finds that (1) California's protectiveness determination (
                    <E T="03">i.e.,</E>
                     that California standards will be, in the aggregate, as protective of public health and welfare as applicable federal standards) is arbitrary and capricious, (2) California does not need such standards to meet compelling and extraordinary conditions, or (3) the California standards and accompanying enforcement procedures are not consistent with section 209 of the Act.
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         States are expressly preempted from adopting or attempting to enforce any standard or other requirement relating to the control of emissions from new nonroad engines which are used in construction equipment or vehicles or used in farm equipment or vehicles and which are smaller than 175 horsepower. Such express preemption under CAA section 209(e)(1) also applies to new locomotives or new engines used in locomotives.
                    </P>
                </FTNT>
                <P>
                    On July 20, 1994, EPA promulgated a rule (the 1994 rule) interpreting the three criteria set forth in CAA section 209(e)(2)(A) that EPA must consider before granting any California authorization request for nonroad engine or vehicle emission standards.
                    <SU>6</SU>
                    <FTREF/>
                     EPA revised these regulations in 1997.
                    <SU>7</SU>
                    <FTREF/>
                     As stated in the preamble to the 1994 rule, EPA has interpreted the consistency inquiry under the third criterion, outlined above and set forth in section 209(e)(2)(A)(iii), to require, at minimum, that California standards and enforcement procedures be consistent with section 209(a), section 209(e)(1), and section 209(b)(1)(C) of the Act.
                    <SU>8</SU>
                    <FTREF/>
                     In order to be consistent with section 209(a), California's nonroad standards and enforcement procedures must not apply to new motor vehicles or new motor vehicle engines. To be consistent with section 209(e)(1), California's nonroad standards and enforcement procedures must not attempt to regulate engine categories that are permanently preempted from state regulation. To determine consistency with section 209(b)(1)(C), EPA typically reviews nonroad authorization requests under the same “consistency” criteria that are applied to motor vehicle waiver requests under CAA section 209(b)(1)(C). That section provides that the Administrator shall not grant California a motor vehicle waiver if the Administrator finds that California “standards and accompanying enforcement procedures are not consistent with section 202(a)” of the Act.
                </P>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         See “Air Pollution Control; Preemption of State Regulation for Nonroad Engine and Vehicle Standards,” 59 FR 36969 (July 20, 1994).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>7</SU>
                         See “Control of Air Pollution: Emission Standards for New Nonroad Compression-Ignition Engines at or Above 37 Kilowatts; Preemption of State Regulation for Nonroad Engine and Vehicle Standards; Amendments to Rules,” 62 FR 67733 (December 30, 1997). The applicable regulations are now found in 40 CFR part 1074, subpart B, Part 1074.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>8</SU>
                         EPA has interpreted section 209(b)(1)(C) in the context of section 209(b) motor vehicle waivers.
                    </P>
                </FTNT>
                <P>
                    CARB determined that these standards and accompanying enforcement procedures do not cause California's standards, in the aggregate, to be less protective to public health and welfare than the applicable Federal standards. The administrative record, including information presented to me by parties opposing California's 
                    <PRTPAGE P="642"/>
                    authorization request, did not demonstrate that California arbitrarily or capriciously reached this protectiveness determination. Therefore, based on the record, I cannot find California's determination to be arbitrary and capricious under section 209(e)(2)(A)(i).
                </P>
                <P>CARB has demonstrated the existence of compelling and extraordinary conditions justifying the need for such State standards. The administrative record, including information presented to me by parties opposing California's authorization request, did not demonstrate that California does not need such State standards to meet compelling and extraordinary conditions. Thus, based on the record, I cannot deny the authorization based on section 209(e)(2)(A)(ii).</P>
                <P>CARB has submitted information that its emission standards and test procedures are consistent with section 209(a), section 209(e)(1), and section 209(b)(1)(C) of the Act. The administrative record, including information presented to me by parties opposing California's authorization request, did not satisfy the burden of persuading EPA that the standards are not consistent with section 209. Thus, based on the record, I cannot deny the authorization based on section 209(e)(2)(A)(iii).</P>
                <P>Accordingly, I hereby granted the authorization requested by California.</P>
                <P>Section 307(b)(1) of the CAA governs judicial review of final actions by the EPA. Petitions for review must be filed by March 7, 2025.</P>
                <P>As with past authorization decisions, this action is not a rule as defined by Executive Order 12866. Therefore, it is exempt from review by the Office of Management and Budget as required for rules and regulations by Executive Order 12866.</P>
                <P>In addition, this action is not a rule as defined in the Regulatory Flexibility Act, 5 U.S.C. 601(2). Therefore, EPA has not prepared a supporting regulatory flexibility analysis addressing the impact of this action on small business entities.</P>
                <P>
                    The Congressional Review Act, 5 U.S.C. 801 
                    <E T="03">et seq.,</E>
                     as added by the Small Business Regulatory Enforcement Fairness Act of 1996, does not apply because this action is not a rule, for purposes of 5 U.S.C. 804(3).
                </P>
                <SIG>
                    <NAME>Michael S. Regan,</NAME>
                    <TITLE>Administrator.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31123 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6560-50-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">ENVIRONMENTAL PROTECTION AGENCY</AGENCY>
                <DEPDOC>[EPA-HQ-OAR-2023-0292; FRL-11010-02-OAR]</DEPDOC>
                <SUBJECT>California State Motor Vehicle and Engine Pollution Control Standards; Advanced Clean Cars II; Waiver of Preemption; Notice of Decision</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Environmental Protection Agency (EPA).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of decision.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Environmental Protection Agency (“EPA”) is providing notice of its decision granting the California Air Resources Board's (“CARB's”) request for a waiver of Clean Air Act preemption for its Advanced Clean Cars II (“ACC II”) regulations. EPA's decision was issued under the authority of the Clean Air Act (“CAA” or “Act”) section 209.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Petitions for review must be filed by March 7, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        EPA has established a docket for this action under Docket ID EPA-HQ-OAR-2023-0292. All documents relied upon in making this decision, including those submitted to EPA by CARB, are contained in the public docket. Publicly available docket materials are available either electronically through 
                        <E T="03">www.regulations.gov</E>
                         or in hard copy at the EPA Docket Center, WJC West Building, Room 3334, 1301 Constitution Avenue NW, Washington, DC 20004. The Docket Center's hours of operation are 8:30 a.m. to 4:30 p.m.; generally, it is open Monday through Friday, except Federal holidays. The electronic mail (email) address for the EPA Docket Center is: 
                        <E T="03">a-and-r-Docket@epa.gov.</E>
                         An electronic version of the public docket is available through the Federal government's electronic public docket and comment system. You may access EPA dockets at 
                        <E T="03">http://www.regulations.gov.</E>
                         After opening the 
                        <E T="03">www.regulations.gov</E>
                         website, enter EPA-HQ-OAR-2023-0292 in the “Enter Keyword or ID” fill-in box to view documents in the record. Although a part of the official docket, the public docket does not include Confidential Business Information (“CBI”) or other information whose disclosure is restricted by statute.
                    </P>
                    <P>
                        EPA's Office of Transportation and Air Quality (“OTAQ”) maintains a web page that contains general information on its review of California waiver and authorization requests. Included on that page are links to prior waiver 
                        <E T="04">Federal Register</E>
                         notices, some of which are cited in this notice; the page can be accessed at: 
                        <E T="03">https://www.epa.gov/state-and-local-transportation/vehicle-emissions-california-waivers-and-authorizations.</E>
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Michael Olechiw, Office of Transportation and Air Quality, U.S. Environmental Protection Agency, 2000 Traverwood Drive, Ann Arbor, MI 48105. Telephone: 734-214-4297. Email: 
                        <E T="03">California-Waivers-and-Authorizations@epa.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    On December 26, 2023, EPA published a 
                    <E T="04">Federal Register</E>
                     notice announcing its receipt of CARB's waiver request. In that notice, EPA invited public comment on California's waiver request and an opportunity to present testimony at a public hearing.
                    <SU>1</SU>
                    <FTREF/>
                     EPA held a public hearing on January 10, 2024, and the written comment period closed on February 27, 2024.
                    <SU>2</SU>
                    <FTREF/>
                     EPA has considered all comments submitted to the public docket on this matter.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         88 FR 88908 (December 26, 2023).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         A transcript of the public hearing is located at EPA-HQ-OAR-2023-0292-0056 and all written comments are also located at 
                        <E T="03">regulations.gov</E>
                         at EPA-HQ-OAR-2023-0292.
                    </P>
                </FTNT>
                <P>
                    On December 17, 2024, I signed a Decision Document granting California a waiver of preemption pursuant to section 209(b) of the CAA, as amended, 42 U.S.C. 7543(b), for regulations applicable to new 2026 and subsequent model year (MY) California on-road light- and medium-duty vehicles, hereafter the Advanced Clean Cars II (“ACC II”) regulations.
                    <SU>3</SU>
                    <FTREF/>
                     The ACC II program includes a series of requirements regarding California's low emission vehicle (“LEV”) IV regulation and a series of requirements regarding its zero-emission vehicle (“ZEV”) program.
                    <SU>4</SU>
                    <FTREF/>
                     The LEV IV requirements include, for example, applying exhaust and evaporative emission fleet-average standards solely to vehicles powered by internal combustion engines and excluding ZEVs from the fleet calculation. The LEV IV requirements reduce the maximum allowed exhaust and evaporative emission rates from 
                    <PRTPAGE P="643"/>
                    vehicles under the existing fleet-average standard and aim to reduce cold-start emissions by applying the emissions standards to a broader range of in-use driving conditions. The ZEV requirements of ACC II include, for example, a requirement for vehicle manufacturers to sell increasing percentages of ZEVs beginning with the 2026 MY. Manufacturers can meet up to 20 percent of their sales requirements using plug-in hybrid vehicles (PHEVs) that meet specified requirements. A comprehensive description of California's ACC II program can be found in the Decision Document for this waiver and in materials submitted to the Docket by CARB.
                </P>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         EPA's Decision Document can be found at EPA-HQ-OAR-2023-0292. In addition to the Decision Document, EPA prepared a Supplemental Response to Comments document that is also part of the Administrator's waiver decision. The Supplemental Response to Comments document can also be found at EPA-HQ-OAR-2023-0292.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         EPA's waiver decision includes the entire ACC II regulatory text that can be found in Attachment 7 to CARB's May 22, 2023, ACC II waiver request (the ACC II Waiver Support Document) found at EPA-HQ-OAR-2023-0292-0034. (CARB's entire waiver submission to EPA is found at EPA-HQ-OAR-2023-0292). The specific regulatory provisions under EPA's waiver consideration can be found at footnote 36 to the ACC II Waiver Support Document.
                    </P>
                </FTNT>
                <P>Section 209(b) of the Act provides that the Administrator, after notice and opportunity for public hearing, shall waive Federal preemption for California to enforce new motor vehicle emission standards and accompanying enforcement procedures unless certain criteria are met. The criteria for denying such a waiver include consideration of whether California arbitrarily and capriciously determined that its standards are, in the aggregate, at least as protective of public health and welfare as the applicable Federal standards; whether California does not need such State standards to meet compelling and extraordinary conditions; and whether such State standards and accompanying enforcement procedures are not consistent with section 202(a) of the Act.</P>
                <P>CARB determined that these standards and accompanying enforcement procedures do not cause California's standards, in the aggregate, to be less protective to public health and welfare than the applicable Federal standards. The administrative record, including information presented to me by parties opposing California's waiver, did not demonstrate that California arbitrarily or capriciously reached this protectiveness determination. Therefore, based on the record, I cannot find California's determination to be arbitrary and capricious under section 209(b)(1)(A).</P>
                <P>CARB has demonstrated the existence of compelling and extraordinary conditions justifying the need for such State standards. The administrative record, including information presented to me by parties opposing California's waiver request, did not demonstrate that California does not need such State standards to meet compelling and extraordinary conditions. Thus, based on the record, I cannot deny the waiver based on section 209(b)(1)(B).</P>
                <P>CARB has submitted information that its emission standards and test procedures are technologically feasible, present no inconsistency with Federal requirements, and are consistent with section 202(a) of the Act. The administrative record, including information presented to me by parties opposing California's waiver request, did not satisfy the burden of persuading EPA that the standards are not consistent with section 202(a). Thus, based on the record, I cannot deny the waiver based on section 209(b)(1)(C).</P>
                <P>Accordingly, I hereby granted the waiver requested by California.</P>
                <P>Section 307(b)(1) of the CAA governs judicial review of final actions by the EPA. Petitions for review must be filed by March 7, 2025.</P>
                <P>As with past waiver decisions, this action is not a rule as defined by Executive Order 12866. Therefore, it is exempt from review by the Office of Management and Budget as required for rules and regulations by Executive Order 12866.</P>
                <P>In addition, this action is not a rule as defined in the Regulatory Flexibility Act, 5 U.S.C. 601(2). Therefore, EPA has not prepared a supporting regulatory flexibility analysis addressing the impact of this action on small business entities.</P>
                <P>
                    The Congressional Review Act, 5 U.S.C. 801 
                    <E T="03">et seq.,</E>
                     as added by the Small Business Regulatory Enforcement Fairness Act of 1996, does not apply because this action is not a rule, for purposes of 5 U.S.C. 804(3).
                </P>
                <SIG>
                    <NAME>Michael S. Regan,</NAME>
                    <TITLE>Administrator.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31128 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6560-50-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">ENVIRONMENTAL PROTECTION AGENCY</AGENCY>
                <DEPDOC>[EPA-HQ-OAR-2022-0332; FRL-9902-02-OAR]</DEPDOC>
                <SUBJECT>
                    California State Motor Vehicle and Engine and Nonroad Engine Pollution Control Standards; The “Omnibus” Low NO
                    <E T="0735">X</E>
                     Regulation; Waiver of Preemption; Notice of Decision
                </SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Environmental Protection Agency (EPA).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of decision.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        The Environmental Protection Agency (“EPA”) is providing notice of its decision to grant the California Air Resources Board's (“CARB”) request for a waiver of Clean Air Act (CAA) preemption for its Heavy-Duty Vehicle and Engine “Omnibus” Low NO
                        <E T="52">X</E>
                         Regulations (“Omnibus Low NO
                        <E T="52">X</E>
                         program”). EPA's decision also includes an authorization for portions of the Omnibus Low NO
                        <E T="52">X</E>
                         program that pertain to off-road diesel engines. This decision was issued under the authority of the Clean Air Act (“CAA” or “Act”) section 209.
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Petitions for review must be filed by March 7, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        EPA has established a docket for this action under Docket ID EPA-HQ-OAR-2022-0332. All documents relied upon in making this decision, including those submitted to EPA by CARB, are contained in the public docket. Publicly available docket materials are available either electronically through 
                        <E T="03">www.regulations.gov</E>
                         or in hard copy at the EPA Docket Center, WJC West Building, Room 3334, 1301 Constitution Avenue NW, Washington, DC 20004. The Docket Center's hours of operation are 8:30 a.m. to 4:30 p.m.; generally, it is open Monday through Friday, except Federal holidays. The electronic mail (email) address for the EPA Docket is: 
                        <E T="03">a-and-r-Docket@epa.gov.</E>
                         An electronic version of the public docket is available through the Federal government's electronic public docket and comment system. You may access EPA dockets at 
                        <E T="03">http://www.regulations.gov.</E>
                         After opening the 
                        <E T="03">www.regulations.gov</E>
                         website, enter EPA-HQ-OAR-2022-0332 in the “Enter Keyword or ID” fill-in box to view documents in the record. Although a part of the official docket, the public docket does not include Confidential Business Information (“CBI”) or other information whose disclosure is restricted by statute.
                    </P>
                    <P>
                        EPA's Office of Transportation and Air Quality (“OTAQ”) maintains a web page that contains general information on its review of California waiver and authorization requests. Included on that page are links to prior waiver 
                        <E T="04">Federal Register</E>
                         notices, some of which are cited in this notice; the page can be accessed at: 
                        <E T="03">https://www.epa.gov/state-and-local-transportation/vehicle-emissions-california-waivers-and-authorizations.</E>
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Brian Nelson, Office of Transportation and Air Quality, U.S. Environmental Protection Agency, 2000 Traverwood Drive, Ann Arbor, Michigan 48105. Telephone: 734-214-4278. Email: 
                        <E T="03">California-Waivers-and-Authorizations@epa.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    On June 13, 2022, EPA published a 
                    <E T="04">Federal Register</E>
                     notice announcing its receipt of California's waiver request. In that notice, EPA invited public comment on 
                    <PRTPAGE P="644"/>
                    California's waiver request and an opportunity to present testimony at a public hearing.
                    <SU>1</SU>
                    <FTREF/>
                     EPA held a public hearing on June 29 and June 30, 2022; EPA has considered all comments submitted, including those submitted after the close of the comment period.
                    <SU>2</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         87 FR 35765 (June 13, 2022).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         A transcript for each day of the hearing (June 29th and 30th, 2022) can be found in the docket: June 29th Hearing Transcript, Docket No. EPA-HQ-OAR-2022-0332-0035; June 30th Hearing Transcript, Docket No. EPA-HQ-OAR-2022-0332-0036. All written comments are also located at 
                        <E T="03">regulations.gov</E>
                         at EPA-HQ-OAR-2022-0332.
                    </P>
                </FTNT>
                <P>
                    On December 17, 2024, I signed a Decision Document granting California a waiver of preemption pursuant to section 209(b) of the CAA, as amended, 42 U.S.C. 7543(b), for regulations applicable to new 2024 and subsequent model year (MY) California on-road heavy-duty vehicles and engines, hereafter the Omnibus Low NO
                    <E T="52">X</E>
                     regulations.
                    <SU>3</SU>
                    <FTREF/>
                     The Omnibus Low NO
                    <E T="52">X</E>
                     program includes requirements for revised heavy-duty emission standards, test procedures, regulatory useful life, and emissions warranty. As part of my decision, I have also decided to grant an authorization pursuant to section 209(e) of the CAA, as amended, 42 U.S.C. 7543(e) for portions of the Omnibus Low NO
                    <E T="52">X</E>
                     program regarding off-road diesel engines. The Omnibus Low NO
                    <E T="52">X</E>
                     program includes new PM emission standards for off-road diesel-fueled auxiliary power units. A comprehensive description of California's Omnibus Low NO
                    <E T="52">X</E>
                     program can be found in the Decision Document for this waiver and in materials submitted to the Docket by the California Air Resources Board (CARB).
                    <SU>4</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         EPA's Decision Document is located at EPA-HQ-OAR-2022-0332. EPA's waiver decision includes the Omnibus Low NO
                        <E T="52">X</E>
                         Regulation which was adopted by the California Air Resources Board on August 27, 2020 by Resolution 20-23, and includes amendments approved by the CARB Executive Officer on September 9, 2021 under CARB Order No. R-21-007. The Omnibus Low NO
                        <E T="52">X</E>
                         Regulation is comprised of new title 13, California Code of Regulations (Cal. Code Regs.) sections 2139.5, and 2169.1 through 2169.8; amendments to title 13, Cal. Code Regs., sections 1900, 1956.8, 1961.2, 1965, 1968.2, 1971.1, 1971.5, 2035, 2036, 2111, 2112, 2113, 2114, 2115, 2116, 2117, 2118, 2119, 2121, 2123, 2125, 2126, 2127, 2128, 2129, 2130, 2131, 2133, 2137, 2139, 2140, 2141, 2142, 2143, 2144, 2145, 2146, 2147, 2148, 2149, 2166, 2166.1, 2167, 2168, 2169, 2170, 2423, and 2485; and amendments to title 17 Cal. Code Regs. sections 95662 and 95663. EPA's waiver decision also includes the 2023 Targeted Amendments to Omnibus which were adopted on December 28, 2023 by CARB Executive Order No. R-23-006. The 2023 Targeted Amendments are comprised of title 13, California Code of Regulations (Cal. Code Regs.) sections 1956.8, 1971.1, and 1971.5.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         The Decision Document can be found at EPA-HQ-OAR-2022-0332.
                    </P>
                </FTNT>
                <P>
                    For the portions of the Omnibus Low NO
                    <E T="52">X</E>
                     program that pertain to on-road emission standards, section 209(b) of the Act provides that the Administrator, after notice and opportunity for public hearing, shall waive Federal preemption for California to enforce new motor vehicle emission standards and accompanying enforcement procedures unless certain criteria are met. The criteria of denying such a waiver include consideration of whether California arbitrarily and capriciously determined that its standards are, in the aggregate, at least as protective of public health and welfare as the applicable Federal standards; whether California does not need such State standards to meet compelling and extraordinary conditions; and whether such State standards and accompanying enforcement procedures are not consistent with section 202(a) of the Act.
                </P>
                <P>
                    For the portions of the Omnibus Low NO
                    <E T="52">X</E>
                     program that pertain to nonroad emission standards, section 209(e)(1) of the Act permanently preempts any state, or political subdivision thereof, from adopting or attempting to enforce any standard or other requirement relating to the control of emissions for certain new nonroad engines or vehicles.
                    <SU>5</SU>
                    <FTREF/>
                     For all other nonroad engines (including “non-new” engines), states generally are preempted from adopting and enforcing standards and other requirements relating to the control of emissions, except that section 209(e)(2)(A) of the Act requires EPA, after notice and opportunity for public hearing, to authorize California to adopt and enforce such regulations unless EPA makes one of three enumerated findings. Specifically, EPA must deny authorization if the Administrator finds that (1) California's protectiveness determination (
                    <E T="03">i.e.,</E>
                     that California standards will be, in the aggregate, as protective of public health and welfare as applicable federal standards) is arbitrary and capricious, (2) California does not need such standards to meet compelling and extraordinary conditions, or (3) the California standards and accompanying enforcement procedures are not consistent with section 209 of the Act.
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         States are expressly preempted from adopting or attempting to enforce any standard or other requirement relating to the control of emissions from new nonroad engines which are used in construction equipment or vehicles or used in farm equipment or vehicles and which are smaller than 175 horsepower. Such express preemption under section 209(e)(1) of the Act also applies to new locomotives or new engines used in locomotives.
                    </P>
                </FTNT>
                <P>
                    On July 20, 1994, EPA promulgated a rule interpreting the three criteria set forth in section 209(e)(2)(A) that EPA must consider before granting any California authorization request for nonroad engine or vehicle emission standards.
                    <SU>6</SU>
                    <FTREF/>
                     EPA revised these regulations in 1997.
                    <SU>7</SU>
                    <FTREF/>
                     As stated in the preamble to the 1994 rule, EPA has interpreted the consistency inquiry under the third criterion, outlined above and set forth in section 209(e)(2)(A)(iii), to require, at minimum, that California standards and enforcement procedures be consistent with section 209(a), section 209(e)(1), and section 209(b)(1)(C) of the Act.
                    <SU>8</SU>
                    <FTREF/>
                     In order to be consistent with section 209(a), California's nonroad standards and enforcement procedures must not apply to new motor vehicles or new motor vehicle engines. To be consistent with section 209(e)(1), California's nonroad standards and enforcement procedures must not attempt to regulate engine categories that are permanently preempted from state regulation. To determine consistency with section 209(b)(1)(C), EPA typically reviews nonroad authorization requests under the same “consistency” criteria that are applied to motor vehicle waiver requests under section 209(b)(1)(C). That provision provides that the Administrator shall not grant California a motor vehicle waiver if the Administrator finds that California “standards and accompanying enforcement procedures are not consistent with section 202(a)” of the Act.
                </P>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         See “Air Pollution Control; Preemption of State Regulation for Nonroad Engine and Vehicle Standards,” 59 FR 36969 (July 20, 1994).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>7</SU>
                         See “Control of Air Pollution: Emission Standards for New Nonroad Compression-Ignition Engines at or Above 37 Kilowatts; Preemption of State Regulation for Nonroad Engine and Vehicle Standards; Amendments to Rules,” 62 FR 67733 (December 30, 1997). The applicable regulations are now found in 40 CFR part 1074, subpart B, Part 1074.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>8</SU>
                         EPA has interpreted section 209(b)(1)(C) in the context of section 209(b) motor vehicle waivers.
                    </P>
                </FTNT>
                <P>CARB determined that these standards and accompanying enforcement procedures do not cause California's standards, in the aggregate, to be less protective to public health and welfare than the applicable Federal standards. The administrative record, including information presented to me by parties opposing California's waiver, did not demonstrate that California arbitrarily or capriciously reached this protectiveness determination. Therefore, based on the record, I cannot find California's determination to be arbitrary and capricious under section 209(b)(1)(A) or section 209(e)(2)(A)(i).</P>
                <P>
                    CARB has demonstrated the existence of compelling and extraordinary conditions justifying the need for its own motor vehicle emission control 
                    <PRTPAGE P="645"/>
                    program as well and justifying the need for its own nonroad vehicle emission control program, which includes the subject standards and procedures. Although EPA believes it unnecessary, CARB has also demonstrated the need for the Omnibus Low NO
                    <E T="52">X</E>
                     standards within the Omnibus regulations. The administrative record, including information presented to me by parties opposing California's waiver (and authorization) request, did not demonstrate that California no longer has compelling and extraordinary conditions justifying a need for its own motor vehicle emission control program and its own nonroad vehicle emission control program, or alternatively, a need for the Omnibus Low NO
                    <E T="52">X</E>
                     standards. Therefore, based on the record, I agree that California continues to have compelling and extraordinary conditions which require its own programs, or alternatively, a need for the Omnibus Low NO
                    <E T="52">X</E>
                     standards. Information presented to me by parties opposing the waiver did not demonstrate otherwise. Thus, I cannot deny the waiver based on section 209(b)(1)(B) or section 209(e)(2)(A)(ii).
                </P>
                <P>CARB has submitted information that its emission standards and test procedures are technologically feasible and present no inconsistency with Federal requirements and are, therefore, consistent with section 202(a) of the Act and are consistent with section 209 as required by section 209(e)(2)(A)(iii). The administrative record, including information presented to me by parties opposing California's waiver and authorization requests, did not satisfy the burden of persuading EPA that the standards are not technologically feasible within the available lead time, considering costs, or are otherwise inconsistent with section 202(a) (for onroad) or section 209 (for nonroad). Thus, based on the record, I cannot deny the waiver based on section 209(b)(1)(C) or section 209(e)(2)(A)(iii).</P>
                <P>Accordingly, I hereby granted the waiver and authorization requested by California.</P>
                <P>Section 307(b)(1) of the CAA govern judicial review of final actions by EPA. Petitions for review must be filed by March 7, 2025.</P>
                <P>As with past waiver and authorization decisions, this action is not a rule as defined by Executive Order 12866. Therefore, it is exempt from review by the Office of Management and Budget as required for rules and regulations by Executive Order 12866.</P>
                <P>In addition, this action is not a rule as defined in the Regulatory Flexibility Act, 5 U.S.C. 601(2). Therefore, EPA has not prepared a supporting regulatory flexibility analysis addressing the impact of this action on small business entities.</P>
                <P>
                    The Congressional Review Act, 5 U.S.C. 801 
                    <E T="03">et seq.,</E>
                     as added by the Small Business Regulatory Enforcement Fairness Act of 1996, does not apply because this action is not a rule, for purposes of 5 U.S.C. 804(3).
                </P>
                <SIG>
                    <NAME>Michael S. Regan,</NAME>
                    <TITLE>Administrator.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31125 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6560-50-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">ENVIRONMENTAL PROTECTION AGENCY</AGENCY>
                <DEPDOC>[EPA-HQ-OPPT-2018-0320; FRL-11655-02-OCSPP]</DEPDOC>
                <SUBJECT>Toxic Substances Control Act (TSCA) Review of CBI Claims for the Identity of Chemicals in the TSCA Inventory; Extension of Review Period</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Environmental Protection Agency (EPA).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Environmental Protection Agency (EPA or Agency) is announcing the extension of the review period for Confidential Business Information (CBI) claims for specific identities of all active chemical substances listed on the confidential portion of the Toxic Substances Control Act (TSCA) Inventory submitted to the EPA under TSCA. EPA has determined that a further extension of the statutory review period for the review of CBI claims under TSCA is necessary to allow the Agency to complete the required reviews under TSCA.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>The review period is extended to February 19, 2026.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        The docket for this action, identified by docket identification (ID) number EPA-HQ-OPPT-2018-0320, is available online at 
                        <E T="03">https://www.regulations.gov</E>
                        . Additional instructions for visiting the docket, along with more information about dockets generally, is available at 
                        <E T="03">https://www.epa.gov/dockets</E>
                        .
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P/>
                    <P>
                        <E T="03">For technical information:</E>
                         Jessica Barkas, Project Management and Operations Division (7401), Office of Pollution Prevention and Toxics, Environmental Protection Agency, 1200 Pennsylvania Ave. NW, Washington, DC 20460-0001; telephone number: (202) 250-8880; email address: 
                        <E T="03">barkas.jessica@epa.gov</E>
                        .
                    </P>
                    <P>
                        <E T="03">For general information:</E>
                         The TSCA-Hotline, ABVI-Goodwill, 422 South Clinton Ave., Rochester, NY 14620; telephone number: (202) 554-1404; email address: 
                        <E T="03">TSCA-Hotline@epa.gov</E>
                        .
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">I. Does this action apply to me?</HD>
                <P>You may be affected by this action if you submitted a Notice of Activity Form A to EPA under TSCA section 8(b)(4) and 40 CFR part 710, subpart B and asserted any CBI claims concerning the specific identities of the chemical substances you reported. Persons who seek information on such submissions may also be affected by this action. The following list of North American Industrial Classification System (NAICS) codes is not intended to be exhaustive, but rather provides a guide to help readers determine whether this document applies to them. Potentially affected entities may include:</P>
                <P>
                    • Manufacturers, importers, or processors of chemical substances (NAICS codes 325 and 324110), 
                    <E T="03">e.g.,</E>
                     chemical manufacturing and petroleum refineries.
                </P>
                <P>
                    If you have any questions regarding the applicability of this action to a particular entity, consult the technical contact person listed under 
                    <E T="02">FOR FURTHER INFORMATION CONTACT</E>
                    .
                </P>
                <HD SOURCE="HD1">II. What is the Agency's authority for taking this action?</HD>
                <P>TSCA authorizes the extension of the Review Plan deadline in TSCA section 8(b)(4)(E)(ii)(I), 15 U.S.C. 2607(b)(4)(E)(ii)(I).</P>
                <HD SOURCE="HD1">III. What action is the Agency taking?</HD>
                <P>
                    EPA is announcing to the public that it is further extending an Agency review deadline pursuant to the authority in TSCA section 8(b)(4)(E)(ii)(I), 15 U.S.C. 2607(b)(4)(E)(ii)(I). The additional time is necessary to complete the reviews given the volume of submissions that require review, information technology issues, insufficient resources and other legal and administrative delays that have affected the review process. EPA previously extended the review period by one year, to February 19, 2025 (89 FR 4605, January 24, 2024 (FRL-11655-01-OCSPP)). As discussed in that document, EPA has evaluated its progress toward completing the requirements for the Agency to review CBI substantiations outlined in the final rule titled “Procedures for Review of CBI Claims for the Identity of Chemicals in the TSCA Inventory” (Review Plan rule), (85 FR 13062, March 6, 2020 (FRL-10005-48)) and has concluded that a further one year extension will be necessary to complete the Review Plan reviews.
                    <PRTPAGE P="646"/>
                </P>
                <HD SOURCE="HD1">IV. What is the TSCA Review Plan?</HD>
                <P>
                    Pursuant to TSCA section 8(b), EPA finalized the Review Plan rule establishing, 
                    <E T="03">inter alia,</E>
                     the Agency's plan for reviewing all active TSCA Inventory CBI claims concerning specific chemical identities that had been made in Active-Inactive rule reporting taking place in 2017 and 2018 (see 40 CFR part 710, subparts B (Commercial Activity Notification) and C (Review Plan)). Consistent with TSCA section 8(b)(4)(E)(i), which allows a five-year period for these reviews following compilation of an initial list of active substances, the reviews were targeted for completion by February 19, 2024 (see 40 CFR 710.55(d). Since finalizing the Review Plan rule, however, EPA has encountered issues that have prevented meeting this original target. These issues and/or their effects persist to the present, making meeting the extended target of February 19, 2025, impossible. Consequently, consistent with TSCA section 8(b)(4)(E)(ii)(I) and 40 CFR 710.55(e), which permit EPA to extend the review period by up to two years, EPA is further extending the target review completion date until February 19, 2026.
                </P>
                <P>
                    Several issues and factors caused delays that prevented EPA from completing its review within the five-year period (and are going to prevent completion within the previous one-year extension). These issues are described in more detail in the document at 89 FR 4605-4606, but include a large universe of claims to review (more than 4,805 chemical substances in 5,787 often-complex submissions) and concurrent activities to update the public portion of the TSCA Inventory, consistent with the requirements of TSCA sections 8(b) and 14. Also, adapting and maintaining the Agency's information technology (IT) systems to complete these reviews has continued to contribute to delays in reviewing these CBI claims. The size (
                    <E T="03">i.e.</E>
                     very large file size) and other features of certain submissions caused IT difficulties that halted the CBI review process for about nine months while available resources were prioritized to address more critical IT needs. A lack of requested appropriated funds in FY24 and FY25 resulted in insufficient contract resources to address IT system issues in addition to not allowing EPA to maintain the necessary staffing level to make progress on these reviews. Finally, EPA was delayed in commencing Review Plan reviews for approximately six months to a year as a result of the decision of the U.S. Court of Appeals for the District of Columbia Circuit in 
                    <E T="03">Environmental Defense Fund</E>
                     v. 
                    <E T="03">EPA,</E>
                     922 F.3d 446 (D.C. Cir. 2019), which resulted in a need for additional rulemaking activity to add a reporting requirement. The additional reporting requirement created confusion among some reporting entities, further slowing the review process.
                </P>
                <P>These issues and factors together justify extending the review period deadline by a total of two years, consistent with TSCA section 8(b)(4)(E)(ii)(I).</P>
                <P>
                    <E T="03">Authority:</E>
                     15 U.S.C. 2607(b).
                </P>
                <SIG>
                    <DATED>Dated: December 20, 2024.</DATED>
                    <NAME>Michal Freedhoff,</NAME>
                    <TITLE>Assistant Administrator, Office of Chemical Safety and Pollution Prevention.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31291 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6560-50-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">EQUAL EMPLOYMENT OPPORTUNITY COMMISSION</AGENCY>
                <SUBJECT>Agency Information Collection Activities: Extension Without Change of An Existing Collection; Comment Request</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Equal Employment Opportunity Commission.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Final notice of information collection—Uniform Guidelines on Employee Selection Procedures—extension without change.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>In accordance with the Paperwork Reduction Act of 1995, the Equal Employment Opportunity Commission (EEOC or Commission) announces that it has submitted the information described below to the Office of Management and Budget (OMB) for a three-year extension without change.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Written comments on this notice must be submitted on or before February 5, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        Written comments should be sent within 30 days of publication of this final notice to 
                        <E T="03">www.reginfo.gov/public/do/PRAMain.</E>
                         Find this particular information collection by selecting “Currently under 30-day Review—Open for Public Comments” or by using the search function.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Gary Hozempa, Senior Attorney, at (202) 921-2672 or 
                        <E T="03">Gary.Hozempa@eeoc.gov.</E>
                         Requests for this notice in an alternative format should be made to the Office of Communications and Legislative Affairs at (202) 921-3191 (voice), (800) 669-6820 (TTY), or (844) 234-5122 (ASL Video Phone).
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P/>
                <HD SOURCE="HD1">Overview of Current Information Collection</HD>
                <P>
                    <E T="03">Collection Title:</E>
                     Recordkeeping Requirements of the Uniform Guidelines on Employee Selection Procedures, 29 CFR part 1607, 41 CFR part 60-3, 28 CFR part 50, 5 CFR part 300.
                </P>
                <P>
                    <E T="03">OMB Number:</E>
                     3046-0017.
                </P>
                <P>
                    <E T="03">Type of Respondent:</E>
                     Businesses or other institutions; Federal Government; State or local governments and farms.
                </P>
                <P>
                    <E T="03">North American Industry Classification System (NAICS) Code:</E>
                     Multiple.
                </P>
                <P>
                    <E T="03">Standard Industrial Classification Code (SIC):</E>
                     Multiple.
                </P>
                <P>
                    <E T="03">Description of Affected Public:</E>
                     Any employer, Government contractor, labor organization, or employment agency covered by the Federal equal employment opportunity laws.
                </P>
                <P>
                    <E T="03">Respondents:</E>
                     887,869.
                </P>
                <P>
                    <E T="03">Responses:</E>
                     887,869.
                </P>
                <P>
                    <E T="03">Recordkeeping Hours:</E>
                     15,422,941 per year.
                </P>
                <P>
                    <E T="03">Number of Forms:</E>
                     None.
                </P>
                <P>
                    <E T="03">Form Number:</E>
                     None.
                </P>
                <P>
                    <E T="03">Frequency of Report:</E>
                     None.
                </P>
                <P>
                    <E T="03">Abstract:</E>
                     The Uniform Guidelines provide fundamental guidance for all title VII-covered employers about the use of employment selection procedures. The records addressed by UGESP are used by respondents to ensure that they are complying with title VII and Executive Order 11246; by the Federal agencies that enforce title VII and Executive Order 11246 to investigate, conciliate, and litigate charges of employment discrimination; and by complainants to establish violations of Federal equal employment opportunity laws. While there is no data available to quantify these benefits, the collection of accurate applicant flow data enhances each employer's ability to address deficiencies in recruitment and selection processes, including detecting barriers to equal employment opportunity.
                </P>
                <P>On October 29, 2024, the Commission published a 60-Day Notice informing the public of its intent to request an extension without change of the information collection requirements from the Office of Management and Budget (89 FR 85963 (October 29, 2024). Public comments were solicited. None were submitted as of the December 30, 2024 deadline for filing.</P>
                <P>
                    <E T="03">Burden Statement:</E>
                     There are no reporting requirements associated with UGESP. The burden being estimated is the cost of collecting and storing a job applicant's gender, race, and ethnicity data.
                </P>
                <P>
                    The only paperwork burden derives from this recordkeeping. Only 
                    <PRTPAGE P="647"/>
                    employers covered under title VII and Executive Order 11246 are subject to UGESP. However, for the purposes of burden calculation, data for all employers are counted.
                    <SU>1</SU>
                    <FTREF/>
                     The number of employers with 15 or more employees is estimated at 887,869 which combines estimates from private employment,
                    <SU>2</SU>
                    <FTREF/>
                     the public sector,
                    <SU>3</SU>
                    <FTREF/>
                     colleges and universities,
                    <SU>4</SU>
                    <FTREF/>
                     apprenticeship programs,
                    <SU>5</SU>
                    <FTREF/>
                     and referral unions.
                    <SU>6</SU>
                    <FTREF/>
                     Employers with 15 or more employees represent approximately 13.5% of all employers in the U.S. and employ about 86.2% of all employees in the U.S.
                    <SU>7</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         In calculating burden, data from multiple sources are used. Some of these sources do not allow us to identify only those employers who are covered by Title VII (employers with 15 or more employees).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         Source of original data: U.S Census Bureau, 2021 Statistics of U.S. Businesses (SUSB) (Dec. 2023). (
                        <E T="03">https://www.census.gov/data/tables/2021/econ/susb/2021-susb-annual.html</E>
                        ). Local Downloadable CSV data. Select U.S. &amp; states, 6 digit NAICS. The original number of employers was adjusted to only include those with 15 or more employees.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         Source of original data: 2022 Census of Governments: Employment. Individual Government Data File (
                        <E T="03">https://www.census.gov/data/datasets/2022/econ/apes/2022.html</E>
                        ), Local Downloadable Data zip file “Individual Unit Files”. The original number of government entities was adjusted to only include those with 15 or more employees.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         Source: U.S. Department of Education, National Center for Education Statistics, IPEDS, Fall 2022, Institutional Characteristics component (provisional data). See Table 1, “Number and percentage distribution of Title IV institutions, by control of institution, level of institution, and region: United States and other U.S. jurisdictions, academic year 2022-23” (
                        <E T="03">https://nces.ed.gov/ipeds/search/viewtable?tableId=35945&amp;returnUrl=%2Fsearch</E>
                        ).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         Source: U.S. Department of Labor, Registered Apprenticeship National Results Fiscal Year 2021, Number of active apprenticeship programs in 2021 (
                        <E T="03">https://www.dol.gov/agencies/eta/apprenticeship/about/statistics/2021</E>
                        ).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         The EEOC has undertaken measures to enhance the agency's existing EEO-3 data frame (
                        <E T="03">i.e.,</E>
                         roster) of potentially eligible filers that was most recently used during the 2022 EEO-3 data collection. The number of referral unions was estimated by comparing the EEOC's 2022 EEO-3 frame to a list of active unions from the U.S. Department of Labor's Office of Labor Management Standards (OLMS) Online Public Disclosure Room (OPDR) database (
                        <E T="03">https://olmsapps.dol.gov/olpdr/</E>
                        ).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>7</SU>
                         Source of original data: U.S Census Bureau, 2021 Statistics of U.S. Businesses (SUSB) (Dec. 2023). (
                        <E T="03">https://www.census.gov/data/tables/2021/econ/susb/2021-susb-annual.html</E>
                        ). Local Downloadable CSV data. Select U.S. &amp; states, 6 digit NAICS. The original number of employers was adjusted to only include those with 15 or more employees.
                    </P>
                </FTNT>
                <P>
                    This burden assessment is based on an estimate of the number of job applications submitted to all employers in one year, including paper-based and electronic applications. The total number of job applications submitted every year to covered employers is estimated to be 1,850,752,956 based on an average of approximately 26 applications 
                    <SU>8</SU>
                    <FTREF/>
                     for every hire and a Bureau of Labor Statistics data estimate of 71,046,000 annual hires.
                    <SU>9</SU>
                    <FTREF/>
                     This figure also includes 136,806 applicants for union membership reported on the EEO-3 form for 2022. The employer burden associated with collecting and storing applicant demographic data is based on the following assumptions: applicants would need to be asked to provide three pieces of information—sex, race/ethnicity, and an identification number (a total of approximately 13 keystrokes); the employer may need to transfer information received to a database either manually or electronically; and the employer would need to store the 13 characters of information for each applicant. Recordkeeping costs and burden are assumed to be the time cost associated with entering 13 keystrokes.
                </P>
                <FTNT>
                    <P>
                        <SU>8</SU>
                         The average number of applicants per job opening in 2023, according to the iCIMS 2024 January Workforce Report (https://icims.drift.click/January-2024-Workforce-Report).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>9</SU>
                         Bureau of Labor Statistics Job Openings and Labor Turnover Survey, 2023 annual level data (seasonally adjusted), (
                        <E T="03">http://www.bls.gov/jlt/data.htm</E>
                        ) is the source of the original data. The BLS figure includes new hires in both the public and the private sectors across all employer sizes.
                    </P>
                </FTNT>
                <P>
                    Assuming that the required recordkeeping takes 30 seconds per record, and assuming a total of 1,850,752,956 paper and electronic applications per year (as calculated above), the resulting UGESP burden hours would be 15,422,941. Based on a wage rate of $22.94 
                    <SU>10</SU>
                    <FTREF/>
                     per hour for the individuals entering the data, the collection and storage of applicant demographic data would come to approximately $353,802,267 per year. The foregoing assumptions likely are over-inclusive because many employers have electronic job application processes that should be able to capture applicant flow data automatically. While the burden hours and costs for the UGESP recordkeeping requirement seem large, the average burden per employer is relatively small. UGESP applies to an estimated 887,869 employers, or about 13.5% of employers in the U.S, and these employers employ about 86.2% of employees in the U.S.
                    <SU>11</SU>
                    <FTREF/>
                     Therefore, the estimated cost per covered employer is about $398. Additionally, 36.4% of employees work for firms with at least 5,000 employees,
                    <SU>12</SU>
                    <FTREF/>
                     for which the burden of data entry is transferred to the applicants via use of electronic application systems. Finally, UGESP allows for simplified recordkeeping for employers with more than 15 but less than 100 employees.
                    <SU>13</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>10</SU>
                         Burden hour cost estimates are based on the median hourly wage rate of $22.94 for Human Resources Assistants, except payroll and timekeeping obtained from the Bureau of Labor Statistics, May 2023 (see U.S. Department of Labor, Bureau of Labor Statistics, Occupational Employment and Wage Statistics, 
                        <E T="03">https://www.bls.gov/oes/current/oes434161.htm</E>
                        ).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>11</SU>
                         Source of original data: U.S Census Bureau, 2021 Statistics of U.S. Businesses (SUSB) (Dec. 2023). (
                        <E T="03">https://www.census.gov/data/tables/2021/econ/susb/2021-susb-annual.html</E>
                        ). Local Downloadable CSV data. Select U.S. &amp; states, 6 digit NAICS. The original number of employers was adjusted to only include those with 15 or more employees.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>12</SU>
                         Source of original data: 2021 Economic Census. (
                        <E T="03">https://www.census.gov/data/tables/2021/econ/susb/2021-susb-annual.html</E>
                        ). Local Downloadable CSV data. Select U.S. &amp; states, 6 digit NAICS. The original number of employers was adjusted to only include those with 15 or more employees.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>13</SU>
                         
                        <E T="03">See</E>
                         29 CFR 1607.15A(1): 
                        <E T="03">Simplified recordkeeping for users with less than 100 employees.</E>
                         In order to minimize recordkeeping burdens on employers who employ one hundred (100) or fewer employees, and other users not required to file EEO-1, 
                        <E T="03">et seq.,</E>
                         reports, such users may satisfy the requirements of this section 15 if they maintain and have available records showing, for each year: (a) The number of persons hired, promoted, and terminated for each job, by sex, and where appropriate by race and national origin; (b)The number of applicants for hire and promotion by sex and where appropriate by race and national origin; and (c) The selection procedures utilized (either standardized or not standardized).
                    </P>
                </FTNT>
                <SIG>
                    <P>For the Commission.</P>
                    <DATED>Dated: December 31, 2024.</DATED>
                    <NAME>Charlotte A. Burrows,</NAME>
                    <TITLE>Chair.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31755 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6570-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">FEDERAL ELECTION COMMISSION</AGENCY>
                <SUBJECT>Sunshine Act Meetings</SUBJECT>
                <PREAMHD>
                    <HD SOURCE="HED">FEDERAL REGISTER CITATION OF PREVIOUS ANNOUNCEMENT:</HD>
                    <P>89 FR 105048.</P>
                </PREAMHD>
                <PREAMHD>
                    <HD SOURCE="HED">PREVIOUSLY ANNOUNCED TIME AND DATE OF THE MEETING:</HD>
                    <P>Thursday, January 9, 2025, at 10:00 a.m.</P>
                </PREAMHD>
                <PREAMHD>
                    <HD SOURCE="HED">CHANGES IN THE MEETING:</HD>
                    <P>The meeting was rescheduled for Tuesday, January 14, 2025, at 10:00 a.m.</P>
                </PREAMHD>
                <PREAMHD>
                    <HD SOURCE="HED">CONTACT PERSON FOR MORE INFORMATION: </HD>
                    <P>Judith Ingram, Press Officer. Telephone: (202) 694-1220.</P>
                </PREAMHD>
                <EXTRACT>
                    <FP>(Authority: Government in the Sunshine Act, 5 U.S.C. 552b)</FP>
                </EXTRACT>
                <SIG>
                    <NAME>Vicktoria J. Allen,</NAME>
                    <TITLE>Deputy Secretary of the Commission.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2025-00017 Filed 1-2-25; 11:15 am]</FRDOC>
            <BILCOD>BILLING CODE 6715-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">FEDERAL TRADE COMMISSION</AGENCY>
                <DEPDOC>[File No. 222 3156]</DEPDOC>
                <SUBJECT>accessiBe; Analysis of Proposed Consent Order To Aid Public Comment</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Federal Trade Commission.</P>
                </AGY>
                <ACT>
                    <PRTPAGE P="648"/>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Proposed consent agreement; request for comment.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The consent agreement in this matter settles alleged violations of Federal law prohibiting unfair or deceptive acts or practices. The attached Analysis of Proposed Consent Order to Aid Public Comment describes both the allegations in the complaint and the terms of the consent order—embodied in the consent agreement—that would settle these allegations.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Comments must be received on or before February 5, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        Interested parties may file comments online or on paper by following the instructions in the Request for Comment part of the 
                        <E T="02">SUPPLEMENTARY INFORMATION</E>
                         section below. Please write “accessiBe; File No. 222 3156” on your comment and file your comment online at 
                        <E T="03">https://www.regulations.gov</E>
                         by following the instructions on the web-based form. If you prefer to file your comment on paper, please mail your comment to: Federal Trade Commission, Office of the Secretary, 600 Pennsylvania Avenue NW, Mail Stop H-144 (Annex W), Washington, DC 20580.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Kristin Williams (202-326-2619), Division of Advertising Practices, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue NW, Washington, DC 20580.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    Pursuant to section 6(f) of the Federal Trade Commission Act, 15 U.S.C. 46(f), and FTC Rule § 2.34, 16 CFR 2.34, notice is hereby given that the above-captioned consent agreement containing a consent order to cease and desist, having been filed with and accepted, subject to final approval, by the Commission, has been placed on the public record for a period of 30 days. The following Analysis to Aid Public Comment describes the terms of the consent agreement and the allegations in the complaint. An electronic copy of the full text of the consent agreement package can be obtained at 
                    <E T="03">https://www.ftc.gov/news-events/commission-actions.</E>
                </P>
                <P>
                    You can file a comment online or on paper. For the Commission to consider your comment, we must receive it on or before February 5, 2025. Write “accessiBe; File No. 222 3156” on your comment. Your comment—including your name and your State—will be placed on the public record of this proceeding, including, to the extent practicable, on the 
                    <E T="03">https://www.regulations.gov</E>
                     website.
                </P>
                <P>
                    Because of heightened security screening, postal mail addressed to the Commission will be subject to delay. We strongly encourage you to submit your comments online through the 
                    <E T="03">https://www.regulations.gov</E>
                     website. If you prefer to file your comment on paper, write “accessiBe; File No. 222 3156” on your comment and on the envelope, and send it via overnight service to: Federal Trade Commission, Office of the Secretary, 600 Pennsylvania Avenue NW, Mail Stop H-144 (Annex W), Washington, DC 20580.
                </P>
                <P>
                    Because your comment will be placed on the publicly accessible website at 
                    <E T="03">https://www.regulations.gov,</E>
                     you are solely responsible for making sure your comment does not include any sensitive or confidential information. In particular, your comment should not include sensitive personal information, such as your or anyone else's Social Security number; date of birth; driver's license number or other State identification number, or foreign country equivalent; passport number; financial account number; or credit or debit card number. You are also solely responsible for making sure your comment does not include sensitive health information, such as medical records or other individually identifiable health information. In addition, your comment should not include any “trade secret or any commercial or financial information which . . . is privileged or confidential”—as provided by section 6(f) of the FTC Act, 15 U.S.C. 46(f), and FTC Rule § 4.10(a)(2), 16 CFR 4.10(a)(2)—including competitively sensitive information such as costs, sales statistics, inventories, formulas, patterns, devices, manufacturing processes, or customer names.
                </P>
                <P>
                    Comments containing material for which confidential treatment is requested must be filed in paper form, must be clearly labeled “Confidential,” and must comply with FTC Rule § 4.9(c). In particular, the written request for confidential treatment that accompanies the comment must include the factual and legal basis for the request and must identify the specific portions of the comment to be withheld from the public record. 
                    <E T="03">See</E>
                     FTC Rule § 4.9(c). Your comment will be kept confidential only if the General Counsel grants your request in accordance with the law and the public interest. Once your comment has been posted on the 
                    <E T="03">https://www.regulations.gov</E>
                     website—as legally required by FTC Rule § 4.9(b)—we cannot redact or remove your comment from that website, unless you submit a confidentiality request that meets the requirements for such treatment under FTC Rule § 4.9(c), and the General Counsel grants that request.
                </P>
                <P>
                    Visit the FTC website at 
                    <E T="03">https://www.ftc.gov</E>
                     to read this document and the news release describing the proposed settlement. The FTC Act and other laws the Commission administers permit the collection of public comments to consider and use in this proceeding, as appropriate. The Commission will consider all timely and responsive public comments it receives on or before February 5, 2025. For information on the Commission's privacy policy, including routine uses permitted by the Privacy Act, see 
                    <E T="03">https://www.ftc.gov/site-information/privacy-policy.</E>
                </P>
                <HD SOURCE="HD1">Analysis of Proposed Consent Order To Aid Public Comment</HD>
                <P>The Federal Trade Commission (“Commission”) has accepted, subject to final approval, an agreement containing a consent order from accessiBe Inc. and accessiBe Ltd. (collectively, “accessiBe”).</P>
                <P>The proposed consent order (“proposed order”) has been placed on the public record for 30 days for receipt of comments by interested persons. Comments received during this period will become part of the public record. After 30 days, the Commission will again review the agreement and the comments received and will decide whether it should withdraw from the agreement and take appropriate action or make final the agreement's proposed order.</P>
                <P>This matter involves accessiBe's marketing and sale of a web accessibility software plug in called accessWidget. accessiBe represented that accessWidget could make any website compliant with the Web Content Accessibility Guidelines (“WCAG”), a comprehensive set of technical criteria used to assess website accessibility. accessiBe advertised these claims on its website and social media, as well as in articles that were formatted as impartial and objective reviews on third-party websites. accessiBe also failed to disclose its material connections with the publishers of those third-party articles.</P>
                <P>
                    The proposed complaint alleges that accessWidget did not make all websites WCAG compliant, and that the company's claims were false, misleading, or unsubstantiated. The proposed complaint also alleges that formatting the third-party articles and reviews as independent opinions by impartial authors and publishers was false and misleading, and that accessiBe's failure to disclose its material connections with the publishers of those articles was deceptive.
                    <PRTPAGE P="649"/>
                </P>
                <P>The proposed order contains provisions designed to prevent accessiBe from engaging in these and similar acts and practices in the future. Provision I prohibits accessiBe from representing that its automated products, including accessWidget's artificial intelligence and other automated technology, can make any website WCAG compliant, or can ensure continued compliance with WCAG over time as web content changes, unless the company has competent and reliable evidence to support the representations. Provision II prohibits accessiBe from misrepresenting any fact material to consumers about any of the company's products or services, such as the value or total cost; any material restrictions, limitations, or conditions; or any material aspect of its performance, features, benefits, efficacy, nature, or central characteristics. Provision III prohibits accessiBe from misrepresenting that statements made in third-party reviews, articles, or blog posts about its automated products, including accessWidget's artificial intelligence and other automated technology, are independent opinions by impartial authors; that an endorser is an independent or ordinary user of the automated product; or that the endorser is an independent organization or is providing objective information.</P>
                <P>Provision IV requires accessiBe to disclose clearly and conspicuously, and in close proximity to representations about its automated products, including accessWidget's artificial intelligence and other automated technology, any unexpected material connection that an endorser has to accessiBe, to the product or service, or to affiliated individuals or entities. Provision V requires accessiBe to disclose, in connection with representations that accessWidget or the company's other artificial intelligence or automated products correct accessibility barriers on a website, that such products or services will not correct barriers on third-party web domains or subdomains that may be part of the overall user experience, unless those domains also use the product. Such disclosure must be made clearly and conspicuously, and prior to the consumer incurring any financial obligation.</P>
                <P>Provision VI requires accessiBe to pay the Commission $1,000,000 in monetary relief. Provision VII describes procedures and legal rights related to that payment. Provision VIII requires accessiBe to provide sufficient customer information to enable the Commission to efficiently administer consumer redress. Provisions IX through XIII are reporting and compliance provisions.</P>
                <P>Provision IX mandates that accessiBe acknowledge receipt of the order, distribute the order to principals, officers, and certain employees and agents, and obtain signed acknowledgments from them. Provision X requires accessiBe to submit compliance reports to the Commission one year after the order's issuance and submit notifications when certain events occur. Under Provision XI, accessiBe must create certain records for 10 years and retain them for five years. Provision XII requires accessiBe to provide information or documents necessary for the Commission to monitor compliance with the order during the period of the order's effective dates. Finally, Provision XIII provides the order's effective dates, including that, with exceptions, the order will terminate in 20 years.</P>
                <P>The purpose of this analysis is to facilitate public comment on the proposed order. It is not intended to constitute an official interpretation of the complaint or proposed order, or to modify the proposed order's terms in any way.</P>
                <SIG>
                    <P>By direction of the Commission.</P>
                    <NAME>April J. Tabor,</NAME>
                    <TITLE>Secretary. </TITLE>
                </SIG>
                <HD SOURCE="HD1">Concurring Statement of Commissioner Andrew N. Ferguson, Joined by Commissioner Melissa Holyoak</HD>
                <P>
                    Today we vote to approve an administrative complaint and proposed consent order with accessiBe, which advertised its accessWidget as “the #1 fully automated ADA [Americans with Disabilities Act] and WCAG [Web Content Accessibility Guidelines] compliance solution,” “always ensuring compliance by rescanning and re-analyzing your website every 24 hours to remediate new content, widgets, pages, and anything else you may add.” The complaint alleges that accessiBe's automated solution fell far short of its promise and failed to correct many website accessibility issues.
                    <SU>1</SU>
                    <FTREF/>
                     The complaint also accuses accessiBe of misrepresenting that various reviews and testimonials of accessWidget were independent and impartial when they were in fact bought and paid for by accessiBe.
                    <SU>2</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         Complaint ¶¶ 77-90.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         
                        <E T="03">Id.</E>
                         ¶¶ 52-76, 91-96.
                    </P>
                </FTNT>
                <P>
                    I write separately to clarify my vote in favor of the count accusing accessiBe of misrepresenting its product's performance. Each subscription to accessWidget covers only one domain, but websites sometimes depend on subdomains or third-party domains for critical functionality, like making a reservation or processing a payment.
                    <SU>3</SU>
                    <FTREF/>
                     The complaint alleges that “[accessiBe] also fail[ed] to disclose, or disclose adequately, that accessWidget does not remediate website content hosted on third-party web domains or subdomains (unless the third party or subdomains also happen to use accessWidget).” 
                    <SU>4</SU>
                    <FTREF/>
                     The consent order requires that accessiBe disclose this limitation in the future. My vote should not be taken as endorsing the position that the ADA, or the WCAG, require a website operator to ensure that some or all of the third-party domains or subdomains with which it integrates are accessible. I take no position on that question, which involves the interpretation of a complex law that Congress has tasked other agencies with interpreting and enforcing. I concur in the deception count because the remaining allegations involving misrepresentations of the product's ability to bring the user's own domain into compliance are sufficient to state a claim of deception against accessiBe. Subject to that clarification, I concur in the filing of this complaint and settlement.
                </P>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         See 
                        <E T="03">id.</E>
                         ¶ 85.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         
                        <E T="03">Id.</E>
                         ¶ 86.
                    </P>
                </FTNT>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31765 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6750-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">FEDERAL TRADE COMMISSION</AGENCY>
                <DEPDOC>[File No. 241 0082]</DEPDOC>
                <SUBJECT>Planned Companies; Analysis of Agreement Containing Consent Order To Aid Public Comment</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Federal Trade Commission.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Proposed consent agreement; request for comment.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The consent agreement in this matter settles alleged violations of Federal law prohibiting unfair methods of competition. The attached Analysis of Proposed Consent Order to Aid Public Comment describes both the allegations in the complaint and the terms of the consent order—embodied in the consent agreement—that would settle these allegations.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Comments must be received on or before February 5, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        Interested parties may file comments online or on paper by following the instructions in the Request for Comment part of the 
                        <E T="02">SUPPLEMENTARY INFORMATION</E>
                         section below. Please write: “Planned Companies; File No. 241 0029” on your comment and file your comment online 
                        <PRTPAGE P="650"/>
                        at 
                        <E T="03">https://www.regulations.gov</E>
                         by following the instructions on the web-based form. If you prefer to file your comment on paper, please mail your comment to the following address: Federal Trade Commission, Office of the Secretary, 600 Pennsylvania Avenue NW, Mail Stop H-144 (Annex N), Washington, DC 20580.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Erik Herron (202-326-3535), Bureau of Competition, Federal Trade Commission, 400 7th Street SW, Washington, DC 20024.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    Pursuant to section 6(f) of the Federal Trade Commission Act, 15 U.S.C. 46(f), and FTC Rule § 2.34, 16 CFR 2.34, notice is hereby given that the above-captioned consent agreement containing a consent order to cease and desist, having been filed with and accepted, subject to final approval, by the Commission, has been placed on the public record for a period of 30 days. The following Analysis of Agreement Containing Consent Order to Aid Public Comment describes the terms of the consent agreement and the allegations in the complaint. An electronic copy of the full text of the consent agreement package can be obtained from the FTC website at this web address: 
                    <E T="03">https://www.ftc.gov/news-events/commission-actions.</E>
                </P>
                <P>
                    The public is invited to submit comments on this document. For the Commission to consider your comment, we must receive it on or before February 5, 2025. Write “Planned Companies; File No. 241 0029” on your comment. Your comment—including your name and your State—will be placed on the public record of this proceeding, including, to the extent practicable, on the 
                    <E T="03">https://www.regulations.gov</E>
                     website.
                </P>
                <P>
                    Because of the agency's heightened security screening, postal mail addressed to the Commission will be delayed. We strongly encourage you to submit your comments online through the 
                    <E T="03">https://www.regulations.gov</E>
                     website. If you prefer to file your comment on paper, write “Planned Companies; File No. 241 0029” on your comment and on the envelope, and mail your comment by overnight service to: Federal Trade Commission, Office of the Secretary, 600 Pennsylvania Avenue NW, Mail Stop H-144 (Annex N), Washington, DC 20580.
                </P>
                <P>
                    Because your comment will be placed on the publicly accessible website at 
                    <E T="03">https://www.regulations.gov,</E>
                     you are solely responsible for making sure your comment does not include any sensitive or confidential information. In particular, your comment should not include sensitive personal information, such as your or anyone else's Social Security number; date of birth; driver's license number or other State identification number, or foreign country equivalent; passport number; financial account number; or credit or debit card number. You are also solely responsible for making sure your comment does not include sensitive health information, such as medical records or other individually identifiable health information. In addition, your comment should not include any “trade secret or any commercial or financial information which . . . is privileged or confidential”—as provided by section 6(f) of the FTC Act, 15 U.S.C. 46(f), and FTC Rule § 4.10(a)(2), 16 CFR 4.10(a)(2)—including competitively sensitive information such as costs, sales statistics, inventories, formulas, patterns, devices, manufacturing processes, or customer names.
                </P>
                <P>
                    Comments containing material for which confidential treatment is requested must be filed in paper form, must be clearly labeled “Confidential,” and must comply with FTC Rule § 4.9(c). In particular, the written request for confidential treatment that accompanies the comment must include the factual and legal basis for the request and must identify the specific portions of the comment to be withheld from the public record. 
                    <E T="03">See</E>
                     FTC Rule § 4.9(c). Your comment will be kept confidential only if the General Counsel grants your request in accordance with the law and the public interest. Once your comment has been posted on 
                    <E T="03">https://www.regulations.gov</E>
                    —as legally required by FTC Rule § 4.9(b)—we cannot redact or remove your comment from that website, unless you submit a confidentiality request that meets the requirements for such treatment under FTC Rule § 4.9(c), and the General Counsel grants that request.
                </P>
                <P>
                    Visit the FTC website at 
                    <E T="03">https://www.ftc.gov</E>
                     to read this document and the news release describing this matter. The FTC Act and other laws the Commission administers permit the collection of public comments to consider and use in this proceeding, as appropriate. The Commission will consider all timely and responsive public comments it receives on or before February 5, 2025. For information on the Commission's privacy policy, including routine uses permitted by the Privacy Act, see 
                    <E T="03">https://www.ftc.gov/site-information/privacy-policy.</E>
                </P>
                <HD SOURCE="HD1">Analysis of Agreement Containing Consent Order To Aid Public Comment</HD>
                <HD SOURCE="HD2">I. Introduction</HD>
                <P>The Federal Trade Commission (“Commission”) has accepted for public comment, subject to final approval, an Agreement Containing Consent Order (“Consent Agreement”) with Planned Building Services, Inc., Planned Lifestyle Services Inc., Planned Security Services, Inc., and Planned Technologies Services, Inc. (collectively and separately, “Planned” or “Respondents”). The proposed Decision and Order (“Order”), included in the Consent Agreement and subject to final Commission approval, is designed to remedy the anticompetitive effects that have resulted from Respondents' use of restrictive covenants in some of their contracts with building owners and managers that limit the ability of those building owners and managers to solicit or hire Respondents' employees (“No-Hire Agreements”). The term No-Hire Agreement refers to a term in an agreement between two or more companies that restricts, imposes conditions on, or otherwise limits a company's ability to solicit, recruit, or hire another company's employees, during employment or afterwards, directly or indirectly, including by imposing a fee or damages in connection with such conduct, or that otherwise inhibits competition between companies for each other's employees' services.</P>
                <P>The Consent Agreement settles charges that Respondents have engaged in unfair methods of competition in violation of section 5 of the FTC Act, as amended, 15 U.S.C. 45, by entering into No-Hire Agreements with customers. Respondents' No-Hire Agreements constitute unreasonable restraints of trade that are unlawful under section 1 of the Sherman Act, 15 U.S.C. 1, and are thus unfair methods of competition in violation of section 5 of the FTC Act. Independent of the Sherman Act, Respondents' use of the No-Hire Agreements constitutes an unfair method of competition with a tendency or likelihood to harm competition, consumers, and employees in the building services industry, in violation of section 5.</P>
                <P>
                    The proposed Order has been placed on the public record for 30 days in order to receive comments from interested persons. Comments received during this period will become part of the public record. After 30 days, the Commission will again review the Consent Agreement and the comments received and will decide whether it should withdraw from the Consent Agreement 
                    <PRTPAGE P="651"/>
                    and take appropriate action or make the proposed Order final.
                </P>
                <HD SOURCE="HD2">II. The Respondents</HD>
                <P>Respondents, Planned Building Services, Inc. (“PBS”), Planned Lifestyle Services Inc. (“PLS”), Planned Security Services, Inc. (“PSS”), and Planned Technologies Services, Inc. (“PTS”), are divisions of Planned Companies Holdings, Inc. Planned Companies Holdings, Inc., is a non-wholly owned, loosely controlled subsidiary of FirstService Corporation, a publicly traded Canadian company and one of the largest property management companies in North America. PBS provides cleaning and maintenance services at residential and commercial buildings; PLS provides doorperson and concierge services at residential buildings; PSS provides security guard services at residential and commercial buildings; and PTS provides technology related services. Respondents are headquartered in New Jersey and employ more than 3,000 building services workers, primarily in the Northeast and Mid-Atlantic, but also in the metro regions of Boston, the District of Columbia, Atlanta, San Francisco, and Florida. The complaint focuses on Respondents' conduct in New York and New Jersey.</P>
                <HD SOURCE="HD2">III. The Complaint</HD>
                <P>The complaint alleges that Respondents sell building services to building owners and property management companies, primarily consisting of the labor of janitors, security guards, maintenance workers, and concierge desk workers who are directly employed by Respondents. These employees perform their work at residential and commercial buildings in various States, but predominantly in New York City and Northern New Jersey.</P>
                <P>The complaint also alleges that Respondents and their building owner and property manager customers are direct competitors in labor markets for building services workers. These include the markets for workers to perform concierge, security, janitorial, maintenance, and related services.</P>
                <P>As alleged in the complaint, Respondents use standard-form agreements with their customers that include No-Hire Agreements. The No-Hire Agreements restrict the ability of Respondents' customers to (1) directly hire workers employed by Respondents, and (2) indirectly hire workers employed by Respondents through a competing building services contractor after the competitor wins the customers' business away from Respondents. These restrictions apply during the term of Respondents' contracts and for six months thereafter. Earlier versions of the No-Hire Agreements applied not just to Respondents' employees staffed to provide services for a particular customer, but to all of Respondents' building services employees.</P>
                <P>The complaint alleges that Respondents' No-Hire Agreements are facially anticompetitive because they are horizontal agreements among competitors not to compete. Respondents and their customer building owners and property managers are competitors for the labor of building services workers like Respondents' employees. The No-Hire Agreements are horizontal agreements that prohibit buildings and property management companies from hiring building services workers, thereby undermining competition for labor, reducing worker bargaining power, and suppressing wages. For these reasons, the complaint alleges that the No-Hire Agreements constitute unreasonable restraints of trade that are unlawful under section 1 of the Sherman Act, 15 U.S.C. 1, and are thus unfair methods of competition in violation of section 5 of the FTC Act, as amended, 15 U.S.C. 45.</P>
                <P>Independent of the Sherman Act, the complaint alleges that Respondents' conduct constitutes an unfair method of competition with a tendency or likelihood to harm competition, consumers, and employees in the building services industry, in violation of section 5 of the FTC Act. According to the complaint, the No-Hire Agreements limit the ability of building owners and managers to hire Respondents' employees. This harms Respondents' employees because it limits their ability to negotiate for higher wages, better benefits, and improved working conditions. Employees may suffer further hardship if the building they work at brings services in-house because the No-Hire Agreements force them to leave their jobs in some circumstances. The complaint further alleges that the No-Hire Agreements harm building owners and managers because they may be foreclosed from bringing services in-house due to the prospect of losing long-serving workers with extensive, building-specific experience.</P>
                <HD SOURCE="HD2">IV. Proposed Order</HD>
                <P>The proposed Order seeks to remedy Respondents' unfair methods of competition. Section II of the proposed Order prohibits Respondents from entering into, maintaining, or enforcing a No-Hire Agreement, or communicating to a customer or any other person that any Planned employee is subject to a No-Hire Agreement.</P>
                <P>Paragraph III.A of the proposed Order requires Respondents to provide written notice to customers that are subject to No-Hire Agreements that (i) the restriction is null and void, and (ii) any customer or a subsequent building services contractor for a customer is no longer subject to the restrictions or penalties related to the No-Hire Agreements in Respondents' contracts.</P>
                <P>Paragraph III.B of the proposed Order requires Respondents to provide written notice to employees who are subject to a No-Hire Agreement. Paragraph III.C requires that Respondents post clear and conspicuous notice that employees are not subject to No-Hire Agreements and may seek or accept a job with the building directly, or any company that wins the building's business.</P>
                <P>Paragraphs IV.A and IV.B of the proposed Order provide a timeline according to which the obligations enumerated in Section III must be met. Paragraphs IV.C-E set forth Respondents' ongoing compliance obligations.</P>
                <P>Other paragraphs contain standard provisions regarding compliance reports, requirements for Respondents to provide notice to the FTC of material changes to their business, and access for the FTC to documents and personnel. The term of the proposed Order is ten years.</P>
                <P>The purpose of this analysis is to facilitate public comment on the Consent Agreement and proposed Order to aid the Commission in determining whether it should make the proposed Order final. This analysis is not an official interpretation of the proposed Order and does not modify its terms in any way.</P>
                <SIG>
                    <P>By direction of the Commission.</P>
                    <NAME>April J. Tabor,</NAME>
                    <TITLE>Secretary.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31763 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6750-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">GENERAL SERVICES ADMINISTRATION</AGENCY>
                <DEPDOC>[Notice-Q-2024-07; Docket No. 2024-0002; Sequence No. 58]</DEPDOC>
                <SUBJECT>Federal Secure Cloud Advisory Committee Request for Applications</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Federal Acquisition Service (Q), General Services Administration (GSA).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        GSA is seeking applications to fill three (3) membership seats on the 
                        <PRTPAGE P="652"/>
                        Federal Secure Cloud Advisory Committee (hereinafter “the Committee” or “the FSCAC”), a Federal advisory committee required by statute.
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        GSA will consider complete applications that are received no later than 5 p.m. eastern standard time on Monday, January 20, 2025. Applications will be accepted via the application form online at 
                        <E T="03">https://forms.gle/Aezt29xYzqy7Q4gv5,</E>
                         which can also be found on FSCAC's website, 
                        <E T="03">https://gsa.gov/fscac.</E>
                    </P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        Applications will be accepted electronically. Please submit applications via 
                        <E T="03">https://forms.gle/Aezt29xYzqy7Q4gv5,</E>
                         and email accompanying documents to 
                        <E T="03">fscac@gsa.gov</E>
                         with the subject line: FSCAC APPLICATION—[Applicant Name]. The form and associated instructions will be available online at 
                        <E T="03">https://gsa.gov/fscac.</E>
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Michelle White, Designated Federal Officer (DFO), FSCAC, GSA, 703-489-4160, 
                        <E T="03">fscac@gsa.gov.</E>
                         Additional information about the Committee is available online at 
                        <E T="03">https://gsa.gov/fscac.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">Background</HD>
                <P>GSA, in compliance with the FedRAMP Authorization Act of 2022, established the FSCAC, an advisory committee in accordance with the provisions of the Federal Advisory Committee Act, as amended (5 U.S.C. ch. 10). The Federal Risk and Authorization Management Program (FedRAMP) within GSA is responsible for providing a standardized, reusable approach to security assessment and authorization for cloud computing products and services that process unclassified information used by agencies.</P>
                <P>The FSCAC will provide advice and recommendations to the Administrator of GSA, the FedRAMP Board, and agencies on technical, financial, programmatic, and operational matters regarding the secure adoption of cloud computing products and services. The FSCAC will ensure effective and ongoing coordination of agency adoption, use, authorization, monitoring, acquisition, and security of cloud computing products and services to enable agency mission and administrative priorities. The purposes of the Committee are:</P>
                <P>• To examine the operations of FedRAMP and determine ways that authorization processes can continuously be improved, including the following:</P>
                <P>○ Measures to increase agency reuse of FedRAMP authorizations.</P>
                <P>○ Proposed actions that can be adopted to reduce the burden, confusion, and cost associated with FedRAMP authorizations for cloud service providers.</P>
                <P>○ Measures to increase the number of FedRAMP authorizations for cloud computing products and services offered by small businesses concerns (as defined by section 3(a) of the Small Business Act (15 U.S.C. 632(a)).</P>
                <P>○ Proposed actions that can be adopted to reduce the burden and cost of FedRAMP authorizations for agencies.</P>
                <P>• Collect information and feedback on agency compliance with, and implementation of, FedRAMP requirements.</P>
                <P>• Serve as a forum that facilitates communication and collaboration among the FedRAMP stakeholder community.</P>
                <P>The FSCAC will meet no fewer than three (3) times a calendar year. Meetings shall occur as frequently as needed, called, and approved by the DFO. Meetings may be held virtually or in person. Members will serve without compensation and may be allowed travel expenses, including per diem, in accordance with 5 U.S.C. 5703.</P>
                <P>The Committee shall be comprised of not more than 15 members who are qualified representatives from the public and private sectors, appointed by the Administrator, in consultation with the Director of OMB, as follows:</P>
                <P>i. The GSA Administrator or the GSA Administrator's designee, who shall be the Chair of the Committee.</P>
                <P>ii. At least one representative each from the Cybersecurity and Infrastructure Security Agency and the National Institute of Standards and Technology.</P>
                <P>iii. At least two officials who serve as the Chief Information Security Officer within an agency, who shall be required to maintain such a position throughout the duration of their service on the Committee.</P>
                <P>iv. At least one official serving as Chief Procurement Officer (or equivalent) in an agency, who shall be required to maintain such a position throughout the duration of their service on the Committee.</P>
                <P>v. At least one individual representing an independent assessment organization.</P>
                <P>vi. At least five representatives from unique businesses that primarily provide cloud computing services or products, including at least two representatives from a small business (as defined by section 3(a) of the Small Business Act (15 U.S.C. 632(a))).</P>
                <P>vii. At least two other representatives from the Federal Government as the Administrator determines to be necessary to provide sufficient balance, insights, or expertise to the Committee.</P>
                <P>Each member shall be appointed for a term of three (3) years, except the initial terms, which were staggered into one (1), two (2) or three (3) year terms to establish a rotation in which one third of the members are selected. No member shall be appointed for more than two (2) consecutive terms nor shall any member serve for more than six (6) consecutive years. GSA values opportunities to increase diversity, equity, inclusion and accessibility on its federal advisory committees.</P>
                <P>
                    Members will be designated as Regular Government Employees (RGEs) or Representative members as appropriate and consistent with Section 3616(d) of the FedRAMP Authorization Act of 2022. GSA's Office of General Counsel will assist the Designated Federal Officer (DFO) to determine the advisory committee member designations. Representatives are members selected to represent a specific point of view held by a particular group, organization, or association. Members who are full time or permanent part-time Federal civilian officers or employees shall be appointed to serve as Regular Government Employee (RGE) members. In accordance with OMB Final Guidance published in the 
                    <E T="04">Federal Register</E>
                     on October 5, 2011 and revised on August 13, 2014, federally registered lobbyists may not serve on the Committee in an individual capacity to provide their own individual best judgment and expertise, such as RGEs members. This ban does not apply to lobbyists appointed to provide the Committee with the views of a particular group, organization, or association, such as Representative members.
                </P>
                <HD SOURCE="HD1">Applications</HD>
                <P>Applications are being accepted to fill the remaining term of one (1) vacant seat as an RGE member and to fill two (2) seats with upcoming expiring terms as Representative members.</P>
                <P>One (1) seat for an official who serves as the Chief Information Security Officer within an agency, who shall be required to maintain such a position throughout the duration of their service on the Committee, will be appointed to serve for the remainder of the vacant term, scheduled to end on May 14, 2026.</P>
                <P>
                    One (1) seat for a representative of a unique business that primarily provides cloud computing products or services will be appointed for a three year term.
                    <PRTPAGE P="653"/>
                </P>
                <P>One (1) seat for a representative of an independent assessment service will be appointed for a three year term.</P>
                <P>Applications for membership on the Committee will be accepted until 5 p.m. eastern standard time on Monday, January 20, 2025.</P>
                <P>
                    There are two parts to submitting an application. First, complete the information requested via this electronic form 
                    <E T="03">https://forms.gle/Aezt29xYzqy7Q4gv5.</E>
                     Next, email your CV or resume and a letter of endorsement from your organization or organization's leadership, endorsing you to represent your company, in .PDF format to 
                    <E T="03">fscac@gsa.gov</E>
                     with the subject line: FSCAC APPLICATION—[Applicant Name]. The letter of endorsement must come from your organization or organization's leadership. If you are the CEO, then it must come from another member of the executive team of your organization, as you cannot endorse yourself. The letter must be signed and specifically state that you are authorized to apply to FSCAC as a representative of your organization.
                </P>
                <P>Applications that do not include the completion of the above instructions will not be considered.</P>
                <P>Letters of Recommendation may also be submitted if desired by the applicant; however, please note they may or may not have an impact on final appointments and are not required for an application to be considered.</P>
                <SIG>
                    <NAME>Margaret Dugan,</NAME>
                    <TITLE>Service-Level Liaison, Federal Acquisition Service, General Services Administration.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31554 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 6820-34-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF HEALTH AND HUMAN SERVICES</AGENCY>
                <SUBAGY>Food and Drug Administration</SUBAGY>
                <DEPDOC>[Docket No. FDA-2021-N-0403]</DEPDOC>
                <SUBJECT>Food Contact Notifications That Are No Longer Effective</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Food and Drug Administration, HHS.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Food and Drug Administration (FDA or we) is announcing its determination that the Food Contact Notifications (FCNs) listed in this notice are no longer effective. Several manufacturers notified FDA in writing that they ceased producing, supplying, or using the listed food contact substances (FCSs) for their intended use in the United States. We are taking this action in accordance with the process set out in our regulations, by which FDA may determine that an FCN is no longer effective.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Applicable date:</E>
                         This determination for the FCNs listed in table 1 and table 2 is effective January 6, 2025.
                    </P>
                    <P>
                        <E T="03">Compliance date:</E>
                         June 30, 2025, is the compliance date for the FCSs listed in table 2 that were produced, supplied, or used by the manufacturer or supplier prior to the effective date of this determination.
                    </P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        For access to the docket to read background documents or comments received go to 
                        <E T="03">https://www.regulations.gov</E>
                         and insert the docket number found in brackets in the heading of this document into the “Search” box and follow the prompts, and/or go to the Dockets Management Staff, 5630 Fishers Lane, Rm. 1061, Rockville, MD 20852.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Lillian Mawby, Office of Food Chemical Safety, Dietary Supplements, and Innovation, Human Foods Program, Food and Drug Administration, 5001 Campus Dr., College Park, MD 20740, 301-796-4041 or Carrol Bascus, Office of Policy, Regulations and Information, Human Foods Program, Food and Drug Administration, 5001 Campus Dr., College Park, MD 20740, 240-402-2378.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">I. Background</HD>
                <P>
                    In the 
                    <E T="04">Federal Register</E>
                     of March 22, 2024 (89 FR 20306), FDA issued a final rule to amend its regulations at § 170.105 (21 CFR 170.105) to provide additional reasons, other than safety, that may form the basis to determine that an FCN is no longer effective. One reason we may determine that an FCN is no longer effective is when the manufacturer or supplier has ceased or will cease the production, supply, or use of the food contact substance for its intended use authorized by the FCN (referred to as “abandonment”).
                </P>
                <P>Several manufacturers or suppliers notified FDA, through voluntary commitment letters (Ref. 1), that they have ceased producing, supplying, or using authorized FCSs for their intended food contact use in the United States. FDA received this information before issuing the final rule. After the final rule's effective date of May 21, 2024, consistent with § 170.105(a)(2)(ii)(A), we contacted the manufacturers or suppliers to inform them that their voluntary commitment letters demonstrate that they had ceased, and did not intend to resume in the future, producing, supplying, or using the subject FCSs for their intended food contact use. We provided the manufacturers or suppliers an opportunity to respond and did not receive any responses that disagreed with our findings. Therefore, in accordance with § 170.105(a)(2)(ii)(B), we determined that the FCNs are no longer effective based on abandonment. This notice constitutes the detailed summary of the basis for FDA's determination that these specific FCNs are no longer effective in accordance with § 170.105(b).</P>
                <P>Tables 1 and 2 identify FCNs that are no longer effective, as well as the FCSs no longer authorized by these FCNs, as of the publication date of this notice. Based on the end of sales dates provided by the manufacturers for the FCSs listed in FCNs in table 1, we expect any existing stocks of these FCSs to have already been exhausted from the U.S. market. For the FCSs listed in the FCNs in table 2, we are providing a compliance date for existing stocks of products that were produced, supplied, or used by the manufacturer or supplier before January 6, 2025. Based on the information provided in the voluntary commitment letter from that manufacturer, we expect any existing stocks of these products to be exhausted by June 30, 2025. We have determined that providing a compliance date of June 30, 2025, to exhaust these existing stocks would be protective of public health. For this reason, in accordance with § 170.105(b) we are establishing a compliance date of June 30, 2025, for the use of FCSs listed in table 2 in food contact articles if the FCSs were produced, supplied, or used by the manufacturer or supplier before January 6, 2025.</P>
                <GPOTABLE COLS="3" OPTS="L2,nj,p7,7/8,i1" CDEF="xs40,r150,r50">
                    <TTITLE>Table 1—Food Contact Notifications (FCNs) No Longer Effective as of January 6, 2025</TTITLE>
                    <BOXHD>
                        <CHED H="1">FCN No.</CHED>
                        <CHED H="1">FCS</CHED>
                        <CHED H="1">Manufacturer/supplier</CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">59</ENT>
                        <ENT>Glycine, N,N-bis[2-hydroxy-3-(2-propenyloxy)propyl]-, monosodium salt, reaction products with ammonium hydroxide and pentafluoroiodoethane-tetrafluoroethylene telomer (CAS Reg. No. 220459-70-1)</ENT>
                        <ENT>BASF Corporation.</ENT>
                    </ROW>
                    <ROW>
                        <PRTPAGE P="654"/>
                        <ENT I="01">187</ENT>
                        <ENT>Fluorinated polyurethane anionic resin (CAS Reg. No. 328389-91-9) prepared by reacting perfluoropolyether diol (CAS Reg. No. 88645-29-8), isophorone diisocyanate (CAS Reg. No. 4098-71-9), 2,2-dimethylolpropionic acid (CAS Reg. No. 4767-03-7), and triethylamine (CAS Reg. No. 121-44-8)</ENT>
                        <ENT>Solvay Specialty Polymers Italy S.p.A.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">195</ENT>
                        <ENT>Diphosphoric acid, polymers with ethoxylated reduced Me esters of reduced polymerized oxidized tetrafluoroethylene (CAS Reg. No. 200013-65-6). This substance is also known as: phosphate esters of ethoxylated perfluoroether, prepared by reaction of ethoxylated perfluoroether diol (CAS Reg. No. 162492-15-1) with phosphorous pentoxide (CAS Reg. No. 1314-56-3) or pyrophosphoric acid (CAS Reg. No. 2466-09-3)</ENT>
                        <ENT>Solvay Specialty Polymers Italy S.p.A.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">206</ENT>
                        <ENT>Copolymer of 2-perfluoroalkylethyl acrylate, 2-N,N-diethylaminoethyl methacrylate, and glycidyl methacrylate</ENT>
                        <ENT>DuPont Chemical Solutions Enterprise.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">255</ENT>
                        <ENT>3-cyclohexane-1-carboxylic acid, 6-((di-2-propenylamino)carbonyl)-,(1R,6R), reaction products with pentafluoroiodoethane-tetrafluoroethylene telomer, ammonium salts</ENT>
                        <ENT>BASF Corporation.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">311</ENT>
                        <ENT>Copolymers of 2-perfluoroalkylethyl acrylate, 2-N,N-diethylaminoethyl methacrylate, and glycidyl methacrylate</ENT>
                        <ENT>DuPont Chemical Solutions Enterprise.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">314</ENT>
                        <ENT>2-Propen-1-ol, reaction products with pentafluoroiodoethane-tetrafluoroethylene telomer, dehydroiodinated, reaction products with epichlorohydrin and triethylenetetramine (CAS Reg. No. 464178-90-3)</ENT>
                        <ENT>Solenis LLC.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">338</ENT>
                        <ENT>Copolymers of 2-perfluoroalkylethyl acrylate, 2-N,N-diethylaminoethyl methacrylate, and glycidyl methacrylate</ENT>
                        <ENT>DuPont Chemical Solutions Enterprise.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">398</ENT>
                        <ENT>Perfluoropolyether dicarboxylic acid (CAS Reg. No. 69991-62-4), ammonium salt</ENT>
                        <ENT>Solvay Specialty Polymers Italy S.p.A.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">416</ENT>
                        <ENT>Diphosphoric acid, polymers with ethoxylated reduced methyl esters of reduced polymerized oxidized tetrafluoroethylene (CAS Reg. No. 200013-65-6). This substance is also known as phosphate esters of ethoxylated perfluoroether, prepared by reaction of ethoxylated perfluoroether diol (CAS Reg. No. 162492-15-1) with phosphorous pentoxide (CAS Reg. No. 1314-56-3) or pyrophosphoric acid (CAS Reg. No. 2466-09-3)</ENT>
                        <ENT>Solvay Specialty Polymers Italy S.p.A.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">487</ENT>
                        <ENT>2-propen-1-ol, reaction products with pentafluoroiodoethane-tetrafluoroethylene telomer, dehydroiodinated, reaction products with epichlorohydrin and triethylenetetramine (CAS Reg. No. 464178-90-3)</ENT>
                        <ENT>Solenis LLC.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">518</ENT>
                        <ENT>2-propen-1-ol, reaction products with pentafluoroiodoethane-tetrafluoroethylene telomer, dehydroiodinated, reaction products with epichlorohydrin and triethylenetetramine (CAS Reg. No 464178-90-3)</ENT>
                        <ENT>Solenis LLC.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">538</ENT>
                        <ENT>Perfluoropolyether dicarboxylic acid (CAS Reg. No. 69991-62-4), ammonium salt</ENT>
                        <ENT>Solvay Specialty Polymers Italy S.p.A.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">542</ENT>
                        <ENT>2-propen-1-ol, reaction products with 1,1,1,2,2,3,3,4,4,5,5,6,6-tridecafluoro-6-iodohexane, dehydroiodinated, reaction products with epichlorohydrin and triethylenetetramine (CAS Reg. No. 464178-94-7)</ENT>
                        <ENT>Solenis LLC.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">628</ENT>
                        <ENT>Copolymer of 2-perfluoroalkylethyl acrylate, 2-(dimethylamino)ethyl methacrylate, and oxidized 2-(dimethylamino)ethyl methacrylate (CAS Reg. No. 479029-28-2)</ENT>
                        <ENT>Clariant Corporation.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">646</ENT>
                        <ENT>Copolymers of 2-perfluoroalkylethyl acrylate, 2-N,N-diethylaminoethyl methacrylate, glycidyl methacrylate, acrylic acid, and methacrylic acid (CAS Reg. No. 870465-08-0)</ENT>
                        <ENT>Dupont Chemical Solutions Enterprise.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">746</ENT>
                        <ENT>2-propen-1-ol, reaction products with 1,1,1,2,2,3,3,4,4,5,5,6,6-tridecafluoro-6-iodohexane, dehydroiodinated, reaction products with epichlorohydrin and triethylenetetramine (CAS Reg. No. 464178-94-7) as manufactured in accordance with the description in the FCN</ENT>
                        <ENT>Solenis LLC.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">783</ENT>
                        <ENT>2-propen-1-ol, reaction products with 1,1,1,2,2,3,3,4,4,5,5,6,6-tridecafluoro-6-iodohexane, dehydroiodinated, reaction products with epichlorohydrin and triethylenetetramine (CAS Reg. No. 464178-94-7) as manufactured in accordance with the description in the FCN</ENT>
                        <ENT>Solenis LLC.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">820</ENT>
                        <ENT>2-Propenoic acid, 3,3,4,4,5,5,6,6,7,7,8,8,8-tridecafluorooctyl ester, polymer with α-(1-oxo-2-propen-1-yl)-ω-hydroxypoly(oxy-1,2-ethanediyl)</ENT>
                        <ENT>Daikin America, Inc.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">827</ENT>
                        <ENT>2-propenoic acid, 2-hydroxyethyl ester, polymer with α-(1-oxo-2-propen-1-yl)-ω-hydroxypoly(oxy-1,2-ethanediyl), α-(1-oxo-2-propen-1-yl)-ω-[(1-oxo-2-propen-1-yl)oxy]poly(oxy-1,2-ethanediyl) and 3,3,4,4,5,5,6,6,7,7,8,8,8-tridecafluorooctyl 2-propenoate (CAS Reg. No. 1012783-70-8)</ENT>
                        <ENT>Daikin America, Inc.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">885</ENT>
                        <ENT>2-propenoic acid, 2-methyl-, polymer with 2-(diethylamino)ethyl 2-methyl-2-propenoate, 2-propenoic acid and 3,3,4,4,5,5,6,6,7,7,8,8,8-tridecafluorooctyl 2-methyl-2-propenoate, acetate (CAS Reg. No. 1071022-26-8)</ENT>
                        <ENT>The Chemours Company FC, LLC.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">888</ENT>
                        <ENT>2-propenoic acid, 2-hydroxyethyl ester, polymer with α-(1-oxo-2-propen-1-yl)-ω-hydroxypoly(oxy-1,2-ethanediyl), α-(1-oxo-2-propen-1-yl)-ω-[(1-oxo-2-propen-1-yl)oxy]poly(oxy-1,2-ethanediyl) and 3,3,4,4,5,5,6,6,7,7,8,8,8-tridecafluorooctyl 2-propenoate (CAS Reg. No. 1012783-70-8)</ENT>
                        <ENT>Daikin America, Inc.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">933</ENT>
                        <ENT>2-propenoic acid, 2-methyl-, polymer with 2-hydroxyethyl 2-methyl-2-propenoate, α-(1-oxo-2-propen-1-yl)-ω-hydroxypoly(oxy-1,2-ethanediyl) and 3,3,4,4,5,5,6,6,7,7,8,8,8-tridecafluorooctyl 2-propenoate sodium salt (CAS Reg. No. 1158951-86-0)</ENT>
                        <ENT>Daikin America, Inc.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">940</ENT>
                        <ENT>Hexane, 1,6-diisocyanato-, homopolymer, 3,3,4,4,5,5,6,6,7,7,8,8,8-tridecafluoro-1-octanol-blocked (CAS Reg. No. 357624-15-8)</ENT>
                        <ENT>The Chemours Company FC, LLC.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">962</ENT>
                        <ENT>Diphosphoric acid, polymers with ethoxylated reduced methyl esters of reduced polymerized oxidized tetrafluoroethylene (CAS Reg. No. 200013-65-6). This substance is also known as phosphate esters of ethoxylated perfluoroether, prepared by reaction of ethoxylated perfluoroether diol (CAS Reg. No. 162492-15-1) with phosphorous pentoxide (CAS Reg. No. 1314-56-3) or pyrophosphoric acid (CAS Reg. No. 2466-09-3)</ENT>
                        <ENT>Solvay Specialty Polymers USA, LLC.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">1027</ENT>
                        <ENT>2-propenoic acid, 2-methyl-, polymer with 2-(diethylamino)ethyl 2-methyl-2-propenoate, 2-propenoic acid and 3,3,4,4,5,5,6,6,7,7,8,8,8-tridecafluorooctyl 2-methyl-2-propenoate, acetate (CAS Reg. No. 1071022-26-8)</ENT>
                        <ENT>The Chemours Company FC, LLC.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">1044</ENT>
                        <ENT>2-propenoic acid, 2-methyl-, 2-hydroxyethyl ester polymer with 1-ethyenyl-2-pyrrolidinone, 2-propenoic acid and 3,3,4,4,5,5,6,6,7,7,8,8,8-tridecafluorooctyl 2-propenoate sodium salt (CAS Reg. No. 1206450-10-3)</ENT>
                        <ENT>Daikin America, Inc.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">1097</ENT>
                        <ENT>Hexane, 1,6-diisocyanato-, homopolymer, α-[1-[[[3-[[3 (dimethylamino)propyl]amino]propyl]amino]carbonyl]-1,2,2,2-tetrafluoroethyl]-ω-(1,1,2,2,3,3,3-heptafluoropropoxy)poly[oxy[trifluoro(trifluoromethyl)-1,2-ethanediyl]]-blocked (CAS Reg. No. 1279108-20-1)</ENT>
                        <ENT>Archroma U.S., Inc.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">1360</ENT>
                        <ENT>2-Propenoic acid, 2-methyl-, 2-(dimethylamino)ethyl ester, polymer with 1-ethenyl-2-pyrrolidinone and 3,3,4,4,5,5,6,6,7,7,8,8,8-tridecafluorooctyl 2-propenoate, acetate (CAS Reg. No. 1334473-84-5)</ENT>
                        <ENT>Daikin America, Inc.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">1451</ENT>
                        <ENT>2-Propenoic acid, 2-methyl-, 2-(dimethylamino)ethyl ester, polymer with 1-ethenyl-2-pyrrolidinone and 3,3,4,4,5,5,6,6,7,7,8,8,8-tridecafluorooctyl 2-propenoate, acetate (CAS Reg. No. 1334473-84-5)</ENT>
                        <ENT>Daikin America, Inc.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">1493</ENT>
                        <ENT>Copolymer of 2-(dimethylamino) ethyl methacrylate with 3,3,4,4,5,5,6,6,7,7,8,8,8-tridecafluorooctyl methacrylate, N-oxide, acetate (CAS Reg. 1440528-04-0)</ENT>
                        <ENT>Archroma Management GmbH.</ENT>
                    </ROW>
                </GPOTABLE>
                <PRTPAGE P="655"/>
                <GPOTABLE COLS="3" OPTS="L2,nj,p7,7/8,i1" CDEF="xs40,r150,r50">
                    <TTITLE>Table 2—Food Contact Notifications (FCNs) No Longer Effective as of January 6, 2025 With a Compliance Date of June 30, 2025</TTITLE>
                    <BOXHD>
                        <CHED H="1">FCN No.</CHED>
                        <CHED H="1">FCS</CHED>
                        <CHED H="1">Manufacturer/supplier</CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">599</ENT>
                        <ENT>Copolymer of perfluorohexylethyl methacrylate, 2-N,N-diethylaminoethyl methacrylate, 2-hydroxyethyl methacrylate, and 2,2'-ethylenedioxydiethyl dimethacrylate, acetic acid salt (CAS Reg. No. 863408-20-2) or malic acid salt (CAS Reg. No. 1225273-44-8)</ENT>
                        <ENT>Asahi Glass Co., Ltd. (Manufacturer) and AGC Chemicals Americas, Incorporated.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">604</ENT>
                        <ENT>Copolymer of perfluorohexylethyl methacrylate, 2-N,N-diethylaminoethyl methacrylate, 2-hydroxyethyl methacrylate, and 2,2'-ethylenedioxydiethyl dimethacrylate, acetic acid salt (CAS Reg. No. 863408-20-2) or malic acid salt (CAS Reg. No. 1225273-44-8)</ENT>
                        <ENT>Asahi Glass Co., Ltd. (Manufacturer) and AGC Chemicals Americas, Incorporated.</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">1186</ENT>
                        <ENT>Butanedioic acid, 2-methylene-, polymer with 2-hydroxyethyl, 2-methyl-2-propenoate, 2-methyl-2-propenoic acid and 3,3,4,4,5,5,6,6,7,7,8,8,8-tridecafluorooctyl 2-methyl-2-propenoate, sodium salt (CAS Reg. No. 1345817-52-8)</ENT>
                        <ENT>
                            Asahi Glass Co., Ltd.
                            <LI>AGC Chemicals Americas, Inc.</LI>
                        </ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">1676</ENT>
                        <ENT>2-propenoic acid, 2-methyl-, 2-hydroxyethyl ester, polymer with 2-propenoic acid and 3,3,4,4,5,5,6,6,7,7,8,8,8-tridecafluorooctyl 2-methyl-2-propenoate, sodium salt (CAS Reg. No. 1878204-24-0)</ENT>
                        <ENT>
                            Asahi Glass Co., Ltd.
                            <LI>AGC Chemicals Americas, Inc.</LI>
                        </ENT>
                    </ROW>
                </GPOTABLE>
                <P>
                    To reflect these changes in status of the affected FCNs, we established an Inventory of Food Contact Notifications That are No Longer Effective on FDA's website. The Inventory may be viewed at 
                    <E T="03">https://www.hfpappexternal.fda.gov/scripts/fdcc/index.cfm?set=FCN-no-longer-effective.</E>
                </P>
                <P>
                    We also updated our Inventory of Effective Food Contact Notifications accordingly at 
                    <E T="03">https://www.hfpappexternal.fda.gov/scripts/fdcc/index.cfm?set=FCN.</E>
                </P>
                <P>A food additive is deemed unsafe unless that substance and its use conform with a regulation issued under section 409 of the Federal Food, Drug, and Cosmetic Act (FD&amp;C Act) (21 U.S.C. 348) or there is an FCN submitted under section 409(h) of the FD&amp;C Act that is effective (section 409(a) of the FD&amp;C Act). An effective FCN is specific only to the intended use of the substance prepared by the manufacturer or supplier identified in the FCN (section 409(h)(1)(C)).</P>
                <P>Our determination that an FCN is no longer effective does not preclude any manufacturers or suppliers from submitting a new FCN for the same FCS, including for the same intended use, after FDA has determined that an FCN is no longer effective, unless the intended use of the FCS is authorized by a food additive regulation or the subject of an issued threshold of regulation exemption, per 21 CFR 170.105(c).</P>
                <HD SOURCE="HD1">II. Analysis of Environmental Impact</HD>
                <P>We have determined under 21 CFR 25.32(m) that this action is of a type that does not individually or cumulatively have a significant effect on the human environment. Therefore, neither an environmental assessment nor an environmental impact statement is required.</P>
                <HD SOURCE="HD1">III. References</HD>
                <P>
                    The following references are on display at the Dockets Management Staff, (HFA-305), Food and Drug Administration, 5630 Fishers Lane, Rm. 1061, Rockville, MD 20852, 240-402-7500 and are available for viewing by interested persons between 9 a.m. and 4 p.m., Monday through Friday; they also are available electronically at 
                    <E T="03">https://www.regulations.gov.</E>
                     Although FDA has verified the website addresses in this document, please note that websites are subject to change over time.
                </P>
                <EXTRACT>
                    <FP SOURCE="FP-2">
                        1. FDA, Market Phase-Out of Grease-Proofing Substances Containing PFAS, Commitment Letters from Industry available at: 
                        <E T="03">https://www.fda.gov/food/process-contaminants-food/market-phase-out-grease-proofing-substances-containing-pfas.</E>
                    </FP>
                </EXTRACT>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>P. Ritu Nalubola,</NAME>
                    <TITLE>Associate Commissioner for Policy.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31692 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4164-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF HEALTH AND HUMAN SERVICES</AGENCY>
                <SUBAGY>Food and Drug Administration</SUBAGY>
                <DEPDOC>[Docket No. FDA-2024-N-5889]</DEPDOC>
                <SUBJECT>Request for Nominations of Voting Members on a Public Advisory Committee; National Mammography Quality Assurance Advisory Committee</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Food and Drug Administration, HHS.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Food and Drug Administration (FDA) is requesting nominations for voting members to serve on the National Mammography Quality Assurance Advisory Committee in the Center for Devices and Radiological Health. Nominations will be accepted for current and upcoming vacancies effective February 1, 2025, with this notice. FDA seeks to include the views of women and men, members of all racial and ethnic groups, and individuals with and without disabilities on its advisory committees and, therefore, encourages nominations of appropriately qualified candidates from these groups.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Nominations received on or before March 7, 2025, will be given first consideration for membership on the National Mammography Quality Assurance Advisory Committee. Nominations received after March 7, 2025, will be considered for nomination to the committee as later vacancies occur.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        All nominations for membership should be submitted electronically by logging into the FDA Advisory Nomination Portal at 
                        <E T="03">https://www.accessdata.fda.gov/scripts/FACTRSPortal/FACTRS/index.cfm</E>
                         or by mail to Advisory Committee Oversight and Management Staff, Food and Drug Administration, 10903 New Hampshire Ave., Bldg. 32, Rm. 5103, Silver Spring, MD 20993-0002. Information about becoming a member on an FDA advisory committee can also be obtained by visiting FDA's website at 
                        <E T="03">https://www.fda.gov/AdvisoryCommittees/default.htm.</E>
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        <E T="03">Regarding all nomination questions for membership:</E>
                         James P. Swink, Center for Devices and Radiological Health, Food and Drug Administration, 10903 New Hampshire Ave., Bldg. 66, Rm. 5211, Silver Spring, MD 20993, 301-796-6313, 
                        <E T="03">James.Swink@fda.hhs.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>FDA is requesting nominations for voting members to fill upcoming vacancies on the National Mammography Quality Assurance Advisory Committee.</P>
                <HD SOURCE="HD1">I. General Description of the Committee Duties</HD>
                <P>
                    The National Mammography Quality Assurance Advisory Committee advises the Commissioner of Food and Drugs (the Commissioner) or designee on: (1) developing appropriate quality standards and regulations for mammography facilities; (2) developing appropriate standards and regulations 
                    <PRTPAGE P="656"/>
                    for bodies accrediting mammography facilities under this program; (3) developing regulations with respect to sanctions; (4) developing procedures for monitoring compliance with standards; (5) establishing a mechanism to investigate consumer complaints; (6) reporting new developments concerning breast imaging that should be considered in the oversight of mammography facilities; (7) determining whether there exists a shortage of mammography facilities in rural and health professional shortage areas and determining the effects of personnel on access to the services of such facilities in such areas; (8) determining whether there will exist a sufficient number of medical physicists after October 1, 1999; and (9) determining the costs and benefits of compliance with these requirements.
                </P>
                <HD SOURCE="HD1">II. Criteria for Voting Members</HD>
                <P>The committee consists of a core of 15 members, including the Chair. Members and the Chair are selected by the Commissioner or designee from among physicians, practitioners, and other health professionals, whose clinical practice, research specialization, or professional expertise includes a significant focus on mammography. Members will be invited to serve for overlapping terms of up to 4 years. Almost all members of this committee serve as Special Government Employees.</P>
                <HD SOURCE="HD1">III. Nomination Procedures</HD>
                <P>
                    Any interested person may nominate one or more qualified persons for membership on the advisory committee. Self-nominations are also accepted. Nominations must include a current, complete résumé or curriculum vitae for each nominee, including current business address, telephone number, and email address if available, and a signed copy of the Acknowledgement and Consent form available at the FDA Advisory Nomination Portal (see 
                    <E T="02">ADDRESSES</E>
                    ). Nominations must specify the advisory committee for which the nominee is recommended. Nominations must also acknowledge that the nominee is aware of the nomination unless self-nominated. FDA will ask potential candidates to provide detailed information concerning such matters related to financial holdings, employment, and research grants and/or contracts to permit evaluation of possible sources of conflict of interest.
                </P>
                <P>
                    This notice is issued under the Federal Advisory Committee Act (5 U.S.C. 1001 
                    <E T="03">et seq.</E>
                    ), and 21 CFR part 14, relating to advisory committees.
                </P>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <NAME>P. Ritu Nalubola,</NAME>
                    <TITLE>Associate Commissioner for Policy.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31703 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4164-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF HEALTH AND HUMAN SERVICES</AGENCY>
                <SUBAGY>Health Resources and Services Administration</SUBAGY>
                <SUBJECT>National Vaccine Injury Compensation Program; List of Petitions Received</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Health Resources and Services Administration (HRSA), Department of Health and Human Services (HHS).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>HRSA is publishing this notice of petitions received under the National Vaccine Injury Compensation Program (the Program), as required by the Public Health Service (PHS) Act, as amended. While the Secretary of HHS is named as the respondent in all proceedings brought by the filing of petitions for compensation under the Program, the United States Court of Federal Claims is charged by statute with responsibility for considering and acting upon the petitions.</P>
                </SUM>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        For information about requirements for filing petitions, and the Program in general, contact Lisa L. Reyes, Clerk of Court, United States Court of Federal Claims, 717 Madison Place NW, Washington, DC 20005, (202) 357-6400. For information on HRSA's role in the Program, contact the Director, National Vaccine Injury Compensation Program, 5600 Fishers Lane, Room 8W-25A, Rockville, Maryland 20857; (301) 443-6593, or visit our website at: 
                        <E T="03">http://www.hrsa.gov/vaccinecompensation/index.html.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The Program provides a system of no-fault compensation for certain individuals who have been injured by specified childhood vaccines. Subtitle 2 of title XXI of the PHS Act, 42 U.S.C. 300aa-10 
                    <E T="03">et seq.,</E>
                     provides that those seeking compensation are to file a petition with the United States Court of Federal Claims and to serve a copy of the petition to the Secretary of HHS, who is named as the respondent in each proceeding. The Secretary has delegated this responsibility under the Program to HRSA. The Court is directed by statute to appoint special masters who take evidence, conduct hearings as appropriate, and make initial decisions as to eligibility for, and amount of, compensation.
                </P>
                <P>A petition may be filed with respect to injuries, disabilities, illnesses, conditions, and deaths resulting from vaccines described in the Vaccine Injury Table (the Table) set forth at 42 CFR 100.3. This Table lists for each covered childhood vaccine the conditions that may lead to compensation and, for each condition, the time period for occurrence of the first symptom or manifestation of onset or of significant aggravation after vaccine administration. Compensation may also be awarded for conditions not listed in the Table and for conditions that are manifested outside the time periods specified in the Table, but only if the petitioner shows that the condition was caused by one of the listed vaccines.</P>
                <P>
                    Section 2112(b)(2) of the PHS Act, 42 U.S.C. 300aa-12(b)(2), requires that “[w]ithin 30 days after the Secretary receives service of any petition filed under section 2111 the Secretary shall publish notice of such petition in the 
                    <E T="04">Federal Register</E>
                    .” Set forth below is a list of petitions received by HRSA on November 1, 2024, through November 30, 2024. This list provides the name of the petitioner, city, and state of vaccination (if unknown then the city and state of the person or attorney filing the claim), and case number. In cases where the Court has redacted the name of a petitioner and/or the case number, the list reflects such redaction.
                </P>
                <P>Section 2112(b)(2) also provides that the special master “shall afford all interested persons an opportunity to submit relevant, written information” relating to the following:</P>
                <P>1. The existence of evidence “that there is not a preponderance of the evidence that the illness, disability, injury, condition, or death described in the petition is due to factors unrelated to the administration of the vaccine described in the petition,” and</P>
                <P>2. Any allegation in a petition that the petitioner either:</P>
                <P>a. “[S]ustained, or had significantly aggravated, any illness, disability, injury, or condition not set forth in the Vaccine Injury Table but which was caused by” one of the vaccines referred to in the Table, or</P>
                <P>b. “[S]ustained, or had significantly aggravated, any illness, disability, injury, or condition set forth in the Vaccine Injury Table the first symptom or manifestation of the onset or significant aggravation of which did not occur within the time period set forth in the Table but which was caused by a vaccine” referred to in the Table.</P>
                <P>
                    In accordance with section 2112(b)(2), all interested persons may submit written information relevant to the issues described above in the case of the 
                    <PRTPAGE P="657"/>
                    petitions listed below. Any person choosing to do so should file an original and three (3) copies of the information with the Clerk of the United States Court of Federal Claims at the address listed above (under the heading 
                    <E T="02">For Further Information Contact</E>
                    ), with a copy to HRSA addressed to Director, Division of Injury Compensation Programs, Health Systems Bureau, 5600 Fishers Lane, 8W-25A, Rockville, Maryland 20857. The Court's caption (
                    <E T="03">Petitioner's Name</E>
                     v. 
                    <E T="03">Secretary of HHS</E>
                    ) and the docket number assigned to the petition should be used as the caption for the written submission. Chapter 35 of Title 44, United States Code, related to paperwork reduction, does not apply to information required for purposes of carrying out the Program.
                </P>
                <SIG>
                    <NAME>Diana Espinosa,</NAME>
                    <TITLE>Principal Deputy Administrator.</TITLE>
                </SIG>
                <HD SOURCE="HD1">List of Petitions Filed</HD>
                <EXTRACT>
                    <FP SOURCE="FP-2">1. Joann Chamberlain, Woodstock, New York, Court of Federal Claims No: 24-1794V</FP>
                    <FP SOURCE="FP-2">2. Daniel Weihert, Terre Haute, Indiana, Court of Federal Claims No: 24-1795V</FP>
                    <FP SOURCE="FP-2">3. Philip Dahl, Shreveport, Louisiana, Court of Federal Claims No: 24-1796V</FP>
                    <FP SOURCE="FP-2">4. Lauren Belanger, Portland, Maine, Court of Federal Claims No: 24-1797V</FP>
                    <FP SOURCE="FP-2">5. Jesus Rodriguez, Edinburg, Texas, Court of Federal Claims No: 24-1799V</FP>
                    <FP SOURCE="FP-2">6. Amber Berry, LaFayette, Georgia, Court of Federal Claims No: 24-1800V</FP>
                    <FP SOURCE="FP-2">7. Chava Stark, Troy, New York, Court of Federal Claims No: 24-1804V</FP>
                    <FP SOURCE="FP-2">8. Darren Haimer, Lakewood Ranch, Florida, Court of Federal Claims No: 24-1805V</FP>
                    <FP SOURCE="FP-2">9. Robert Friend, Woodbury, New Jersey, Court of Federal Claims No: 24-1807V</FP>
                    <FP SOURCE="FP-2">10. Tamma Adkins, Lancaster, Kentucky, Court of Federal Claims No: 24-1808V</FP>
                    <FP SOURCE="FP-2">11. Peter Deveau, Waterford, Connecticut, Court of Federal Claims No: 24-1809V</FP>
                    <FP SOURCE="FP-2">12. Steven T. Maupin, Cuyahoga Falls, Ohio, Court of Federal Claims No: 24-1813V</FP>
                    <FP SOURCE="FP-2">13. Vickie L. Carpenter, Gaylord, Michigan, Court of Federal Claims No: 24-1814V</FP>
                    <FP SOURCE="FP-2">14. David Novak, Libertyville, Illinois, Court of Federal Claims No: 24-1815V</FP>
                    <FP SOURCE="FP-2">15. Emma Montgomery, Brooklyn, New York, Court of Federal Claims No: 24-1817V</FP>
                    <FP SOURCE="FP-2">16. Vickie Perry, Milton, Vermont, Court of Federal Claims No: 24-1819V</FP>
                    <FP SOURCE="FP-2">17. Rebecca Tyser, Palm Harbor, Florida, Court of Federal Claims No: 24-1823V</FP>
                    <FP SOURCE="FP-2">18. Davie Ward, Bakersfield, California, Court of Federal Claims No: 24-1825V</FP>
                    <FP SOURCE="FP-2">19. Jennifer Alves, San Jose, California, Court of Federal Claims No: 24-1826V</FP>
                    <FP SOURCE="FP-2">20. Lesia Powe on behalf of Timothy Powe, Deceased, West Point, Mississippi, Court of Federal Claims No: 24-1827V</FP>
                    <FP SOURCE="FP-2">21. Kristin Morris, Thornton, Colorado, Court of Federal Claims No: 24-1829V</FP>
                    <FP SOURCE="FP-2">22. Ricki Dayner, Aurora, Colorado, Court of Federal Claims No: 24-1830V</FP>
                    <FP SOURCE="FP-2">23. Carl Nielson, Charleston, South Carolina, Court of Federal Claims No: 24-1839V</FP>
                    <FP SOURCE="FP-2">24. Ramona Santana, New York, New York, Court of Federal Claims No: 24-1841V</FP>
                    <FP SOURCE="FP-2">25. Loretta Dawley, Longview, Washington, Court of Federal Claims No: 24-1842V</FP>
                    <FP SOURCE="FP-2">26. Luzita Powell, New Berlin, Wisconsin, Court of Federal Claims No: 24-1843V</FP>
                    <FP SOURCE="FP-2">27. Carmen K. Foster, Richmond, Kentucky, Court of Federal Claims No: 24-1844V</FP>
                    <FP SOURCE="FP-2">28. Rachael Denholm, Columbus, Ohio, Court of Federal Claims No: 24-1845V</FP>
                    <FP SOURCE="FP-2">29. David Shmoel, Brooklyn, New York, Court of Federal Claims No: 24-1848V</FP>
                    <FP SOURCE="FP-2">30. Sharon Knight, Eugene, Oregon, Court of Federal Claims No: 24-1850V</FP>
                    <FP SOURCE="FP-2">31. Samuel Heron, III, Woodridge, Illinois, Court of Federal Claims No: 24-1851V</FP>
                    <FP SOURCE="FP-2">32. Franice Deleon, New Braunfels, Texas, Court of Federal Claims No: 24-1852V</FP>
                    <FP SOURCE="FP-2">33. Anna Maryanski, Jeanette, Pennsylvania, Court of Federal Claims No: 24-1853V</FP>
                    <FP SOURCE="FP-2">34. Danah Moore, Poughkeepsie, New York, Court of Federal Claims No: 24-1854V</FP>
                    <FP SOURCE="FP-2">35. Joy Terrell, Philadelphia, Pennsylvania, Court of Federal Claims No: 24-1855V</FP>
                    <FP SOURCE="FP-2">36. Cory Mandrel Welch, Fox Lake, Wisconsin, Court of Federal Claims No: 24-1856V</FP>
                    <FP SOURCE="FP-2">37. Beth D. Bajus, Grandview, Ohio, Court of Federal Claims No: 24-1857V</FP>
                    <FP SOURCE="FP-2">38. Janice Weil, Lake George, Colorado, Court of Federal Claims No: 24-1858V</FP>
                    <FP SOURCE="FP-2">39. Miriam Zamago, Mission Hills, California, Court of Federal Claims No: 24-1860V</FP>
                    <FP SOURCE="FP-2">40. Janelle Marrero on behalf of S. M., Brandon, Florida, Court of Federal Claims No: 24-1861V</FP>
                    <FP SOURCE="FP-2">41. Michael T. Smith, Fulton, New York, Court of Federal Claims No: 24-1864V</FP>
                    <FP SOURCE="FP-2">42. Earlene Hall, Commerce City, Colorado, Court of Federal Claims No: 24-1865V</FP>
                    <FP SOURCE="FP-2">43. Jeffrey Upin, Boston, Massachusetts, Court of Federal Claims No: 24-1867V</FP>
                    <FP SOURCE="FP-2">44. Karyna Franke, Yakima, Washington, Court of Federal Claims No: 24-1870V</FP>
                    <FP SOURCE="FP-2">45. Michele Greenstein, Nottingham, Maryland, Court of Federal Claims No: 24-1871V</FP>
                    <FP SOURCE="FP-2">46. Geralyn Sale, Branford, Connecticut, Court of Federal Claims No: 24-1872V</FP>
                    <FP SOURCE="FP-2">47. Betty Wagner, Roseburg, Oregon, Court of Federal Claims No: 24-1874V</FP>
                    <FP SOURCE="FP-2">48. Abby Kirsch, Sun Valley, Idaho, Court of Federal Claims No: 24-1876V</FP>
                    <FP SOURCE="FP-2">49. Casey Hogan, Cambridge, Massachusetts, Court of Federal Claims No: 24-1877V</FP>
                    <FP SOURCE="FP-2">50. Bonnie Gabel, Amarillo, Texas, Court of Federal Claims No: 24-1878V</FP>
                    <FP SOURCE="FP-2">51. Fei Cai, Los Angeles, California, Court of Federal Claims No: 24-1881V</FP>
                    <FP SOURCE="FP-2">52. Roderick Robinson on behalf of I. R., Bogalusa, Louisiana, Court of Federal Claims No: 24-1884V</FP>
                    <FP SOURCE="FP-2">53. Maribell Seiglie, Cresskill, New Jersey, Court of Federal Claims No: 24-1885V</FP>
                    <FP SOURCE="FP-2">54. Rebecca Heineman on behalf of Jennell Jaquays, Deceased, Dallas, Texas, Court of Federal Claims No: 24-1886V</FP>
                    <FP SOURCE="FP-2">55. Andrew Lavecchio, Pinellas Park, Florida, Court of Federal Claims No: 24-1887V</FP>
                    <FP SOURCE="FP-2">56. Mark Streech, Stevensville, Montana, Court of Federal Claims No: 24-1888V</FP>
                    <FP SOURCE="FP-2">57. Brooke Gorzelanczyk, Lake in the Hills, Illinois, Court of Federal Claims No: 24-1889V</FP>
                    <FP SOURCE="FP-2">58. Joanne Sarazin, Lakewood, Colorado, Court of Federal Claims No: 24-1890V</FP>
                    <FP SOURCE="FP-2">59. Stephanie Brandmeyer, Irvine, California, Court of Federal Claims No: 24-1891V</FP>
                    <FP SOURCE="FP-2">60. Anthony Barnes, Oshkosh, Wisconsin, Court of Federal Claims No: 24-1892V</FP>
                    <FP SOURCE="FP-2">61. Leonard Casoria, Boston, Massachusetts, Court of Federal Claims No: 24-1894V</FP>
                    <FP SOURCE="FP-2">62. David Franklin Peeples, Knoxville, Tennessee, Court of Federal Claims No: 24-1895V</FP>
                    <FP SOURCE="FP-2">63. Matt Pello, Wyndmoor, Pennsylvania, Court of Federal Claims No: 24-1896V</FP>
                    <FP SOURCE="FP-2">64. Maria DeGraaf, Vista, California, Court of Federal Claims No: 24-1898V</FP>
                    <FP SOURCE="FP-2">65. Bruce A. Ling, Tallahassee, Florida, Court of Federal Claims No: 24-1899V</FP>
                    <FP SOURCE="FP-2">66. Nelson Balanga, Ventura, California, Court of Federal Claims No: 24-1900V</FP>
                    <FP SOURCE="FP-2">67. Amit Patil, Naperville, Illinois, Court of Federal Claims No: 24-1901V</FP>
                    <FP SOURCE="FP-2">68. Jessica Gutierrez, Brownsville, Texas, Court of Federal Claims No: 24-1902V</FP>
                    <FP SOURCE="FP-2">69. Joan Freeman, Anderson, South Carolina, Court of Federal Claims No: 24-1903V</FP>
                    <FP SOURCE="FP-2">70. Pamela Bohle, Bloomingdale, Illinois, Court of Federal Claims No: 24-1904V</FP>
                    <FP SOURCE="FP-2">71. Mark Saunders, Watertown, Massachusetts, Court of Federal Claims No: 24-1907V</FP>
                    <FP SOURCE="FP-2">72. Crystal Boone, Seattle, Washington, Court of Federal Claims No: 24-1908V</FP>
                    <FP SOURCE="FP-2">73. Geralyn Santiago, Medford, New York, Court of Federal Claims No: 24-1910V</FP>
                    <FP SOURCE="FP-2">74. Jordan Preston, Columbus, Ohio, Court of Federal Claims No: 24-1911V</FP>
                    <FP SOURCE="FP-2">75. Lewis Bartell, Fairfax, Virginia, Court of Federal Claims No: 24-1912V</FP>
                    <FP SOURCE="FP-2">76. Jane-Alexandra Krehbiel on behalf of Matthew Krehbiel, Deceased, Louisa, Virginia, Court of Federal Claims No: 24-1917V</FP>
                    <FP SOURCE="FP-2">77. Gabriella Ramsby, Los Angeles, California, Court of Federal Claims No: 24-1918V</FP>
                    <FP SOURCE="FP-2">78. Patrice Sneed, Houston, Texas, Court of Federal Claims No: 24-1919V</FP>
                    <FP SOURCE="FP-2">79. Porchia Allen, Alton, Illinois, Court of Federal Claims No: 24-1921V</FP>
                    <FP SOURCE="FP-2">80. Eun Sup Kim, Marietta, Georgia, Court of Federal Claims No: 24-1922V</FP>
                    <FP SOURCE="FP-2">81. Yeji Kim, New York, New York, Court of Federal Claims No: 24-1928V</FP>
                    <FP SOURCE="FP-2">82. Nikki Kight, Crawfordville, Florida, Court of Federal Claims No: 24-1930V</FP>
                    <FP SOURCE="FP-2">83. Kathleen Bondi, Downers Grove, Illinois, Court of Federal Claims No: 24-1935V</FP>
                    <FP SOURCE="FP-2">84. Pamela Bedwell, Boston, Massachusetts, Court of Federal Claims No: 24-1938V</FP>
                    <FP SOURCE="FP-2">85. Michael Koffski, Algonquin, Illinois, Court of Federal Claims No: 24-1941V</FP>
                    <FP SOURCE="FP-2">86. Mary Jo Tracy, Bonita Springs, Florida, Court of Federal Claims No: 24-1942V</FP>
                    <FP SOURCE="FP-2">87. Lynette Ward, Rochester, New York, Court of Federal Claims No: 24-1946V</FP>
                    <FP SOURCE="FP-2">88. Christine Matthews, Chicago, Illinois, Court of Federal Claims No: 24-1947V</FP>
                    <FP SOURCE="FP-2">89. Bethania Bacigalupe, Waltham, Massachusetts, Court of Federal Claims No: 24-1948V</FP>
                    <FP SOURCE="FP-2">90. Bradley Hayes, Mt. Sterling, Illinois, Court of Federal Claims No: 24-1949V</FP>
                    <FP SOURCE="FP-2">91. Kimberly Jewel DeLuna, Colorado Springs, Colorado, Court of Federal Claims No: 24-1950V</FP>
                    <FP SOURCE="FP-2">92. Bruce Larson, Fargo, North Dakota, Court of Federal Claims No: 24-1951V</FP>
                    <FP SOURCE="FP-2">
                        93. Jasmine Monroe, Thomasville, Georgia, 
                        <PRTPAGE P="658"/>
                        Court of Federal Claims No: 24-1952V
                    </FP>
                    <FP SOURCE="FP-2">94. Charles Gregg, Elkton, Maryland, Court of Federal Claims No: 24-1957V</FP>
                    <FP SOURCE="FP-2">95. Angela Schuh, Duryea, Pennsylvania, Court of Federal Claims No: 24-1959V</FP>
                    <FP SOURCE="FP-2">96. Dominic Yannuzzi, Hazleton, Pennsylvania, Court of Federal Claims No: 24-1960V</FP>
                    <FP SOURCE="FP-2">97. Denise Dicato, Boston, Massachusetts, Court of Federal Claims No: 24-1962V</FP>
                    <FP SOURCE="FP-2">98. Adrien Lozada, Sparta, Illinois, Court of Federal Claims No: 24-1963V</FP>
                    <FP SOURCE="FP-2">99. John Zell, Jr., Charlotte, North Carolina, Court of Federal Claims No: 24-1964V</FP>
                </EXTRACT>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31614 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4165-15-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF HEALTH AND HUMAN SERVICES</AGENCY>
                <DEPDOC>[Document Identifier: OS-0990-0481]</DEPDOC>
                <SUBJECT>Agency Information Collection Request; 60-Day Public Comment Request</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Office of the Secretary, HHS.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>In compliance with the requirement of the Paperwork Reduction Act of 1995, the Office of the Secretary (OS), Department of Health and Human Services, is publishing the following summary of a proposed collection for public comment.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Comments on the ICR must be received on or before March 7, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        Submit your comments to 
                        <E T="03">Sherrette.Funn@hhs.gov</E>
                         or by calling (202) 264-0041 and 
                        <E T="03">PRA@HHS.GOV</E>
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        When submitting comments or requesting information, please include the document identifier 0990-0481-60D and project title for reference, to Sherrette A. Funn, email: 
                        <E T="03">Sherrette.Funn@hhs.gov, PRA@HHS.GOV</E>
                         or call (202) 264-0041 the Reports Clearance Officer.
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>Interested persons are invited to send comments regarding this burden estimate or any other aspect of this collection of information, including any of the following subjects: (1) The necessity and utility of the proposed information collection for the proper performance of the agency's functions; (2) the accuracy of the estimated burden; (3) ways to enhance the quality, utility, and clarity of the information to be collected; and (4) the use of automated collection techniques or other forms of information technology to minimize the information collection burden.</P>
                <P>
                    <E T="03">Title of the Collection:</E>
                     For HHS/OASH Consultation Process, Institutional Review Board (IRB) Records.
                </P>
                <P>
                    <E T="03">Type of Collection:</E>
                     Renewal, 3-year extension without change.
                </P>
                <P>
                    <E T="03">OMB No.:</E>
                     0990-0481
                </P>
                <P>
                    <E T="03">Abstract:</E>
                     The Office of the Assistant Secretary for Health (OASH), Office for Human Research Protections (OHRP) is requesting a 3-year extension without change to the currently approved information collection request, For OASH/HHS Consultation Process, Institutional Review Board (IRB) Records, OMB No. 0990-0481. The purpose of the collection is for OHRP to receive IRB records when an IRB or an institution requests an HHS consultation process for proposed research that is not otherwise approvable by an IRB involving, respectively: (1) pregnant women, human fetuses and neonates; (2) prisoners; or, (3) children, as subjects. The information that must be submitted to OHRP by an IRB or institution includes the research protocol, consent form, parental permission and child assent forms (if relevant), and other relevant IRB records (
                    <E T="03">e.g.,</E>
                     IRB minutes). The Office of the Assistant Secretary for Health, on behalf of the Secretary of HHS, may determine that such research can be conducted or supported by HHS after consulting with experts and meeting other procedural requirements.
                </P>
                <P>
                    <E T="03">Likely Respondents:</E>
                     IRBs.
                </P>
                <GPOTABLE COLS="06" OPTS="L2,i1" CDEF="s40,xs54,12,12,12,12">
                    <TTITLE>Annualized Burden Hour Table</TTITLE>
                    <BOXHD>
                        <CHED H="1">45 CFR part 46—HHS consultation process provision</CHED>
                        <CHED H="1">Respondent type</CHED>
                        <CHED H="1">
                            Number of 
                            <LI>respondents</LI>
                        </CHED>
                        <CHED H="1">
                            Number of 
                            <LI>respondents</LI>
                        </CHED>
                        <CHED H="1">
                            Average 
                            <LI>burden per </LI>
                            <LI>response </LI>
                            <LI>(in hours)</LI>
                        </CHED>
                        <CHED H="1">
                            Total 
                            <LI>burden </LI>
                            <LI>hours</LI>
                        </CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">subpart B, § 46. 207</ENT>
                        <ENT>IRBs</ENT>
                        <ENT>3</ENT>
                        <ENT>1</ENT>
                        <ENT>1</ENT>
                        <ENT>3</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">subpart C, § 46.306 (iii) and (iv)</ENT>
                        <ENT>IRBs</ENT>
                        <ENT>3</ENT>
                        <ENT>1</ENT>
                        <ENT>1</ENT>
                        <ENT>3</ENT>
                    </ROW>
                    <ROW RUL="n,n,s">
                        <ENT I="01">subpart D, § 46.407</ENT>
                        <ENT>IRBs</ENT>
                        <ENT>4</ENT>
                        <ENT>1</ENT>
                        <ENT>1</ENT>
                        <ENT>4</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">Total</ENT>
                        <ENT/>
                        <ENT/>
                        <ENT/>
                        <ENT/>
                        <ENT>10</ENT>
                    </ROW>
                </GPOTABLE>
                <SIG>
                    <NAME>Vivianna P. Cowl,</NAME>
                    <TITLE>Paperwork Reduction Act Reports Clearance Officer, Health and Human Services, Office of the Secretary.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31615 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4150-31-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF HOMELAND SECURITY</AGENCY>
                <SUBAGY>U.S. Customs and Border Protection</SUBAGY>
                <SUBJECT>Implementation of the Commonwealth of the Northern Mariana Islands (CNMI) Economic Vitality &amp; Security Travel Authorization Program (EVS-TAP)</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>U.S. Customs and Border Protection, DHS.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>General notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        This document announces the implementation of the Commonwealth of the Northern Mariana Islands (CNMI) Economic Vitality &amp; Security Travel Authorization Program (EVS-TAP). The CNMI EVS-TAP is a restricted sub-program of the Guam-CNMI Visa Waiver Program and allows prescreened nationals of the People's Republic of China to travel to the CNMI without a visa under specified conditions. In accordance with Department of Homeland Security regulations, DHS will begin implementation of the CNMI EVS-TAP requirements 45 days after publication of this notification of implementation in the 
                        <E T="04">Federal Register</E>
                        .
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Implementation of the CNMI EVS-TAP requirements will begin as of February 20, 2024.</P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Neyda Yejo, Office of Field Operations, U.S. Customs and Border Protection, (202) 344-2373, or via email at 
                        <E T="03">Neyda.I.Yejo@cbp.dhs.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">Background</HD>
                <P>
                    On January 18, 2024, the Department of Homeland Security (DHS), through U.S. Customs and Border Protection (CBP), published an interim final rule (IFR) in the 
                    <E T="04">Federal Register</E>
                     (89 FR 3299) with an effective date of September 30, 2024. The IFR, promulgated in consultation with the Secretary of the Interior and the 
                    <PRTPAGE P="659"/>
                    Secretary of State, amended DHS regulations to establish an electronic travel authorization process for individuals traveling to Guam or the Commonwealth of the Northern Mariana Islands (CNMI) under the Guam-CNMI Visa Waiver Program (G-CNMI VWP). 
                    <E T="03">See</E>
                     § 212.1(q)(9) of title 8 of the Code of Federal Regulations (8 CFR 212.1(q)(9)). The IFR also amended DHS regulations to establish the CNMI Economic Vitality &amp; Security Travel Authorization Program (EVS-TAP) that also includes an electronic travel authorization process for certain nationals of the People's Republic of China (PRC) traveling to the CNMI only. 
                    <E T="03">See</E>
                     8 CFR 212.1(r). As detailed in the IFR, to fully integrate the two automated systems in an efficient and cost-effective manner, DHS would implement the CNMI EVS-TAP after the system for G-CNMI VWP automation became fully operational. 89 FR at 3303, 3310. The IFR explained that when DHS was ready to fully implement CNMI EVS-TAP, DHS would provide notification in the 
                    <E T="04">Federal Register</E>
                    , and the CNMI EVS-TAP would be implemented 45 days after publication as set forth in 8 CFR 212.1(r)(11). 
                    <E T="03">Id.</E>
                </P>
                <HD SOURCE="HD1">Implementation of CNMI EVS-TAP</HD>
                <P>
                    Although the IFR was effective on September 30, 2024, DHS incorporated a 60-day transition period to facilitate travelers adjusting to the new collection method. 
                    <E T="03">See</E>
                     8 CFR 212.1(q)(9)(i). This 60-day transition period ended on November 29, 2024, and the system for G-CNMI VWP automation is fully operational. Accordingly, carriers must now deny boarding to travelers without a visa or without an approved electronic travel authorization. 
                    <E T="03">See</E>
                     8 CFR 212.1(q)(5)(iv).
                </P>
                <P>
                    DHS is now ready to implement CNMI EVS-TAP. Pursuant to 8 CFR 212.1(r)(11), this document provides notification that CBP is implementing the requirements of CNMI EVS-TAP set forth in 8 CFR 212.1(r) for certain PRC nationals as of February 20, 2024. At that time, eligible nationals from the PRC seeking to travel to the CNMI only for a period not to exceed 14 days without a visa under the CNMI EVS-TAP will be required to obtain an electronic travel authorization from CBP prior to embarking on such travel. 
                    <E T="03">See</E>
                     8 CFR 212.1(r). Concurrently, the current parole policy for PRC nationals seeking to enter the CNMI will be discontinued on February 20, 2024.
                </P>
                <SIG>
                    <NAME>Alejandro N. Mayorkas,</NAME>
                    <TITLE>Secretary of Homeland Security.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31326 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 9111-14-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF HOMELAND SECURITY</AGENCY>
                <SUBAGY>Federal Emergency Management Agency</SUBAGY>
                <DEPDOC>[Docket ID: FEMA-2024-0010]</DEPDOC>
                <SUBJECT>Public Assistance Program and Policy Guide, FP 104-009-2</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Federal Emergency Management Agency, Department of Homeland Security.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of availability.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Federal Emergency Management Agency (FEMA) is announcing availability of the final version of the Public Assistance Program and Policy Guide Version 5.0.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>The policy will apply to incidents declared on or after January 6, 2025.</P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Robert Pesapane, Director, Public Assistance Division, Federal Emergency Management Agency, 
                        <E T="03">fema-recovery-pa-policy@fema.dhs.gov,</E>
                         (202) 646-3834.
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>This document announces the availability of Version 5.0 of the Public Assistance Program and Policy Guide (PAPPG). The PAPPG provides a comprehensive and streamlined guide for evaluating eligibility under the Public Assistance (PA) Program. It consolidates relevant policies into a single document, while also referencing external FEMA policies and resources to support stakeholders involved in the implementation of each step in the recovery process. The release of Version 5.0 reflects FEMA's continued commitment to improving access to the PA Program, reducing the documentation burden on our customers, and promoting timely recovery efforts. By integrating cost-effective hazard mitigation measures, Version 5.0 also helps facilitate resilient rebuilding in communities affected by disasters.</P>
                <P>
                    Version 5.0 is available in docket ID FEMA-2024-0010. For access to the docket go to 
                    <E T="03">https://www.regulations.gov</E>
                     and search for the docket ID. It is also available on FEMA's internet site, located at 
                    <E T="03">https://www.fema.gov/assistance/public.</E>
                </P>
                <P>
                    <E T="03">Authority:</E>
                     The Robert T. Stafford Disaster Relief and Emergency Assistance Act, as amended (Stafford Act), 42 U.S.C. 5121 
                    <E T="03">et seq.;</E>
                     44 CFR part 206.
                </P>
                <SIG>
                    <NAME>Deanne Criswell,</NAME>
                    <TITLE>Administrator, Federal Emergency Management Agency.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-30084 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 9111-23-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF THE INTERIOR</AGENCY>
                <DEPDOC>[Docket No. FWS-HQ-IA-2024-0033; FXIA16710900000-245-FF09A10000]</DEPDOC>
                <SUBJECT>Conference of the Parties to the Convention on International Trade in Endangered Species of Wild Fauna and Flora (CITES); Twentieth Regular Meeting: Taxa Being Considered for Amendments to the CITES Appendices and Proposed Resolutions, Decisions, and Agenda Items Being Considered; Observer Information</SUBJECT>
                <HD SOURCE="HD2">Correction</HD>
                <P>In Notice document 2024-30698, appearing on pages 105074 through 105089, in the issue of Thursday, December 26, 2024, make the following correction:</P>
                <P>
                    On page 105075, in the first column, in the 
                    <E T="02">DATES</E>
                     section, the text “January 16, 2025” should read “January 27, 2025”.
                </P>
            </PREAMB>
            <FRDOC>[FR Doc. C1-2024-30698 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 0099-10-D</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF THE INTERIOR</AGENCY>
                <SUBAGY>Fish and Wildlife Service</SUBAGY>
                <DEPDOC>[Docket No. FWS-R7-NWRS-2023-0072; FF07R00000-245-FXRS12610700000]</DEPDOC>
                <SUBJECT>Notice of Availability; Draft Supplemental Environmental Impact Statement for a Potential Land Exchange Involving Izembek National Wildlife Refuge Lands; Extension of Public Comment Period</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Fish and Wildlife Service, Interior.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of availability; extension of public comment period.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>We, the U.S. Fish and Wildlife Service (FWS), announce that we are extending the public comment period for a draft supplemental environmental impact statement (draft supplemental EIS) to consider the effects of a potential land exchange of certain lands owned by the King Cove Corporation with certain lands owned by the U.S. Government and located within the Izembek National Wildlife Refuge and Izembek Wilderness Area. If a land exchange is approved, King Cove Corporation would use the acquired land for a road corridor for noncommercial use. We invite comment on the draft supplemental EIS from the public and local, State, Tribal, and Federal agencies. Comments previously submitted need not be resubmitted, as they will be fully considered.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Submitting Comments:</E>
                         The comment period for the draft 
                        <PRTPAGE P="660"/>
                        supplemental EIS, notice of which published on November 15, 2024 (89 FR 90306), is extended. We must receive your written comments on or before February 13, 2025. Comments submitted online at 
                        <E T="03">https://www.regulations.gov/</E>
                         must be received by 11:59 p.m. eastern time on February 13, 2025.
                    </P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P/>
                    <P>
                        <E T="03">Obtaining Documents:</E>
                         The draft supplemental EIS, as well as any comments and other materials that we receive, will be available for public inspection online in Docket No. FWS-R7-NWRS-2023-0072 at 
                        <E T="03">https://www.regulations.gov</E>
                        . In addition, to inform public comment, we are also making FWS's 2013 EIS and record of decision (ROD) documents available for review at 
                        <E T="03">https://www.regulations.gov</E>
                         in Docket No. FWS-R7-NWRS-2023-0072. However, we are not taking public comments on those documents at this time.
                    </P>
                    <P>
                        <E T="03">Submitting Public Comments:</E>
                         You may submit comments by any of the following methods:
                    </P>
                    <P>
                        • 
                        <E T="03">Online: https://www.regulations.gov</E>
                        . Follow the instructions for submitting comments on Docket No. FWS-R7-NWRS-2023-0072.
                    </P>
                    <P>
                        • 
                        <E T="03">U.S. mail:</E>
                         Public Comments Processing, Attn: Docket No. FWS-R7-NWRS-2023-0072; U.S. Fish and Wildlife Service, MS: PRB/3W; 5275 Leesburg Pike; Falls Church, VA 22041-3803.
                    </P>
                    <P>
                        We will post all written comments on 
                        <E T="03">https://www.regulations.gov</E>
                        . This generally means that we will post any personal information you provide us (see Public Review Process for more information).
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Bobbie Jo Skibo, Project Leader, by telephone at 907-441-1539; by email at 
                        <E T="03">bobbiejo_skibo@fws.gov</E>
                        ; or by U.S. mail at U.S. Fish and Wildlife Service, Alaska Region, National Wildlife Refuge System, 1011 East Tudor Road, Anchorage, AK 99503. Contact Bobbie Jo Skibo to have your name added to our mailing list. Individuals in the United States who are deaf, deafblind, hard of hearing, or have a speech disability may dial 711 (TTY, TDD, or TeleBraille) to access telecommunications relay services. Individuals outside the United States should use the relay services offered within their country to make international calls to the point-of-contact in the United States.
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">Introduction</HD>
                <P>
                    On November 15, 2024 (89 FR 90306), we, the U.S. Fish and Wildlife Service (FWS), announced via the 
                    <E T="04">Federal Register</E>
                     the availability of a draft supplemental environmental impact statement (draft supplemental EIS) to consider the effects of a potential land exchange of certain lands owned by the King Cove Corporation with certain lands that are owned by the U.S. Government and located within the Izembek National Wildlife Refuge and Izembek Wilderness Area. We are now extending the public comment period on the draft supplemental EIS. We are taking this action in accordance with the National Environmental Policy Act of 1969, as amended (NEPA; 42 U.S.C. 4321 
                    <E T="03">et seq.</E>
                    ), and the Alaska National Interest Lands Conservation Act of 1980, as amended (ANILCA; Pub. L. 96-487, sec. 1302(h), Dec. 2, 1980; 16 U.S.C. 3192(h)), along with other laws as applicable. If a land exchange is approved, King Cove would use the acquired land for a road corridor for noncommercial health, safety, and subsistence uses. The draft supplemental EIS updates information used in FWS's 2013 analysis on the impacts of a then-proposed land exchange and proposed road corridor and the viability of alternatives to provide safe and reliable transportation between the City of King Cove, Alaska, and the airport at Cold Bay, Alaska, and also includes a new land exchange and road corridor alternative. We invite comments on the draft supplemental EIS from the public and local, State, Tribal, and Federal agencies. Comments previously submitted need not be resubmitted, as they will be fully considered.
                </P>
                <HD SOURCE="HD1">Potentially Affected Land Areas</HD>
                <P>The Izembek National Wildlife Refuge (417,533 acres (ac)) and the North Creek (8,452 ac) and Pavlof (1,447,264 ac) units of the Alaska Peninsula National Wildlife Refuge are located at the westernmost tip of the Alaska Peninsula. To the north of the Izembek Refuge is the Bering Sea; to the south is the Pacific Ocean. The Izembek Wilderness covers much of the Izembek National Wildlife Refuge and includes pristine streams, extensive wetlands, steep mountains, tundra, and sand dunes, and provides high scenic, wildlife, and scientific values, as well as opportunities for solitude and recreation. The Izembek National Wildlife Refuge includes the traditional homelands of the Unanga people.</P>
                <P>
                    The King Cove Corporation is an Alaska Native Village Corporation established under the Alaska Native Claims Settlement Act of 1971 (ANCSA; 43 U.S.C. 1601 
                    <E T="03">et seq.</E>
                    ). Under the authority of ANCSA, Congress granted to King Cove Corporation land entitlements within and adjacent to Izembek Refuge.
                </P>
                <HD SOURCE="HD1">Previous Actions</HD>
                <P>In the Omnibus Public Land Management Act of 2009 (Pub. L. 111-11, title VI, subtitle E (herein referred to as the 2009 Act)), Congress directed FWS to prepare an EIS under NEPA and its implementing regulations (40 CFR parts 1500 through 1508) to evaluate the impacts of a proposed land exchange with the State of Alaska and the King Cove Corporation for the purpose of constructing a single-lane gravel road between the communities of King Cove and Cold Bay, Alaska. The 2009 Act required that the road “shall be used primarily for health and safety purposes (including access to and from the Cold Bay Airport) and only for noncommercial purposes,” with limited exceptions. The land exchange contemplated by the 2009 Act would have involved the conveyance of approximately 206 ac within the Izembek Wilderness portion of Izembek National Wildlife Refuge for the road corridor and approximately 1,600 ac of Federal land within the Alaska Maritime National Wildlife Refuge on Sitkinak Island. In exchange, FWS would have received approximately 43,093 ac of land owned by the State of Alaska and approximately 13,300 ac of land owned by the King Cove Corporation. These lands are located around Cold Bay and are adjacent to the North Creek Unit of the Alaska Peninsula National Wildlife Refuge.</P>
                <P>In accordance with section 6402(b)(2)(B) of the 2009 Act, an EIS completed in 2013 (2013 EIS; February 6, 2013, 78 FR 8577) analyzed the proposed land exchange and the potential construction and operation of a road between the communities of King Cove and Cold Bay, Alaska, and, among other alternatives, evaluated a specific road corridor through the Izembek Refuge that was identified in consultation with the State of Alaska, the City of King Cove, and the Agdaagux Tribe of King Cove. In accordance with the 2009 Act, subsequent to the preparation of the 2013 EIS and in conjunction with the 2013 record of decision (2013 ROD; February 20, 2014, 79 FR 9759), Secretary of the Interior Sally Jewell decided not to enter a land exchange after determining that the proposed land exchange (including the construction of the proposed road) was not in the public interest.</P>
                <P>
                    On July 3, 2019, Secretary of the Interior David Bernhardt signed a memorandum titled “Findings and Conclusions Concerning a Proposed 
                    <PRTPAGE P="661"/>
                    Land Exchange Between the Secretary of the Interior and King Cove Corporation for Lands Within Izembek National Wildlife Refuge, Alaska” (2019 Secretarial Memorandum). That memorandum laid the foundation for the concurrent approval of a land exchange agreement (2019 Exchange Agreement) between the Department of the Interior (Department) and King Cove Corporation. The 2019 Secretarial Memorandum stated that the purpose of the 2019 Exchange Agreement was to allow a road across the Izembek National Wildlife Refuge to improve access by the residents of King Cove to the airport at Cold Bay. Since the authorities under the 2009 Act had expired, the 2019 Exchange Agreement relied on the general exchange authority found at in section 1302(h) of ANILCA. However, the 2019 Exchange Agreement relied in large part on the record developed for the exchange analyzed under the 2013 EIS and rejected by Secretary Jewell in the 2013 ROD.
                </P>
                <P>On June 1, 2020, the District Court for the District of Alaska vacated the 2019 Exchange Agreement based on several legal defects in the decision. On appeal to the Ninth Circuit Court of Appeals, a three-judge appellate panel reversed the district court. However, an en banc panel of the Ninth Circuit then vacated the three-judge panel's decision and agreed to a new review. On March 14, 2023, Secretary of the Interior Deb Haaland issued a new decision memorandum withdrawing the Department from the 2019 Exchange Agreement. That decision memorandum identified as a procedural flaw the failure to consider the effects of the exchange on subsistence uses, and highlighted shortcomings in the record regarding NEPA and ESA analyses. In addition, the Secretary expressed significant policy concerns regarding the nonpublic manner in which the 2019 Exchange Agreement was accomplished, as well as the terms of the Exchange Agreement, which differed from the exchange evaluated in the 2013 EIS. In June 2023, the Ninth Circuit dismissed the lawsuit because the issue had become moot due to Secretary Haaland's decision memorandum.</P>
                <HD SOURCE="HD1">Notice of Intent</HD>
                <P>
                    On May 18, 2023 (88 FR 31813), we published a 
                    <E T="04">Federal Register</E>
                     notice of intent to prepare a supplemental EIS to consider the effects of a potential land exchange. In that notice, we requested information and suggestions on the proposed supplemental EIS. In particular, we sought information to assist us in updating information we used in our 2013 analysis on the impacts of the then-proposed exchange and road corridor and the viability of alternatives to provide safe and reliable transportation between the City of King Cove, Alaska, and the airport at Cold Bay, Alaska. Comments we received are at 
                    <E T="03">https://www.regulations.gov</E>
                     in Docket No. FWS-R7-NWRS-2023-0072. The final scoping report, which summarizes comments, is attached as an appendix to the draft SEIS.
                </P>
                <HD SOURCE="HD1">Current Action</HD>
                <P>
                    While the authorities in the 2009 Act remain expired, the FWS has prepared a draft supplemental EIS to address a potential exchange under section 1302(h) of ANILCA. The FWS's draft supplemental EIS analysis assesses the potential impacts of a land exchange and road construction and use, allows for public participation, and integrates the NEPA analysis with an evaluation under ANILCA section 810. The FWS is also using and coordinating the NEPA process to help inform the Department's processes and analysis under section 106 of the National Historic Preservation Act (54 U.S.C. 306108), the ESA, ANILCA (including any land exchange's furtherance of the statute's conservation and subsistence purposes), ANCSA, the National Wildlife Refuge System Improvement Act of 1997 (16 U.S.C. 668dd), and the Wilderness Act of 1964 (16 U.S.C. 1131 
                    <E T="03">et seq.</E>
                    ). Alternatives reviewed include the 2013 EIS alternatives and an additional new alternative for the terms of the proposed land exchange involving the same road corridor in the 2019 Exchange Agreement but involving different terms.
                </P>
                <HD SOURCE="HD1">Public Review Process</HD>
                <HD SOURCE="HD2">Request for Public Comments</HD>
                <P>
                    You may submit written comments and materials concerning the draft supplemental EIS by one of the methods listed in 
                    <E T="02">ADDRESSES</E>
                    . Comments previously submitted need not be resubmitted, as they will be fully considered.
                </P>
                <HD SOURCE="HD2">Public Availability of Comments</HD>
                <P>
                    If you submit a comment via 
                    <E T="03">https://www.regulations.gov,</E>
                     your entire comment, including any personal identifying information such as your address, phone number, and email address, will be posted on the website. If you submit a hardcopy comment that includes personal identifying information, you may request at the top of your document that we withhold this information from public review. However, we cannot guarantee that we will be able to do so. We will post all hardcopy comments on 
                    <E T="03">https://www.regulations.gov</E>
                    .
                </P>
                <HD SOURCE="HD1">Tribal Consultation and Comment</HD>
                <P>The meaningful input of Alaska Native Tribes and Alaska Native Corporations is of critical importance to the supplemental EIS. Therefore, and as expressed in Executive Order 13175, “Consultation and Coordination with Indian Tribal Governments,” the Federal officials that have been delegated authority by the Secretary are committed to honoring the unique government-to-government political relationship that exists between the Federal Government and federally recognized Tribes. Consultation with Alaska Native Corporations is based on Pub. L. 108-199, div. H, sec. 161, January 23, 2004, 118 Stat. 452, as amended by Pub. L. 108-447, div. H, title V, sec. 518, December 8, 2004, 118 Stat. 3267, which provides that: “The Director of the Office of Management and Budget and all Federal agencies shall hereafter consult with Alaska Native corporations on the same basis as Indian Tribes under Executive Order No. 13175.” FWS will hold individual consultation meetings upon request. The Secretary of the Interior will consider Alaska Native Tribes' and Alaska Native Corporations' information, input, and recommendations, and address their concerns as much as practicable.</P>
                <SIG>
                    <NAME>Shannon Estenoz,</NAME>
                    <TITLE>Assistant Secretary for Fish and Wildlife and Parks.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31657 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4333-15-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF THE INTERIOR</AGENCY>
                <SUBAGY>Bureau of Indian Affairs</SUBAGY>
                <DEPDOC>[256A2100DD/AAKC001030/A0A501010.999900]</DEPDOC>
                <SUBJECT>Receipt of Documented Petition for Federal Acknowledgment as an American Indian Tribe</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Bureau of Indian Affairs, Interior.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Department of the Interior (Department) gives notice that the group known as the Mattaponi Indian Tribe and Reservation has filed a documented petition for Federal acknowledgment as an American Indian Tribe with the Assistant Secretary—Indian Affairs. The Department seeks comment and evidence from the public on the petition.</P>
                </SUM>
                <DATES>
                    <PRTPAGE P="662"/>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Comments and evidence must be postmarked by May 6, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        Copies of the narrative portion of the documented petition, as submitted by the petitioner (with any redactions appropriate under 25 CFR 83.21(b)), and other information are available at the Office of Federal Acknowledgement's (OFA) website: 
                        <E T="03">www.bia.gov/as-ia/ofa.</E>
                         Submit any comments or evidence to: Department of the Interior, Office of the Assistant Secretary—Indian Affairs, Attention: Office of Federal Acknowledgment, Mail Stop 4071 MIB, 1849 C Street NW, Washington, DC 20240, or by email to: 
                        <E T="03">Ofa_Info@bia.gov.</E>
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Ms. Nikki Bass, OFA Director, Office of the Assistant Secretary—Indian Affairs, Department of the Interior, by phone: (202) 513-7650; or by email: 
                        <E T="03">Ofa_Info@bia.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>On July 31, 2015, the Department's revisions to 25 CFR part 83 became final and effective (80 FR 37861). A key goal of the revisions was to improve transparency through increased notice of petitions and providing improved public access to petitions. Today the Department informs the public that a complete documented petition has been submitted under the current regulations, that portions of that petition are publicly available on the website identified above for easy access, and that we are seeking public comment early in the process on this petition.</P>
                <P>Under 25 CFR 83.22(b)(1), the OFA publishes notice that the following group has filed a documented petition for Federal acknowledgment as an American Indian Tribe to the Assistant Secretary—Indian Affairs: Mattaponi Indian Tribe and Reservation. The contact information for the petitioner is Mr. Mark T. Falling Start Custalow, 1314 Mattaponi Reservation Circle, West Point, Virginia 23181.</P>
                <P>Also, under 25 CFR 83.22(b)(1), OFA publishes on its website the following:</P>
                <P>i. The narrative portion of the documented petition, as submitted by the petitioner (with any redactions appropriate under 25 CFR 83.21(b));</P>
                <P>ii. The name, location, and mailing address of the petitioner and other information to identify the entity;</P>
                <P>iii. The date of receipt;</P>
                <P>iv. The opportunity for individuals and entities to submit comments and evidence supporting or opposing the petitioner's request for acknowledgment within 120 days of the date of the website posting; and</P>
                <P>v. The opportunity for individuals and entities to request to be kept informed of general actions regarding a specific petitioner.</P>
                <HD SOURCE="HD1">Authority</HD>
                <P>The Department publishes this notice and request for comment in the exercise of authority delegated by the Secretary of the Interior to the Assistant Secretary—Indian Affairs by Department Manual part 209, chapter 8.</P>
                <SIG>
                    <NAME>Bryan Newland,</NAME>
                    <TITLE>Assistant Secretary—Indian Affairs.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31647 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4337-15-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF THE INTERIOR</AGENCY>
                <SUBAGY>Bureau of Land Management</SUBAGY>
                <DEPDOC>[PO #4820000251]</DEPDOC>
                <SUBJECT>New Recreation Fee Areas and Requirement To Obtain an Individual Special Recreation Permit for On-River Camping Within the Upper Colorado River Special Recreation Management Areas, Colorado</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Bureau of Land Management, Interior.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of new fees.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>Pursuant to the Federal Lands Recreation Enhancement Act (FLREA), the Bureau of Land Management (BLM), Kremmling Field Office (KFO) and the Colorado River Valley Field Office (CRVFO) are establishing new Special Areas and new recreation fee areas (campgrounds, designated campsites, and day use fees) within the two Upper Colorado River (UCR) Special Recreation Management Areas (SRMAs) managed by the field offices.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        New fees will take effect on July 7, 2025, unless the BLM publishes a 
                        <E T="04">Federal Register</E>
                         notice to the contrary.
                    </P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        Documents concerning this fee change may be reviewed at the Kremmling Field Office, 2103 East Park Ave., Kremmling, CO 80459; at the Colorado River Valley Field Office, 2300 River Frontage Road, Silt, CO 81652; and online at: 
                        <E T="03">https://www.blm.gov/sites/default/files/docs/2024-10/Business%20Plan%20for%20the%20UCR.pdf.</E>
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Stephen Leonard, Field Manager, Kremmling Field Office at Kremmling Field Office, phone: (970) 724-3000, email: 
                        <E T="03">sleonard@blm.gov;</E>
                         or Hilary Boyd, Assistant Field Manager, Colorado River Valley Field Office; phone: (970) 876-9003, email: 
                        <E T="03">hboyd@blm.gov.</E>
                         Individuals in the United States who are deaf, deafblind, hard of hearing, or have a speech disability may dial 711 (TTY, TDD, or TeleBraille) to access telecommunications relay services. Individuals outside the United States should use the relay services offered within their country to make international calls to the point-of-contact in the United States.
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>Consistent with FLREA, the intent of recreation fees is to help protect natural resources, provide for public health and safety, and facilitate access to public lands and related waters, not to maximize fee revenue. Fees are a way of ensuring that those who actively use recreation opportunities make a greater, but reasonable, contribution toward protecting and enhancing those opportunities than those who do not utilize recreational opportunities.</P>
                <P>
                    FLREA directs the Secretary of the Interior to publish a 6-month advance notice in the 
                    <E T="04">Federal Register</E>
                     whenever new recreation fee areas are established. In accordance with BLM policy, the Business Plan for the UCR SRMAs explains the fee collection process and how fees will be used at these sites.
                </P>
                <P>KFO will charge Standard Amenity fees of $10 per day per vehicle, $5 per day for individuals (motorcycle, bicycle, or walk-in), and $20 per day per high-capacity vehicle (carrying capacity greater than 15 passengers), and will offer a $50 day-use season pass (valid for all day-use sites) at Confluence Recreation Area, Gore Canyon Ranch Access, Inspiration Flats Recreation Area, Radium Warm Springs Recreation Area, and State Bridge Recreation Area/Piney Peak Access.</P>
                <P>CRVFO will implement new Standard Amenity fees of $10 per day per vehicle, $5 per day for individuals (motorcycle, bicycle, or walk-in), and $20 per day per high-capacity vehicle (carrying capacity greater than 15 passengers), and will offer a $50 day-use season pass (valid for all day-use sites) at Two Bridges River Access, Catamount Recreation Site, Pinball Recreation Site, Cottonwood Island Recreation Site, Lyon's Gulch Recreation Site, and Dotsero Landing River Access.</P>
                <P>
                    KFO and CRVFO will implement an Expanded Amenity recreation fee of $25 for Single Campsites (up to 10 visitors, with the first two vehicles included in the campsite fee; additional vehicles will pay a day-use fee), and $75 for Group Campsites (up to 30 visitors, with the first two vehicles included in the campsite fee; additional vehicles will pay a day-use fee) at the following campground sites: Pumphouse Recreation Area Campground, Radium Recreation Area Campground, Radium Warm Springs Campground, Catamount 
                    <PRTPAGE P="663"/>
                    Campground, Pinball Campground, and Lyon's Gulch Campground.
                </P>
                <P>
                    The Upper Colorado River SRMA Season Pass will apply to day-use sites in both field offices and will be adjusted from $20 per season to $50 per season. This 
                    <E T="04">Federal Register</E>
                     notice also provides the required notification that a Special Area and associated Individual Special Recreation Permit (ISRP) fee structure are established for the KFO UCR SRMA and the CRVFO UCR SRMA for on-river camping. KFO is establishing a Special Area for KFO's UCR SRMA based on the 2019 Upper Colorado River Recreation Area Management Plan. CRVFO has completed an environmental assessment to establish a Special Area for CRVFO's UCR SRMA. An ISRP fee (float-in only) of $5 per participant/night will apply to 25 designated campsites in the KFO's UCR SRMA. An ISRP fee (float-in only) of $5 per participant/night will apply to the 11 on-river designated campsites in the CRVFO's UCR SRMA. The campsites subject to the ISRP fee are identified in the Business Plan.
                </P>
                <P>Under 16 U.S.C. 6802(g)(2)(A) and (C) of FLREA, developed campgrounds and rental cabins qualify as sites wherein visitors can be charged an “Expanded Amenity Recreation Fee.” Pursuant to FLREA and implementing regulations at 43 CFR subpart 2933, fees may be charged for overnight camping, rental of cabins, and group use reservations where specific amenities and services are provided. The required amenities are provided, or will be provided prior to fee implementation, at all the campgrounds identified in this notice as subject to an Expanded Amenity Recreation Fee. Specific visitor fees will be identified and posted at each campground or rental cabin.</P>
                <P>Under 16 U.S.C. 6802(f)(4) of FLREA, all day-use sites in this notice qualify as areas wherein visitors can be charged a “Standard Amenity Recreation Fee”. Pursuant to FLREA and implementing regulations at 43 CFR part 2930 subpart 2933, fees may be charged for an area where there are significant opportunities for outdoor recreation and where fees can be efficiently collected, and that has substantial Federal investments and contains specific amenities and services. Specific visitor fees will be identified and posted at each day-use site.</P>
                <P>In response to increasing recreation demands and visitation on the BLM lands, the KFO and CRVFO developed a combined recreation fee business plan to achieve consistency across the UCR SRMA administrative boundaries. Standard Amenity, Expanded Amenity, and Special Area ISRP fees are needed to maintain visitor facilities and visitor services, replace aging infrastructure, and improve access to recreational opportunities. The business plan explains: (1) consistency with the BLM recreation fee program policy; (2) the KFO and CRVFO recreation management direction for the UCR SRMAs; (3) the need for fee collection; (4) how the fees will be used in the area; (5) Resource Advisory Council (RAC) coordination; and (6) guidance on future fee increases. As analyzed in the business plan, the recreation use fees are consistent with other nearby Federal land management agency fees and are lower than the fees charged at privately owned campgrounds.</P>
                <P>The BLM posted public notices of the proposed fees at each recreation site during the 2023 use season. The KFO and CRVFO will contact local governments and local special recreation permit holders who may be affected. Following FLREA guidelines, the BLM Northwest RAC recommended the proposed fee structure for approval on June 22, 2023. The RAC voted to recommend the proposed business plan, giving the BLM the discretion to raise the fees without returning to the RAC for approval within the following ranges: $10 to $15 for a normal vehicle; $5 to $10 for a bike, motorcycle, or walk-in; and $20 to $30 for a high-capacity vehicle, based on the 2023 consumer price index (CPI). Fees will initially be implemented at the lower proposed fee schedule. The CPI will be utilized in future years to increase fees as needed, with CPI escalation allowed for any inflationary adjustment above 2023 dollars.</P>
                <P>A public comment period on the draft business plan, announced by news release, ran from October 7, 2024, through November 6, 2024. The Colorado State Director approved the final business plan on December 20, 2024.</P>
                <EXTRACT>
                    <FP>(Authority: 16 U.S.C. 6803(b) and 43 CFR 2933.22)</FP>
                </EXTRACT>
                <SIG>
                    <NAME>Douglas J. Vilsack,</NAME>
                    <TITLE>Colorado State Director. </TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31749 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4331-16-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF THE INTERIOR</AGENCY>
                <SUBAGY>Bureau of Ocean Energy Management</SUBAGY>
                <DEPDOC>[Docket No. BOEM-2024-0061]</DEPDOC>
                <SUBJECT>Commercial Leasing for Wind Power Development on the Guam Outer Continental Shelf—Call for Information and Nominations</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Bureau of Ocean Energy Management, Interior.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Call for information and nominations; request for comments.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        This call for information and nominations (Call or notice) invites public comment on, and assesses interest in, possible commercial wind energy leasing on the Outer Continental Shelf (OCS) offshore Guam as part of planning for commercial leasing in the region. The Bureau of Ocean Energy Management (BOEM) will consider information received in response to this Call to determine whether to schedule a competitive lease sale or to issue a noncompetitive lease for any portion of the area described in this Call (Call Area). Those interested in providing comments or information regarding site conditions, resources, and multiple uses in close proximity to or within the Call Area should provide the information requested in section 8, “Requested Information from Interested or Affected Parties,” under the 
                        <E T="02">SUPPLEMENTARY INFORMATION</E>
                         heading of this Call.
                    </P>
                    <P>Those interested in leasing within the Call Area for a commercial wind energy project should provide the information described in section 9, “Required Nomination Information.” BOEM may or may not offer a lease for a commercial offshore wind energy project within the Call Area after further consultations, public participation, and environmental analyses.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>BOEM must receive your interest in or comments on commercial leasing within the Call Area no later than April 7, 2025. BOEM may not consider late submissions.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        Please submit nomination information for commercial leasing as discussed in section 9, entitled, “Required Nomination Information,” electronically via email to 
                        <E T="03">renewableenergypocs@boem.gov</E>
                         or by hard copy by mail to the following address: Bureau of Ocean Energy Management, Pacific Region, Office of Strategic Resources, 760 Paseo Camarillo (CM 102), Camarillo, California 93010. If you elect to mail a hard copy, also include an electronic copy on a portable storage device. Do not submit nominations via the Federal 
                        <PRTPAGE P="664"/>
                        eRulemaking Portal. BOEM will list the qualified parties that submitted nominations and the aggregated locations of nominated areas on its website after review of the nominations.
                    </P>
                    <P>Please submit all other comments and information by either of the following two methods:</P>
                    <P>
                        1. 
                        <E T="03">Federal eRulemaking Portal: http://www.regulations.gov.</E>
                         In the search box at the top of the web page, enter BOEM-2024-0061 and then click “search.” Follow the instructions to submit public comments and to view supporting and related materials.
                    </P>
                    <P>
                        2. 
                        <E T="03">By mail to the following address:</E>
                         Bureau of Ocean Energy Management, Pacific Region, Office of Strategic Resources, 760 Paseo Camarillo (CM 102), Camarillo, California 93010.
                    </P>
                    <P>
                        Treatment of confidential information is addressed in section 10 of this notice entitled, “Protection of Privileged, Personal, or Confidential Information.” BOEM will post all comments received on 
                        <E T="03">regulations.gov</E>
                         unless labeled as confidential.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Deanna Meier, Renewable Energy Specialist, BOEM, Pacific Region, Office of Strategic Resources, 760 Paseo Camarillo (CM 102), Camarillo, California 93010, (805) 384-6265 or 
                        <E T="03">deanna.meier@boem.gov.</E>
                    </P>
                    <P>
                        For information regarding qualification requirements to hold an OCS wind energy lease, contact Lakeisha Douglas, BOEM, Pacific Region, Office of Strategic Resources, at 
                        <E T="03">lakeisha.douglas@boem.gov</E>
                         or (805) 384-6394.
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">1. Authority</HD>
                <P>This Call is published under subsection 8(p)(3) of the Outer Continental Shelf Lands Act (OCSLA), 43 U.S.C. 1337(p)(3), and its implementing regulations at 30 CFR 585.210 and 585.211.</P>
                <HD SOURCE="HD1">2. Purpose</HD>
                <P>The OCSLA requires BOEM to award leases competitively unless BOEM determines that there is no competitive interest (43 U.S.C. 1337(p)(3)). The primary purpose of this Call is to collect further information and feedback on industry interest, site conditions, resources, and ocean uses within, and surrounding, the Call Area.</P>
                <P>An essential part of BOEM's renewable energy leasing process for Guam is working closely with Federal agencies, Indigenous Peoples, State and local governments, industry, and ocean users to identify areas that may be suitable for potential offshore wind development to provide electric power to Guam communities. BOEM has not yet determined which areas, if any, within the Call Area may be offered for lease. Your input is essential and will help BOEM determine areas that may be suitable for offshore wind energy development. There will also be multiple opportunities to provide feedback throughout the renewable energy planning and leasing process. A detailed description of the Call Area may be found below in section 6, “Description of Call Area.” For more information about BOEM's competitive and noncompetitive leasing processes, please see section 4, “BOEM's Planning and Leasing Process.”</P>
                <HD SOURCE="HD1">3. Background</HD>
                <P>The Energy Policy Act of 2005 amended OCSLA by adding subsection 8(p)(1)(C), which authorizes the Secretary of the Interior (Secretary) to grant leases, easements, and rights-of-way on the OCS for activities that are not otherwise authorized by law and that produce or support production, transportation, or transmission of energy from sources other than oil or gas, including renewable energy sources. Furthermore, under section 3(3) of OCSLA (43 U.S.C. 1332(3)), BOEM considers leasing the OCS for offshore wind development because “the Outer Continental Shelf is a vital national resource reserve held by the Federal Government for the public, which should be made available for expeditious and orderly development, subject to environmental safeguards, in a manner which is consistent with the maintenance of competition and other national needs.”</P>
                <P>
                    The Secretary delegated these OCSLA authorities to the BOEM Director. On April 29, 2009, the Department of the Interior (Department) published regulations entitled, “Renewable Energy and Alternate Uses of Existing Facilities on the Outer Continental Shelf,” 
                    <SU>1</SU>
                    <FTREF/>
                     which were subsequently re-codified at 30 CFR part 585.
                    <SU>2</SU>
                    <FTREF/>
                     On May 15, 2024, the Department amended its offshore renewable energy regulations through the publication of the final Renewable Energy Modernization Rule.
                    <SU>3</SU>
                    <FTREF/>
                     This final rule reduced regulatory burdens and streamlined processes and incorporated recommendations from stakeholders. The Renewable Energy Modernization Rule became effective on July 15, 2024.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         74 FR 19638 (April 29, 2009).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         76 FR 64432 (October 18, 2011).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         89 FR 42602 (May 15, 2024).
                    </P>
                </FTNT>
                <P>Section 50251(b) of the Inflation Reduction Act of 2022 (IRA) expanded the definition of the OCS under OCSLA to include submerged lands within the exclusive economic zone adjacent to U.S. territories. The IRA directs the Secretary to issue calls for interest in offshore wind leasing off territorial coasts and authorizes wind lease sales in areas deemed feasible and of interest after the Secretary has consulted with the Territorial Governor. BOEM and the Government of Guam have initiated the first planning step in the BOEM renewable energy authorization process by establishing the BOEM Guam Intergovernmental Renewable Energy Task Force (Task Force) at the request of the Honorable Lourdes “Lou” Aflague Leon Guerrero, the Governor of Guam.</P>
                <P>In a subsection entitled, “Offshore Wind for the Territories,” the IRA imposed several deadlines for wind energy leasing offshore the U.S. territories. Specifically, in Section 50251(b)(2), the IRA directs the Secretary to issue an initial Call for Information and Nominations no later than September 30, 2025. This Call meets the relevant requirements and deadline from the IRA.</P>
                <P>
                    On October 4, 2023, the Department amended its offshore renewable energy regulations to conform with the IRA. The regulation entitled, “Conformity with the Inflation Reduction Act for Renewable Energy on the Outer Continental Shelf” 
                    <SU>4</SU>
                    <FTREF/>
                     became effective on December 4, 2023.
                </P>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         88 FR 68460 (October 4, 2023).
                    </P>
                </FTNT>
                <P>
                    Because Guam is a volcanically-formed island in the Pacific Ocean, it has a narrow coastal shelf with steep continental slopes, and thus the ocean deepens quickly from shore. As a result, the Call Area is in water depths too deep for traditional fixed bottom foundation designs, and offshore wind development in these areas will require floating technology and designs. On September 15, 2022, the Biden Administration announced the goal of deploying 15 GW of floating offshore wind power in the U.S. by 2035, building on the existing goal of 30 GW of total offshore wind energy by 2030. BOEM is committed to this ambitious goal by responsibly fostering the growth of offshore wind energy capacity and participating in collaborative, data-based planning to inform decisions involving shared ocean resources and the many users that depend on them. To this end, BOEM's five-year renewable energy leasing schedule includes a potential lease sale for a U.S. Territory in 2028.
                    <SU>5</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         See this Press Release for additional information on the five-year schedule: 
                        <E T="03">https://www.doi.gov/pressreleases/secretary-haaland-announces-new-five-year-offshore-wind-leasing-schedule.</E>
                    </P>
                </FTNT>
                <PRTPAGE P="665"/>
                <P>
                    Notably, upon release of this Call, BOEM intends to continue engagement with the Indigenous Peoples of Guam. Indigenous knowledge about the local environment and concerns of Indigenous Peoples about offshore wind project development constitute crucial information to be considered during the BOEM offshore wind planning and leasing process. BOEM appreciates the importance of coordinating its planning with other OCS users, regulators, and relevant Federal agencies including, but not limited to, the U.S. Fish and Wildlife Service, the National Park Service, the U.S. Army Corps of Engineers, the U.S. Coast Guard, the National Oceanic and Atmospheric Administration (NOAA), the Department of the Interior's Office of Insular Affairs, and the Department of Defense (DoD). BOEM also coordinates with and requests input from the Western Pacific Regional Fishery Management Council and Guam Sea Grant; both of these organizations consider Indigenous fishing practices. In addition, BOEM uses other information sources in its decision-making, such as data and information on the location of marine life and habitat areas, cultural resources, transportation links, fishing areas, and other human uses that must be considered when offshore energy or other infrastructure projects are proposed. In 2024, BOEM received a request from Guam's Governor to convene a regional intergovernmental renewable energy task force and begin the process of investigating offshore wind as an option for Guam. In response, BOEM established the BOEM Guam Intergovernmental Renewable Energy Task Force to facilitate coordination among relevant Federal agencies and Territorial and local governments throughout the leasing and planning process. The first Task Force meeting was held on September 11, 2024. Materials from the Task Force meeting are available on the BOEM website at: 
                    <E T="03">https://www.boem.gov/renewable-energy/state-activities/guam-activities.</E>
                </P>
                <P>
                    The Task Force meeting was followed by a two-day BOEM/National Centers for Coastal Ocean Science (NCCOS) Data Workshop, which was held on September 12 and 13, 2024. Attendees from Federal, Territorial, and local agencies and non-governmental organizations provided data and insight on potential data gaps. Information about the NCCOS process can be found on the NOAA NCCOS website at: 
                    <E T="03">https://coastalscience.noaa.gov/project/marine-biogeographic-assessment-of-u-s-territories/.</E>
                </P>
                <P>Guam's electricity is provided entirely by the Guam Power Authority (GPA), a public utility company overseen by the Consolidated Commission on Utilities and regulated by the Guam Public Utilities Commission. In 2019, Guam Public Law 35-46 amended GPA's renewable energy portfolio standard goal to 100 percent by 2045. GPA included a pathway to 100 percent renewable energy by 2040 in its Clean Energy Master Plan, along with an interim goal of 50 percent renewable energy by 2030. Solar photovoltaic energy and energy storage system projects have paved the way for renewables and contributed toward achievement of GPA's renewable energy goals thus far.</P>
                <HD SOURCE="HD1">4. BOEM's Planning and Leasing Process</HD>
                <HD SOURCE="HD2">a. Determination of Competitive Interest</HD>
                <P>Subsection 8(p)(3) of OCSLA states that “the Secretary shall issue a lease, easement, or right-of-way . . . on a competitive basis unless the Secretary determines after public notice of a proposed lease, easement, or right-of-way that there is no competitive interest.”</P>
                <P>If BOEM determines both that competitive interest exists in acquiring a lease to develop offshore wind energy and that the areas within the Call Area are appropriate to lease, BOEM may hold one or more competitive lease sales for those areas. If BOEM holds a lease sale, all qualified bidders, including bidders that did not submit a nomination in response to this Call, will be able to participate in the lease sale.</P>
                <P>BOEM reserves the right to refrain from offering for lease any areas that are nominated as a result of this Call and to modify nominated areas before offering them for lease.</P>
                <HD SOURCE="HD2">b. Competitive Leasing Process</HD>
                <P>BOEM will follow the steps required by 30 CFR 585.211 through 585.226 if it decides to proceed with the competitive leasing process after analyzing the responses to this Call. Those steps are:</P>
                <P>
                    (1) Area Identification: BOEM will identify areas for consideration for leasing. Those areas will constitute Wind Energy Areas (WEAs) and will be subject to environmental analysis in consultation with appropriate Federal agencies, Indigenous Peoples, Territorial and local governments, and other interested parties. Before finalizing the WEAs, BOEM may publish draft WEAs with a public comment period and a docket on
                    <E T="03"> regulations.gov.</E>
                </P>
                <P>
                    (2) Proposed Sale Notice (PSN): If BOEM decides to proceed with a competitive lease sale within the WEAs, BOEM will publish a PSN in the 
                    <E T="04">Federal Register</E>
                     with a public comment period of 60 days, unless BOEM specifies another time period of not less than 30 days. The PSN will describe the areas that BOEM intends to offer for leasing, the proposed conditions of a lease sale, the proposed auction format of the lease sale, and the lease instrument, including the proposed lease addenda. Additionally, the PSN will describe the criteria and process for evaluating bids in the lease sale.
                </P>
                <P>
                    (3) Final Sale Notice (FSN): After considering the comments on the PSN and completing its environmental analysis and consultations, if BOEM decides to proceed with a competitive lease sale, it will publish an FSN in the 
                    <E T="04">Federal Register</E>
                     at least 30 days before the date of the lease sale. The FSN will provide the final terms and conditions for a lease sale, including the date, time, and location for the sale itself. The FSN will also include a list of the companies that have legally, technically and financially qualified to participate in the lease sale.
                </P>
                <P>
                    (4) Bid Submission and Evaluation: Following the publication of the FSN in the 
                    <E T="04">Federal Register</E>
                    , BOEM will offer the lease area(s) through a competitive sale process using procedures specified in the FSN. BOEM will review the sale, including bids and bid deposits, for technical and legal adequacy. BOEM will ensure that bidders have complied with all applicable regulations. BOEM reserves the right to reject all bids and to withdraw an offer to lease an area, even after bids have been submitted.
                </P>
                <P>(5) Issuance of a Lease: Following identification of the winning bidder on a lease area, BOEM will notify that bidder and provide the lease documents for signature.</P>
                <HD SOURCE="HD1">5. Development of the Call Area</HD>
                <P>
                    BOEM began discussions in 2024 with the Government of Guam and several Federal agencies (
                    <E T="03">i.e.,</E>
                     NOAA and DoD) on the potential for offshore wind leasing on the OCS offshore Guam. The breadth of relevant spatial data representing marine natural resources and ocean uses available in the area surrounding Guam must be further understood. Therefore, BOEM's strategy for the Guam Call Area is to start with an expanded geographic area to allow for broad information collection and geospatial analysis.
                </P>
                <P>
                    BOEM defined the northern boundary of the Call Area as the area halfway between Guam and the nearby island of Rota. BOEM removed only a limited number of areas from the Call Area, including areas in which offshore wind 
                    <PRTPAGE P="666"/>
                    energy development cannot occur as a result of law, jurisdictional, or technical considerations. These include:
                </P>
                <P>• Areas between the shoreline and 3 nautical miles from shore;</P>
                <P>• Areas deeper than 2600 meters.</P>
                <P>
                    The Call Area is the area within which BOEM is seeking to identify one or more locations suitable for offshore wind development. It is not indicative of the area that may ultimately be developed. BOEM recognizes that the Call Area may include areas where future offshore wind energy development could conflict with existing ocean uses (
                    <E T="03">e.g.,</E>
                     fishing, shipping) and sensitive habitats that are important to the conservation and recovery of protected species, including specific areas which BOEM previously received feedback on during the September 2024 Task Force meeting (
                    <E T="03">e.g.,</E>
                     fishing areas to the north of Guam). The intention of defining a large Call Area is to receive feedback across a broad area on specific locations that may or may not be well suited for offshore wind based on a variety of factors. The feedback and information provided can then be incorporated into the offshore wind planning process.
                </P>
                <HD SOURCE="HD1">6. Description of Call Area</HD>
                <P>
                    The Call Area consists of 2,114,344 acres located off the coast of Guam (see Figure 1). The map depicting the Call Area (Figure 1), a spreadsheet listing its specific OCS blocks, and an Esri shapefile are available for download on the BOEM website at: 
                    <E T="03">https://www.boem.gov/renewable-energy/state-activities/guam-activities.</E>
                </P>
                <GPH SPAN="3" DEEP="356">
                    <GID>EN06JA25.005</GID>
                </GPH>
                <HD SOURCE="HD1">7. Guam Next Steps</HD>
                <P>The Call Area identifies broad portions of the OCS offshore Guam for further analysis. That analysis will include consideration of commercial nominations and public comments submitted in response to this Call so that potential use conflicts can be analyzed during the next step in the leasing process: the designation of specific WEAs (Area Identification). BOEM's analysis during Area Identification will evaluate the appropriateness of the Call Area for offshore wind energy development, balanced against potential ocean user conflicts.</P>
                <P>BOEM will consider environmental information, consultations, public comments, and continued coordination with the BOEM Guam Intergovernmental Renewable Energy Task Force, which includes relevant Federal, Territorial, and local governments. If BOEM continues to proceed with the process, BOEM anticipates designating specific WEAs within the Call Area and developing lease terms and conditions to avoid, minimize, or mitigate potential impacts from leasing and site assessment activities. Starting with the Call and continuing through the subsequent stages in BOEM's leasing process, BOEM is committed to working with the following groups:</P>
                <HD SOURCE="HD2">a. Coordination With the Guam Governor's Office</HD>
                <P>
                    BOEM coordinated with staff from the Governor's office to plan the first Task Force meeting and to engage with Territorial and local agencies and Indigenous Peoples. BOEM coordinated 
                    <PRTPAGE P="667"/>
                    with the Governor's office while developing the Call Area and will continue coordination to convene the Task Force to enhance collaboration and address challenges associated with the siting of offshore wind leasing areas.
                </P>
                <HD SOURCE="HD2">b. BOEM/NCCOS Partnership</HD>
                <P>
                    In September 2022, BOEM announced enhancements to its Area Identification process.
                    <SU>6</SU>
                    <FTREF/>
                     One of these enhancements is a partnership with NCCOS to employ a spatial model that analyzes entire marine ecosystems to identify the least conflicted areas for wind energy sites. NCCOS and BOEM are leveraging a team of expert spatial planners, marine and fisheries scientists, project coordinators, environmental policy analysts, and other subject matter experts to develop the Guam Offshore Wind Suitability Model (suitability model).
                </P>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         
                        <E T="03">BOEM Enhances its Processes to Identify Future Offshore Wind Energy Areas.</E>
                         (September 16, 2022). Bureau of Ocean Energy Management. 
                        <E T="03">https://www.boem.gov/newsroom/notes-stakeholders/boem-enhances-its-processes-identify-future-offshore-wind-energy-areas.</E>
                    </P>
                </FTNT>
                <P>BOEM and NCCOS intend to use the suitability modeling methods that were previously applied to offshore wind energy siting efforts in the Gulf of Mexico, Gulf of Maine, Oregon, and Central Atlantic regions during Area Identification. NCCOS's spatial modeling approach provides a tool for identifying areas that are most suitable for offshore wind energy development, particularly when large areas of the OCS offshore a state or territory have potential for such development. Additionally, BOEM intends for this partnership and modeling approach to enhance transparency, improve engagement, and provide a consistent, reproducible methodology for understanding and deconflicting ocean space. As described in Section 3, BOEM and NCCOS held a Data Workshop in September 2024 to begin the process of gathering data and forming collaborations between multiple Federal, Territorial, and local agencies and non-governmental organizations to discuss data in the region.</P>
                <HD SOURCE="HD2">c. Coordination With DoD</HD>
                <P>
                    DoD conducts offshore training and operations within portions of the Call Area. BOEM intends to refine the Call Area during the Area Identification process based on DoD's assessment of compatibility between commercial offshore wind energy development and DoD activities as described in the “Memorandum of Understanding Between the Department of Defense and the Department of the Interior Regarding Renewable Energy Development on the Outer Continental Shelf” signed in October 2024.
                    <SU>7</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>7</SU>
                         BOEM. 2024. Memorandum of Understanding Between the Department of Defense and the Department of the Interior Regarding Renewable Energy Development on the Outer Continental Shelf. Available at: 
                        <E T="03">https://www.boem.gov/sites/default/files/documents/about-boem/regulations-guidance/BOEM%20DOD%20MOU%20-Collaboration%20on%20Offshore%20Wind%20Development.pdf</E>
                        .
                    </P>
                </FTNT>
                <P>BOEM is currently working with DoD and will continue collaborating closely with DoD on Guam's offshore wind energy mission compatibility assessment. That assessment may identify areas incompatible for wind energy leasing, areas potentially incompatible with mitigation measures, and/or areas compatible with wind energy development. Potentially incompatible areas are those that will require site-specific mitigation to ensure that offshore wind energy facilities are compatible with DoD activities. These mitigation measures may include, among others: hold and save harmless agreements; mandatory coordination with DoD on specified activities; restrictions on electromagnetic emissions; and evacuation procedures from the lease area for safety reasons when notified by DoD. BOEM may remove from leasing consideration any OCS blocks identified as incompatible with DoD's activities in the compatibility assessment.</P>
                <HD SOURCE="HD2">d. Coordination With Chamoru Community and Indigenous Peoples</HD>
                <P>Local and Territorial agencies with associations with the Chamoru community are members of or have been invited to be a part of the Task Force. BOEM will continue to engage with members of these agencies and other local groups during the offshore wind planning process, including Area Identification. Some of the concerns identified are potential impacts on Indigenous fishing practices, traditional navigation and paddling, and land use associated with offshore wind projects; additionally, meeting fatigue and capacity issues were also cited as concerns. BOEM will engage further with these groups to identify additional concerns through outreach and ongoing studies in the region. BOEM has started engagement with the Indigenous Peoples of Guam and the Commonwealth of Northern Mariana Islands through the BOEM-funded study entitled, “Maritime Heritage of the U.S. Pacific Islands,” which will continue through 2027.</P>
                <HD SOURCE="HD2">e. Coordination With NOAA National Marine Fisheries Service (NMFS) Pacific Islands Regional Office (PIRO)</HD>
                <P>NMFS has broad responsibility in research and management of the marine environment, including management of sustainable fisheries, and conservation and recovery of protected resources. BOEM and the NMFS Pacific Island Regional Office (PIRO) will collaborate closely throughout the offshore wind planning process by partnering to close information gaps; engage with Indigenous, recreational and commercial fishers; and on data collection and sharing. PIRO will be an important partner in the NCCOS Area Identification process. After the Area Identification process, BOEM plans to conduct an Environmental Assessment under the National Environmental Policy Act (NEPA) prior to leasing. BOEM would also initiate the necessary consultations with NMFS under the Endangered Species Act and the Magnuson-Stevens Fishery Conservation and Management Act (MSA) regarding potential impacts.</P>
                <HD SOURCE="HD2">f. Coordination With Western Pacific Regional Fishery Management Council</HD>
                <P>The Western Pacific Regional Fishery Management Council (Council) is one of eight regional councils established by the MSA. The Council manages fisheries within the Exclusive Economic Zone (EEZ) off Hawai'i, American Samoa, Guam, the Commonwealth of the Northern Mariana Islands, and eight remote islands. BOEM coordinates with the Council by providing status updates on offshore wind planning for Guam and will continue coordination throughout the planning and leasing process. The Council provides crucial feedback on managed fisheries and Indigenous Peoples' fishing in the region.</P>
                <HD SOURCE="HD1">8. Requested Information From Interested or Affected Parties</HD>
                <P>
                    Feedback from interested or affected parties is essential to help BOEM identify areas that may be suitable for potential offshore wind development. Commenters should be as specific and detailed as possible to help BOEM understand and address the comments. Where applicable, spatial information should be submitted in a format compatible with Esri ArcGIS (Esri shapefile or Esri file geodatabase) in the WGS84 geographic coordinate system. BOEM requests comments regarding the following features, activities, mitigations, or concerns within or around the Call Area.
                    <PRTPAGE P="668"/>
                </P>
                <P>a. Information on geological, geophysical, and biological sea floor conditions (including bottom and shallow hazards and live bottom).</P>
                <P>b. Information on protected species.</P>
                <P>c. Information on other uses of the OCS in or near the Call Area, particularly with regard to vessel navigation. Additional information regarding recreational, commercial and Indigenous fisheries, including, but not limited to, the use of the areas, the fishing gear types used, seasonal use, and recommendations for reducing use conflicts.</P>
                <P>d. Information on potential locations of unexploded ordnance (UXO); other historic dumping or disposal in the marine environment.</P>
                <P>
                    e. Information on current energy use, renewable energy goals and potential interest in offshore wind development on the OCS near islands surrounding Guam (
                    <E T="03">e.g.,</E>
                     Commonwealth of the Northern Mariana Islands).
                </P>
                <P>f. Information on renewable energy cost analyses or wind datasets that may be available. Relatedly, BOEM is providing funding to the National Renewable Energy Laboratory for work to inform the Levelized Cost of Energy for offshore wind off Guam that will include modeled wind speeds in and around the Call Area. BOEM welcomes additional information on these topics.</P>
                <P>g. Information from the offshore wind energy industry on the considerations for offshore energy development in deep waters, including greater than 1,300 meter water depths, and in areas where the seafloor slope is greater than 10 degrees, with respect to mooring configurations and subsea transmission cables. Feedback on other development considerations in deep waters, such as available floating technology, transmission distance, water depth, seafloor conditions, and operations and maintenance feasibility and costs.</P>
                <P>h. Information regarding the identification of historic properties or potential effects to historic properties from leasing, site assessment activities (including the installation of meteorological buoys), or commercial wind energy development in the Call Area. This includes potential offshore archaeological sites, cultural resources, or other historic properties within the areas described in this notice and onshore historic properties that could potentially be affected by renewable energy activities within the Call Area. This information will inform BOEM's review of future undertakings conducted pursuant to Section 106 of the National Historic Preservation Act (NHPA) and the NEPA.</P>
                <P>
                    i. Information relating to visual and scenic resources, including seascape, landscape, and ocean character aesthetics; visually sensitive areas along the coastline that are sensitive to changes in ocean views (
                    <E T="03">e.g.,</E>
                     scenic seaside trails, National Park System units, National Wildlife Refuges, Territorial parks, historic districts, conservation areas, and other special designations with scenic value); suggestions for potential key observation points for evaluating potential visual impacts (
                    <E T="03">i.e.,</E>
                     places that people visit, recreate, work, and live where ocean views contribute to the quality of experience); general or specific public concerns over potential visual impacts by wind energy development; and potential strategies to help minimize or mitigate any visual effects. BOEM welcomes input on the degree of acceptable or unacceptable levels of offshore wind energy visibility as would be seen from the coastline, and thresholds of diminished or increased visibility as influenced by distances between onshore viewers and wind energy facilities.
                </P>
                <P>j. Information regarding the potential for interference with radar systems covering the Call Area, including, but not limited to, the use of surface and airborne radar systems for offshore search and rescue operations and environmental monitoring.</P>
                <P>k. Information regarding locations and activities associated with potential, ongoing and future exploration of offshore sand resources, including nearshore resources and placement areas that may be impacted by a potential future lease area or possible electrical cable transmission routes.</P>
                <P>l. Information on the constraints and advantages of possible electrical cable transmission routes, including onshore landing and interconnection points for cables connecting offshore wind energy facilities to the onshore electrical grid, and information regarding future demand for electricity in the region.</P>
                <P>m. Information regarding the size and number of WEAs, taking into consideration the offshore wind energy goals of Guam. BOEM requests further information on what additional factors it should consider in determining the size and number of WEAs.</P>
                <P>n. Information related to Indigenous Peoples in the region and interactions with potential offshore wind energy facilities, such as potential impacts to CHamoru cultural practices; lands; resources; ancestral lands; sacred sites, including sites that are submerged; and access to traditional areas of cultural or religious importance on federally managed lands and waters. BOEM will protect confidential information shared by Indigenous Peoples in response to this Call to the extent authorized by Federal law. Treatment of confidential information is addressed in section 10 of this notice entitled, “Protection of Privileged, Personal, or Confidential Information.”</P>
                <P>o. Socioeconomic information for communities potentially affected by wind energy leasing in the Call Area, including community profiles, vulnerability and resiliency data, and information on environmental justice communities. BOEM also solicits comments on how best to meaningfully engage with these communities.</P>
                <P>p. Information on coastal or onshore activities needed to support offshore wind energy development, such as port and transmission infrastructure, and associated potential impacts to recreation, scenic, cultural, historical, and natural resources relating to those activities.</P>
                <P>q. Any other relevant information that you think BOEM should consider during its planning and decision-making process for the purpose of identifying areas to lease within the Call Area.</P>
                <HD SOURCE="HD1">9. Required Nomination Information</HD>
                <P>BOEM previously received information that its former practice of publishing the areas nominated by each qualified company in response to a Call may disincentivize entities from submitting nominations. Nominations and the accompanying rationale are extremely useful to help BOEM understand and model the commercial viability of portions of the OCS. Therefore, BOEM will not publish individual maps of each qualified company's nominations received in response to this Call. BOEM will publish a heatmap that shows an aggregated view of all the nominations and a list of the qualified companies that submitted nominations. Where applicable, qualified companies should submit spatial information in a format compatible with Esri ArcGIS (Esri shapefile or Esri file geodatabase) in the WGS84 geographic coordinate system.</P>
                <P>If you wish to nominate one or more areas for a commercial wind energy lease within the Call Area, you must provide the following information for each nomination:</P>
                <P>
                    (a) The BOEM protraction name, number, and the specific whole or partial OCS blocks within the Call Area that you are interested in leasing. If your nomination includes one or more partial blocks, please describe those partial blocks in terms of sixteenths (
                    <E T="03">i.e.,</E>
                     sub-block) of an OCS block. Each area you 
                    <PRTPAGE P="669"/>
                    nominate should be sized appropriately to accommodate the development of a reasonable wind energy facility for the region (
                    <E T="03">e.g.,</E>
                     a facility with the generation capacity of up to 350 megawatts) plus a buffer (generation capacity of up to 500 megawatts). Nominations that considerably exceed the acreage needed to support a generation capacity of up to 500 megawatts, such as a nomination for the entire Call Area, may be deemed unreasonable and not accepted by BOEM.
                </P>
                <P>(b) A rationale describing why you selected the nominated areas. The more detailed the rationale provided, the more informative it will be to BOEM's process. BOEM is particularly interested in how factors like wind speed, water depth, seafloor slope, bottom type, and interconnection points factor into the nomination process.</P>
                <P>(c) A description of your objectives and the facilities that you would use to achieve those objectives.</P>
                <P>(d) A preliminary schedule of proposed activities, including those leading to commercial operations.</P>
                <P>(e) Available and pertinent data and information concerning renewable energy resources and environmental conditions in each area that you wish to lease, including energy and resource data, and other information used to evaluate the area.</P>
                <P>
                    (f) Documentation demonstrating that you are legally, technically, and financially qualified to hold an OCS wind energy lease, as set forth in 30 CFR 585.107—585.108. Qualification materials should be developed in accordance with the guidelines available at 
                    <E T="03">https://www.boem.gov/Renewable-Energy-Qualification-Guidelines.</E>
                     For examples of documentation appropriate for demonstrating your legal qualifications and related guidance, contact Lakeisha Douglas, BOEM, Pacific Region, Office of Strategic Resources, at 
                    <E T="03">lakeisha.douglas@boem.gov</E>
                     or (805) 384-6394.
                </P>
                <HD SOURCE="HD1">10. Protection of Privileged, Personal, or Confidential Information</HD>
                <HD SOURCE="HD2">a. Freedom of Information Act</HD>
                <P>BOEM will protect privileged or confidential information that you submit when required by the Freedom of Information Act (FOIA). Exemption 4 of FOIA applies to trade secrets and commercial or financial information that is privileged or confidential. If you wish to protect the confidentiality of such information, clearly label it and request that BOEM treat it as confidential. BOEM will not disclose such information if BOEM determines under 30 CFR 585.114(b) that it qualifies for exemption from disclosure under FOIA. Please label privileged or confidential information “Contains Confidential Information” and consider submitting such information as a separate attachment.</P>
                <P>BOEM will not treat as confidential any aggregate summaries of such information or comments not containing such privileged or confidential information. Information that is not labeled as privileged or confidential may be regarded by BOEM as suitable for public release.</P>
                <HD SOURCE="HD2">b. Personally Identifiable Information</HD>
                <P>
                    BOEM encourages you not to submit anonymous comments. Please include your name and address as part of your comment. You should be aware that your entire comment, including your name, address, and any personally identifiable information (PII) included in your comment, may be made publicly available. All submissions from identified individuals, businesses, and organizations will be available for public viewing on 
                    <E T="03">regulations.gov</E>
                    . Note that BOEM will make available for public inspection all comments, in their entirety, submitted by organizations and businesses, or by individuals identifying themselves as representatives of organizations or businesses.
                </P>
                <P>For BOEM to consider withholding your PII from disclosure, you must identify any information contained in your comments that, if released, would constitute a clearly unwarranted invasion of your personal privacy. You must also briefly describe any possible harmful consequences of the disclosure of information, such as embarrassment, injury, or other harm. Even if BOEM withholds your information in the context of this Call, your submission is subject to FOIA and, if your submission is requested under FOIA, your information will be withheld only if a determination is made that one of FOIA's exemptions to disclosure applies. Such a determination will be made in accordance with the Department's FOIA regulations and applicable law.</P>
                <HD SOURCE="HD2">c. Section 304 of the NHPA (54 U.S.C. 307103(a))</HD>
                <P>After consultation with the Secretary, BOEM is required to withhold the location, character, or ownership of historic resources if it determines that disclosure may, among other things, risk harm to the historic resources or impede the use of a traditional religious site by practitioners. Indigenous Peoples, communities, and organizations should designate information that falls under Section 304 of the NHPA as confidential.</P>
                <HD SOURCE="HD1">11. BOEM's Environmental Review Process</HD>
                <P>Before deciding whether leases may be issued, BOEM will prepare an Environmental Assessment (EA) under NEPA (including public comment periods to determine the scope of the EA and to review and comment on the draft EA). The EA will analyze anticipated impacts from leasing within the WEAs and site characterization and assessment activities expected to occur after a lease is issued. Site characterization activities include geophysical, geotechnical, archaeological, and biological surveys, and site assessment activities, including the installation and operation of meteorological buoys. BOEM will also conduct appropriate consultations with Federal agencies, Territorial agencies, and local governments during preparation of the EA. These consultations include, but are not limited to, those required by the Coastal Zone Management Act, the Magnuson-Stevens Fishery Conservation and Management Act, the Endangered Species Act, and Section 106 of the NHPA.</P>
                <P>Before BOEM allows any construction of a wind energy project in the Call Area, BOEM must approve a construction and operations plan (COP) submitted by a Lessee. Prior to the approval of a COP, BOEM will need to consider the potential environmental effects of the construction and operation of any wind energy facility under a separate, project-specific NEPA analysis. This analysis will include additional opportunities for public involvement and may result in the publication of an environmental impact statement.</P>
                <SIG>
                    <NAME>Elizabeth Klein,</NAME>
                    <TITLE>Director, Bureau of Ocean Energy Management.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31231 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4340-98-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <PRTPAGE P="670"/>
                <AGENCY TYPE="N">INTERNATIONAL TRADE COMMISSION</AGENCY>
                <DEPDOC>[Investigation No. 337-TA-1380]</DEPDOC>
                <SUBJECT>Certain Video Capable Electronic Devices, Including Computers, Streaming Devices, Televisions, and Components Thereof; Notice of Request for Submissions on the Public Interest</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>U.S. International Trade Commission.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>Notice is hereby given that on December 20, 2024, the presiding administrative law judge (“ALJ”) issued an Initial Determination on Violation of Section 337. The ALJ also issued a Recommended Determination on remedy and bonding should a violation be found in the above-captioned investigation. The Commission is soliciting submissions on public interest issues raised by the recommended relief should the Commission find a violation. This notice is soliciting comments from the public and interested government agencies only.</P>
                </SUM>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Robert J. Needham, Esq., Office of the General Counsel, U.S. International Trade Commission, 500 E Street SW, Washington, DC 20436, telephone (202) 708-5468. Copies of non-confidential documents filed in connection with this investigation may be viewed on the Commission's electronic docket (EDIS) at 
                        <E T="03">https://edis.usitc.gov.</E>
                         For help accessing EDIS, please email 
                        <E T="03">EDIS3Help@usitc.gov.</E>
                         General information concerning the Commission may also be obtained by accessing its internet server at 
                        <E T="03">https://www.usitc.gov.</E>
                         Hearing-impaired persons are advised that information on this matter can be obtained by contacting the Commission's TDD terminal on (202) 205-1810.
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>Section 337 of the Tariff Act of 1930 provides that, if the Commission finds a violation, it shall exclude the articles concerned from the United States unless, after considering the effect of such exclusion upon the public health and welfare, competitive conditions in the United States economy, the production of like or directly competitive articles in the United States, and United States consumers, it finds that such articles should not be excluded from entry. (19 U.S.C. 1337(d)(1)). A similar provision applies to cease and desist orders. (19 U.S.C. 1337(f)(1)).</P>
                <P>The Commission is soliciting submissions on public interest issues raised by the recommended relief should the Commission find a violation, specifically: a limited exclusion order directed to certain video capable electronic devices, including computers, streaming devices, televisions, and components and modules thereof imported, sold for importation, and/or sold after importation by respondents Amazon.com, Inc. and Amazon.com Services LLC; and cease and desist orders directed to Amazon.com Inc. and Amazon.com Services LLC. Parties are to file public interest submissions pursuant to 19 CFR 210.50(a)(4).</P>
                <P>The Commission is interested in further development of the record on the public interest in this investigation. Accordingly, members of the public and interested government agencies are invited to file submissions of no more than five (5) pages, inclusive of attachments, concerning the public interest in light of the ALJ's Recommended Determination on Remedy and Bonding issued in this investigation on December 20, 2024. Comments should address whether issuance of the recommended remedial orders in this investigation, should the Commission find a violation, would affect the public health and welfare in the United States, competitive conditions in the United States economy, the production of like or directly competitive articles in the United States, or United States consumers.</P>
                <P>In particular, the Commission is interested in comments that:</P>
                <P>(i) explain how the articles potentially subject to the recommended remedial orders are used in the United States;</P>
                <P>(ii) identify any public health, safety, or welfare concerns in the United States relating to the recommended orders;</P>
                <P>(iii) identify like or directly competitive articles that complainant, its licensees, or third parties make in the United States which could replace the subject articles if they were to be excluded;</P>
                <P>(iv) indicate whether complainant, complainant's licensees, and/or third-party suppliers have the capacity to replace the volume of articles potentially subject to the recommended orders within a commercially reasonable time; and</P>
                <P>(v) explain how the recommended orders would impact consumers in the United States.</P>
                <P>Written submissions must be filed no later than by close of business January 30, 2025.</P>
                <P>
                    Persons filing written submissions must file the original document electronically on or before the deadlines stated above. The Commission's paper filing requirements in 19 CFR 210.4(f) are currently waived. 85 FR 15798 (Mar. 19, 2020). Submissions should refer to the investigation number (“Inv. No. 337-TA-1380”) in a prominent place on the cover page and/or the first page. (
                    <E T="03">See</E>
                     Handbook for Electronic Filing Procedures, 
                    <E T="03">https://www.usitc.gov/secretary/fed_reg_notices/rules/handbook_on_electronic_filing.pdf</E>
                    ). Persons with questions regarding filing should contact the Secretary (202-205-2000).
                </P>
                <P>Any person desiring to submit a document to the Commission in confidence must request confidential treatment by marking each document with a header indicating that the document contains confidential information. This marking will be deemed to satisfy the request procedure set forth in Rules 201.6(b) and 210.5(e)(2) (19 CFR 201.6(b) &amp; 210.5(e)(2)). Documents for which confidential treatment by the Commission is properly sought will be treated accordingly. Any non-party wishing to submit comments containing confidential information must serve those comments on the parties to the investigation pursuant to the applicable Administrative Protective Order. A redacted non-confidential version of the document must also be filed simultaneously with any confidential filing and must be served in accordance with Commission Rule 210.4(f)(7)(ii)(A) (19 CFR 210.4(f)(7)(ii)(A)). All information, including confidential business information and documents for which confidential treatment is properly sought, submitted to the Commission for purposes of this investigation may be disclosed to and used: (i) by the Commission, its employees and Offices, and contract personnel (a) for developing or maintaining the records of this or a related proceeding, or (b) in internal investigations, audits, reviews, and evaluations relating to the programs, personnel, and operations of the Commission including under 5 U.S.C. appendix 3; or (ii) by U.S. Government employees and contract personnel, solely for cybersecurity purposes. All contract personnel will sign appropriate nondisclosure agreements. All nonconfidential written submissions will be available for public inspection on EDIS.</P>
                <P>This action is taken under the authority of section 337 of the Tariff Act of 1930, as amended (19 U.S.C. 1337), and in part 210 of the Commission's Rules of Practice and Procedure (19 CFR part 210).</P>
                <SIG>
                    <P>By order of the Commission.</P>
                    <PRTPAGE P="671"/>
                    <DATED>Issued: December 31, 2024.</DATED>
                    <NAME>Sharon Bellamy,</NAME>
                    <TITLE>Supervisory Hearings and Information Officer.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31726 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7020-02-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF JUSTICE</AGENCY>
                <SUBJECT>Notice of Proposed Settlement Agreement Under the Clean Air Act</SUBJECT>
                <P>
                    On December 31, 2024, the Department of Justice lodged a proposed Consent Decree in the civil action 
                    <E T="03">United States</E>
                     v. 
                    <E T="03">White's Diesel Performance In. [sic] d/b/a White's Diesel Performance Inc. and White's Diesel,</E>
                     Civ. No. 8:24-cv-01791-SDM-SPF (M.D. Fla.). The complaint alleged that those defendants sold or installed illegal devices intended to defeat factory-installed pollution control devices, in violation of the Clean Air Act. The Consent Decree prohibits the defendants from selling or installing such devices in the future and requires the settling defendants to pay a civil penalty of $10,000, based on the defendants' limited financial ability to pay a larger sum.
                </P>
                <P>The publication of this notice opens a period for public comment on the Settlement Agreement. Comments should be addressed to the Assistant Attorney General, Environment and Natural Resources Division, and should refer to Settlement Agreement among the United States and White's Diesel Performance, Inc., D.J. Ref. No. 90-5-2-1-12438. All comments must be submitted no later than thirty (30) days after the publication date of this notice. Comments may be submitted either by email or by mail:</P>
                <GPOTABLE COLS="2" OPTS="L2,nj,tp0,i1" CDEF="xs50,r50">
                    <TTITLE> </TTITLE>
                    <BOXHD>
                        <CHED H="1" O="L">
                            <E T="03">To submit comments:</E>
                        </CHED>
                        <CHED H="1" O="L">
                            <E T="03">Send them to:</E>
                        </CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">By email</ENT>
                        <ENT>
                            <E T="03">pubcomment-ees.enrd@usdoj.gov.</E>
                        </ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">By mail</ENT>
                        <ENT>Assistant Attorney General, U.S. DOJ—ENRD, P.O. Box 7611, Washington, DC 20044-7611.</ENT>
                    </ROW>
                </GPOTABLE>
                <P>Any comments submitted in writing may be filed in whole or in part on the public court docket without notice to the commenter.</P>
                <P>
                    During the public comment period, the Consent Decree may be examined at and downloaded from this Justice Department website: 
                    <E T="03">https://www.justice.gov/enrd/consent-decrees.</E>
                     If you require assistance accessing the Consent Decree you may request assistance by email or by mail to the addresses provided above for submitting comments.
                </P>
                <SIG>
                    <NAME>Scott Bauer,</NAME>
                    <TITLE>Assistant Section Chief, Environmental Enforcement Section, Environment and Natural Resources Division. </TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31760 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4410-15-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF LABOR</AGENCY>
                <SUBAGY>Employee Benefits Security Administration</SUBAGY>
                <SUBJECT>Agency Information Collection Activities; Request for Public Comment</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Employee Benefits Security Administration (EBSA), Department of Labor.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        The Department of Labor (the Department), in accordance with the Paperwork Reduction Act, provides the general public and Federal agencies with an opportunity to comment on proposed and continuing collections of information. This helps the Department assess the impact of its information collection requirements and minimize the public's reporting burden. It also helps the public understand the Department's information collection requirements and provide the requested data in the desired format. The Employee Benefits Security Administration (EBSA) is soliciting comments on the extension of the information collection requests (ICRs) contained in the documents described below. A copy of the ICRs may be obtained by contacting the office listed in the 
                        <E T="02">ADDRESSES</E>
                         section of this notice. ICRs also are available at 
                        <E T="03">reginfo.gov</E>
                         (
                        <E T="03">https://www.reginfo.gov/public/do/PRAMain</E>
                        ).
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        Written comments must be submitted to the office shown in the 
                        <E T="02">ADDRESSES</E>
                         section on or before March 7, 2025.
                    </P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        U.S. Department of Labor, Employee Benefits Security Administration, Office of Research and Analysis, Attention: PRA Officer, 200 Constitution Avenue NW, Room N-5718, Washington, DC 20210, or 
                        <E T="03">ebsa.opr@dol.gov.</E>
                    </P>
                </ADD>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">I. Current Actions</HD>
                <P>This notice requests public comment on the Department's request for extension of the Office of Management and Budget's (OMB) approval of ICRs contained in the rules and prohibited transaction exemptions described below. This action is not related to any pending rulemakings and the Department is not proposing any changes to the existing ICRs at this time. An agency may not conduct or sponsor, and a person is not required to respond to, an information collection unless it displays a valid OMB control number. A summary of the ICRs and the burden estimates follows:</P>
                <P>
                    <E T="03">Agency:</E>
                     Employee Benefits Security Administration, Department of Labor.
                </P>
                <P>
                    <E T="03">Title:</E>
                     Notice of Special Enrollment Rights under Group Health Plans.
                </P>
                <P>
                    <E T="03">Type of Review:</E>
                     Extension of a currently approved collection of information.
                </P>
                <P>
                    <E T="03">OMB Number:</E>
                     1210-0101.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Private sector, Businesses or other for-profits, Not-for-profit institutions.
                </P>
                <P>
                    <E T="03">Respondents:</E>
                     2,007,298.
                </P>
                <P>
                    <E T="03">Responses:</E>
                     8,618,763.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Hours:</E>
                     552.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Cost (Operating and Maintenance):</E>
                     $430,938.
                </P>
                <P>
                    <E T="03">Description:</E>
                </P>
                <P>Section 701(f) of the Employee Retirement Income Security Act (ERISA) provides special enrollment rights to individuals who have previously declined health coverage offered to them to enroll in health coverage upon the occurrence of specified events, including when they lose other coverage, when employer contributions to the cost of other coverage cease, and when they marry, have a child or adopt a child (“special enrollment events”). Plans and issuers are required to provide for 30-day special enrollment periods following any of these events during which individuals who are eligible but not enrolled have a right to enroll without being denied enrollment or having to wait for a late enrollment opportunity (often called “open enrollment”).</P>
                <P>
                    A group health plan may require, as a pre-condition to having a special enrollment right to enroll in group health coverage after losing eligibility under other coverage, that an employee or beneficiary who declines coverage provide the plan a written statement declaring whether he or she is declining coverage because of having other coverage. Failure to provide such a written statement can then be treated as eliminating the individual's right to special enrollment upon losing eligibility for such other coverage. The regulations further establish that the right to special enroll can be denied in such circumstances only if employees are given notice of the requirement for a written statement and the consequences of failing to provide the 
                    <PRTPAGE P="672"/>
                    written statement at the time an employee declines enrollment. As part of the special enrollment notice, it must be given at or before the time the employee is initially offered the opportunity to enroll.
                </P>
                <P>This information collection request covers the requirement in the implementing regulations under section 701(f) for a special enrollment notice. This information collection implements the disclosure obligation of a plan to inform all employees, at or before the time they are initially offered the opportunity to enroll in the plan, of the plan's special enrollment rules. The regulations require plans and their issuers to provide all employees with a notice describing their special enrollment rights, whether or not they enroll.</P>
                <P>The Department has received approval from OMB for this ICR under OMB Control No. 1210-0101. The current approval is scheduled to expire on August 31, 2025.</P>
                <P>
                    <E T="03">Agency:</E>
                     Employee Benefits Security Administration, Department of Labor.
                </P>
                <P>
                    <E T="03">Title:</E>
                     Annual Report for Multiple Employer Welfare Arrangements Form M-1.
                </P>
                <P>
                    <E T="03">Type of Review:</E>
                     Extension of a currently approved collection of information.
                </P>
                <P>
                    <E T="03">OMB Number:</E>
                     1210-0116.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Private sector, Business or other for profits, Not-for-profit institutions.
                </P>
                <P>
                    <E T="03">Respondents:</E>
                     719.
                </P>
                <P>
                    <E T="03">Responses:</E>
                     719.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Hours:</E>
                     1,839.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Cost (Operating and Maintenance):</E>
                     $0.
                </P>
                <P>
                    <E T="03">Description:</E>
                </P>
                <P>The Health Insurance Portability and Accountability Act of 1996 (HIPAA), codified as part 7 of title I of the Employee Retirement Security Act of 1974 (ERISA), was enacted to improve the portability and continuity of health care coverage for participants and beneficiaries of group health plans. HIPAA also added section 101(g) to ERISA, providing the Secretary of Labor (Secretary) with authority to require, by regulation, multiple employer welfare arrangements (MEWAs) as defined in section 3(40) of ERISA, that offer or provide coverage for medical benefits but which are not group health plans (non-plan MEWAs), to report annually for the purpose of determining compliance with part 7 requirements. While the statutory authority was directed at non-plan MEWAs, based on the authority in ERISA sections 101(g), 505, and 734, the Department of Labor (Department) in 2003 promulgated a regulation at 29 CFR 2520.101-2 that required the administrators of both plan MEWAs and non-plan MEWAs that offer or provide coverage for medical benefits, as well certain entities that claim not to be a MEWA solely due to the exception in section 3(40)(A)(i) of ERISA (referred to as “Entities Claiming Exception” or “ECEs”), to file the Form M-1 on an annual basis (Form M-1 annual report).</P>
                <P>The Patient Protection and Affordable Care Act and the Health Care and Education Reconciliation Act of 2010 (these are collectively known as the “Affordable Care Act” or “ACA”) amended section 101(g) of ERISA to require non-plan MEWAs that provide benefits consisting of medical care to register with the Secretary before operating in a State. In 2011, the Department amended the Form M-1 reporting regulations to enact the ACA required provisions by requiring all MEWAs (plan and non-plan MEWAs) that offer or provide coverage for medical benefits and ECEs to register with the Secretary upon occurrence of certain registration events, such as prior to operating in a State, in addition to continued reporting on an annual basis regarding compliance with part 7 of ERISA.</P>
                <P>The Department has received approval from OMB for this ICR under OMB Control No. 1210-0116. The current approval is scheduled to expire on August 31, 2025.</P>
                <P>
                    <E T="03">Agency:</E>
                     Employee Benefits Security Administration, Department of Labor.
                </P>
                <P>
                    <E T="03">Title:</E>
                     Employee Retirement Income Security Act of 1974 Investment Manager Electronic Registration.
                </P>
                <P>
                    <E T="03">Type of Review:</E>
                     Extension of a currently approved collection of information.
                </P>
                <P>
                    <E T="03">OMB Number:</E>
                     1210-0125.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Private sector, Business or other for profits, Not-for-profit institutions.
                </P>
                <P>
                    <E T="03">Respondents:</E>
                     3.
                </P>
                <P>
                    <E T="03">Responses:</E>
                     3.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Hours:</E>
                     3.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Cost (Operating and Maintenance):</E>
                     $230.
                </P>
                <P>
                    <E T="03">Description:</E>
                </P>
                <P>Section 203A(a) of the Investment Advisers Act of 1940 (and the implementing SEC regulations) provides thresholds for when investment advisers must register with the SEC or with one or more states</P>
                <P>To qualify as investment manager under ERISA, investment advisers that register with a state, rather than with the SEC, must satisfy ERISA's section 3(38) requirement to file a copy of the State registration with the Department by electronically registering through the Investment Adviser Registration Depository (IARD). This is a centralized electronic filing system operated by the SEC in conjunction with State securities regulation authorities. Because the IARD was established by the SEC and the states, and made mandatory for advisers required to file with SEC, and because all States permit filing through IARD even for advisers who do not file with SEC, the Department determined that use of the IARD would eliminate the duplication of filing paper copies of State registration forms with the Department and facilitate creation of a uniform and efficient “one-stop” filing system for state-registered filings by advisers who wished to meet the “investment manager” definition of ERISA section 3(38).</P>
                <P>The Department has received approval from OMB for this ICR under OMB Control No. 1210-0125. The current approval is scheduled to expire on August 31, 2025.</P>
                <P>
                    <E T="03">Agency:</E>
                     Employee Benefits Security Administration, Department of Labor.
                </P>
                <P>
                    <E T="03">Title:</E>
                     Multiple Employer Welfare Arrangement Administrative Law Judge Administrative Hearing Procedures.
                </P>
                <P>
                    <E T="03">Type of Review:</E>
                     Extension of a currently approved collection of information.
                </P>
                <P>
                    <E T="03">OMB Number:</E>
                     1210-0148.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Private sector, Business or other for profits, Not-for-profit institutions.
                </P>
                <P>
                    <E T="03">Respondents:</E>
                     10.
                </P>
                <P>
                    <E T="03">Responses:</E>
                     10.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Hours:</E>
                     20.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Cost (Operating and Maintenance):</E>
                     $686,900.
                </P>
                <P>
                    <E T="03">Description:</E>
                </P>
                <P>Section 521 of ERISA, 29 U.S.C. 1151, provides that the Secretary of Labor may issue ex parte cease and desist orders when it appears to the Secretary that the alleged conduct of a multiple employer welfare arrangement (MEWA) under section 3(40) of the Act, 29 U.S.C. 1002(40), is fraudulent, or creates an immediate danger to the public safety or welfare, or is causing or can be reasonably expected to cause significant, imminent, and irreparable public injury. Section 521(b) provides that a person that is adversely affected by the issuance of a cease and desist order may request an administrative hearing regarding the order. The Department has promulgated a final regulation that is the subject of this information collection request, which describes the procedures before an administrative law judge (ALJ) when a person seeks an administrative hearing for review of such an order.</P>
                <P>
                    Under section 2571.3 of the rule, the party that is subject to a cease and desist order issued under ERISA section 521 
                    <PRTPAGE P="673"/>
                    has the burden to initiate an adjudicatory proceeding before an ALJ. Section 2571.3 governs the service of documents necessary to initiate ALJ proceedings by such a party on the Secretary of Labor and the ALJ. The Department has received approval from OMB for this ICR under OMB Control No. 1210-0148. The current approval is scheduled to expire on August 31, 2025.
                </P>
                <P>
                    <E T="03">Agency:</E>
                     Employee Benefits Security Administration, Department of Labor.
                </P>
                <P>
                    <E T="03">Title:</E>
                     Alternative Reporting Methods for Apprenticeship and Training Plans and Top Hat Plans.
                </P>
                <P>
                    <E T="03">Type of Review:</E>
                     Extension of a currently approved collection of information.
                </P>
                <P>
                    <E T="03">OMB Number:</E>
                     1210-0153.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Private sector, Business or other for profits, Not-for-profit institutions.
                </P>
                <P>
                    <E T="03">Respondents:</E>
                     1,800.
                </P>
                <P>
                    <E T="03">Responses:</E>
                     1,800.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Hours:</E>
                     300.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Cost (Operating and Maintenance):</E>
                     $0.
                </P>
                <P>
                    <E T="03">Description:</E>
                </P>
                <P>Section 2520.104-22 provides an exemption to the reporting and provision of part 1 of title I of ERISA for employee welfare benefit plans that provide exclusively apprenticeship and training benefits if the plan administrator meets the following requirements: (1) Files a notice with the Secretary that provides the name of the plan, the plan sponsor's Employer Identification Number, the plan administrator's name, and the name and location of an office or person from whom interested individuals can obtain certain info about courses offered by the plan; and (2) takes steps reasonably designed to ensure that the information required to be contained in the notice is disclosed to employees of employers contribution to the plan who may be eligible to enroll in any course of study sponsored or establish by the plan; (3) and makes the notice available to employees upon request.</P>
                <P>
                    Under 2520.14-23, the Department provides an alternative method of compliance with the reporting and disclosure of Title I of ERISA for unfunded or insured plan established for a select group of management of highly compensated employees (
                    <E T="03">i.e.,</E>
                     top hat plans). In order to satisfy the alternative method of compliance, the plan administrator must file a statement with the Secretary of Labor that includes the name and address of the employer, the employer EIN, a declaration that the employer maintains a plan or plans primarily for the purpose of providing deferred compensation for a select group of management or highly compensated employees, and a statement of the number of such plans and the employees covered by each. Plan documents must be made available to the Secretary upon request, and only one statement needs to be filed for each employer maintaining one or more of the plans. The 2019 final rule requires electronic filing with the Secretary through EBSA's website in accordance with instructions published by the Department.
                </P>
                <P>The Department has received approval from OMB for this ICR under OMB Control No. 1210-0153. The current approval is scheduled to expire on August 31, 2025.</P>
                <P>
                    <E T="03">Agency:</E>
                     Employee Benefits Security Administration, Department of Labor.
                </P>
                <P>
                    <E T="03">Title:</E>
                     Securities Lending by Employee Benefit Plans, Prohibited Transaction Exemption 2006-16.
                </P>
                <P>
                    <E T="03">Type of Review:</E>
                     Extension of a currently approved collection of information.
                </P>
                <P>
                    <E T="03">OMB Number:</E>
                     1210-0065.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Private sector, Business or other for profits.
                </P>
                <P>
                    <E T="03">Respondents:</E>
                     182.
                </P>
                <P>
                    <E T="03">Responses:</E>
                     1,820.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Hours:</E>
                     349.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Cost (Operating and Maintenance):</E>
                     $18,191.
                </P>
                <P>
                    <E T="03">Description:</E>
                </P>
                <P>In 2006, the Department promulgated a final class exemption, PTE 2006-16, which amended and replaced the exemptions previously provided under PTE 81-6 and PTE 82-63. The final exemption incorporates the exemptions into one renumbered exemption and expands the categories of exempted transactions to include securities lending to foreign banks and foreign broker-dealers that are domiciled in specified countries and to allow the use of additional forms of collateral, all subject to specified conditions outlined in the exemption.</P>
                <P>Among other conditions, the class exemption requires a bank or broker-dealer that borrows securities from a plan to provide the lending fiduciary with its most recent audited financial statement and its most recent unaudited statement if the unaudited statement is more recent than the audited financial statement. The borrower must also represent, at the time the loan is negotiated, that there has been no material adverse change in its financial condition since the date of the most recent financial statement provided to the plan that has not been disclosed to the lending fiduciary. The exemption also requires the loan be made pursuant to a written loan agreement. Individual agreements are not required for each transaction; rather the compensation agreement may be made in the form of a master agreement covering a series of transactions.</P>
                <P>The Department has received approval from OMB for this ICR under OMB Control No. 1210-0065. The current approval is scheduled to expire on October 31, 2025.</P>
                <P>
                    <E T="03">Agency:</E>
                     Employee Benefits Security Administration, Department of Labor.
                </P>
                <P>
                    <E T="03">Title:</E>
                     Prohibited Transaction Class Exemption 1988-59, Residential Mortgage Financing Arrangements Involving Employee Benefit Plans.
                </P>
                <P>
                    <E T="03">Type of Review:</E>
                     Extension of a currently approved collection of information.
                </P>
                <P>
                    <E T="03">OMB Number:</E>
                     1210-0095.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Private sector, Business or other for profits, Not-for-profit institutions.
                </P>
                <P>
                    <E T="03">Respondents:</E>
                     2,289.
                </P>
                <P>
                    <E T="03">Responses:</E>
                     11,445.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Hours:</E>
                     7,630.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Cost (Operating and Maintenance):</E>
                     $10,816.
                </P>
                <P>
                    <E T="03">Description:</E>
                </P>
                <P>Prohibited Transaction Class Exemption (PTE) 88-59, which amended and replaced PTE 82-87, allows employee benefit plans to participate in several different types of residential mortgage financing transactions, provided certain conditions are met. The five categories of transactions permitted under the exemption are: (1) issuance of commitments for the provision of mortgage financing to purchasers of residential dwelling units; (2) receipt by a plan of a fee for the issuance of the commitments; (3) the actual making or purchase of a mortgage loan or participation interest therein pursuant to the commitment; (4) the direct making or purchase of an mortgage loan or participation interest therein without the precondition of a commitment; and (5) the sale, exchange or transfer of a mortgage loan or participation interest therein prior to the maturity date of the instrument, provided that the ownership interest sold, exchanged, or transferred represents the plan's entire interest in such investment.</P>
                <P>Among other conditions, the exemption requires a plan to maintain for the duration of any loan made pursuant to this exemption all records necessary to determine whether conditions of the exemption have been met and to make such records available for examination on request by any trustee, investment manager, participant or beneficiary of the plan, or agents of the Department or the IRS.</P>
                <P>
                    The Department has received approval from OMB for this ICR under 
                    <PRTPAGE P="674"/>
                    OMB Control No. 1210-0095. The current approval is scheduled to expire on October 31, 2025.
                </P>
                <P>
                    <E T="03">Agency:</E>
                     Employee Benefits Security Administration, Department of Labor.
                </P>
                <P>
                    <E T="03">Title:</E>
                     Access to Multiemployer Plan Information.
                </P>
                <P>
                    <E T="03">Type of Review:</E>
                     Extension of a currently approved collection of information.
                </P>
                <P>
                    <E T="03">OMB Number:</E>
                     1210-0131.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Private sector, Business or other for profits, Not-for-profit institutions.
                </P>
                <P>
                    <E T="03">Respondents:</E>
                     2,450.
                </P>
                <P>
                    <E T="03">Responses:</E>
                     221,478.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Hours:</E>
                     32,220.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Cost (Operating and Maintenance):</E>
                     $0.
                </P>
                <P>
                    <E T="03">Description:</E>
                </P>
                <P>Section 101(k)(1) of ERISA requires multiemployer plan administrators to furnish certain documents to any plan participant, beneficiary, employee representative, or any employer that has an obligation to contribute to the plan upon written request. The Department issued a final rule that implements the disclosure requirements of ERISA section 101(k) on March 2, 2010 (75 FR 9334). The documents that may be requested are: (1) A copy of any periodic actuarial report (including sensitivity testing) received by the plan for any plan year which has been in the plan's possession for at least 30 days; (2) a copy of any quarterly, semi-annual, or annual financial report prepared for the plan by any plan investment manager or advisor or other fiduciary that has been in the plan's possession for at least 30 days; and (3) a copy of any application filed with the Secretary of the Treasury requesting an extension under section 304 of ERISA (or section 431(d) of the Internal Revenue Code of 1986) and the determination of such Secretary pursuant to such application.</P>
                <P>The information collection provisions of this final regulation are found in 29 CFR 2520.101-6(a), which requires multiemployer defined benefit and defined contribution pension plan administrators to furnish copies of certain actuarial and financial documents to plan participants, beneficiaries, employee representatives, and contributing employers upon request.</P>
                <P>This information constitutes a third-party disclosure from the administrator to participants, beneficiaries, employee representatives, and contributing employers for purposes of the PRA. Pursuant to §  2520.101-6(d)(5), the documents required to be disclosed shall not contain any information that the plan administrator reasonably determines to be either: (i) Individually identifiable information regarding any plan participant, beneficiary, employee, fiduciary, or contributing employer, except that such limitation shall not apply to an investment manager or adviser, or with respect to any other person (other than an employee of the plan) preparing a financial report described in paragraph §  2520.101-6(c)(2); or (ii) proprietary information regarding the plan, any contributing employer, or entity providing services to the plan. The plan administrator must inform the requester if any such information is withheld.</P>
                <P>The Department has received approval from OMB for this ICR under OMB Control No. 1210-0131. The current approval is scheduled to expire on October 31, 2025.</P>
                <P>
                    <E T="03">Agency:</E>
                     Employee Benefits Security Administration, Department of Labor.
                </P>
                <P>
                    <E T="03">Title:</E>
                     National Medical Support Notice—Part B.
                </P>
                <P>
                    <E T="03">Type of Review:</E>
                     Extension of a currently approved collection of information.
                </P>
                <P>
                    <E T="03">OMB Number:</E>
                     1210-0113.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Private sector, Businesses or other for-profits.
                </P>
                <P>
                    <E T="03">Respondents:</E>
                     381,290.
                </P>
                <P>
                    <E T="03">Responses:</E>
                     19,352,287.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Hours:</E>
                     1,215,658.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Cost (Operating and Maintenance):</E>
                     $6,400,769.
                </P>
                <P>
                    <E T="03">Description:</E>
                </P>
                <P>Pursuant to section 401(a) of the CSPIA, the Department of Labor (the Department) and HHS jointly promulgated the National Medical Support Notice Final Rule on December 27, 2000 (65 FR 82128) (NMSN Regulation). The NMSN Regulation simplifies the issuance and processing of medical child support orders; standardizes communication between State agencies, employers, and Plan Administrators; and creates a uniform and streamlined process for enforcement of medical child support to ensure that all eligible children receive the health care coverage to which they are entitled.</P>
                <P>The NMSN Regulation, codified at 29 CFR 2590.609-2, includes a model National Medical Support Notice (NMSN) that is comprised of two parts: part A is a notice from the State agency to the employer, entitled: “Notice to Withhold for Health Care Coverage;” and part B is a notice from the employer to the Plan Administrator, entitled: “Medical Support Notice to Plan Administrator.” Both parts have detailed instructions informing the recipient to whom responses are due depending on varying circumstances. This ICR addresses the Plan Administrator's responsibilities under NMSN Regulation to complete part B of the NMSN, the “Plan Administrator Response,” pursuant to the CSPIA and section 609(a)(5)(C) of title I of ERISA.</P>
                <P>The “Plan Administrator Response” in part B of the NMSN requires the Plan Administrator to provide information verifying whether the child is or will be receiving health care coverage from the group health plan. If enrollment has already occurred or can begin immediately, the Plan Administrator's response in part B serves as notice to the State agency, the participant (parent), the child, their non-participant parent or guardian and the employer that the child is or will begin receiving dependent health care coverage pursuant to the group health plan. When the child is eligible for more than one coverage option, the Administrator must first send the part B response to the State agency so that the agency may choose one option. The Plan Administrator must also use the part B response to notify all of the above-affected persons of any waiting period before enrollment of the child can occur.</P>
                <P>The Department has received approval from OMB for this ICR under OMB Control No. 1210-0113. The current approval is scheduled to expire on November 30, 2025.</P>
                <P>
                    <E T="03">Agency:</E>
                     Employee Benefits Security Administration, Department of Labor.
                </P>
                <P>
                    <E T="03">Title:</E>
                     No Surprises Act: IDR Process.
                </P>
                <P>
                    <E T="03">Type of Review:</E>
                     Extension of a currently approved collection of information.
                </P>
                <P>
                    <E T="03">OMB Number:</E>
                     1210-0169.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Private sector, Business or other for profits, Not-for-profit institutions.
                </P>
                <P>
                    <E T="03">Respondents:</E>
                     22,828.
                </P>
                <P>
                    <E T="03">Responses:</E>
                     163,546.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Hours:</E>
                     89,520.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Cost (Operating and Maintenance):</E>
                     $556,147.
                </P>
                <P>
                    <E T="03">Description:</E>
                </P>
                <P>
                    On December 27, 2020, the Consolidated Appropriations Act, 2021 (CAA), which includes the No Surprises Act, was signed into law. The No Surprises Act provides Federal protections against surprise billing and limits out-of-network cost sharing under many of the circumstances in which surprise bills arise most frequently. The CAA added provisions applicable to group health plans and health insurance issuers in the group and individual markets in a new part D of title XXVII of the Public Health Service Act (PHS Act) and also added new provisions to 
                    <PRTPAGE P="675"/>
                    part 7 of the Employee Retirement Income Security Act (ERISA), and subchapter B of chapter 100 of the Internal Revenue Code (Code).
                </P>
                <P>Section 102 of the No Surprises Act added Code section 9816, ERISA section 716, and PHS Act section 2799A-1, which contain limitations on cost sharing and requirements for initial payments for emergency services and for nonemergency items and services furnished by nonparticipating providers at participating health care facilities. In addition, section 103 of the No Surprises Act amended Code section 9816, ERISA section 716, and PHS Act section 2799A-1 to establish a Federal independent dispute resolution (Federal IDR) process that nonparticipating providers or facilities and group health plans and health insurance issuers in the group and individual market may use following the end of an unsuccessful open negotiation period to determine the out-of-network rate for certain services. More specifically, the Federal IDR provisions may be used to determine the out-of-network rate for certain emergency services, nonemergency items and services furnished by nonparticipating providers at participating health care facilities, where an All-Payer Model Agreement or specified State law does not apply. Finally, section 105 of the No Surprises Act created Code section 9817, ERISA section 717, and PHS Act section 2799A-2 which contain limitations on cost sharing and requirements for initial payments for air ambulance services, and allow plans and issuers and providers of air ambulance services to access the Federal IDR process.</P>
                <P>The Federal IDR process requires a number of disclosures from plans, issuers, FEHB carriers, and nonparticipating providers or nonparticipating emergency facilities. The Department has received approval from OMB for this ICR under OMB Control No. 1210-0169. The current approval is scheduled to expire on November 30, 2025.</P>
                <HD SOURCE="HD1">II. Focus of Comments</HD>
                <P>The Department is particularly interested in comments that:</P>
                <P>• Evaluate whether the collections of information are necessary for the proper performance of the functions of the agency, including whether the information will have practical utility;</P>
                <P>• Evaluate the accuracy of the agency's estimate of the collections of information, including the validity of the methodology and assumptions used;</P>
                <P>• Enhance the quality, utility, and clarity of the information to be collected; and</P>
                <P>
                    • Minimize the burden of the collection of information on those who are to respond, including through the use of appropriate automated, electronic, mechanical, or other technological collection techniques or other forms of information technology, 
                    <E T="03">e.g.,</E>
                     by permitting electronic submissions of responses.
                </P>
                <P>Comments submitted in response to this notice will be summarized and/or included in the ICR for OMB approval of the information collection; they will also become a matter of public record.</P>
                <SIG>
                    <DATED>Signed at Washington, DC, this 26th day of December 2024.</DATED>
                    <NAME>Lisa M. Gomez,</NAME>
                    <TITLE>Assistant Secretary, Employee Benefits Security Administration, U.S. Department of Labor.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31607 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4510-29-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF LABOR</AGENCY>
                <SUBAGY>Employee Benefits Security Administration</SUBAGY>
                <DEPDOC>[Prohibited Transaction Exemption 2024-05; Application No. L-12006]</DEPDOC>
                <SUBJECT>Exemption for Associated General Contractors of America, San Diego Chapter, Inc. Apprenticeship and Training Fund, Located in San Diego, CA</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Employee Benefits Security Administration, Department of Labor.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of exemption.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>This document gives notice of an individual exemption from certain prohibited transaction restrictions of the Employee Retirement Income Security Act of 1974, as amended (ERISA or the Act). The exemption permits the Associated General Contractors of America, San Diego Chapter, Inc. (the Chapter) to lease certain improved real property (the Property) located in San Diego, California to the Associated General Contractors of America, San Diego Chapter, Inc. Apprenticeship and Training Fund (the Plan or the Applicant).</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Exemption date:</E>
                         This final exemption is in effect as of October 1, 2020.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Mr. Frank Gonzalez, Office of Exemption Determinations, Employee Benefits Security Administration, U.S. Department of Labor, (202) 693-8553 (this is not a toll-free number).</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The Plan requested an exemption pursuant to ERISA section 408(a) and supplemented the request with certain additional information (that is collectively, referred to as the “Application”).
                    <SU>1</SU>
                    <FTREF/>
                     On July 22, 2024, the Department published a notice of proposed exemption in the 
                    <E T="04">Federal Register</E>
                     (the Proposed Exemption).
                    <SU>2</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         The procedures for requesting an exemption are set forth in 29 CFR part 2570, subpart B (76 FR 66637, 66644, October 27, 2011). Effective December 31, 1978, section 102 of the Reorganization Plan No. 4 of 1978, 5 U.S.C. app. 1 (1996), transferred the authority of the Secretary of the Treasury to issue administrative exemptions under the Code section 4975(c)(2) to the Secretary of Labor. Accordingly, the Department grants this exemption under its sole authority.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         89 FR 59161.
                    </P>
                </FTNT>
                <P>Based on the Applicant's representations in the Application and the administrative record, the Department has determined to grant the Proposed Exemption. This exemption provides only the relief specified herein and does not provide relief from violations of any law other than the prohibited transaction provisions of ERISA.</P>
                <P>
                    <E T="03">Benefits of the Exemption:</E>
                     The Department is granting retroactive and prospective relief based in part on the Applicant's representations that, among other things, the lease has permitted the Plan to provide benefits more efficiently to its participants during the COVID-19 pandemic and thereafter at a monthly rental rate that saved the Plan $4,359 per month in 2020 and $6,311 per month in 2021, respectively, based on the Property's appraised monthly fair market rental value of $46,938 on October 1, 2020 and $48,890 on October 1, 2021.
                    <SU>3</SU>
                    <FTREF/>
                     The Plan's monthly savings will continue to increase if the appraised rental value increases subject to escalation terms of the lease that are described below. The transaction will be subject to further protection, because an independent fiduciary will be responsible for ensuring that the Plan does not pay more than fair market value rent under the Lease.
                </P>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         This determination is set forth in the Independent Appraiser's written report, dated December 16, 2021.
                    </P>
                </FTNT>
                <P>
                    As discussed below, the Department makes the requisite findings under ERISA section 408(a) based on the Applicant's adherence to all the exemption's conditions at all times. Accordingly, affected parties should be aware that the Applicant's adherence to all conditions incorporated in this exemption is necessary for the Department to grant the relief that the Applicant requested. Absent these conditions, the Department would not have granted this exemption.
                    <PRTPAGE P="676"/>
                </P>
                <HD SOURCE="HD1">Background</HD>
                <P>1. As discussed in the Proposed Exemption, the Plan provides apprenticeship training for construction trade employees within five Southern California counties. The Plan is funded by participating employers (contributing approximately 90% of the Plan's annual funding) and the State of California (contributing approximately 10% of the Plan's annual funding). Apprentices do not contribute to the Plan. The Plan's most recent audited financial statements reflect that the Plan's total assets were $13,681,005 as of March 31, 2024.</P>
                <P>2. The Plan's Board of Trustees (the Board) is comprised of six individual members (the Trustees) of participating construction trade employers. The Trustees make all of the Plan's administrative and investment decisions including decisions about the lease that is the subject of this exemption.</P>
                <HD SOURCE="HD2">The Plan Sponsor: The Chapter</HD>
                <P>3. The Plan is sponsored by the Chapter, which is a trade organization founded in 1927 to promote the interests of employers in the construction industry located in San Diego, California. A Board of Directors comprised of construction trade employers manages the Chapter.</P>
                <HD SOURCE="HD2">The Plan's Facilities Before October 1, 2020</HD>
                <P>4. The Applicant represents that before October 1, 2020, the Plan leased three different properties from unrelated parties comprising 11,293 square feet that it used for administrative, educational, and training purposes. According to the Applicant, the facilities on these properties lacked adequate square footage and had outdated training technology, which resulted in increased costs and wasted resources for the Plan. In addition, one of the properties was located more than three miles from the other two properties.</P>
                <HD SOURCE="HD2">The Chapter's Property</HD>
                <P>5. On January 18, 2018, the Chapter and the Plan entered into a Memorandum of Understanding (MOU) documenting their shared interest in providing a “world class apprenticeship program” in a “modernized facility.” Following execution of the MOU, the Chapter acquired unimproved real property located at 10140 Riverford Road, Lakeside, California (the Parcel) from Lakeside Land Co., a California limited liability corporation (the LLC). The LLC is not a member of the Chapter, there are no common directors between the LLC and the Chapter, and no LLC directors are Plan Trustees. The LLC has neither contributed to nor participated in the Plan, nor does the LLC participate in the Plan's apprenticeship training programs.</P>
                <P>6. In 2020, the Chapter constructed a high-ceiling training space on the Parcel comprising approximately 43,600 square feet (the Building). The Chapter's acquisition of the Parcel, and subsequent construction of the Building, was based on the Plan's intent expressed in the MOU to sign a 10-year lease to use both the Building once constructed and an unimproved exterior lot (the Property).</P>
                <HD SOURCE="HD2">The Lease</HD>
                <P>7. On April 25, 2019, the Plan Trustees acting on behalf of the Plan, caused the Plan to enter into an agreement with the Chapter to lease both a portion of the Building (once constructed) and an unimproved exterior lot located in the Parcel (the Lease), subject to the review and approval of both a qualified independent fiduciary (described below, the Independent Fiduciary) and the Department.</P>
                <P>8. The Lease's term is for 10 years, under which the Plan holds a leasehold interest to occupy and use 90 percent of the Building's rentable space (39,115 square feet of the Building's total space of 43,600 square feet) and an unimproved exterior lot along with rights to use the Property's common areas. The Chapter utilizes the remaining 10 percent of the Building's rentable space and has no present plans to change the Building's space allocation.</P>
                <P>9. The Plan's initial base rent under the Lease is $40,000 per month or approximately $1.02 per square foot (the Base Rent). This expense during a twelve (12) month period is about 3.5 percent of the Plan's total assets as reflected in the Plan's audited financial statements for accounting year ending March 31, 2024. The Base Rent is subject to annual increases that are discussed further below.</P>
                <HD SOURCE="HD2">The Independent Appraiser</HD>
                <P>10. On May 17, 2019, the Plan engaged Cushman &amp; Wakefield Western Inc. as the Independent Appraiser to determine the Property's fair market rental value. Trevor G. Chapman, a California licensed Certified General Real Estate Appraiser, who is an employee of the Independent Appraiser, performed the appraisal.</P>
                <P>11. Mr. Chapman represents that the Independent Appraiser has no present or prospective interest in the Property that is subject to the Lease, and no personal interest with respect to the Plan and the Chapter. In addition, Mr. Chapman represents that the Independent Appraiser's annual gross revenues derived from parties in interest with respect to the Plan represented 0.37% of its gross revenues for the 2020 tax year. Furthermore, the Independent Appraiser's agreement with the Plan does not contain any provisions that provide for the Plan to: (1) directly or indirectly indemnify or reimburse the Independent Appraiser or any other party for any failure to adhere to their contractual obligations or to State or Federal laws applicable to the Independent Appraiser's work; or (2) waive any rights, claims or remedies of the Plan or its participants and beneficiaries under ERISA, the Code, or other Federal and State laws against the Independent Appraiser with respect to the transaction(s) that are the subject of the exemption.</P>
                <P>12. Mr. Chapman inspected the Property on July 1, 2019, to collect primary and secondary data related to the Property, investigate the general trends in the regional economy and local area, analyzed rental data where appropriate, and reviewed (i) the cost estimates based upon submitted architects' plans, and (ii) the proposed Lease using generally accepted market-derived appropriate methods and procedures. In a written report (the Independent Appraisal Report) dated October 23, 2019, Mr. Chapman determined that the Property's fair market rental rate was $44,443 per month, which represented $1.14 per square foot of the Plan's rentable space.</P>
                <P>
                    13. According to the Independent Appraiser, the Lease is a triple net lease, which the Independent Appraiser notes is a type of commercial lease wherein the lessee is responsible for its pro rata share of expenses for common area maintenance, taxes, and insurance.
                    <SU>4</SU>
                    <FTREF/>
                     Notwithstanding the types of commercial leases that may exist in any given marketplace, the Independent Appraiser informed the Department that the Property subject to the Lease is located in a market area in which commercial leases are typically written on a triple-net basis with tenants responsible for all operating expenses, including common area maintenance, taxes, and insurance. Lease terms within the Property's market are generally between 3 and 7 years for industrial 
                    <PRTPAGE P="677"/>
                    tenants and contain annual escalations of 3.0 percent.
                </P>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         Also, in addition to a base rent, tenants subject to triple net leases are often required to reimburse the landlord for certain expenses and recovery provisions for expenses range from absolutely net (whereby the tenant pays all property expenses) to fully gross (in which tenant pays no expenses). These provisions can vary by property type, locale and fall anywhere within the net to gross range.
                    </P>
                </FTNT>
                <HD SOURCE="HD2">The Independent Fiduciary</HD>
                <P>14. On October 27, 2019, the Plan Trustees retained the services of Prudent Fiduciary Services, LLC (PFS) of Los Angeles, California, to serve as the Plan's Independent Fiduciary with respect to the Lease. Specifically, Mr. Miguel Paredes, a principal with PFS, was appointed to undertake the duties and responsibilities on behalf of PFS in its role as the Plan's Independent Fiduciary to ensure that the Lease arrangement complied with ERISA.</P>
                <P>
                    15. The Independent Fiduciary represents that neither Mr. Paredes nor PFS had a pre-existing relationship with the Plan or the Chapter. The Independent Fiduciary also represents that for year 2019 Mr. Paredes and PFS expect to derive approximately 0.55 percent of their combined annual gross revenues from the Plan and parties in interest with respect to the Plan.
                    <SU>5</SU>
                    <FTREF/>
                     The Independent Fiduciary's agreement with the Plan did not contain any provisions that violate ERISA section 410 or the Department's Regulations codified at § 2509.75-4; 
                    <SU>6</SU>
                    <FTREF/>
                     and did not contain any provision requiring the Plan or any other party to (1) directly or indirectly indemnify or reimburse the Independent Fiduciary for any failure to adhere to its contractual obligations or to State or Federal laws applicable the Independent Fiduciary`s work, or (2) waive any rights, claims, or remedies under ERISA, State, or Federal law against the Independent Fiduciary with respect to the transaction(s) that are the subject of the exemption.
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         Furthermore, the Department notes that section II(c)(1) of the exemption requires that the Independent Fiduciary must not be directly or indirectly controlled by or through one or more intermediaries, or under common control with either the Chapter, the Plan, or any related employers' members.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         ERISA section 410 provides, in part, that “except as provided in ERISA Sections 405(b)(1) and 405(d), any provision in an agreement or instrument which purports to relieve a fiduciary from responsibility or liability for any responsibility, obligation, or duty under this part [meaning part 4 of title I of ERISA] shall be void as against public policy.”
                    </P>
                </FTNT>
                <P>
                    16. The Independent Fiduciary examined whether the Lease would be reasonable, prudent, and in the interest and protective of the Plan and its participants and beneficiaries. To perform this examination, the Independent Fiduciary: (a) reviewed various documents, such as the Independent Appraisal Report, trust agreements, IRS Forms 990, financial statements, written policies, guidelines, and procedures, lease agreements, applicable laws and guidance, and the Plan Trustees' meeting minutes; (b) interviewed and/or held discussions with representatives of the Plan; (c) conducted an in-person site visit to the Property; and (e) considered the Plan Trustees' decision-making process with respect to entering into the Lease.
                    <SU>7</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>7</SU>
                         The Independent Fiduciary represents that the Trustees appeared to have undertaken a reasonable and thorough process before making this decision. The Independent Fiduciary represents that the Trustees had explored other alternatives and real estate properties in the area. Specifically, starting in year 2015, the Trustees began searching for new facilities. The Trustees evaluated 12 real properties, comprised of six existing buildings, three parcels of open land for building, two properties for operating engineer usage, and the additional annex near the then current facility.
                    </P>
                </FTNT>
                <P>17. In a report dated October 28, 2019 (the Independent Fiduciary Report), the Independent Fiduciary noted that the Property allows for onsite heavy equipment operator training, which was not an option in the Plan's former location due to space constraints. The new location also represents an upgrade in size and quality compared to the current property, which should translate into better training programs. The Independent Fiduciary stated that having the classrooms and apprenticeship/training offices in the same location as the Chapter offices potentially improves the operation and efficiency of the training programs because the Chapter's oversight and resources are nearby. The Independent Fiduciary also noted that the Plan and Chapter share an interest in providing high quality apprenticeship and continuing training education programs because the Plan would be better able to provide benefits to its participants and beneficiaries and the Chapter would be able to use the training programs to promote its membership.</P>
                <P>18. The Independent Fiduciary reviewed the Independent Appraiser's specific qualifications, including his education, prior experience, and professional licenses, memberships, and affiliations. Based upon its review, the Independent Fiduciary determined that the Independent Appraiser possessed the appropriate training, experience, and facilities to provide a qualified appraisal report on behalf of the Trust Fund regarding the subject property.</P>
                <P>19. The Independent Fiduciary next examined the Independent Appraiser's independence. The Independent Fiduciary represents that it did not find any relationship between Chapman or Cushman, or any affiliates, to the parties that would be engaging in the transaction contemplated by the Lease Agreement. The Independent Fiduciary's review also did not reveal any other information that would call into question the Independent Appraiser's independence.</P>
                <P>20. The Independent Fiduciary next determined whether the payments from the Plan to the Chapter under the Lease would be reasonable. To perform this task, the Independent Fiduciary reviewed the methodology provided by the Independent Appraiser to calculate the fair market rent, which included comparing comparable rental properties, having discussions with local brokers, and testing the Independent Appraiser's conclusions through a return on cost analysis. The Independent Fiduciary adjusted the Lease's base rent of $1.02 per square foot upwards by $0.07 per square foot to account for the Plan's additional $2,579 monthly payments to a Capital Replacement Reserve Fund (the Reserve Fund), which is described in more detail below, and determined that even with the adjusted rate, the Lease's adjusted monthly rent of $1.09 per square foot is less than its appraised fair market value of $1.14 per square foot. Additionally, the Independent Fiduciary noted that leases in the Property's subject market are typically written on a triple net basis, which is consistent with the structure of the Lease. The Independent Fiduciary stated that it also reviewed the properties and key lease information used in the Independent Appraisal Report analysis of rental activity for comparable space in similar properties in the Property's subject market and found that the selected comparable properties were appropriate and reasonably similar. The Independent Fiduciary noted how other lease terms, such as rent escalation clauses, duration, and tenant improvement allowances contained in the comparable leases that the Independent Appraiser identified compared to those in the Lease. For the reasons set forth above, the Independent Fiduciary determined that the arrangements provided under the Lease are necessary for the operation of the Plan and that the compensation to be paid by the Plan to the Chapter is reasonable. It also determined that entering into the Lease was reasonable, prudent, and in the Plan's interest.</P>
                <P>
                    21. On July 28, 2020, the Independent Fiduciary issued an addendum and supplement to the Independent Fiduciary Report. In the addendum, the Independent Fiduciary agreed to perform the following additional duties on behalf of the Plan: (a) monitor the terms of this exemption on an ongoing basis and take all actions that are necessary and proper to enforce the Plan's rights under the Lease to protect the Plan's participants and beneficiaries; (b) review and approve the material 
                    <PRTPAGE P="678"/>
                    terms and conditions of the Lease and make any adjustments thereto; (c) engage the Independent Appraiser and/or other service providers as it reasonably deems necessary; (d) monitor the Lease, including during any subsequent renewal period; and (e) ensure that all conditions of this exemption are met. The obligations in the addendum have been added to the Independent Fiduciary conditions for the exemption below.
                </P>
                <P>22. The exemption requires the Independent Fiduciary to engage a qualified independent appraiser to perform an independent appraisal of the Property following the beginning date of the Lease on a periodic basis as prudence requires to ensure the Plan does not pay more than fair market value rent under the Lease. The Independent Fiduciary must regularly evaluate the prudence of the Plan's continued participation in the Lease and ensure that its participation in the Lease remains in the interest and protective of the interests of the Plan's participants and beneficiaries. The Plan's ongoing participation in the Lease requires the ongoing approval and consent of the Independent Fiduciary. The Independent Fiduciary is responsible for selecting the independent appraiser, the frequency of appraisals, and the assessment of the reliability of the appraisals in determining fair market value rent. The Plan may continue to participate in the Lease during any period only to the extent the Independent Fiduciary has affirmatively determined that participation in the Lease remains in the interest and protective of the Plan and its participants and beneficiaries. The amounts that the Plan has paid or will continue to pay under the Lease may not exceed fair market value rent.</P>
                <P>23. In the July 28, 2020, supplement to the Independent Fiduciary Report, the Independent Fiduciary stated that the Plan needed more space to comply with social distancing requirements and guidelines in the COVID-19 environment and to enable the Plan to offer sufficient classes in a manner compliant with State Division of Apprenticeship Standards Guidelines. In the supplement, the Independent Fiduciary confirmed that the Plan's entering into the Lease was reasonable, prudent, and in the interest of the Plan.</P>
                <P>
                    24. On October 1, 2020, the Plan moved into the Building under the terms of the Lease stating that it urgently needed larger space due to the then COVID-19 health pandemic. Subsequent to the Plan moving into the Building, the Independent Appraiser conducted another appraisal of the Property and determined that the Property's fair market monthly rental value was $46,938 as of October 1, 2020 and $48,890, as of October 1, 2021.
                    <SU>8</SU>
                    <FTREF/>
                     Therefore, the Department notes that the Lease's monthly payment terms that require the Plan to pay a base rent of $40,000 and $2,579 into the Reserve Fund saves the Plan $4,359 and $6,311 on a monthly basis for Lease years 2020 and 2021 compared to the Property's appraised fair market rental value for those years.
                    <SU>9</SU>
                    <FTREF/>
                     Additionally, on January 14, 2022, the Independent Fiduciary represented to the Department that for the period beginning on October 1, 2020, the Lease's terms, including the base monthly rent of $40,000 per month, were in the interest of and of, the Plan and its participants and beneficiaries and reflected a below fair market rent for the subject premises.
                </P>
                <FTNT>
                    <P>
                        <SU>8</SU>
                         This determination is set forth in the Independent Appraiser's written report, dated December 16, 2021.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>9</SU>
                         As described below, the Plan was required to pay, in addition to $40,000 per month, an additional $2,579 into a Reserve Fund for certain maintenance expenses, which is considered an additional component of rent.
                    </P>
                </FTNT>
                <HD SOURCE="HD2">Other Duties of the Independent Fiduciary</HD>
                <P>
                    25. The Independent Fiduciary must ensure that the Lease is in the interest and protective of the Plan and its participants and beneficiaries, including with respect to any amendment or renewal of the Lease. Further, the Independent Fiduciary must take all necessary and proper steps to ensure that the Plan and its participants and beneficiaries are protected in connection with the Lease, which include approving any amendment or renewal thereof. Beginning on the day that the notice of exemption is published in the 
                    <E T="04">Federal Register</E>
                    , the Independent Fiduciary must ensure that the Plan's total payments under the Lease during a twelve (12) month period do not exceed ten (10) percent of the Plan's total assets as reflected in the most recently issued report from the independent accounting firm responsible for auditing the Plan's financial statements.
                </P>
                <P>
                    In order to ensure that the Lease and its terms continue to be in the interest of Plan and its participants and beneficiaries, this exemption requires the Independent Fiduciary to provide prior written notice to the Department's Office of Exemption Determinations at least 60 days before the Lease is amended, modified, or extended, unless such delay would cause imminent harm to the Plan in which case the notice must be provided immediately. The notification must include a complete description of the amendment, modification, or extension, including all material terms.
                    <SU>10</SU>
                    <FTREF/>
                     Additionally, the Independent Fiduciary must notify the Chapter of the Plan's intention to extend the Lease beyond the initial 10-year term, and any subsequent renewal must not exceed five-years.
                </P>
                <FTNT>
                    <P>
                        <SU>10</SU>
                         Because the exemption provides retroactive exemptive relief, within 60 days of the date of publication of the notice of exemption in the 
                        <E T="04">Federal Register</E>
                         (the Publication Date), the Independent Fiduciary will provide a summary of all amendments, modifications, or extensions of the Lease made between October 1, 2020, and the Publication Date.
                    </P>
                </FTNT>
                <P>The Independent Fiduciary while acting on the Plan's behalf with respect to the Lease, must not be directly or indirectly controlled by or through one or more intermediaries or under common control with either the Chapter, the Plan, or any related employers' members.</P>
                <P>26. The Independent Fiduciary has not entered into and must not enter into any agreement or instrument that violates either ERISA section 410 or the Department's Regulations codified at § 2509.75-4; and has not entered and must not enter into any agreement, arrangement, or understanding that includes any provision that provides for the direct or indirect indemnification or reimbursement of the Independent Fiduciary by the Plan or other party for any failure to adhere to its contractual obligations or to State or Federal laws applicable the Independent Fiduciary`s work, or that waives any rights, claims, or remedies of the Plan under ERISA, state, or Federal law against the Independent Fiduciary with respect to the transaction(s) that are the subject of the exemption.</P>
                <HD SOURCE="HD2">Other Lease Terms</HD>
                <P>27. The Lease defines the formula to be used in determining annual increases to the Base Rent as follows:</P>
                <EXTRACT>
                    <P>
                        Beginning on the date that is one (1) year after the Commencement Date [Lease's start date], and on each successive one-year anniversary thereof (each an ‘Adjustment Date’) throughout the [t]erm, the Base Rent shall be increased by the amount of increase in the CPI . . . [s]uch increase shall be calculated by multiplying the then-current Base Rent by a fraction, the numerator of which shall be the CPI for the Adjustment Date and the denominator of which shall be the CPI for the previous Adjustment Date (or the CPI for the Commencement Date in case of the adjustment for the first Adjustment Date). If there is no increase in CPI, or a decrease in CPI, the Base Rent shall remain unchanged.” 
                        <SU>11</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>11</SU>
                             CPI means the Consumer Price Index; the Department's Bureau of Labor Statistics publishes the CPI. The Lease also provides that “. . . [t]he CPI 
                            <PRTPAGE/>
                            for any Adjustment Date shall be the CPI for the most recent month for which it is published before the Adjustment Date (or before the Commencement Date, as the case may be).” The Department understands such Base Rent increase calculation to mean that the Base Rent may increase annually based on the published CPI for the applicable period.
                        </P>
                    </FTNT>
                </EXTRACT>
                <PRTPAGE P="679"/>
                <P>28. Notwithstanding the Lease's CPI Base Rent annual increases provision discussed above, and as further described below, the Independent Fiduciary must ensure that the total amount paid by the Plan in connection with the Lease does not exceed the fair market rental value.</P>
                <P>
                    29. In addition to the Base Rent, the Lease requires the Plan to pay certain operating expenses (the Operating Expenses).
                    <SU>12</SU>
                    <FTREF/>
                     The Operating Expenses are subject to both an annual reconciliation process (the Annual Reconciliation) and the Plan's exercise of audit rights, because of the Building's 90/10 allocation ratio between the Plan and the Chapter. The computation of the Operating Expenses must be made in accordance with fair and reasonable accounting principles customarily applied by owners of similar properties located in San Diego, California.
                    <SU>13</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>12</SU>
                         The Lease defines Operating Expenses as additional rent for costs that the Chapter incurs, which include the following: (1) operation, repair, maintenance, and replacement of the common areas; (2) trash disposal, janitorial and security services; (3) any service provided by the Chapter that is an operating expense under the Lease; (4) the cost of the premiums for the liability and property insurance policies required to be maintained by the Chapter under the Lease; (5) the cost of water, sewer, gas, electricity, solar panels, and other publicly mandated services; (6) labor, salaries and applicable fringe benefits and costs, materials, supplies and tools, used in maintaining and/or cleaning the premises, and accounting and management fees attributable to the operation of the premises; (7) replacing and/or adding improvements mandated by any governmental agency and any repairs or removals necessitated thereby; (8) replacements of equipment or improvements, as amortized over such equipment or improvements' useful life for depreciation purposes according to federal income tax guidelines; (9) reserves set aside for maintenance, repair and/or replacement of common area improvements and equipment as set forth in the Lease's Addendum ; (10) environmental damages and earthquake coverage to the extent not recovered by Chapter directly from any tenants; and (11) all taxes, assessments and charges levied on or with respect to the facility, or any personal property of the Chapter used in the operation thereof and payable by the Chapter.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>13</SU>
                         The Independent Fiduciary's duties include reviewing and approving the Lease's Operating Expenses provisions.
                    </P>
                </FTNT>
                <P>
                    30. The Lease requires both the Plan and the Chapter to make pro rata monthly payments to the Reserve Fund based on their space utilization. The Lease requires the Chapter to pay $136 per month for occupying 4,485 square feet while the Plan must pay $2,579 per month for occupying 39,115 square feet.
                    <SU>14</SU>
                    <FTREF/>
                     The Reserve Fund's monthly amounts will remain the same throughout the Lease's duration, including extensions.
                </P>
                <FTNT>
                    <P>
                        <SU>14</SU>
                         As noted above, the Independent Fiduciary determined that these payments had the effect of adjusting the Lease's base rent of $1.02 per square foot upward by $0.07 per square foot.
                    </P>
                </FTNT>
                <P>
                    31. The Reserve Fund is intended to segregate payments for future replacement needs and its calculations are based on reasonable life expectancy 
                    <SU>15</SU>
                    <FTREF/>
                     and anticipated replacement costs of the Reserve Fund Items; as such, the Reserve Fund is not subject to the Annual Reconciliation provision.
                </P>
                <FTNT>
                    <P>
                        <SU>15</SU>
                         The Lease provides a life cycle costs analysis for the Reserve Fund Items, which considers all costs of acquiring, operating, maintaining, and disposing of a building component or system.
                    </P>
                </FTNT>
                <P>
                    32. The Reserve Fund may only be used for the replacement of certain items (such as roofing, doors, frames and hardware, flooring, asphalt and concrete paving and resealing, fencing and gates, etc.) that are listed in the Lease's addendum. The Reserve Fund may not be used for any other purpose unless agreed to by both the Chapter and the Plan, subject to the Independent Fiduciary's approval.
                    <SU>16</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>16</SU>
                         The Reserve Fund includes the following additional items: backflow preventers on site utilities; casework and countertops; sheet metal, caulking, joint sealants; roofing maintenance and re-roofing; doors, frames, and hardware; operable walls in classroom; coiling service doors; glass and glazing storefront system; ceramic tile; flooring carpet replacement and base; paint and coatings; elevator; plumbing; HVAC equipment; electrical and site lighting; and fire alarm and security system.
                    </P>
                </FTNT>
                <P>
                    33. Further, the Lease requires the Chapter to keep the Property, including interior and exterior walls, roof, and common areas, in good condition and repair except that the Plan is responsible for day-to-day maintenance and repairs to the interior of its allocated rented space to the extent such cost is attributable to causes beyond normal wear and tear. The Lease requires the Chapter to retain funds held in the Reserve Fund in a restricted account that may not be used for any purpose other than to fund the replacement of the items described above. Amounts paid by the Plan into the Reserve Fund constitute a portion of the Plan's overall consideration paid to the landlord, and once the amounts are paid into the Reserve Fund, the Plan has no legal right to such amounts beyond what is described in the Lease. The Lease's termination ends the Plan's right under the Lease. 
                    <SU>17</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>17</SU>
                         As described in more detail above, the Independent Fiduciary determined that the aforementioned Lease terms, including the Reserve Fund provision, were prudent, and in the interest of the Plan. Moreover, this exemption prohibits the Plan's participants from paying any Plan operating expenses, including amounts paid into the Reserve Fund.
                    </P>
                </FTNT>
                <HD SOURCE="HD2">Prohibited Transactions</HD>
                <P>34. Absent an administrative exemption, the Lease would violate ERISA section 406(a)(1)(A), which prohibits a fiduciary from causing a plan to enter into transaction involving a sale, exchange, or lease, of any property between a plan and a party in interest. The Chapter is a party in interest with respect to the Plan under ERISA section 3(14)(D) because it is an employee organization whose members are covered by the Plan. Therefore, the Lease would violate ERISA section 406(a)(1)(A).</P>
                <P>35. Additionally, the Lease would violate ERISA section 406(a)(1)(D), which prohibits a fiduciary from causing the plan to enter into transaction involving the transfer to or use of any plan assets by or for the benefit of a party in interest of a plan. Because the Lease requires monthly cash payments from the Plan's assets to the Chapter, the payments would be considered a transfer of Plan assets to a party in interest in violation of ERISA section 406(a)(1)(D).</P>
                <P>36. Finally, the Lease would violate ERISA section 406(b)(2), which prohibits a plan fiduciary from acting in its individual capacity or in any other capacity in a transaction involving the plan on behalf of a party (or representing a party) whose interests are adverse to the interests of the plan or its participants or beneficiaries. Because both the Trustees and the Board are comprised of individuals representing participating employers who are the Chapter's members, these individuals are involved on both sides of the Lease in violation of ERISA section 406(b)(2).</P>
                <P>37. The Department notes that in addition to the protections described above, this exemption includes protective conditions that allows the Plan to retroactively lease the Property from the Chapter to utilize its office space, classroom space, and training facilities to continue carrying out the Plan's goal of providing apprenticeship training that is related to the construction trade.</P>
                <HD SOURCE="HD1">Written Comments Received Regarding the Proposed Exemption</HD>
                <P>
                    38. In the Proposed Exemption, the Department invited all interested persons to submit written comments and/or requests for a public hearing with respect to such notice, which comment period ended on September 5, 2024. The Department received one comment that was immediately 
                    <PRTPAGE P="680"/>
                    withdrawn and did not receive any hearing requests.
                </P>
                <P>The complete application file (L-12006) is available for public inspection in the Public Disclosure Room of the Employee Benefits Security Administration, Room N-1515, U.S. Department of Labor, 200 Constitution Avenue NW, Washington, DC 20210 reachable by telephone at (202) 693-8673. For a more complete statement of the facts and representations supporting the Department's decision to grant this exemption, please refer to the notice of proposed exemption published on July 22, 2024, at 89 FR 59161.</P>
                <HD SOURCE="HD1">General Information</HD>
                <P>The attention of interested persons is directed to the following:</P>
                <P>(1) The fact that a transaction is the subject of an exemption under ERISA section 408(a) does not relieve a fiduciary or other party in interest or disqualified person from certain other provisions of ERISA and/or the Code, including any prohibited transaction provisions to which the exemption does not apply and the general fiduciary responsibility provisions of ERISA section 404, which, among other things, require a fiduciary to discharge their duties respecting the plan solely in the interest of the participants and beneficiaries of the plan and in a prudent fashion in accordance with ERISA section 404(a)(1)(B);</P>
                <P>(2) As required by ERISA section 408(a), the Department hereby finds that the exemption is (1) administratively feasible, (2) in the interests of the Plan and of its participants and beneficiaries, and (3) protective of the rights of the participants and beneficiaries of the plan;</P>
                <P>(3) The exemption is supplemental to, and not in derogation of, any other ERISA provisions, including statutory or administrative exemptions and transitional rules. Furthermore, the fact that a transaction is subject to an administrative or statutory exemption is not dispositive of whether the transaction is in fact a prohibited transaction; and</P>
                <P>(4) The availability of this exemption is subject to the express condition that the material facts and representations contained in the Application are true and complete at all times, and that the Application accurately describes all material terms of the transaction which is the subject of the exemption.</P>
                <P>
                    Accordingly, after considering the entire record developed in connection with the Applicant's exemption application, the Department has determined to grant the following exemption under the authority of ERISA section 408(a) in accordance with the Department's exemption procedures regulation.
                    <SU>18</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>18</SU>
                         The procedures for requesting an exemption are set forth in 29 CFR part 2570, subpart B (76 FR 66637, 66644, October 27, 2011). Effective December 31, 1978, section 102 of the Reorganization Plan No. 4 of 1978, 5 U.S.C. app. 1 (1996), transferred the authority of the Secretary of the Treasury to issue administrative exemptions under the Code section 4975(c)(2) to the Secretary of Labor. Accordingly, the Department grants this exemption under its sole authority.
                    </P>
                </FTNT>
                <HD SOURCE="HD1">Exemption</HD>
                <HD SOURCE="HD2">Section I. Covered Transaction</HD>
                <P>The restrictions of ERISA sections 406(a)(1)(A), (D), and 406(b)(2) shall not apply, effective October 1, 2020, to the leasing of office, classroom, and training facilities (the Lease) located on an improved parcel of real property (the Property) by the Associated General Contractors of America, San Diego Chapter, Inc. Apprenticeship and Training Fund (the Plan) from the Associated General Contractors of America, San Diego Chapter, Inc. (the Chapter) to provide construction trade apprenticeship training to Plan participants if the conditions set forth in section II are met at all times.</P>
                <HD SOURCE="HD2">Section II. General Conditions</HD>
                <P>(a) The Plan has paid, and will continue to pay, no more than the fair market rental value in connection with the Lease;</P>
                <P>(b) The Plan's participants do not contribute to the Plan;</P>
                <P>(c) A qualified independent fiduciary (the Independent Fiduciary) represents the Plan's interests in all respects to the Lease, including by approving the Lease and, if warranted, any amendment to or renewal of the Lease. Additionally, the Independent Fiduciary, acting on the Plan's behalf with respect to the Lease:</P>
                <P>(1) Must not be directly or indirectly controlled by or through one or more intermediaries, or under common control with either the Chapter, the Plan, or any related employers' members;</P>
                <P>(2) Reviewed the Lease, including the terms and conditions, and determined that the Lease was reasonable and in the interest of and protective of the Plan and its participants and beneficiaries in accordance with ERISA's fiduciary duties of prudence and loyalty;</P>
                <P>(3) Confirmed that the initial base rent did not exceed the current fair market rental value of the Property by reviewing an appraisal performed by a qualified independent appraiser (the Independent Appraiser) both when the Plan entered into the Lease, and when the Plan began occupying the Property;</P>
                <P>(4) Determined in advance of the Plan's entering into the lease for the Property, that the Lease is reasonable, prudent, in the interest and protective of the Plan and its participants and beneficiaries in accordance with ERISA's fiduciary duties of prudence and loyalty;</P>
                <P>(5) Must engage a qualified independent appraiser to perform an independent appraisal of the Property following the beginning date of the Lease on a periodic basis as prudence requires to ensure the Plan does not pay more than fair market value rent under the Lease. The Independent Fiduciary is responsible for the selection of the Independent Appraiser, the frequency of appraisals, and the assessment of the reliability of the appraisals in determining fair market value rent;</P>
                <P>(6) Must regularly evaluate the prudence of the Plan's continued participation in the Lease and ensure that participation in the Lease remains in the interest and protective of the interests of the Plan's participants and beneficiaries;</P>
                <P>(7) Must monitor the parties' compliance with the terms and conditions of the exemption and take all necessary and proper steps to ensure that the Plan and its participants and beneficiaries are completely protected throughout the Lease's term and any related transactions (including any renewal thereof);</P>
                <P>(8) Must review and approve the Lease's operating expenses on an ongoing basis, including but not limited to ensuring that the Plan undergoes both an annual reconciliation for such accrued expenses and it exercises its audit rights when prudently needed.</P>
                <P>(9) Must provide prior written notice to the Chapter of the Plan's intention to extend the Lease beyond its initial 10-year term;</P>
                <P>
                    (10) Has not entered into and must not enter into any agreement or instrument that violates either ERISA section 410 or the Department's Regulations codified at 29 CFR 2509.75-4; 
                    <SU>19</SU>
                    <FTREF/>
                     and
                </P>
                <FTNT>
                    <P>
                        <SU>19</SU>
                         ERISA section 410 provides, in part, that “except as provided in ERISA Sections 405(b)(1) and 405(d), any provision in an agreement or instrument which purports to relieve a fiduciary from responsibility or liability for any responsibility, obligation, or duty under this part [meaning part 4 of ERISA] shall be void as against public policy.”
                    </P>
                </FTNT>
                <P>
                    (11) Has not entered into and must not enter into any agreement, arrangement, or understanding that includes any provision that provides for the Plan or other party to: (i) directly or indirectly indemnify or reimburse the Independent Fiduciary for any failure to 
                    <PRTPAGE P="681"/>
                    adhere to its contractual obligations or to State or Federal laws applicable to the Independent Fiduciary's work, or (ii) waives any rights, claims, or remedies of the Plan under ERISA, State, or Federal law against the Independent Fiduciary with respect to the transaction(s) that are the subject of the exemption;
                </P>
                <P>(d) The Plan's ongoing participation in the Lease requires the continuing approval and consent of the Independent Fiduciary, and the Plan may continue to participate in the Lease during any period only to the extent the Independent Fiduciary has affirmatively determined that participation in the Lease remains in the interest and protective of the Plan and its participants and beneficiaries;</P>
                <P>(e) Any adjustments to the base rent under the Lease must be linked to the Consumer Price Index for All Urban Consumers for the San Diego, California area, as published by the Department's Bureau of Labor Statistics;</P>
                <P>(f) Any renewal of the Lease's initial 10-year term must be made solely at the Plan's discretion subject to approval by the Independent Fiduciary and if the Lease is renewed, the Lease term must not exceed five-years;</P>
                <P>(g) The Independent Appraiser must not have entered into, and must not enter into, any agreement, arrangement, or understanding that includes any provision that provides for the direct or indirect indemnification or reimbursement of the Independent Appraiser by the Plan or any other party for any failure to adhere to its contractual obligations or to State or Federal laws applicable to the Independent Appraiser's work, or that waives any rights, claims or remedies of the Plan or its participants and beneficiaries under ERISA, the Code, or other Federal and State laws against the Independent Appraiser with respect to the transaction(s) that are the subject of the exemption;</P>
                <P>(h) The exemption does not cover any type of service that is otherwise covered under an administrative class exemption or a statutory exemption from ERISA's prohibited transaction provisions;</P>
                <P>
                    (i) Beginning on the day that the notice of exemption is published in the 
                    <E T="04">Federal Register</E>
                    , the Plan's total payments under the Lease during any given twelve (12) month period must not exceed ten (10) percent of the Plan's total assets as reflected in the most recently issued report from the independent accounting firm that audited the Plan's financial statements;
                </P>
                <P>(j) The terms and conditions of the Lease are at least as favorable to the Plan as those which the Plan could obtain in a comparable lease from an unrelated party in an arm's-length transaction;</P>
                <P>(k) All of the material facts and representations provided by the Applicant and set forth in the Proposed Exemption are true and accurate; and</P>
                <P>
                    (l) Within 60 days after publication date of this notice of exemption in the 
                    <E T="04">Federal Register</E>
                     (the Publication Date), the Independent Fiduciary will provide a summary of all amendments, modifications, or extensions of the Lease made between October 1, 2020, and the Publication Date. After the Publication Date and on an ongoing basis, the Independent Fiduciary must inform the Department's Office of Exemption determinations if the Lease is amended, modified, or extended at least 60 days before the amendment, modification, or extension unless such delay would cause imminent harm to the Plan in which case the notice must be provided immediately. The notification must include a complete description of the amendment, modification, or extension, including all material terms thereof.
                </P>
                <P>
                    <E T="03">Exemption Date:</E>
                     The exemption is in effect as of October 1, 2020.
                </P>
                <SIG>
                    <P>Signed at Washington, DC.</P>
                    <NAME>George Christopher Cosby,</NAME>
                    <TITLE>Director, Office of Exemption Determinations, Employee Benefits Security Administration, U.S. Department of Labor.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31599 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4510-29-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF LABOR</AGENCY>
                <SUBAGY>Employment and Training Administration</SUBAGY>
                <SUBJECT>Revised Schedule of Remuneration for the Unemployment Compensation for Ex-Servicemembers (UCX) Program That Reflects the Military Pay Increase Effective January 1, 2025</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Employment and Training Administration, U.S. Department of Labor.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <P>Each year, the Department of Defense issues a Schedule of Remuneration used by states for UCX purposes. States use the schedule to determine Federal military wages for UCX “first claims” only when the Federal Claims Control Center (FCCC) responds to a request for information indicating that there is no Department of Labor copy of the Certificate of Release or Discharge from Active Duty, commonly known DD Form 214 (DD214) for an individual under the social security number provided. A response from the FCCC that indicates “no DD214 on file” will prompt the state to start the affidavit process and to use the attached schedule to calculate the Federal military wages for an unemployment insurance or UCX monetary determination.</P>
                <P>The schedule applies to UCX “first claims” filed beginning with the first day of the first week that begins on or after January 1, 2025, pursuant to the UCX program regulations (see 20 CFR 614.12(c)). States must continue to use the 2024 schedule (or other appropriate schedule) for UCX “first claims” filed before the effective date of the revised schedule. Below is the 2025 Federal Schedule of Remuneration recently released by the Department of Defense.</P>
                <GPOTABLE COLS="4" OPTS="L2,i1" CDEF="s100,12,12,12">
                    <TTITLE>2025 Federal Schedule of Remuneration</TTITLE>
                    <TDESC>[20 CFR 614.12(d)]</TDESC>
                    <BOXHD>
                        <CHED H="1">Pay grade</CHED>
                        <CHED H="1">Monthly rate</CHED>
                        <CHED H="1">
                            Weekly
                            <LI>(7/30th)</LI>
                        </CHED>
                        <CHED H="1">
                            Daily
                            <LI>(1/30th)</LI>
                        </CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="22">1. Commissioned Officers:</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">O-10</ENT>
                        <ENT>24,259.71</ENT>
                        <ENT>5,660.60</ENT>
                        <ENT>808.66</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">O-9</ENT>
                        <ENT>24,259.71</ENT>
                        <ENT>5,660.60</ENT>
                        <ENT>808.66</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">O-8</ENT>
                        <ENT>24,126.29</ENT>
                        <ENT>5,629.47</ENT>
                        <ENT>804.21</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">O-7</ENT>
                        <ENT>21,806.52</ENT>
                        <ENT>5,088.19</ENT>
                        <ENT>726.88</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">O-6</ENT>
                        <ENT>19,001.34</ENT>
                        <ENT>4,433.65</ENT>
                        <ENT>633.38</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">O-5</ENT>
                        <ENT>15,996.69</ENT>
                        <ENT>3,732.56</ENT>
                        <ENT>533.22</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">O-4</ENT>
                        <ENT>13,742.88</ENT>
                        <ENT>3,206.67</ENT>
                        <ENT>458.10</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">O-3</ENT>
                        <ENT>10,914.71</ENT>
                        <ENT>2,546.77</ENT>
                        <ENT>363.82</ENT>
                    </ROW>
                    <ROW>
                        <PRTPAGE P="682"/>
                        <ENT I="03">O-2</ENT>
                        <ENT>8,819.86</ENT>
                        <ENT>2,057.97</ENT>
                        <ENT>294.00</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">O-1</ENT>
                        <ENT>6,914.38</ENT>
                        <ENT>1,613.35</ENT>
                        <ENT>230.48</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="22">2. Commissioned Officers With Over 4 Years Active Duty As An Enlisted Member or Warrant Officer:</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">O-3 E</ENT>
                        <ENT>12,713.01</ENT>
                        <ENT>2,966.37</ENT>
                        <ENT>423.77</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">O-2 E</ENT>
                        <ENT>10,614.32</ENT>
                        <ENT>2,476.67</ENT>
                        <ENT>353.81</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">O-1 E</ENT>
                        <ENT>9,265.92</ENT>
                        <ENT>2,162.05</ENT>
                        <ENT>308.86</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="22">3. Warrant Officer:</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">W-5</ENT>
                        <ENT>14,719.52</ENT>
                        <ENT>3,434.56</ENT>
                        <ENT>490.65</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">W-4</ENT>
                        <ENT>13,505.45</ENT>
                        <ENT>3,151.27</ENT>
                        <ENT>450.18</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">W-3</ENT>
                        <ENT>11,601.59</ENT>
                        <ENT>2,707.04</ENT>
                        <ENT>386.72</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">W-2</ENT>
                        <ENT>9,930.41</ENT>
                        <ENT>2,317.10</ENT>
                        <ENT>331.01</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">W-1</ENT>
                        <ENT>8,418.12</ENT>
                        <ENT>1,964.23</ENT>
                        <ENT>280.60</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="22">4. Enlisted Personnel:</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">E-9</ENT>
                        <ENT>12,643.57</ENT>
                        <ENT>2,950.17</ENT>
                        <ENT>421.45</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">E-8</ENT>
                        <ENT>10,430.73</ENT>
                        <ENT>2,433.84</ENT>
                        <ENT>347.69</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">E-7</ENT>
                        <ENT>9,303.32</ENT>
                        <ENT>2,170.78</ENT>
                        <ENT>310.11</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">E-6</ENT>
                        <ENT>8,189.71</ENT>
                        <ENT>1,910.93</ENT>
                        <ENT>272.99</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">E-5</ENT>
                        <ENT>7,013.27</ENT>
                        <ENT>1,636.43</ENT>
                        <ENT>233.78</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">E-4</ENT>
                        <ENT>5,861.31</ENT>
                        <ENT>1,367.64</ENT>
                        <ENT>195.38</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">E-3</ENT>
                        <ENT>5,283.69</ENT>
                        <ENT>1,232.86</ENT>
                        <ENT>176.12</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">E-2</ENT>
                        <ENT>5,051.89</ENT>
                        <ENT>1,178.78</ENT>
                        <ENT>168.40</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">E-1</ENT>
                        <ENT>4,658.55</ENT>
                        <ENT>1,086.99</ENT>
                        <ENT>155.28</ENT>
                    </ROW>
                    <TNOTE>The Federal Schedule includes columns reflecting derived weekly and daily rates. This revised Federal Schedule of Remuneration is effective for UCX “first claims” filed beginning with the first day of the first week which begins on or after January 1, 2025, pursuant to 20 CFR 614.12(c).</TNOTE>
                </GPOTABLE>
                <SIG>
                    <NAME>José Javier Rodríguez,</NAME>
                    <TITLE>Assistant Secretary for Employment and Training, U.S. Department of Labor.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31608 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4510-FW-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF LABOR</AGENCY>
                <SUBJECT>Agency Information Collection Activities; Submission for OMB Review; Comment Request; Department of Labor-Only Performance Accountability, Information, and Reporting System</SUBJECT>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of availability; request for comments.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Department of Labor (DOL) is submitting this Employment and Training Administration (ETA)-sponsored information collection request (ICR) to the Office of Management and Budget (OMB) for review and approval in accordance with the Paperwork Reduction Act of 1995 (PRA). Public comments on the ICR are invited.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>The OMB will consider all written comments that the agency receives on or before February 5, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        Written comments and recommendations for the proposed information collection should be sent within 30 days of publication of this notice to 
                        <E T="03">www.reginfo.gov/public/do/PRAMain.</E>
                         Find this particular information collection by selecting “Currently under 30-day Review—Open for Public Comments” or by using the search function.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Michael Howell by telephone at 202-693-6782, or by email at 
                        <E T="03">DOL_PRA_PUBLIC@dol.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>This request fulfills Workforce Innovation and Opportunity Act (WIOA) reporting requirements regarding the collection of performance indicators described in sec. 116(b)(2)(A). Requirements for state level collection of this data for the programs contained in this collection are based on WIOA requirements.</P>
                <P>
                    As part of this ICR, the Department of Labor's (DOL) Employment and Training Administration (ETA) has made changes to the Participant Individual Record Layout (ETA-9172), (Program) Performance Report (ETA-9173-APPSHP) to facilitate State and grantee performance reporting. In particular, as part of DOL's effort to streamline program performance reporting for ETA grants with significant apprenticeship components as a primary goal of the program (Apprenticeship grants), DOL is adding the performance information collection requirements for Apprenticeship grants. DOL also is adding a new information collection requirement to this ICR: the Apprenticeship Outreach: Organization/Employer Record Layout. For additional substantive information about this ICR, see the related notice published in the 
                    <E T="04">Federal Register</E>
                     on June 24, 2024 (89 FR 52511).
                </P>
                <P>Comments are invited on: (1) whether the collection of information is necessary for the proper performance of the functions of the Department, including whether the information will have practical utility; (2) the accuracy of the agency's estimates of the burden and cost of the collection of information, including the validity of the methodology and assumptions used; (3) ways to enhance the quality, utility and clarity of the information collection; and (4) ways to minimize the burden of the collection of information on those who are to respond, including the use of automated collection techniques or other forms of information technology.</P>
                <P>
                    This information collection is subject to the PRA. A Federal agency generally cannot conduct or sponsor a collection of information, and the public is generally not required to respond to an information collection, unless the OMB approves it and displays a currently valid OMB Control Number. In addition, notwithstanding any other provisions of law, no person shall generally be subject to penalty for failing to comply with a collection of information that does not display a valid OMB Control Number. 
                    <E T="03">See</E>
                     5 CFR 1320.5(a) and 1320.6.
                </P>
                <P>
                    DOL seeks PRA authorization for this information collection for three (3) years. OMB authorization for an ICR 
                    <PRTPAGE P="683"/>
                    cannot be for more than three (3) years without renewal. The DOL notes that information collection requirements submitted to the OMB for existing ICRs receive a month-to-month extension while they undergo review.
                </P>
                <P>
                    <E T="03">Agency:</E>
                     DOL-ETA.
                </P>
                <P>
                    <E T="03">Title of Collection:</E>
                     DOL-Only Performance Accountability, Information, and Reporting System.
                </P>
                <P>
                    <E T="03">OMB Control Number:</E>
                     1205-0521.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     State, Local, and Tribal Governments.
                </P>
                <P>
                    <E T="03">Total Estimated Number of Respondents:</E>
                     22,687,331.
                </P>
                <P>
                    <E T="03">Total Estimated Number of Responses:</E>
                     46,167,618.
                </P>
                <P>
                    <E T="03">Total Estimated Annual Time Burden:</E>
                     11,735,522 hours.
                </P>
                <P>
                    <E T="03">Total Estimated Annual Other Costs Burden:</E>
                     $9,491,287.
                </P>
                <EXTRACT>
                    <FP>(Authority: 44 U.S.C. 3507(a)(1)(D))</FP>
                </EXTRACT>
                <SIG>
                    <NAME>Michael Howell,</NAME>
                    <TITLE>Senior Paperwork Reduction Act Analyst.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31725 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4510-FN-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF LABOR</AGENCY>
                <SUBJECT>Agency Information Collection Activities; Submission for OMB Review; Comment Request; Workforce Innovation and Opportunity Act (WIOA) Common Performance Reporting</SUBJECT>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of availability; request for comments.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Department of Labor (DOL) is submitting this Employment and Training Administration (ETA)-sponsored information collection request (ICR) to the Office of Management and Budget (OMB) for review and approval in accordance with the Paperwork Reduction Act of 1995 (PRA). Public comments on the ICR are invited.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>The OMB will consider all written comments that the agency receives on or before February 5, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        Written comments and recommendations for the proposed information collection should be sent within 30 days of publication of this notice to 
                        <E T="03">www.reginfo.gov/public/do/PRAMain.</E>
                         Find this particular information collection by selecting “Currently under 30-day Review—Open for Public Comments” or by using the search function.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Michael Howell by telephone at 202-693-6782, or by email at 
                        <E T="03">DOL_PRA_PUBLIC@dol.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The Workforce Innovation and Opportunity Act requires states to report on performance in core programs such as the Wagner-Peyser Act programs, the Adult, Dislocated Worker, and Youth programs, Adult Education and Family Literacy Act programs, and the Vocational Rehabilitation Act programs. This ICR contains the data to be collected for the measure states are to use to report on performance. For additional substantive information about this ICR, see the related notice published in the 
                    <E T="04">Federal Register</E>
                     on June 24, 2024 (89 FR 52511).
                </P>
                <P>Comments are invited on: (1) whether the collection of information is necessary for the proper performance of the functions of the Department, including whether the information will have practical utility; (2) the accuracy of the agency's estimates of the burden and cost of the collection of information, including the validity of the methodology and assumptions used; (3) ways to enhance the quality, utility and clarity of the information collection; and (4) ways to minimize the burden of the collection of information on those who are to respond, including the use of automated collection techniques or other forms of information technology.</P>
                <P>
                    This information collection is subject to the PRA. A Federal agency generally cannot conduct or sponsor a collection of information, and the public is generally not required to respond to an information collection, unless the OMB approves it and displays a currently valid OMB Control Number. In addition, notwithstanding any other provisions of law, no person shall generally be subject to penalty for failing to comply with a collection of information that does not display a valid OMB Control Number. 
                    <E T="03">See</E>
                     5 CFR 1320.5(a) and 1320.6.
                </P>
                <P>DOL seeks PRA authorization for this information collection for three (3) years. OMB authorization for an ICR cannot be for more than three (3) years without renewal. The DOL notes that information collection requirements submitted to the OMB for existing ICRs receive a month-to-month extension while they undergo review.</P>
                <P>
                    <E T="03">Agency:</E>
                     DOL-ETA.
                </P>
                <P>
                    <E T="03">Title of Collection:</E>
                     Workforce Innovation and Opportunity Act (WIOA) Common Performance Reporting.
                </P>
                <P>
                    <E T="03">OMB Control Number:</E>
                     1205-0526.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     State, Local, and Tribal Governments.
                </P>
                <P>
                    <E T="03">Total Estimated Number of Respondents:</E>
                     19,114,129.
                </P>
                <P>
                    <E T="03">Total Estimated Number of Responses:</E>
                     19,114,129.
                </P>
                <P>
                    <E T="03">Total Estimated Annual Time Burden:</E>
                     4,849,727 hours.
                </P>
                <P>
                    <E T="03">Total Estimated Annual Other Costs Burden:</E>
                     $33,300,000.
                </P>
                <EXTRACT>
                    <FP>(Authority: 44 U.S.C. 3507(a)(1)(D))</FP>
                </EXTRACT>
                <SIG>
                    <NAME>Michael Howell,</NAME>
                    <TITLE>Senior Paperwork Reduction Act Analyst.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31728 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4510-FN-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF LABOR</AGENCY>
                <SUBAGY>Occupational Safety and Health Administration</SUBAGY>
                <DEPDOC>[Docket No. OSHA-2011-0008]</DEPDOC>
                <SUBJECT>Commercial Diving Operations Standard; Extension of the Office of Management and Budget's (OMB) Approval of Information Collection (Paperwork) Requirements</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Occupational Safety and Health Administration, Labor.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Request for public comment.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>OSHA solicits public comments concerning the proposal to extend the Office of Management and Budget's (OMB) approval of the information collection requirements specified in the Commercial Diving Operations Standard.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Comments must be submitted (postmarked, sent, or received) by March 7, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P/>
                    <P>
                        <E T="03">Electronically:</E>
                         You may submit comments, including attachments, electronically at 
                        <E T="03">https://www.regulations.gov,</E>
                         which is the Federal eRulemaking Portal. Follow the instructions online for submitting comments.
                    </P>
                    <P>
                        <E T="03">Docket:</E>
                         To read or download comments or other material in the docket, go to 
                        <E T="03">https://www.regulations.gov.</E>
                         Documents in the docket are listed in the 
                        <E T="03">https://www.regulations.gov</E>
                         index; however, some information (
                        <E T="03">e.g.,</E>
                         copyrighted material) is not publicly available to read or download through the website. All submissions, including copyrighted material, are available for inspection through the OSHA Docket Office. Contact the OSHA Docket Office at (202) 693-2350 (TTY (877) 889-5627) for assistance in locating docket submissions.
                    </P>
                    <P>
                        <E T="03">Instructions:</E>
                         All submissions must include the agency name and the OSHA docket number (OSHA-2011-0008) for the Information Collection Request (ICR). OSHA will place comments, including personal information, in the public docket, which may be available online. Therefore, OSHA cautions interested parties about submitting 
                        <PRTPAGE P="684"/>
                        personal information such as social security number and date of birth.
                    </P>
                    <P>
                        For further information on submitting comments, see the “Public Participation” heading in the section of this notice titled 
                        <E T="03">SUPPLEMENTARY INFORMATION</E>
                        .
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Seleda Perryman, Directorate of Standards and Guidance, OSHA, U.S. Department of Labor, telephone (202) 693-2222.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">I. Background</HD>
                <P>
                    The Department of Labor, as part of the continuing effort to reduce paperwork and respondent (
                    <E T="03">i.e.,</E>
                     employer) burden, conducts a preclearance consultation program to provide the public with an opportunity to comment on proposed and continuing information collection requirements in accordance with the Paperwork Reduction Act of 1995 (PRA) (44 U.S.C. 3506(c)(2)(A)). This program ensures that information is in the desired format, reporting burden (time and costs) is minimal, collection instruments are clearly understood, and OSHA's estimate of the information collection burden is accurate. The Occupational Safety and Health Act of 1970 (OSH Act) (29 U.S.C. 651 
                    <E T="03">et seq.</E>
                    ) authorizes information collection by employers as necessary or appropriate for enforcement of the OSH Act or for developing information regarding the causes and prevention of occupational injuries, illnesses, and incidents (29 U.S.C. 657). The OSH Act also requires that OSHA obtain such information with minimum burden upon employers, especially those operating small businesses, and to reduce to the maximum extent feasible unnecessary duplication of effort in obtaining information (29 U.S.C. 657).
                </P>
                <P>The information collection requirements specified in the Commercial Diving Operations (CDO) Standard for general industry helps protect workers from the adverse health effects that may result from their involvement in CDO, and provide access to these records by OSHA, the National Institute for Occupational Safety and Health, the affected workers, and designated representatives. The major information collection requirements of the CDO Standard include the following elements of the Standard.</P>
                <P>
                    <E T="03">§ 1910.401(b).</E>
                     Allows employers to deviate from the requirements of the Subpart to the extent necessary to prevent or minimize a situation that is likely to cause death, serious physical harm, or major environmental damage. They must provide written notice to the OSHA Area Director within 48 hours and must describe the reason for and extent of the deviation.
                </P>
                <P>
                    <E T="03">§§ 1910.410(a)(3) and (a)(4).</E>
                     Employers must train all dive team members in cardiopulmonary resuscitation and first aid (
                    <E T="03">i.e.,</E>
                     the American Red Cross standard course or equivalent). Additionally, employers must train dive team members exposed to hyperbaric conditions, or who control exposure of other workers to such conditions, in diving-related physics and physiology.
                </P>
                <P>
                    <E T="03">§§ 1910.420(a) and (b).</E>
                     Employers must develop and maintain a safe practices manual and make it available to each dive team member at the dive location. For each diving mode used at the dive location, the manual must contain: Safety procedures and checklists for diving operations; assignments and responsibilities of the dive team members; equipment procedures and checklists; and emergency procedures for fire, equipment failures, adverse environmental conditions, and medical illness and injury.
                </P>
                <P>
                    <E T="03">§ 1910.421(b).</E>
                     Employers are to keep at the dive location a list of telephone or call numbers for the following emergency facilities and services: An operational decompression chamber (if such a chamber is not at the dive location), accessible hospitals, available physicians and means of emergency transportation, and the nearest U.S. Coast Guard Rescue Coordination Center.
                </P>
                <P>
                    <E T="03">§ 1910.421(f).</E>
                     Requires employers to brief dive team members on the diving-related tasks they are to perform, safety procedures for the diving mode used at the dive location, any unusual hazards or environmental conditions likely to affect the safety of the diving operation, and any modifications to operating procedures necessitated by the specific diving operation. Before assigning diving-related tasks, employers must ask each dive team member about their current state of physical fitness and inform the member about the procedure for reporting physical problems or adverse physiological effects during and after the dive.
                </P>
                <P>
                    <E T="03">§ 1910.421(h).</E>
                     If the diving operation occurs in an area capable of supporting marine traffic and occurs from a surface other than a vessel, employers are to display a rigid replica of the international code flag “A” that is at least one meter in height so that it is visible from any direction; the employer must illuminate the flag during night diving operations.
                </P>
                <P>
                    <E T="03">§ 1910.422(e).</E>
                     Employers must develop and maintain a depth-time profile for each diver that includes, as appropriate, any breathing gas changes or decompression.
                </P>
                <P>
                    <E T="03">§§ 1910.423(b)(1)(ii) through (b)(2).</E>
                     Requires the employer to: Instruct the diver to report any physical symptoms or adverse physiological effects, including symptoms of decompression sickness (DCS); advise the diver of the location of a decompression chamber that is ready for use; and alert the diver to the potential hazards of flying after diving. For any dive outside the no-decompression limits, deeper than 100 feet, or that uses mixed gas in the breathing mixture, the employer must also inform the diver to remain awake and in the vicinity of the decompression chamber that is at the dive location for at least one hour after the dive or any decompression or treatment associated with the dive.
                </P>
                <P>
                    <E T="03">§ 1910.423(d).</E>
                     Employers are to record and maintain the following information for each diving operation: The names of dive-team members; date, time, and location; diving modes used; general description of the tasks performed; an estimate of the underwater and surface conditions; and the maximum depth and bottom time for each diver. In addition, for each dive outside the no-decompression limits, deeper than 100 feet, or that uses mixed gas in the breathing mixture, the employer must record and maintain the following information for each diver: Depth-time and breathing gas profiles; decompression table designation (including any modifications); and elapsed time since the last pressure exposure if less than 24 hours or the repetitive dive designation. If the dive results in DCS symptoms, or the employer suspects that a diver has DCS, the employer must record and maintain a description of the DCS symptoms (including the depth and time of symptom onset) and the results of treatment.
                </P>
                <P>
                    <E T="03">§ 1910.423(e).</E>
                     Requires employers to assess each DCS incident by: Investigating and evaluating it based on the recorded information, consideration of the past performance of the decompression table used, and the diver's individual susceptibility to DCS; taking appropriate corrective action to reduce the probability of a DCS recurrence; and, within 45 days of the DCS incident, preparing a written evaluation of this assessment, including any corrective action taken.
                </P>
                <P>
                    <E T="03">§§ 1910.430(a), (b)(4), (c)(1)(1) through (c)(1)(iii), (c)(3)(i), (f)(3)(ii), and (g)(2).</E>
                     Employers must record by means of tagging or a logging system any work 
                    <PRTPAGE P="685"/>
                    performed on equipment, including any modifications, repairs, tests, calibrations, or maintenance performed on the equipment. This record is to include a description of the work, the name or initials of the individual who performed the work, and the date they completed the work.
                </P>
                <P>
                    Employers must test two specific types of equipment, including, respectively: The output of air compressor systems used to supply breathing air to divers for air purity every six months by means of samples taken at the connection to the distribution system; and breathing-gas hoses at least annually at one and one-half times their working pressure. Employers must mark each umbilical (
                    <E T="03">i.e.,</E>
                     separate lines supplying air and communications to a diver, as well as a safety line, tied together in a bundle), beginning at the diver's end, in 10-foot increments for 100 feet, then in 50-foot increments thereafter. Employers must also regularly inspect and maintain mufflers located in intake and exhaust lines on decompression chambers and test depth gauges using dead-weight testing or calibrate the gauges against a master reference gauge; such testing or calibration is to occur every six months or if the employer finds a discrepancy larger than two percent of the full scale between any two equivalent gauges. Employers must make a record of the tests, calibrations, inspections, and maintenance performed on the equipment.
                </P>
                <P>
                    <E T="03">§§ 1910.440(a)(2) and (b).</E>
                     Employers must record any diving-related injuries or illnesses that result in a dive-team member remaining in the hospital for at least 24 hours. This record is to describe the circumstances of the incident and the extent of any injuries or illnesses.
                </P>
                <P>Employers must make any record required by the Subpart available, on request, for inspection and copying to an OSHA compliance officer or to a representative of the National Institute for Occupational Safety and Health (NIOSH). Employers are to provide workers, their designated representatives, and OSHA compliance officers with exposure and medical records generated under the Subpart in accordance with § 1910.1020 (“Access to worker exposure and medical records”); these records include safe practices manuals, depth-time profiles, diving records, DCS incident assessments, and hospitalization records. Additionally, employers must make equipment inspection and testing records available to workers and their designated representative on request.</P>
                <P>Employers must retain these records for the following periods: Safe practices manuals, current document only; depth-time profiles, until completing the diving record or the DCS incident assessment; diving records, one year, except five years if a DCS incident occurred during the dive; DCS incident assessments, five years; hospitalization records, five years; and equipment inspections and testing records, current tag or log entry until the employer removes the equipment from service.</P>
                <HD SOURCE="HD1">II. Special Issues for Comment</HD>
                <P>OSHA has a particular interest in comments on the following issues:</P>
                <P>• Whether the proposed information collection requirements are necessary for the proper performance of the agency's functions, including whether the information is useful;</P>
                <P>• The accuracy of OSHA's estimate of the burden (time and costs) of the information collection requirements, including the validity of the methodology and assumptions used;</P>
                <P>• The quality, utility, and clarity of the information collected; and</P>
                <P>• Ways to minimize the burden on employers who must comply; for example, by using automated or other technological information, and transmission techniques.</P>
                <HD SOURCE="HD1">III. Proposed Actions</HD>
                <P>OSHA is requesting that OMB extend the approval of the information collection requirements contained in the Commercial Diving Standard. The agency is requesting an adjustment decrease in the burden hours amount from 170,806 hours to 135,450 hours, a difference of 35,356 hours. This adjustment decrease is due decrease in the number of professional divers, going from 3,460 to 2,900 divers, which resulted in a corresponding decrease in the number of affected facilities.</P>
                <P>OSHA will summarize the comments submitted in response to this notice and will include this summary in the request to OMB to extend the approval of the information collection requirements.</P>
                <P>
                    <E T="03">Type of Review:</E>
                     Extension of currently approved collection.
                </P>
                <P>
                    <E T="03">Title:</E>
                     Commercial Diving Operations Standard.
                </P>
                <P>
                    <E T="03">OMB Control Number:</E>
                     1218-0069.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Business or other for-profits.
                </P>
                <P>
                    <E T="03">Number of Respondents:</E>
                     930.
                </P>
                <P>
                    <E T="03">Number of Responses:</E>
                     1,132,688.
                </P>
                <P>
                    <E T="03">Frequency of Responses:</E>
                     On occasion.
                </P>
                <P>
                    <E T="03">Average Time per Response:</E>
                     Varies.
                </P>
                <P>
                    <E T="03">Estimated Total Burden Hours:</E>
                     135,450.
                </P>
                <P>
                    <E T="03">Estimated Cost (Operation and Maintenance):</E>
                     $0.
                </P>
                <HD SOURCE="HD1">IV. Public Participation—Submission of Comments on This Notice and Internet Access to Comments and Submissions</HD>
                <P>
                    You may submit comments in response to this document as follows: (1) electronically at 
                    <E T="03">https://www.regulations.gov,</E>
                     which is the Federal eRulemaking Portal; (2) by facsimile (fax) to the OSHA docket, if your comments including attachments, are not longer than 10 page, at (202) 693-1948. or (3) by hard copy. All comments, attachments, and other materials must identify the agency name and the OSHA docket number for the ICR (Docket No. OSHA-2011-0008). You may supplement electronic submissions by uploading document files electronically.
                </P>
                <P>
                    Comments and submissions are posted without change at 
                    <E T="03">https://www.regulations.gov.</E>
                     Therefore, OSHA cautions commenters about submitting personal information such as social security numbers and date of birth.
                </P>
                <P>
                    Although all submissions are listed in the 
                    <E T="03">https://www.regulations.gov</E>
                     index, some information (
                    <E T="03">e.g.,</E>
                     copyrighted material) is not publicly available to read or download through this website. All submissions, including copyrighted material, are available for inspection and copying at the OSHA Docket Office. Information on using the 
                    <E T="03">https://www.regulations.gov</E>
                     website to submit comments and access the docket is available at the website's “User Tips” link.
                </P>
                <P>Contact the OSHA Docket Office for information about materials not available through the website, and for assistance in using the internet to locate docket submissions.</P>
                <HD SOURCE="HD1">V. Authority and Signature</HD>
                <P>
                    James S. Frederick, Deputy Assistant Secretary of Labor for Occupational Safety and Health, directed the preparation of this notice. The authority for this notice is the Paperwork Reduction Act of 1995 (44 U.S.C. 3506 
                    <E T="03">et seq.</E>
                    ) and Secretary of Labor's Order No 8-2020 (85 FR 58393).
                </P>
                <SIG>
                    <DATED>Signed at Washington, DC, on December 20, 2024.</DATED>
                    <NAME>James S. Frederick,</NAME>
                    <TITLE>Deputy Assistant Secretary of Labor for Occupational Safety and Health.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31727 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4510-26-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <PRTPAGE P="686"/>
                <AGENCY TYPE="N">NUCLEAR REGULATORY COMMISSION</AGENCY>
                <SUBJECT>722nd Meeting of the Advisory Committee on Reactor Safeguards (ACRS)</SUBJECT>
                <P>
                    In accordance with the purposes of sections 29 and 182b of the Atomic Energy Act (42 U.S.C. 2039, 2232(b)), the Advisory Committee on Reactor Safeguards (ACRS) will hold meetings on February 5-7, 2025. The Committee will be conducting meetings that will include some Members being physically present at the headquarters of the U.S. Nuclear Regulatory Commission (NRC) while other Members participate remotely. Interested members of the public are encouraged to participate remotely in any open sessions via Microsoft (MS) Teams or via phone at 301-576-2978, passcode 103416569#. A more detailed agenda including the MSTeams link may be found at the ACRS public website at 
                    <E T="03">https://www.nrc.gov/reading-rm/doc-collections/acrs/agenda/index.html.</E>
                     If you would like the MSTeams link forwarded to you, please contact the Designated Federal Officer (DFO) as follows: 
                    <E T="03">Quynh.Nguyen@nrc.gov,</E>
                     or 
                    <E T="03">Lawrence.Burkhart@nrc.gov.</E>
                </P>
                <HD SOURCE="HD1">Wednesday, February 5, 2025</HD>
                <P>
                    <E T="03">8:30 a.m.-8:35 a.m.: Opening Remarks by the ACRS Chair (Open)</E>
                    —The ACRS Chair will make opening remarks regarding the conduct of the meeting.
                </P>
                <P>
                    <E T="03">8:35 a.m.-10:30 a.m.: Regulatory Guide (RG) 3.78, Revision 0, Regarding Acceptable American Society of Mechanical Engineers (ASME) Section XI Inservice Inspection Code Cases for Title 10 of the Code of Federal Regulations (10 CFR) Part 72</E>
                     (Open)—The Committee will discuss and deliberate on the subject topic.
                </P>
                <P>
                    <E T="03">10:30 a.m.-1:00 p.m.: Increased Enrichment Draft Rule Language and Associated Draft RGs Including RG 1.183, Revision 2</E>
                     (Open)—The Committee will discuss and deliberate with the NRC staff and other stakeholders regarding the subject topics and proceed to preparation of reports.
                </P>
                <P>
                    <E T="03">1:00 p.m.-6:00 p.m.: Committee Deliberation on Increased Enrichment Draft Rule Language and Associated Draft RGs Including RG 1.183, Revision 2</E>
                     (Open)—The Committee will deliberate on the subject topic and proceed to preparation of reports.
                </P>
                <HD SOURCE="HD1">Thursday, February 6, 2025</HD>
                <P>
                    <E T="03">8:30 a.m.-5:00 p.m.: NuScale Loss-of-Coolant Accident Evaluation Model Topical Report and Continued Committee Deliberation on Increased Enrichment and RG 1.183, Revision 2, Topics</E>
                     (Open/Closed)—The Committee will deliberate with the NRC staff regarding the subject topic and proceed to preparation of reports. [NOTE: Pursuant to 5 U.S.C 552b(c)(4), a portion of this session may be closed in order to discuss and protect information designated as proprietary.]
                </P>
                <HD SOURCE="HD1">Friday, February 7, 2025</HD>
                <P>
                    <E T="03">8:30 a.m.-5:00 p.m.: Planning and Procedures Session/Future ACRS Activities/Reconciliation of ACRS Comments and Recommendations/Preparation of Reports</E>
                     (Open/Closed)—The Committee will hear discussion of the recommendations of the Planning and Procedures Subcommittee regarding items proposed for consideration by the Full Committee during future ACRS meetings, and/or proceed to preparation of reports.
                </P>
                <P>
                    [
                    <E T="03">Note:</E>
                     Pursuant to 5 U.S.C. 552b(c)(2), a portion of this meeting may be closed to discuss organizational and personnel matters that relate solely to internal personnel rules and practices of the ACRS.]
                </P>
                <P>
                    [
                    <E T="03">Note:</E>
                     Pursuant to 5 U.S.C 552b(c)(4), a portion of this session may be closed in order to discuss and protect information designated as proprietary.].
                </P>
                <P>
                    Procedures for the conduct of and participation in ACRS meetings were published in the 
                    <E T="04">Federal Register</E>
                     on June 13, 2019 (84 FR 27662). In accordance with those procedures, oral or written views may be presented by members of the public, including representatives of the nuclear industry. Persons desiring to make oral statements should notify Quynh Nguyen, Cognizant ACRS Staff and the DFO (Telephone: 301-415-5844, Email: 
                    <E T="03">Quynh.Nguyen@nrc.gov</E>
                    ), 5 days before the meeting, if possible, so that appropriate arrangements can be made to allow necessary time during the meeting for such statements. In view of the possibility that the schedule for ACRS meetings may be adjusted by the Chair as necessary to facilitate the conduct of the meeting, persons planning to attend should check with the cognizant ACRS staff if such rescheduling would result in major inconvenience.
                </P>
                <P>An electronic copy of each presentation should be emailed to the cognizant ACRS staff at least one day before the meeting.</P>
                <P>In accordance with subsection 10(d) of Public Law 92-463 and 5 U.S.C. 552b(c), certain portions of this meeting may be closed, as specifically noted above. Use of still, motion picture, and television cameras during the meeting may be limited to selected portions of the meeting as determined by the Chair. Electronic recordings will be permitted only during the open portions of the meeting.</P>
                <P>
                    ACRS meeting agendas, meeting transcripts, and letter reports are available through the NRC Public Document Room (PDR) at 
                    <E T="03">pdr.resource@nrc.gov,</E>
                     or by calling the PDR at 1-800-397-4209, or 301-415-4737, between 8 a.m. and 4 p.m. eastern daylight time (EDT), Monday through Friday, except Federal holidays, or from the Publicly Available Records System component of NRC's Agencywide Documents Access and Management System, which is accessible from the NRC website at 
                    <E T="03">https://www.nrc.gov/reading-rm/adams.html</E>
                     or 
                    <E T="03">https://www.nrc.gov/reading-rm/doc-collections/#ACRS/.</E>
                </P>
                <SIG>
                    <DATED>Dated: December 30, 2024.</DATED>
                    <P>For the Nuclear Regulatory Commission</P>
                    <NAME>Russell E. Chazell,</NAME>
                    <TITLE>Federal Advisory Committee Management Officer, Office of the Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31633 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7590-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">NUCLEAR REGULATORY COMMISSION</AGENCY>
                <DEPDOC>[NRC-2025-0001]</DEPDOC>
                <SUBJECT>Sunshine Act Meetings</SUBJECT>
                <PREAMHD>
                    <HD SOURCE="HED">TIME AND DATE:</HD>
                    <P>
                        Weeks of January 6, 13, 20, 27, and February 3, 10, 2025. The schedule for Commission meetings is subject to change on short notice. The NRC Commission Meeting Schedule can be found on the internet at: 
                        <E T="03">https://www.nrc.gov/public-involve/public-meetings/schedule.html.</E>
                    </P>
                </PREAMHD>
                <PREAMHD>
                    <HD SOURCE="HED">PLACE:</HD>
                    <P>
                        The NRC provides reasonable accommodation to individuals with disabilities where appropriate. If you need a reasonable accommodation to participate in these public meetings or need this meeting notice or the transcript or other information from the public meetings in another format (
                        <E T="03">e.g.,</E>
                         braille, large print), please notify Anne Silk, NRC Disability Program Specialist, at 301-287-0745, by videophone at 240-428-3217, or by email at 
                        <E T="03">Anne.Silk@nrc.gov.</E>
                         Determinations on requests for reasonable accommodation will be made on a case-by-case basis.
                    </P>
                </PREAMHD>
                <PREAMHD>
                    <HD SOURCE="HED">STATUS:</HD>
                    <P>Public.</P>
                    <P>
                        Members of the public may request to receive the information in these notices electronically. If you would like to be added to the distribution, please contact the Nuclear Regulatory Commission, Office of the Secretary, Washington, DC 20555, at 301-415-1969, or by email at 
                        <E T="03">Betty.Thweatt@nrc.gov</E>
                         or 
                        <E T="03">Samantha.Miklaszewski@nrc.gov.</E>
                    </P>
                </PREAMHD>
                <PREAMHD>
                    <PRTPAGE P="687"/>
                    <HD SOURCE="HED">MATTERS TO BE CONSIDERED:</HD>
                    <P/>
                </PREAMHD>
                <HD SOURCE="HD1">Week of January 6, 2025</HD>
                <P>There are no meetings scheduled for the week of January 6, 2025.</P>
                <HD SOURCE="HD1">Week of January 13, 2025—Tentative</HD>
                <HD SOURCE="HD2">Tuesday, January 14, 2025</HD>
                <FP SOURCE="FP-2">9:00 a.m. Strategic Programmatic Overview of the Decommissioning and Low-Level Waste and Nuclear Materials Users Business Lines (Public Meeting) (Contact: Araceli Billoch Colon: 301-415-3302)</FP>
                <P>
                    <E T="03">Additional Information:</E>
                     The meeting will be held in the Commissioners' Hearing Room, 11555 Rockville Pike, Rockville, Maryland. The public is invited to attend the Commission's meeting in person or watch live via webcast at the Web address—
                    <E T="03">https://video.nrc.gov/.</E>
                </P>
                <HD SOURCE="HD1">Week of January 20, 2025—Tentative</HD>
                <P>There are no meetings scheduled for the week of January 20, 2025.</P>
                <HD SOURCE="HD1">Week of January 27, 2025—Tentative</HD>
                <P>There are no meetings scheduled for the week of January 27, 2025.</P>
                <HD SOURCE="HD1">Week of February 3, 2025—Tentative</HD>
                <HD SOURCE="HD2">Thursday, February 6, 2025</HD>
                <FP SOURCE="FP-2">9:00 a.m. Briefing on ADVANCE Act Activities (Public Meeting) (Contact: Wesley Held: 301-287-3591)</FP>
                <P>
                    <E T="03">Additional Information:</E>
                     The meeting will be held in the Commissioners' Hearing Room, 11555 Rockville Pike, Rockville, Maryland. The public is invited to attend the Commission's meeting in person or watch live via webcast at the Web address—
                    <E T="03">https://video.nrc.gov/.</E>
                </P>
                <HD SOURCE="HD1">Week of February 10, 2025—Tentative</HD>
                <P>There are no meetings scheduled for the week of February 10, 2025.</P>
                <PREAMHD>
                    <HD SOURCE="HED">CONTACT PERSON FOR MORE INFORMATION: </HD>
                    <P>
                        For more information or to verify the status of meetings, contact Wesley Held at 301-287-3591 or via email at 
                        <E T="03">Wesley.Held@nrc.gov.</E>
                    </P>
                    <P>The NRC is holding the meetings under the authority of the Government in the Sunshine Act, 5 U.S.C. 552b.</P>
                </PREAMHD>
                <SIG>
                    <P>Dated: January 2, 2025.</P>
                    <P>For the Nuclear Regulatory Commission.</P>
                    <NAME>Wesley W. Held</NAME>
                    <TITLE>Policy Coordinator, Office of the Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2025-00117 Filed 1-2-25; 4:15 pm]</FRDOC>
            <BILCOD>BILLING CODE 7590-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 17, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1095 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-870, K2025-871.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31677 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service 
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 17, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1102 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-877, K2025-878.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31684 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 19, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail &amp; USPS Ground Advantage® Contract 557 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-913, K2025-914.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31723 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <PRTPAGE P="688"/>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1188 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-983, K2025-982.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31743 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1180 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-968, K2025-967.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31739 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 19, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1126 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-907, K2025-908.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31690 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service 
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 17, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1099 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-874, K2025-875.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31681 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1156 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-941, K2025-942.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31718 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 18, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">
                        USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 
                        <PRTPAGE P="689"/>
                        1107 to Competitive Product List.
                    </E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-882, K2025-883.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31689 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1179 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-967, K2025-966.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31738 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 18, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1105 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-880, K2025-881.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31687 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 17, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1103 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-878, K2025-879.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31685 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service 
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 18, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail &amp; USPS Ground Advantage® Contract 551 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-884, K2025-885.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31673 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service 
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 17, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1098 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-873, K2025-874.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31680 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <PRTPAGE P="690"/>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 17, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1096 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-871, K2025-872.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31678 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 19, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1148 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-933, K2025-934.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31711 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 19, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1130 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-912, K2025-913.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31706 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail &amp; USPS Ground Advantage® Contract 565 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-974, K2025-973.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31729 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 18, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail &amp; USPS Ground Advantage® Contract 556 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-910, K2025-911.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31722 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        The Postal Service gives notice of filing a request with the Postal 
                        <PRTPAGE P="691"/>
                        Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 19, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1151 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-936, K2025-937.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31714 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail &amp; USPS Ground Advantage® Contract 567 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-976, K2025-975.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31731 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1187 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-982, K2025-981.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31742 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1189 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-984, K2025-983.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31744 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 19, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1129 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-911, K2025-912.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31705 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <PRTPAGE P="692"/>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 18, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail &amp; USPS Ground Advantage® Contract 553 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-886, K2025-887.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31675 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1178 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-966, K2025-965.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31737 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 19, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1144 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-929, K2025-930.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31707 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service 
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 17, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1100 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-875, K2025-876.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31682 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1153 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-938, K2025-939.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31715 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">
                        USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 
                        <PRTPAGE P="693"/>
                        1173 to Competitive Product List.
                    </E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-961, K2025-960.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31721 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail and USPS Ground Advantage ® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service ® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 18, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail &amp; USPS Ground Advantage® Contract 550 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-883, K2025-884.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law. </TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31672 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1193 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-988, K2025-987.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31748 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1175 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-963, K2025-962.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31734 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1176 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-964, K2025-963.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31735 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service 
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 17, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1101 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-876, K2025-877.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31683 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <PRTPAGE P="694"/>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1192 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-987, K2025-986.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31747 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service 
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 19, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1146 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-931, K2025-932.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31709 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1172 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-960, K2025-959.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31720 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1186 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-981, K2025-980.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31741 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1154 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-939, K2025-940.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31716 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <PRTPAGE P="695"/>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1171 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-959, K2025-958.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31719 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 19, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1149 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-934, K2025-935.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31712 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 17, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1106 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-881, K2025-882.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31688 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1177 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-965, K2025-964.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31736 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service 
                        <E T="51">TM</E>
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 18, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail &amp; USPS Ground Advantage® Contract 551 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-884, K2025-885.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31674 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <PRTPAGE P="696"/>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 17, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1104 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-879, K2025-880.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31686 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 19, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1150 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-935, K2025-936.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31713 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 19, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1147 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-932, K2025-933.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31710 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail &amp; USPS Ground Advantage® Contract 566 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-975, K2025-974.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31730 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 19, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1127 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-908, K2025-909.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31691 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 19, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">
                        USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 
                        <PRTPAGE P="697"/>
                        1155 to Competitive Product List.
                    </E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-940, K2025-941.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31717 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1190 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-985, K2025-984.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31745 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1191 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-986, K2025-985.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31746 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail &amp; USPS Ground Advantage® Contract 568 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-989, K2025-988.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31732 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <P/>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service 
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 17, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1097 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-872, K2025-873.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31679 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1174 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-962, K2025-961.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31733 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <PRTPAGE P="698"/>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 19, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1145 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-930, K2025-931.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31708 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 20, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1181 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-969, K2025-968.
                </P>
                <SIG>
                    <NAME>Sean C. Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31740 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 19, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1128 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-909, K2025-910.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31704 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">POSTAL SERVICE</AGENCY>
                <SUBJECT>Product Change—Priority Mail Express, Priority Mail, and USPS Ground Advantage® Negotiated Service Agreement</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>
                        Postal Service
                        <E T="51">TM</E>
                        .
                    </P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Postal Service gives notice of filing a request with the Postal Regulatory Commission to add a domestic shipping services contract to the list of Negotiated Service Agreements in the Mail Classification Schedule's Competitive Products List.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        <E T="03">Date of required notice:</E>
                         January 6, 2025.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Sean C. Robinson, 202-268-8405.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The United States Postal Service® hereby gives notice that, pursuant to 39 U.S.C. 3642 and 3632(b)(3), on December 17, 2024, it filed with the Postal Regulatory Commission a 
                    <E T="03">USPS Request to Add Priority Mail Express, Priority Mail &amp; USPS Ground Advantage® Contract 1094 to Competitive Product List.</E>
                     Documents are available at 
                    <E T="03">www.prc.gov,</E>
                     Docket Nos. MC2025-869, K2025-870.
                </P>
                <SIG>
                    <NAME>Sean Robinson,</NAME>
                    <TITLE>Attorney, Corporate and Postal Business Law.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31676 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 7710-12-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">SECURITIES AND EXCHANGE COMMISSION</AGENCY>
                <DEPDOC>[Release No. 34-102064; File No. SR-CboeBYX-2024-050]</DEPDOC>
                <SUBJECT>Self-Regulatory Organizations; Cboe BYX Exchange, Inc.; Notice of Filing and Immediate Effectiveness of Proposed Rule Change To Establish Fees for Industry Members Related to Reasonably Budgeted CAT Costs of the National Market System Plan Governing the Consolidated Audit Trail for 2025</SUBJECT>
                <DATE>December 31, 2024.</DATE>
                <P>
                    Pursuant to Section 19(b)(1) of the Securities Exchange Act of 1934 (“Act”),
                    <SU>1</SU>
                    <FTREF/>
                     and Rule 19b-4 thereunder,
                    <SU>2</SU>
                    <FTREF/>
                     notice is hereby given that on December 20, 2024, Cboe BYX Exchange, Inc. (“Exchange”) filed with the Securities and Exchange Commission (“Commission”) the proposed rule change as described in Item I below, which Item has been substantially prepared by the Exchange. The Exchange has designated this proposal for immediate effectiveness pursuant to Section 19(b)(3)(A) of the Act 
                    <SU>3</SU>
                    <FTREF/>
                     and Rule 19b-4(f) thereunder.
                    <SU>4</SU>
                    <FTREF/>
                     The Commission is publishing this notice to solicit comments on the proposed rule change from interested persons.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         15 U.S.C. 78s(b)(1).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         17 CFR 240.19b-4.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         15 U.S.C. 78s(b)(3)(A).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         17 CFR 240.19b-4(f). At any time within 60 days of the filing of the proposed rule change, the Commission summarily may temporarily suspend such rule change if it appears to the Commission that such action is necessary or appropriate in the public interest, for the protection of investors, or otherwise in furtherance of the purposes of the Act. If the Commission takes such action, the Commission will institute proceedings to determine whether the proposed rule change should be approved or disapproved.
                    </P>
                </FTNT>
                <PRTPAGE P="699"/>
                <HD SOURCE="HD1">I. Self-Regulatory Organization's Statement of the Terms of Substance of the Proposed Rule Change</HD>
                <P>The Exchange proposes to amend its “Consolidated Audit Trail Funding Fees” fee schedule to establish the CAT Fee 2025-1 fee rate of $0.000022 per executed equivalent share.</P>
                <P>
                    The proposed rule change, including the Exchange's statement of the purpose of, and statutory basis for, the proposed rule change, is available on the Exchange's website at 
                    <E T="03">http://www.cboe.com/AboutCBOE/CBOELegalRegulatoryHome.aspx,</E>
                     at the principal office of the Exchange, and on the Commission's website at 
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-CboeBYX-2024-050.</E>
                </P>
                <HD SOURCE="HD1">II. Solicitation of Comments</HD>
                <P>
                    Interested persons are invited to submit written data, views, and arguments concerning the foregoing, including whether the proposed rule change is consistent with the Act.
                    <SU>5</SU>
                    <FTREF/>
                     Comments may be submitted electronically by using the Commission's internet comment form (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-CboeBYX-2024-050</E>
                    ) or by sending an email to 
                    <E T="03">rule-comments@sec.gov.</E>
                     Please include file number SR- CboeBYX-2024-050 on the subject line. Alternatively, paper comments may be sent to Secretary, Securities and Exchange Commission, 100 F Street NE, Washington, DC 20549-1090. All submissions should refer to file number SR-CboeBYX-2024-050. To help the Commission process and review your comments more efficiently, please use only one method. The Commission will post all comments on the Commission's internet website (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-CboeBYX-2024-050</E>
                    ). Do not include personal identifiable information in submissions; you should submit only information that you wish to make available publicly. We may redact in part or withhold entirely from publication submitted material that is obscene or subject to copyright protection. All submissions should refer to file number SR-CboeBYX-2024-050 and should be submitted on or before January 27, 2025.
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         Copies of the submission, all subsequent amendments, all written statements with respect to the proposed rule change that are filed with the Commission, and all written communications relating to the proposed rule change between the Commission and any person, other than those that may be withheld from the public in accordance with the provisions of 5 U.S.C. 552, will be available for website viewing and printing in the Commission's Public Reference Room, 100 F Street NE, Washington, DC 20549, on official business days between the hours of 10 a.m. and 3 p.m. Copies of the filing also will be available for inspection and copying at the principal office of SRO.
                    </P>
                </FTNT>
                <SIG>
                    <P>
                        For the Commission, by the Division of Trading and Markets, pursuant to delegated authority.
                        <SU>6</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>6</SU>
                             17 CFR 200.30-3(a)(12).
                        </P>
                    </FTNT>
                    <NAME>Stephanie J. Fouse,</NAME>
                    <TITLE>Assistant Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31770 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8011-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">SECURITIES AND EXCHANGE COMMISSION</AGENCY>
                <DEPDOC>[Release No. 34-102056; File No. SR-NYSE-2024-83]</DEPDOC>
                <SUBJECT>Self-Regulatory Organizations; New York Stock Exchange LLC; Notice of Filing and Immediate Effectiveness of Proposed Rule Change To Extend Bond Trading License Fee Waivers</SUBJECT>
                <DATE>December 30, 2024.</DATE>
                <P>
                    Pursuant to Section 19(b)(1) 
                    <SU>1</SU>
                    <FTREF/>
                     of the Securities Exchange Act of 1934 (“Act”) 
                    <SU>2</SU>
                    <FTREF/>
                     and Rule 19b-4 thereunder,
                    <SU>3</SU>
                    <FTREF/>
                     notice is hereby given that on December 19, 2024, New York Stock Exchange LLC (“NYSE” or the “Exchange”) filed with the Securities and Exchange Commission (the “Commission”) the proposed rule change as described in Item I below, which Item has been prepared by the self-regulatory organization. The Exchange has designated this proposal for immediate effectiveness pursuant to Section 19(b)(3)(A) of the Act 
                    <SU>4</SU>
                    <FTREF/>
                     and Rule 19b-4(f) thereunder.
                    <SU>5</SU>
                    <FTREF/>
                     The Commission is publishing this notice to solicit comments on the proposed rule change from interested persons.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         15 U.S.C. 78s(b)(1).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         15 U.S.C. 78a.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         17 CFR 240.19b-4.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         15 U.S.C. 78s(b)(3)(A).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         17 CFR 240.19b-4(f). At any time within 60 days of the filing of the proposed rule change, the Commission summarily may temporarily suspend such rule change if it appears to the Commission that such action is necessary or appropriate in the public interest, for the protection of investors, or otherwise in furtherance of the purposes of the Act. If the Commission takes such action, the Commission will institute proceedings to determine whether the proposed rule change should be approved or disapproved.
                    </P>
                </FTNT>
                <HD SOURCE="HD1">I. Self-Regulatory Organization's Statement of the Terms of Substance of the Proposed Rule Change</HD>
                <P>The Exchange proposes to amend its Price List to (1) extend a fee waiver for new firm application fees for applicants seeking only to obtain a bond trading license (“BTL”) for 2025; and (2) waive the BTL fee for 2025.</P>
                <P>
                    The proposed rule change, including the Exchange's statement of the purpose of, and statutory basis for, the proposed rule change, is available on the Exchange's website at 
                    <E T="03">https://www.nyse.com</E>
                     and on the Commission's website at 
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-NYSE-2024-83.</E>
                </P>
                <HD SOURCE="HD1">II. Solicitation of Comments</HD>
                <P>
                    Interested persons are invited to submit written data, views, and arguments concerning the foregoing, including whether the proposed rule change is consistent with the Act.
                    <SU>6</SU>
                    <FTREF/>
                     Comments may be submitted electronically by using the Commission's internet comment form (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-NYSE-2024-83</E>
                    ) or by sending an email to 
                    <E T="03">rule-comments@sec.gov.</E>
                     Please include file number SR-NYSE-2024-83 on the subject line. Alternatively, paper comments may be sent to Secretary, Securities and Exchange Commission, 100 F Street NE, Washington, DC 20549-1090. All submissions should refer to file number SR-SR-NYSE-2024-83. To help the Commission process and review your comments more efficiently, please use only one method. The Commission will post all comments on the Commission's internet website (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-NYSE-2024-83</E>
                    ). Do not include personal identifiable information in submissions; you should submit only information that you wish 
                    <PRTPAGE P="700"/>
                    to make available publicly. We may redact in part or withhold entirely from publication submitted material that is obscene or subject to copyright protection. 
                </P>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         Copies of the submission, all subsequent amendments, all written statements with respect to the proposed rule change that are filed with the Commission, and all written communications relating to the proposed rule change between the Commission and any person, other than those that may be withheld from the public in accordance with the provisions of 5 U.S.C. 552, will be available for website viewing and printing in the Commission's Public Reference Room, 100 F Street NE, Washington, DC 20549, on official business days between the hours of 10 a.m. and 3 p.m. Copies of the filing also will be available for inspection and copying at the principal office of SRO.
                    </P>
                </FTNT>
                <P>All submissions should refer to file number SR-NYSE-2024-83 and should be submitted on or before January 27, 2025. </P>
                <SIG>
                    <P>
                        For the Commission, by the Division of Trading and Markets, pursuant to delegated authority.
                        <SU>7</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>7</SU>
                             17 CFR 200.30-3(a)(12).
                        </P>
                    </FTNT>
                    <NAME>Stephanie J. Fouse,</NAME>
                    <TITLE>Assistant Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31611 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8011-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">SECURITIES AND EXCHANGE COMMISSION</AGENCY>
                <DEPDOC>[Release No. 34-102068; File No. SR-CboeEDGA-2024-052]</DEPDOC>
                <SUBJECT>Self-Regulatory Organizations; Cboe EDGA Exchange, Inc.; Notice of Filing and Immediate Effectiveness of Proposed Rule Change To Establish Fees for Industry Members Related to Reasonably Budgeted CAT Costs of the National Market System Plan Governing the Consolidated Audit Trail for 2025</SUBJECT>
                <DATE>December 31, 2024.</DATE>
                <P>
                    Pursuant to Section 19(b)(1) of the Securities Exchange Act of 1934 (“Act”),
                    <SU>1</SU>
                    <FTREF/>
                     and Rule 19b-4 thereunder,
                    <SU>2</SU>
                    <FTREF/>
                     notice is hereby given that on December 20, 2024, Cboe EDGA Exchange, Inc. (“Exchange”) filed with the Securities and Exchange Commission (“Commission”) the proposed rule change as described in Item I below, which Item has been substantially prepared by the Exchange. The Exchange has designated this proposal for immediate effectiveness pursuant to Section 19(b)(3)(A) of the Act 
                    <SU>3</SU>
                    <FTREF/>
                     and Rule 19b-4(f) thereunder.
                    <SU>4</SU>
                    <FTREF/>
                     The Commission is publishing this notice to solicit comments on the proposed rule change from interested persons.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         15 U.S.C. 78s(b)(1).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         17 CFR 240.19b-4.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         15 U.S.C. 78s(b)(3)(A).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         17 CFR 240.19b-4(f). At any time within 60 days of the filing of the proposed rule change, the Commission summarily may temporarily suspend such rule change if it appears to the Commission that such action is necessary or appropriate in the public interest, for the protection of investors, or otherwise in furtherance of the purposes of the Act. If the Commission takes such action, the Commission will institute proceedings to determine whether the proposed rule change should be approved or disapproved.
                    </P>
                </FTNT>
                <HD SOURCE="HD1">I. Self-Regulatory Organization's Statement of the Terms of Substance of the Proposed Rule Change</HD>
                <P>The Exchange proposes to amend its “Consolidated Audit Trail Funding Fees” fee schedule to establish the CAT Fee 2025-1 fee rate of $0.000022 per executed equivalent share.</P>
                <P>
                    The proposed rule change, including the Exchange's statement of the purpose of, and statutory basis for, the proposed rule change, is available on the Exchange's website at 
                    <E T="03">http://www.cboe.com/AboutCBOE/CBOELegalRegulatoryHome.aspx,</E>
                     at the principal office of the Exchange, and on the Commission's website at 
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-CboeEDGA-2024-052.</E>
                </P>
                <HD SOURCE="HD1">II. Solicitation of Comments</HD>
                <P>
                    Interested persons are invited to submit written data, views, and arguments concerning the foregoing, including whether the proposed rule change is consistent with the Act.
                    <SU>5</SU>
                    <FTREF/>
                     Comments may be submitted electronically by using the Commission's internet comment form (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-CboeEDGA-2024-052</E>
                    ) or by sending an email to 
                    <E T="03">rule-comments@sec.gov.</E>
                     Please include file number SR-CboeEDGA-2024-052 on the subject line. Alternatively, paper comments may be sent to Secretary, Securities and Exchange Commission, 100 F Street NE, Washington, DC 20549-1090. All submissions should refer to file number SR-CboeEDGA-2024-052. To help the Commission process and review your comments more efficiently, please use only one method. The Commission will post all comments on the Commission's internet website (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-CboeEDGA-2024-052</E>
                    ). Do not include personal identifiable information in submissions; you should submit only information that you wish to make available publicly. We may redact in part or withhold entirely from publication submitted material that is obscene or subject to copyright protection. All submissions should refer to file number SR-CboeEDGA-2024-052 and should be submitted on or before January 27, 2025.
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         Copies of the submission, all subsequent amendments, all written statements with respect to the proposed rule change that are filed with the Commission, and all written communications relating to the proposed rule change between the Commission and any person, other than those that may be withheld from the public in accordance with the provisions of 5 U.S.C. 552, will be available for website viewing and printing in the Commission's Public Reference Room, 100 F Street NE, Washington, DC 20549, on official business days between the hours of 10 a.m. and 3 p.m. Copies of the filing also will be available for inspection and copying at the principal office of SRO.
                    </P>
                </FTNT>
                <SIG>
                    <P>
                        For the Commission, by the Division of Trading and Markets, pursuant to delegated authority.
                        <SU>6</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>6</SU>
                             17 CFR 200.30-3(a)(12).
                        </P>
                    </FTNT>
                    <NAME>Stephanie J. Fouse,</NAME>
                    <TITLE>Assistant Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31774 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8011-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">SECURITIES AND EXCHANGE COMMISSION</AGENCY>
                <DEPDOC>[Release No. 34-102053; File No. SR-FINRA-2024-023]</DEPDOC>
                <SUBJECT>Self-Regulatory Organizations; Financial Industry Regulatory Authority, Inc.; Notice of Filing and Immediate Effectiveness of a Proposed Rule Change To Amend FINRA Rule 6897 (Consolidated Audit Trail Funding Fees) To Establish Fees for Industry Members Related to Prospective Costs of the National Market System Plan Governing the Consolidated Audit Trail</SUBJECT>
                <DATE>December 30, 2024.</DATE>
                <P>
                    Pursuant to Section 19(b)(1) of the Securities Exchange Act of 1934 (“Act”),
                    <SU>1</SU>
                    <FTREF/>
                     and Rule 19b-4 thereunder,
                    <SU>2</SU>
                    <FTREF/>
                     notice is hereby given that on December 20, 2024, the Financial Industry Regulatory Authority, Inc. (“FINRA”) filed with the Securities and Exchange Commission (“Commission”) the proposed rule change as described in Item I below, which Item has been substantially prepared by FINRA. FINRA has designated this proposal for immediate effectiveness pursuant to Section 19(b)(3)(A) of the Act 
                    <SU>3</SU>
                    <FTREF/>
                     and Rule 19b-4(f) thereunder.
                    <SU>4</SU>
                    <FTREF/>
                     The Commission is publishing this notice to solicit comments on the proposed rule change from interested persons.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         15 U.S.C. 78s(b)(1).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         17 CFR 240.19b-4.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         15 U.S.C. 78s(b)(3)(A).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         17 CFR 240.19b-4(f). At any time within 60 days of the filing of the proposed rule change, the Commission summarily may temporarily suspend such rule change if it appears to the Commission that such action is necessary or appropriate in the public interest, for the protection of investors, or otherwise in furtherance of the purposes of the Act. If the Commission takes such action, the Commission will institute proceedings to determine whether the proposed rule change should be approved or disapproved.
                    </P>
                </FTNT>
                <PRTPAGE P="701"/>
                <HD SOURCE="HD1">I. Self-Regulatory Organization's Statement of the Terms of Substance of the Proposed Rule Change</HD>
                <P>
                    FINRA is proposing to amend FINRA Rule 6897 (Consolidated Audit Trail Funding Fees) to establish fees for Industry Members 
                    <SU>5</SU>
                    <FTREF/>
                     related to reasonably budgeted Consolidated Audit Trail (“CAT”) costs of the National Market System Plan Governing the Consolidated Audit Trail (the “CAT NMS Plan” or “Plan”) for 2025. These fees would be payable to Consolidated Audit Trail, LLC (“CAT LLC” or the “Company”) and referred to as “CAT Fee 2025-1.”
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         An “Industry Member” is defined as “a member of a national securities exchange or a member of a national securities association.” 
                        <E T="03">See</E>
                         FINRA Rule 6810(u). 
                        <E T="03">See also</E>
                         Section 1.1 of the CAT NMS Plan. Unless otherwise specified, capitalized terms used in this rule filing are defined as set forth in the CAT NMS Plan and/or the CAT Compliance Rule. 
                        <E T="03">See</E>
                         FINRA Rule 6800 Series (Consolidated Audit Trail Compliance Rule).
                    </P>
                </FTNT>
                <P>
                    The fee rate for CAT Fee 2025-1 would be $0.000022 per executed equivalent share. CAT Executing Brokers will receive their first monthly invoice for CAT Fee 2025-1 in February 2025 calculated based on their transactions as CAT Executing Brokers for the Buyer (“CEBB”) and/or CAT Executing Brokers for the Seller (“CEBS”) in January 2025. CAT Fee 2025-1 is anticipated to be in place for six months, and is anticipated to recover approximately one-half of the costs set forth in the reasonably budgeted CAT costs for 2025. CAT LLC intends for CAT Fee 2025-1 to replace CAT Fee 2024-1 (which has a fee rate of $0.000035).
                    <SU>6</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         
                        <E T="03">See</E>
                         FINRA Rule 6897(a)(1)(C) of FINRA Rule Series 6800 (Consolidated Audit Trail Compliance Rule). 
                        <E T="03">See also</E>
                         Securities Exchange Act Release No. 100881 (August 30, 2024), 89 FR 72478 (September 5, 2024) (Notice of Filing and Immediate Effectiveness of File No. SR-FINRA-2024-011) (“Fee Filing for CAT Fee 2024-1”).
                    </P>
                </FTNT>
                <P>
                    The proposed rule change, including FINRA's statement of the purpose of, and statutory basis for, the proposed rule change, is available on FINRA's website at 
                    <E T="03">https://www.finra.org,</E>
                     at the principal office of FINRA and on the Commission's website at 
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/finra?file_number=SR-FINRA-2024-023.</E>
                </P>
                <HD SOURCE="HD1">II. Solicitation of Comments</HD>
                <P>
                    Interested persons are invited to submit written data, views, and arguments concerning the foregoing, including whether the proposed rule change is consistent with the Act.
                    <SU>7</SU>
                    <FTREF/>
                     Comments may be submitted electronically by using the Commission's internet comment form (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/finra?file_number=SR-FINRA-2024-023</E>
                    ) or by sending an email to 
                    <E T="03">rule-comments@sec.gov.</E>
                     Please include file number SR-FINRA-2024-023 on the subject line. Alternatively, paper comments may be sent to Secretary, Securities and Exchange Commission, 100 F Street NE, Washington, DC 20549-1090. All submissions should refer to file number SR-FINRA-2024-023. To help the Commission process and review your comments more efficiently, please use only one method. The Commission will post all comments on the Commission's internet website (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/finra?file_number=SR-FINRA-2024-023</E>
                    ). Do not include personal identifiable information in submissions; you should submit only information that you wish to make available publicly. We may redact in part or withhold entirely from publication submitted material that is obscene or subject to copyright protection. All submissions should refer to file number SR-FINRA-2024-023 and should be submitted on or before January 27, 2025.
                </P>
                <FTNT>
                    <P>
                        <SU>7</SU>
                         Copies of the submission, all subsequent amendments, all written statements with respect to the proposed rule change that are filed with the Commission, and all written communications relating to the proposed rule change between the Commission and any person, other than those that may be withheld from the public in accordance with the provisions of 5 U.S.C. 552, will be available for website viewing and printing in the Commission's Public Reference Room, 100 F Street NE, Washington, DC 20549, on official business days between the hours of 10 a.m. and 3 p.m. Copies of the filing also will be available for inspection and copying at the principal office of SRO.
                    </P>
                </FTNT>
                <SIG>
                    <P>
                        For the Commission, by the Division of Trading and Markets, pursuant to delegated authority.
                        <SU>8</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>8</SU>
                             17 CFR 200.30-3(a)(12).
                        </P>
                    </FTNT>
                    <NAME>Stephanie J. Fouse,</NAME>
                    <TITLE>Assistant Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31612 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8011-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">SECURITIES AND EXCHANGE COMMISSION</AGENCY>
                <DEPDOC>[Release No. 34-102066; File No. SR-C2-2024-025]</DEPDOC>
                <SUBJECT>Self-Regulatory Organizations; Cboe C2 Exchange, Inc.; Notice of Filing and Immediate Effectiveness of Proposed Rule Change To Establish Fees for Industry Members Related to Reasonably Budgeted CAT Costs of the National Market System Plan Governing the Consolidated Audit Trail for 2025</SUBJECT>
                <DATE>December 31, 2024.</DATE>
                <P>
                    Pursuant to Section 19(b)(1) of the Securities Exchange Act of 1934 (“Act”),
                    <SU>1</SU>
                    <FTREF/>
                     and Rule 19b-4 thereunder,
                    <SU>2</SU>
                    <FTREF/>
                     notice is hereby given that on December 20, 2024, Cboe C2 Exchange, Inc. (“Exchange”) filed with the Securities and Exchange Commission (“Commission”) the proposed rule change as described in Item I below, which Item has been substantially prepared by the Exchange. The Exchange has designated this proposal for immediate effectiveness pursuant to Section 19(b)(3)(A) of the Act 
                    <SU>3</SU>
                    <FTREF/>
                     and Rule 19b-4(f) thereunder.
                    <SU>4</SU>
                    <FTREF/>
                     The Commission is publishing this notice to solicit comments on the proposed rule change from interested persons.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         15 U.S.C. 78s(b)(1).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         17 CFR 240.19b-4.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         15 U.S.C. 78s(b)(3)(A).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         17 CFR 240.19b-4(f). At any time within 60 days of the filing of the proposed rule change, the Commission summarily may temporarily suspend such rule change if it appears to the Commission that such action is necessary or appropriate in the public interest, for the protection of investors, or otherwise in furtherance of the purposes of the Act. If the Commission takes such action, the Commission will institute proceedings to determine whether the proposed rule change should be approved or disapproved.
                    </P>
                </FTNT>
                <HD SOURCE="HD1">I. Self-Regulatory Organization's Statement of the Terms of Substance of the Proposed Rule Change</HD>
                <P>The Exchange proposes to amend its “Consolidated Audit Trail Funding Fees” fee schedule to establish the CAT Fee 2025-1 fee rate of $0.000022 per executed equivalent share.</P>
                <P>
                    The proposed rule change, including the Exchange's statement of the purpose of, and statutory basis for, the proposed rule change, is available on the Exchange's website at 
                    <E T="03">http://www.cboe.com/AboutCBOE/CBOELegalRegulatoryHome.aspx,</E>
                     at the principal office of the Exchange, and on the Commission's website at 
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-C2-2024-025.</E>
                    <PRTPAGE P="702"/>
                </P>
                <HD SOURCE="HD1">II. Solicitation of Comments</HD>
                <P>
                    Interested persons are invited to submit written data, views, and arguments concerning the foregoing, including whether the proposed rule change is consistent with the Act.
                    <SU>5</SU>
                    <FTREF/>
                     Comments may be submitted electronically by using the Commission's internet comment form (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-C2-2024-025</E>
                    ) or by sending an email to 
                    <E T="03">rule-comments@sec.gov.</E>
                     Please include file number SR-C2-2024-025 on the subject line. Alternatively, paper comments may be sent to Secretary, Securities and Exchange Commission, 100 F Street NE, Washington, DC 20549-1090. All submissions should refer to file number SR-C2-2024-025. To help the Commission process and review your comments more efficiently, please use only one method. The Commission will post all comments on the Commission's internet website (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-C2-2024-025</E>
                    ). Do not include personal identifiable information in submissions; you should submit only information that you wish to make available publicly. We may redact in part or withhold entirely from publication submitted material that is obscene or subject to copyright protection. All submissions should refer to file number SR-C2-2024-025 and should be submitted on or before January 27, 2025.
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         Copies of the submission, all subsequent amendments, all written statements with respect to the proposed rule change that are filed with the Commission, and all written communications relating to the proposed rule change between the Commission and any person, other than those that may be withheld from the public in accordance with the provisions of 5 U.S.C. 552, will be available for website viewing and printing in the Commission's Public Reference Room, 100 F Street NE, Washington, DC 20549, on official business days between the hours of 10 a.m. and 3 p.m. Copies of the filing also will be available for inspection and copying at the principal office of SRO.
                    </P>
                </FTNT>
                <SIG>
                    <P>
                        For the Commission, by the Division of Trading and Markets, pursuant to delegated authority.
                        <SU>6</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>6</SU>
                             17 CFR 200.30-3(a)(12).
                        </P>
                    </FTNT>
                    <NAME>Stephanie J. Fouse,</NAME>
                    <TITLE>Assistant Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31772 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8011-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">SECURITIES AND EXCHANGE COMMISSION</AGENCY>
                <DEPDOC>[Release No. 34-102063; File No. SR-CBOE-2024-059]</DEPDOC>
                <SUBJECT>Self-Regulatory Organizations; Cboe Exchange, Inc.; Notice of Filing and Immediate Effectiveness of Proposed Rule Change To Establish Fees for Industry Members Related to Reasonably Budgeted CAT Costs of the National Market System Plan Governing the Consolidated Audit Trail for 2025</SUBJECT>
                <DATE>December 31, 2024.</DATE>
                <P>
                    Pursuant to Section 19(b)(1) of the Securities Exchange Act of 1934 (“Act”),
                    <SU>1</SU>
                    <FTREF/>
                     and Rule 19b-4 thereunder,
                    <SU>2</SU>
                    <FTREF/>
                     notice is hereby given that on December 20, 2024, Cboe Exchange, Inc. (“Exchange”) filed with the Securities and Exchange Commission (“Commission”) the proposed rule change as described in Item I below, which Item has been substantially prepared by the Exchange. The Exchange has designated this proposal for immediate effectiveness pursuant to Section 19(b)(3)(A) of the Act 
                    <SU>3</SU>
                    <FTREF/>
                     and Rule 19b-4(f) thereunder.
                    <SU>4</SU>
                    <FTREF/>
                     The Commission is publishing this notice to solicit comments on the proposed rule change from interested persons.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         15 U.S.C. 78s(b)(1).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         17 CFR 240.19b-4.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         15 U.S.C. 78s(b)(3)(A).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         17 CFR 240.19b-4(f). At any time within 60 days of the filing of the proposed rule change, the Commission summarily may temporarily suspend such rule change if it appears to the Commission that such action is necessary or appropriate in the public interest, for the protection of investors, or otherwise in furtherance of the purposes of the Act. If the Commission takes such action, the Commission will institute proceedings to determine whether the proposed rule change should be approved or disapproved.
                    </P>
                </FTNT>
                <HD SOURCE="HD1">I. Self-Regulatory Organization's Statement of the Terms of Substance of the Proposed Rule Change</HD>
                <P>The Exchange proposes to amend its “Consolidated Audit Trail Funding Fees” fee schedule to establish the CAT Fee 2025-1 fee rate of $0.000022 per executed equivalent share.</P>
                <P>
                    The proposed rule change, including the Exchange's statement of the purpose of, and statutory basis for, the proposed rule change, is available on the Exchange's website at 
                    <E T="03">http://www.cboe.com/AboutCBOE/CBOELegalRegulatoryHome.aspx,</E>
                     at the principal office of the Exchange, and on the Commission's website at 
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-CBOE-2024-059.</E>
                </P>
                <HD SOURCE="HD1">II. Solicitation of Comments</HD>
                <P>
                    Interested persons are invited to submit written data, views, and arguments concerning the foregoing, including whether the proposed rule change is consistent with the Act.
                    <SU>5</SU>
                    <FTREF/>
                     Comments may be submitted electronically by using the Commission's internet comment form (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-CBOE-2024-059</E>
                    ) or by sending an email to 
                    <E T="03">rule-comments@sec.gov.</E>
                     Please include file number SR-CBOE-2024-059 on the subject line. Alternatively, paper comments may be sent to Secretary, Securities and Exchange Commission, 100 F Street NE, Washington, DC 20549-1090. All submissions should refer to file number SR-CBOE-2024-059. To help the Commission process and review your comments more efficiently, please use only one method. The Commission will post all comments on the Commission's internet website (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-CBOE-2024-059</E>
                    ). Do not include personal identifiable information in submissions; you should submit only information that you wish to make available publicly. We may redact in part or withhold entirely from publication submitted material that is obscene or subject to copyright protection. All submissions should refer to file number SR-CBOE-2024-059 and should be submitted on or before January 27, 2025.
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         Copies of the submission, all subsequent amendments, all written statements with respect to the proposed rule change that are filed with the Commission, and all written communications relating to the proposed rule change between the Commission and any person, other than those that may be withheld from the public in accordance with the provisions of 5 U.S.C. 552, will be available for website viewing and printing in the Commission's Public Reference Room, 100 F Street NE, Washington, DC 20549, on official business days between the hours of 10 a.m. and 3 p.m. Copies of the filing also will be available for inspection and copying at the principal office of SRO.
                    </P>
                </FTNT>
                <SIG>
                    <P>
                        For the Commission, by the Division of Trading and Markets, pursuant to delegated authority.
                        <SU>6</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>6</SU>
                             17 CFR 200.30-3(a)(12).
                        </P>
                    </FTNT>
                    <NAME>Stephanie J. Fouse,</NAME>
                    <TITLE>Assistant Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31769 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8011-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <PRTPAGE P="703"/>
                <AGENCY TYPE="S">SECURITIES AND EXCHANGE COMMISSION</AGENCY>
                <DEPDOC>[Release No. 34-102062; File No. SR-FINRA-2024-024]</DEPDOC>
                <SUBJECT>Self-Regulatory Organizations; Financial Industry Regulatory Authority, Inc.; Notice of Filing and Immediate Effectiveness of a Proposed Rule Change To Amend FINRA Rule 6897(b) (CAT Cost Recovery Fees) To Implement a Consolidated Audit Trail Cost Recovery Fee</SUBJECT>
                <DATE>December 31, 2024.</DATE>
                <P>
                    Pursuant to Section 19(b)(1) of the Securities Exchange Act of 1934 (“Act”),
                    <SU>1</SU>
                    <FTREF/>
                     and Rule 19b-4 thereunder,
                    <SU>2</SU>
                    <FTREF/>
                     notice is hereby given that on December 20, 2024, the Financial Industry Regulatory Authority, Inc. (“FINRA”) filed with the Securities and Exchange Commission (“Commission”) the proposed rule change as described in Item I below, which Item has been substantially prepared by FINRA. FINRA has designated this proposal for immediate effectiveness pursuant to Section 19(b)(3)(A) of the Act 
                    <SU>3</SU>
                    <FTREF/>
                     and Rule 19b-4(f) thereunder.
                    <SU>4</SU>
                    <FTREF/>
                     The Commission is publishing this notice to solicit comments on the proposed rule change from interested persons.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         15 U.S.C. 78s(b)(1).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         17 CFR 240.19b-4.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         15 U.S.C. 78s(b)(3)(A).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         17 CFR 240.19b-4(f). At any time within 60 days of the filing of the proposed rule change, the Commission summarily may temporarily suspend such rule change if it appears to the Commission that such action is necessary or appropriate in the public interest, for the protection of investors, or otherwise in furtherance of the purposes of the Act. If the Commission takes such action, the Commission will institute proceedings to determine whether the proposed rule change should be approved or disapproved.
                    </P>
                </FTNT>
                <HD SOURCE="HD1">I. Self-Regulatory Organization's Statement of the Terms of Substance of the Proposed Rule Change</HD>
                <P>
                    FINRA is proposing to amend FINRA Rule 6897(b) (CAT Cost Recovery Fees) to implement a Consolidated Audit Trail (“CAT”) cost recovery fee designed to permit FINRA to recoup its designated portion of the reasonably budgeted CAT costs of the National Market System Plan Governing the Consolidated Audit Trail (the “CAT NMS Plan” or “Plan”) for the period of January 1, 2025 through December 31, 2025.
                    <SU>5</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         Pursuant to Section 11.3(a) of the CAT NMS Plan, FINRA filed a separate proposed rule change to establish fees assessed to Industry Members, payable to Consolidated Audit Trail, LLC, related to the recovery of approximately one-half of the reasonably budgeted CAT costs for the period of January 1, 2025 through December 31, 2025. 
                        <E T="03">See</E>
                         File No. SR-FINRA-2024-023. Unless otherwise specified, capitalized terms used in this rule filing are defined as set forth in the CAT NMS Plan and FINRA Rule 6800 Series (Consolidated Audit Trail Compliance Rule).
                    </P>
                </FTNT>
                <P>
                    The proposed rule change, including FINRA's statement of the purpose of, and statutory basis for, the proposed rule change, is available on FINRA's website at 
                    <E T="03">https://www.finra.org,</E>
                     at the principal office of FINRA and on the Commission's website at 
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/finra?file_number=SR-FINRA-2024-024.</E>
                </P>
                <HD SOURCE="HD1">II. Solicitation of Comments</HD>
                <P>
                    Interested persons are invited to submit written data, views, and arguments concerning the foregoing, including whether the proposed rule change is consistent with the Act.
                    <SU>6</SU>
                    <FTREF/>
                     Comments may be submitted electronically by using the Commission's internet comment form (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/finra?file_number=SR-FINRA-2024-024</E>
                    ) or by sending an email to 
                    <E T="03">rule-comments@sec.gov.</E>
                     Please include file number SR-FINRA-2024-024 on the subject line. Alternatively, paper comments may be sent to Secretary, Securities and Exchange Commission, 100 F Street NE, Washington, DC 20549-1090. All submissions should refer to file number SR-FINRA-2024-024. To help the Commission process and review your comments more efficiently, please use only one method. The Commission will post all comments on the Commission's internet website (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/finra?file_number=SR-FINRA-2024-024</E>
                    ). Do not include personal identifiable information in submissions; you should submit only information that you wish to make available publicly. We may redact in part or withhold entirely from publication submitted material that is obscene or subject to copyright protection. All submissions should refer to file number SR-FINRA-2024-024 and should be submitted on or before January 27, 2025.
                </P>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         Copies of the submission, all subsequent amendments, all written statements with respect to the proposed rule change that are filed with the Commission, and all written communications relating to the proposed rule change between the Commission and any person, other than those that may be withheld from the public in accordance with the provisions of 5 U.S.C. 552, will be available for website viewing and printing in the Commission's Public Reference Room, 100 F Street NE, Washington, DC 20549, on official business days between the hours of 10 a.m. and 3 p.m. Copies of the filing also will be available for inspection and copying at the principal office of SRO.
                    </P>
                </FTNT>
                <SIG>
                    <P>
                        For the Commission, by the Division of Trading and Markets, pursuant to delegated authority.
                        <SU>7</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>7</SU>
                             17 CFR 200.30-3(a)(12).
                        </P>
                    </FTNT>
                    <NAME>Stephanie J. Fouse,</NAME>
                    <TITLE>Assistant Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31768 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8011-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">SECURITIES AND EXCHANGE COMMISSION</AGENCY>
                <DEPDOC>[Release No. 34-102067; File No. SR-CboeBZX-2024-130]</DEPDOC>
                <SUBJECT>Self-Regulatory Organizations; Cboe BZX Exchange, Inc.; Notice of Filing and Immediate Effectiveness of Proposed Rule Change To Establish Fees for Industry Members Related to Reasonably Budgeted CAT Costs of the National Market System Plan Governing the Consolidated Audit Trail for 2025</SUBJECT>
                <DATE>December 31, 2024.</DATE>
                <P>
                    Pursuant to Section 19(b)(1) of the Securities Exchange Act of 1934 (“Act”),
                    <SU>1</SU>
                    <FTREF/>
                     and Rule 19b-4 thereunder,
                    <SU>2</SU>
                    <FTREF/>
                     notice is hereby given that on December 20, 2024, Cboe BZX Exchange, Inc. (“Exchange”) filed with the Securities and Exchange Commission (“Commission”) the proposed rule change as described in Item I below, which Item has been substantially prepared by the Exchange. The Exchange has designated this proposal for immediate effectiveness pursuant to Section 19(b)(3)(A) of the Act 
                    <SU>3</SU>
                    <FTREF/>
                     and Rule 19b-4(f) thereunder.
                    <SU>4</SU>
                    <FTREF/>
                     The Commission is publishing this notice to solicit comments on the proposed rule change from interested persons.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         15 U.S.C. 78s(b)(1).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         17 CFR 240.19b-4.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         15 U.S.C. 78s(b)(3)(A).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         17 CFR 240.19b-4(f). At any time within 60 days of the filing of the proposed rule change, the Commission summarily may temporarily suspend such rule change if it appears to the Commission that such action is necessary or appropriate in the public interest, for the protection of investors, or otherwise in furtherance of the purposes of the Act. If the Commission takes such action, the Commission will institute proceedings to determine whether the proposed rule change should be approved or disapproved.
                    </P>
                </FTNT>
                <HD SOURCE="HD1">I. Self-Regulatory Organization's Statement of the Terms of Substance of the Proposed Rule Change</HD>
                <P>The Exchange proposes to amend its “Consolidated Audit Trail Funding Fees” fee schedule to establish the CAT Fee 2025-1 fee rate of $0.000022 per executed equivalent share.</P>
                <P>
                    The proposed rule change, including the Exchange's statement of the purpose of, and statutory basis for, the proposed 
                    <PRTPAGE P="704"/>
                    rule change, is available on the Exchange's website at 
                    <E T="03">http://www.cboe.com/AboutCBOE/CBOELegalRegulatoryHome.aspx,</E>
                     at the principal office of the Exchange, and on the Commission's website at 
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-CboeBZX-2024-130.</E>
                </P>
                <HD SOURCE="HD1">II. Solicitation of Comments</HD>
                <P>
                    Interested persons are invited to submit written data, views, and arguments concerning the foregoing, including whether the proposed rule change is consistent with the Act.
                    <SU>5</SU>
                    <FTREF/>
                     Comments may be submitted electronically by using the Commission's internet comment form (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-CboeBZX-2024-130</E>
                    ) or by sending an email to 
                    <E T="03">rule-comments@sec.gov.</E>
                     Please include file number SR-CboeBZX-2024-130 on the subject line. Alternatively, paper comments may be sent to Secretary, Securities and Exchange Commission, 100 F Street NE, Washington, DC 20549-1090. All submissions should refer to file number SR-CboeBZX-2024-130. To help the Commission process and review your comments more efficiently, please use only one method. The Commission will post all comments on the Commission's internet website (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-CboeBZX-2024-130</E>
                    ). Do not include personal identifiable information in submissions; you should submit only information that you wish to make available publicly. We may redact in part or withhold entirely from publication submitted material that is obscene or subject to copyright protection. All submissions should refer to file number SR-CboeBZX-2024-130 and should be submitted on or before January 27, 2025.
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         Copies of the submission, all subsequent amendments, all written statements with respect to the proposed rule change that are filed with the Commission, and all written communications relating to the proposed rule change between the Commission and any person, other than those that may be withheld from the public in accordance with the provisions of 5 U.S.C. 552, will be available for website viewing and printing in the Commission's Public Reference Room, 100 F Street NE, Washington, DC 20549, on official business days between the hours of 10 a.m. and 3 p.m. Copies of the filing also will be available for inspection and copying at the principal office of SRO.
                    </P>
                </FTNT>
                <SIG>
                    <P>
                        For the Commission, by the Division of Trading and Markets, pursuant to delegated authority.
                        <SU>6</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>6</SU>
                             17 CFR 200.30-3(a)(12).
                        </P>
                    </FTNT>
                    <NAME>Stephanie J. Fouse,</NAME>
                    <TITLE>Assistant Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31773 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8011-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">SECURITIES AND EXCHANGE COMMISSION</AGENCY>
                <DEPDOC>[Release No. 34-102065; File No. SR-ISE-2024-62]</DEPDOC>
                <SUBJECT>Self-Regulatory Organizations; Nasdaq ISE, LLC; Notice of Filing of Proposed Rule Change To Increase the Position and Exercise Limits for iShares Bitcoin Trust ETF</SUBJECT>
                <DATE>December 31, 2024.</DATE>
                <P>
                    Pursuant to Section 19(b)(1) of the Securities Exchange Act of 1934 (“Act”),
                    <SU>1</SU>
                    <FTREF/>
                     and Rule 19b-4 thereunder,
                    <SU>2</SU>
                    <FTREF/>
                     notice is hereby given that on December 20, 2024, Nasdaq ISE, LLC (“ISE” or “Exchange”) filed with the Securities and Exchange Commission (“Commission”) the proposed rule change as described in Items I and II below, which Items have been prepared by ISE. The Commission is publishing this notice to solicit comments on the proposed rule change from interested persons.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         15 U.S.C. 78s(b)(1).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         17 CFR 240.19b-4.
                    </P>
                </FTNT>
                <HD SOURCE="HD1">I. Self-Regulatory Organization's Statement of the Terms of Substance of the Proposed Rule Change</HD>
                <P>The Exchange proposes to amend Options 9, Sections 13 and 15 to propose an increase to the position and exercise limits for iShares Bitcoin Trust ETF (“IBIT”).</P>
                <P>
                    The text of the proposed rule change is available on the Exchange's website at 
                    <E T="03">https://listingcenter.nasdaq.com/rulebook/ise/rules,</E>
                     at the principal office of the Exchange, and at the Commission's Public Reference Room.
                </P>
                <HD SOURCE="HD1">II. Self-Regulatory Organization's Statement of the Purpose of, and Statutory Basis for, the Proposed Rule Change</HD>
                <P>In its filing with the Commission, the Exchange included statements concerning the purpose of and basis for the proposed rule change and discussed any comments it received on the proposed rule change. The text of these statements may be examined at the places specified in Item IV below. The Exchange has prepared summaries, set forth in sections A, B, and C below, of the most significant aspects of such statements.</P>
                <HD SOURCE="HD2">A. Self-Regulatory Organization's Statement of the Purpose of, and Statutory Basis for, the Proposed Rule Change</HD>
                <HD SOURCE="HD3">1. Purpose</HD>
                <P>The Exchange proposes to amend Options 9, Section 13, Position Limits, and Options 9, Section 15, Exercise Limits, to increase the position and exercise limits for options on IBIT from 25,000 to 250,000 contracts.</P>
                <P>
                    IBIT is an Exchange-Traded Fund (“ETF”) that holds bitcoin and is listed on The Nasdaq Stock Market LLC.
                    <SU>3</SU>
                    <FTREF/>
                     On September 20, 2024, ISE received approval to list options on IBIT.
                    <SU>4</SU>
                    <FTREF/>
                     The position and exercise limits for IBIT options are 25,000 contracts as stated in Options 9, Sections 13 and 15, the lowest limit available in options.
                    <SU>5</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         Nasdaq received approval to list and trade Bitcoin-Based Commodity-Based Trust Shares in IBIT pursuant to Rule 5711(d) of Nasdaq. 
                        <E T="03">See</E>
                         Securities Exchange Act Release No. 99306 (January 10, 2024), 89 FR 3008 (January 17, 2024) (SR-NASDAQ-2023-016) (Order Granting Accelerated Approval of Proposed Rule Changes, as Modified by Amendments Thereto, To List and Trade Bitcoin-Based Commodity-Based Trust Shares and Trust Units). IBIT started trading on January 11, 2024.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         
                        <E T="03">See</E>
                         Securities Exchange Act Release No. 101128 (September 20, 2024), 89 FR 78942 (September 26, 2024) (SR-ISE-2024-03) (Notice of Filing of Amendment Nos. 4 and 5 and Order Granting Accelerated Approval of a Proposed Rule Change, as Modified by Amendment Nos. 1, 4, and 5, To Permit the Listing and Trading of Options on the iShares Bitcoin Trust) (“IBIT Approval Order”). ISE began trading IBIT options on November 19, 2024.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         Options on Fidelity Wise Origin Bitcoin Fund, ARK 21Shares Bitcoin ETF, Grayscale Bitcoin Trust (BTC), Grayscale Bitcoin Mini Trust BTC, and Bitwise Bitcoin ETF are also subject to a 25,000 contract position and exercise limit.
                    </P>
                </FTNT>
                <P>
                    Per the Commission “rules regarding position and exercise limits are intended to prevent the establishment of options positions that can be used or might create incentives to manipulate or disrupt the underlying market so as to benefit the options positions.” 
                    <SU>6</SU>
                    <FTREF/>
                     For this reason, the Commission requires that “position and exercise limits must be sufficient to prevent investors from disrupting the market for the underlying security by acquiring and exercising a number of options contracts disproportionate to the deliverable supply and average trading volume of the underlying security.” 
                    <SU>7</SU>
                    <FTREF/>
                     Based on its review of the data and analysis provided by the Exchange, the Commission concluded that the 25,000 contract position limit for non-FLEX IBIT options satisfied these objectives.
                    <SU>8</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         
                        <E T="03">See supra</E>
                         note 4, IBIT Approval Order, 89 FR 78946.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>7</SU>
                         
                        <E T="03">See id.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>8</SU>
                         
                        <E T="03">See id.</E>
                    </P>
                </FTNT>
                <PRTPAGE P="705"/>
                <P>
                    While the Exchange proposed an aggregated 25,000 contract position limit for IBIT options in its IBIT Approval Order, it nonetheless believed that evidence existed to support a much higher position limit. Specifically, the Commission has considered and reviewed the Exchange's analysis in its IBIT Approval Order that the exercisable risk associated with a position limit of 25,000 contracts represented only 0.4% of the outstanding shares of IBIT.
                    <SU>9</SU>
                    <FTREF/>
                     The Commission also has considered and reviewed the Exchange's statement its IBIT Approval Order that with a position limit of 25,000 contracts on the same side of the market and 611,040,00 shares of IBIT outstanding, 244 market participants would have to simultaneously exercise their positions to place IBIT under stress.
                    <SU>10</SU>
                    <FTREF/>
                     Based on the Commission's review of this information and analysis, the Commission concluded that the proposed position and exercise limits of 25,000 contracts were designed to prevent investors from disrupting the market for the underlying security by acquiring and exercising a number of options contracts disproportionate to the deliverable supply and average trading volume of the underlying security, and to prevent the establishment of options positions that can be used or might create incentives to manipulate or disrupt the underlying market so as to benefit the options position.
                    <SU>11</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>9</SU>
                         
                        <E T="03">See id.</E>
                         Data represents figures from August 12, 2024.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>10</SU>
                         
                        <E T="03">See id.</E>
                         Data represents figures from August 12, 2024.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>11</SU>
                         
                        <E T="03">See id.</E>
                    </P>
                </FTNT>
                <P>
                    IBIT currently qualifies for a 250,000 contract position limit pursuant to the criteria in Options 9, Section 13(g), which requires that, for the most recent six-month period, trading volume for the underlying security be at least 100,000,000 shares.
                    <SU>12</SU>
                    <FTREF/>
                     As of November 25, 2024, the market capitalization for IBIT was $46,783,480,800 
                    <SU>13</SU>
                    <FTREF/>
                     with an average daily volume (“ADV”), for the preceding three months prior to November 25, 2024, of 39,421,877 shares. IBIT is well above the requisite minimum of 100,000,000 shares necessary to qualify for the 250,000 contract position limit. Also, as of November 25, 2024, there are 19,787,762 bitcoins in circulation.
                    <SU>14</SU>
                    <FTREF/>
                     At a price of $94,830,
                    <SU>15</SU>
                    <FTREF/>
                     that equates to a market capitalization of greater than $1.876 trillion US. If a position limit of 250,000 contracts were considered, the exercisable risk would represent 2.89% 
                    <SU>16</SU>
                    <FTREF/>
                     of the outstanding shares outstanding of IBIT. Given IBIT's liquidity, the current 25,000 position limit is extremely conservative.
                </P>
                <FTNT>
                    <P>
                        <SU>12</SU>
                         Options 9, Section 13(g), Equity Option Position Limits, provides at subparagraph (i) that the position limit shall be 250,000 contracts for options: (a) on an underlying stock or Exchange-Traded Fund Share which had trading volume of at least 100,000,000 shares during the most recent six-month trading period; or (b) on an underlying stock or Exchange-Traded Fund Share which had trading volume of at least 75,000,000 shares during the most recent six-month trading period and has at least 300,000,000 shares currently outstanding.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>13</SU>
                         The market capitalization was determined by multiplying a settlement price of ($54.02) by the number of shares outstanding (866,040,000). This figure was acquired as of November 25, 2024. 
                        <E T="03">See https://www.ishares.com/us/products/333011/ishares-bitcoin-trust-etf.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>14</SU>
                         
                        <E T="03">See https://www.coingecko.com/en/coins/bitcoin.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>15</SU>
                         This is the approximate price of bitcoin from 4:00pm ET on November 25, 2024.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>16</SU>
                         This percentage is arrived at with this equation: (250,000 contract limit * 100 shares per option/866,040,000 shares outstanding).
                    </P>
                </FTNT>
                <P>Position limits, and exercise limits, are designed to limit the number of options contracts traded on the exchange in an underlying security that an investor, acting alone or in concert with others directly or indirectly, may control. These limits, which are described in ISE Options 9, Sections 13 and 15, are intended to address potential manipulative schemes and adverse market impacts surrounding the use of options, such as disrupting the market in the security underlying the options. Position and exercise limits must balance concerns regarding mitigating potential manipulation and the cost of inhibiting potential hedging activity that could be used for legitimate economic purposes. To achieve this balance, ISE proposes to increase IBIT's position and exercise limits from 25,000 to 250,000 contracts. ISE believes that 250,000 contracts is the appropriate position and exercise limit based on its analysis described below.</P>
                <P>
                    First, ISE considered IBIT's market capitalization and Average Daily Volume (“ADV”), and prospective position limit in relation to other securities. In measuring IBIT against other securities, ISE aggregated market capitalization and volume data for securities that have defined position limits utilizing data from The Options Clearing Corporations (“OCC”).
                    <SU>17</SU>
                    <FTREF/>
                     This pool of data took into consideration 3,897 options on single stock securities, excluding broad based ETFs.
                    <SU>18</SU>
                    <FTREF/>
                     Next, the data was aggregated based on market capitalization and ADV and grouped by option symbol and position limit utilizing statistical thresholds for ADV, based on ninety days, and market capitalization that were one standard deviation above the mean for each position limit category (
                    <E T="03">i.e.,</E>
                     25,000, 50,000 to 65,000, 75,000, 100,000 to less than 250,000, and 250,000).
                    <SU>19</SU>
                    <FTREF/>
                     This exercise was performed to demonstrate IBIT's position limit relative to other options symbols in terms of market capitalization and ADV. For reference, the market capitalization for IBIT was $46,783,480,800 
                    <SU>20</SU>
                    <FTREF/>
                     with an ADV, for the preceding three months prior to November 25, 2024, of 39,421,877 shares.
                </P>
                <FTNT>
                    <P>
                        <SU>17</SU>
                         The computations are based on OCC data from November 25, 2024. Data displaying zero values in market capitalization or ADV were removed.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>18</SU>
                         IBIT has one asset and therefore is not comparable to a broad based ETF where there are typically multiple components.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>19</SU>
                         ISE Options 9, Section 13(d) sets out position limits for various contracts. For example, a 25,000 contract limit applies to those options having an underlying security that does not meet the requirements for a higher options contract limit. The Exchange notes that position limits may also be higher due to corporate actions in the underlying equities, such as a stock split. 
                        <E T="03">See https://www.theocc.com/market-data/market-data-reports/series-and-trading-data/position-limits.</E>
                         As a result, the Exchange's pool of data considered higher position limits than 250,000 contracts, where applicable.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>20</SU>
                         The market capitalization was determined by multiplying a settlement price of ($54.02) by the number of shares outstanding (866,040,000). This figure was acquired as of November 25, 2024. 
                        <E T="03">See https://www.ishares.com/us/products/333011/ishares-bitcoin-trust-etf.</E>
                    </P>
                </FTNT>
                <GPOTABLE COLS="8" OPTS="L2,tp0,p7,7/8,i1" CDEF="s50,14,14,14,14,16,16,16">
                    <TTITLE> </TTITLE>
                    <BOXHD>
                        <CHED H="1">
                            Market cap 
                            <LI>statistics</LI>
                        </CHED>
                        <CHED H="1">25k</CHED>
                        <CHED H="1">50k</CHED>
                        <CHED H="1">75k</CHED>
                        <CHED H="1">100k-&lt;250k</CHED>
                        <CHED H="1">250k-&lt;500k</CHED>
                        <CHED H="1">500k-1mm</CHED>
                        <CHED H="1">&gt;1mm</CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01"># of observations</ENT>
                        <ENT>562</ENT>
                        <ENT>473</ENT>
                        <ENT>651</ENT>
                        <ENT>240</ENT>
                        <ENT>1934</ENT>
                        <ENT>27</ENT>
                        <ENT>10</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">average</ENT>
                        <ENT>1,038,795,162</ENT>
                        <ENT>2,957,127,045</ENT>
                        <ENT>4,466,049,699</ENT>
                        <ENT>5,390,836,360</ENT>
                        <ENT>26,286,624,063</ENT>
                        <ENT>67,390,777,100</ENT>
                        <ENT>717,540,906,097</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">median</ENT>
                        <ENT>360,130,143</ENT>
                        <ENT>889,627,570</ENT>
                        <ENT>1,445,831,231</ENT>
                        <ENT>1,643,123,279</ENT>
                        <ENT>3,535,963,213</ENT>
                        <ENT>27,063,940,966</ENT>
                        <ENT>90,047,209,478</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">min</ENT>
                        <ENT>2,204,436</ENT>
                        <ENT>4,211,156</ENT>
                        <ENT>3,830,532</ENT>
                        <ENT>5,090,230</ENT>
                        <ENT>1,616,094</ENT>
                        <ENT>2,762,394,749</ENT>
                        <ENT>11,786,645,969</ENT>
                    </ROW>
                    <ROW RUL="n,s">
                        <ENT I="01">max</ENT>
                        <ENT>36,120,249,097</ENT>
                        <ENT>70,846,805,916</ENT>
                        <ENT>174,820,296,591</ENT>
                        <ENT>106,971,594,180</ENT>
                        <ENT>3,573,884,443,220</ENT>
                        <ENT>733,972,714,698</ENT>
                        <ENT>3,358,647,600,000</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">IBIT % rank</ENT>
                        <ENT>100.00%</ENT>
                        <ENT>98.94%</ENT>
                        <ENT>98.77%</ENT>
                        <ENT>98.33%</ENT>
                        <ENT>88.57%</ENT>
                        <ENT>59.26%</ENT>
                        <ENT>20.00%</ENT>
                    </ROW>
                </GPOTABLE>
                <PRTPAGE P="706"/>
                <GPOTABLE COLS="8" OPTS="L2,tp0,p7,7/8,i1" CDEF="s50,14,14,14,14,16,16,16">
                    <TTITLE> </TTITLE>
                    <BOXHD>
                        <CHED H="1">
                            90-Day ADV 
                            <LI>statistics</LI>
                        </CHED>
                        <CHED H="1">25k</CHED>
                        <CHED H="1">50k</CHED>
                        <CHED H="1">75k</CHED>
                        <CHED H="1">100k-&lt;250k</CHED>
                        <CHED H="1">250k-&lt;500k</CHED>
                        <CHED H="1">500k-1mm</CHED>
                        <CHED H="1">&gt;1mm</CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01"># of observations</ENT>
                        <ENT>562</ENT>
                        <ENT>473</ENT>
                        <ENT>651</ENT>
                        <ENT>240</ENT>
                        <ENT>1934</ENT>
                        <ENT>27</ENT>
                        <ENT>10</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">average</ENT>
                        <ENT>76,586</ENT>
                        <ENT>213,419</ENT>
                        <ENT>425,542</ENT>
                        <ENT>623,888</ENT>
                        <ENT>3,510,784</ENT>
                        <ENT>5,930,607</ENT>
                        <ENT>44,610,385</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">median</ENT>
                        <ENT>67,231</ENT>
                        <ENT>206,402</ENT>
                        <ENT>409,177</ENT>
                        <ENT>625,882</ENT>
                        <ENT>1,620,931</ENT>
                        <ENT>4,724,248</ENT>
                        <ENT>18,017,607</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">min</ENT>
                        <ENT>4,791</ENT>
                        <ENT>10,084</ENT>
                        <ENT>18,191</ENT>
                        <ENT>105,713</ENT>
                        <ENT>16,276</ENT>
                        <ENT>1,207,242</ENT>
                        <ENT>1,771,544</ENT>
                    </ROW>
                    <ROW RUL="n,s">
                        <ENT I="01">max</ENT>
                        <ENT>244,499</ENT>
                        <ENT>564,451</ENT>
                        <ENT>989,341</ENT>
                        <ENT>1,339,553</ENT>
                        <ENT>88,351,060</ENT>
                        <ENT>22,397,311</ENT>
                        <ENT>271,230,790</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="03">IBIT % rank</ENT>
                        <ENT>100.00%</ENT>
                        <ENT>100.00%</ENT>
                        <ENT>100.00%</ENT>
                        <ENT>100.00%</ENT>
                        <ENT>99.43%</ENT>
                        <ENT>100.00%</ENT>
                        <ENT>80.00%</ENT>
                    </ROW>
                </GPOTABLE>
                <P>Based on the above table, if IBIT were compared to the 1,934 stocks that have position limits of 250,000 contracts to less than 500,000 contracts it would rank in the 88th percentile for market capitalization and the 99th percentile for ADV.</P>
                <P>
                    The Exchange also analyzed the position limits for IBIT by regressing the market capitalization figures and 90-day ADV of all non-ETF equities, against their respective position limit figures. From this regression, the Exchange was able to determine the implied coefficients to create a formulaic method for determining an appropriate position limit.
                    <SU>21</SU>
                    <FTREF/>
                     In this case, the modeled position limit is 565,796 contracts.
                    <SU>22</SU>
                    <FTREF/>
                     The results of the study are below.
                </P>
                <FTNT>
                    <P>
                        <SU>21</SU>
                         The Exchange utilized Excel's Data Analysis Package to model the position limit.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>22</SU>
                         The Exchange utilized this formula to arrive at the number of contracts: ((46,783,380,800 mkt cap * 0.0000002630 market cap coefficient) + (39,421,877 ADV * 0.0140402219 ADV coefficient)).
                    </P>
                </FTNT>
                <GPOTABLE COLS="2" OPTS="L2,nj,p1,8/9,i1" CDEF="s50,14">
                    <TTITLE>Regression Statistics</TTITLE>
                    <BOXHD>
                        <CHED H="1"> </CHED>
                        <CHED H="1"> </CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">Multiple R</ENT>
                        <ENT>0.496800597</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">R Square</ENT>
                        <ENT>0.246810833</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Adjusted R Square</ENT>
                        <ENT>0.246361643</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Standard Error</ENT>
                        <ENT>202227.4271</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Observations</ENT>
                        <ENT>3905</ENT>
                    </ROW>
                </GPOTABLE>
                <GPOTABLE COLS="5" OPTS="L2,i1" CDEF="s50,12,12,12,12">
                    <TTITLE>ANOVA</TTITLE>
                    <BOXHD>
                        <CHED H="1"> </CHED>
                        <CHED H="1">df</CHED>
                        <CHED H="1">SS</CHED>
                        <CHED H="1">MS</CHED>
                        <CHED H="1">F</CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">Regression</ENT>
                        <ENT>2</ENT>
                        <ENT>5.2304E+13</ENT>
                        <ENT>2.6152E+13</ENT>
                        <ENT>639.482566</ENT>
                    </ROW>
                    <ROW RUL="n,s">
                        <ENT I="01">Residual</ENT>
                        <ENT>3903</ENT>
                        <ENT>1.5962E+14</ENT>
                        <ENT>4.0896E+10</ENT>
                        <ENT/>
                    </ROW>
                    <ROW RUL="s">
                        <ENT I="03">Total</ENT>
                        <ENT>3905</ENT>
                        <ENT>2.1192E+14</ENT>
                        <ENT/>
                        <ENT/>
                    </ROW>
                    <ROW RUL="s">
                        <ENT I="25"> </ENT>
                        <ENT>Coefficients</ENT>
                        <ENT>Standard error</ENT>
                        <ENT>t Stat</ENT>
                        <ENT>P-value</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Intercept</ENT>
                        <ENT>0</ENT>
                        <ENT>#N/A</ENT>
                        <ENT>#N/A</ENT>
                        <ENT>#N/A</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">Market Cap</ENT>
                        <ENT>0.0000002630</ENT>
                        <ENT>3.3371E-08</ENT>
                        <ENT>7.88130564</ENT>
                        <ENT>4.1699E-15</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">90-day ADV</ENT>
                        <ENT>0.0140402219</ENT>
                        <ENT>0.00055818</ENT>
                        <ENT>25.1533643</ENT>
                        <ENT>1.613E-129</ENT>
                    </ROW>
                </GPOTABLE>
                <P>Based on the aforementioned analysis, the Exchange believes that the proposed 250,000 contracts for position and exercise limits is appropriate.</P>
                <P>
                    Second, ISE reviewed IBIT's data relative to the market capitalization of the entire bitcoin market in terms of exercise risk and availability of deliverables. As of November 25, 2024, there are 19,787,762 bitcoins in circulation.
                    <SU>23</SU>
                    <FTREF/>
                     At a price of $94,830,
                    <SU>24</SU>
                    <FTREF/>
                     that equates to a market capitalization of greater than $1.876 trillion US. If a position limit of 250,000 contracts were considered, the exercisable risk would represent 2.89% 
                    <SU>25</SU>
                    <FTREF/>
                     of the outstanding shares outstanding of IBIT. Since IBIT has a creation and redemption process managed through the issuer, the position limit can be compared to the total market capitalization of the entire bitcoin market and in that case, the exercisable risk for options on IBIT would represent less than .072% of all bitcoin outstanding.
                    <SU>26</SU>
                    <FTREF/>
                     Assuming a scenario where all options on IBIT shares were exercised given the proposed 250,000 contract position limit (and exercise limit), this would have a virtually unnoticed impact on the entire bitcoin market. This analysis demonstrates that the proposed 250,000 per same side position and exercise limit is appropriate for options on IBIT given its liquidity.
                </P>
                <FTNT>
                    <P>
                        <SU>23</SU>
                         
                        <E T="03">See https://www.coingecko.com/en/coins/bitcoin.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>24</SU>
                         This is the approximate price of bitcoin from 4:00 pm ET on November 25, 2024.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>25</SU>
                         This percentage is arrived at with this equation: (250,000 contract limit * 100 shares per option/866,040,000 shares outstanding).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>26</SU>
                         This number was arrived at with this calculation: ((250,000 limit * 100 shares per option * $54.02 settle) / (19,787,762 BTC outstanding * $94,830 BTC price)).
                    </P>
                </FTNT>
                <P>
                    Third, ISE reviewed the proposed position limit by comparing it to position limits for derivative products regulated by the Commodity Futures Trading Commission (“CFTC”). While the CFTC, through the relevant Designated Contract Markets, only regulates options positions based upon delta equivalents (creating a less stringent standard), ISE examined equivalent bitcoin futures position limits. In particular, ISE looked to the CME bitcoin futures contract 
                    <SU>27</SU>
                    <FTREF/>
                     that has a position limit of 8,000 futures.
                    <SU>28</SU>
                    <FTREF/>
                     On October 22, 2024, CME bitcoin futures settled at $94,945.
                    <SU>29</SU>
                    <FTREF/>
                     On October 22, 2024, IBIT settled at $54.02, which would equate to greater than 17,557,898 shares of IBIT if the CME notional position limit was utilized. Since substantial portions of any distributed options portfolio is likely to be out of the money on expiration, an options position limit equivalent to the CME position limit for bitcoin futures (considering that all options deltas are &lt;=1.00) should be a bit higher than the CME implied 175,578 limit. Of note, unlike options contracts, CME position limits are calculated on a net futures-equivalent basis by contract and include contracts that aggregate into one or more base contracts according to an aggregation ratio(s).
                    <SU>30</SU>
                    <FTREF/>
                     Therefore, if a 
                    <PRTPAGE P="707"/>
                    portfolio includes positions in options on futures, CME would aggregate those positions into the underlying futures contracts in accordance with a table published by CME on a delta equivalent value for the relevant spot month, subsequent spot month, single month and all month position limits.
                    <SU>31</SU>
                    <FTREF/>
                     If a position exceeds position limits because of an option assignment, CME permits market participants to liquidate the excess position within one business day without being considered in violation of its rules. Additionally, if at the close of trading, a position that includes options exceeds position limits for futures contracts, when evaluated using the delta factors as of that day's close of trading, but does not exceed the limits when evaluated using the previous day's delta factors, then the position shall not constitute a position limit violation. Based on the aforementioned analysis, the Exchange believes that the proposed 250,000 contracts for position and exercise limits is appropriate.
                </P>
                <FTNT>
                    <P>
                        <SU>27</SU>
                         CME Bitcoin Futures are described in Chapter 350 of CME's Rulebook.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>28</SU>
                         
                        <E T="03">See</E>
                         the Position Accountability and Reportable Level Table in the Interpretations &amp; Special Notices Section of Chapter 5 of CME's Rulebook.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>29</SU>
                         2,000 futures at a 5 bitcoin multiplier (per the contract specifications) equates to $949,450,000 (2000 contracts * 5 BTC per contract * $94,945 price of November BTC future) of notional value.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>30</SU>
                         
                        <E T="03">See https://www.cmegroup.com/education/courses/market-regulation/position-limits/position-limits-aggregation-of-contracts-and-table.htm.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>31</SU>
                         
                        <E T="03">Id.</E>
                    </P>
                </FTNT>
                <P>
                    Fourth, ISE analyzed a position and exercise limit of 250,000 for IBIT against other options on ETFs with an underling commodity, namely SPDR Gold Shares (“GLD”), iShares Silver Trust (“SLV”), and ProShares Bitcoin ETF (“BITO”).
                    <SU>32</SU>
                    <FTREF/>
                     GLD has a float of 306.1 million shares 
                    <SU>33</SU>
                    <FTREF/>
                     and a position limit of 250,000 contract. SLV has a float of 520.7 million shares,
                    <SU>34</SU>
                    <FTREF/>
                     and a position limit of 250,000 contracts. Finally, BITO has 107.65 million shares outstanding 
                    <SU>35</SU>
                    <FTREF/>
                     and a position limit of 250,000 contracts. As previously noted, position and exercise limits are designed to limit the number of options contracts traded on the exchange in an underlying security that an investor, acting alone or in concert with others directly or indirectly, may control. A position limit exercise in GLD would represent 8.17% of the float of GLD; a position limit exercise in SLV would represent 4.8% of the float of SLV, and a position limit exercise of BITO would represent 23.22% of the float of BITO. In comparison, a 250,000 contract position limit in IBIT would represent 2.89% of the float of IBIT. Consequently, the 250,000 proposed IBIT options position and exercise limit is more conservative than the standard applied to GLD, SLV and BITO, and appropriate. Additionally, the Exchange notes that the Cboe Bitcoin U.S. ETF Index Options (CBTX) and the Cboe Mini Bitcoin U.S. ETF Index Options (MBTX),
                    <SU>36</SU>
                    <FTREF/>
                     which trade exclusively on Cboe, are comprised of multiple bitcoin ETFs of which IBIT is the highest weighted (at 20%) in the index composition.
                    <SU>37</SU>
                    <FTREF/>
                     These indices currently trade pursuant to a 24,000 contract position and exercise limit.
                    <SU>38</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>32</SU>
                         GLD, SLV and BITO each hold one asset in trust similar to IBIT.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>33</SU>
                         
                        <E T="03">See https://www.ssga.com/us/en/intermediary/etfs/spdr-gold-shares-gld.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>34</SU>
                         
                        <E T="03">See https://www.ishares.com/us/products/239855/ishares-silver-trust-fund.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>35</SU>
                         
                        <E T="03">See https://www.marketwatch.com/investing/fund/bito.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>36</SU>
                         MBTX is based on 1/10th the value of the Cboe Bitcoin U.S. ETF Index.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>37</SU>
                         
                        <E T="03">See https://www.cboe.com/tradable_products/bitcoin-etf-index-options?utm_source=mcae&amp;utm_medium=email&amp;utm_campaign=bitcoin_eft_options_launch.</E>
                         Cboe's website provides a product comparison chart indicating that CBTX and MBTX are permitted to trade FLEX as compared to spot bitcoin ETF options. 
                        <E T="03">See https://cdn.cboe.com/resources/membership/Cboe_Bitcoin_US_ETF_Options_Comparative_Overview.pdf?_gl=1*1xmm04c*_up*MQ..*_ga*MTc0MjU1NzU1Ni4xNzM0NTU2NTky*_ga_5Q99WB9X71*MTczNDU1NjU5MC4xLjAuMTczNDU1NjU5MC4wLjAuMA.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>38</SU>
                         
                        <E T="03">See</E>
                         Cboe Rule 8.32(a). The Exchange notes that given the multiplier and notional value of CBTX, the index has a position and exercise limit that equates to 1,000,000 contracts of in kind exposure to IBIT, which is more than 40 times greater than the exposure for options on IBIT at the current 25,000 contract position and exercise limit.
                    </P>
                </FTNT>
                <P>
                    Fifth, ISE notes that IBIT is likely to trade in penny increments as of January 2, 2025, provided it is able to meet the applicable criteria.
                    <SU>39</SU>
                    <FTREF/>
                     The Commission noted that evidence contained in both the Exchanges' Report and the Cornerstone analysis demonstrates that the Penny Pilot has benefitted investors and other market participants in the form of narrower spreads.
                    <SU>40</SU>
                    <FTREF/>
                     The most actively traded options classes are included in the Penny Program based on certain objective criteria (trading volume thresholds and initial price tests). As noted in the Penny Approval Order, the Penny Program reflects a certain level of trading interest (either because the class is newly listed or a class that experience a significant growth in investor interest) to quote in finer trading increments, which in turn should benefit market participants by reducing the cost of trading such options.
                    <SU>41</SU>
                    <FTREF/>
                     If IBIT options were to enter the Penny Program, it will be among a select group of products that have achieved a certain level of liquidity that have garnered it the ability to trade in finer increments. The Exchange believes that if IBIT options were to trade in penny increments, failing to increase position and exercise limits once it started trading in finer increments, may artificially inhibit liquidity and create price inefficiency.
                </P>
                <FTNT>
                    <P>
                        <SU>39</SU>
                         The Exchange may add to the Penny Program a newly listed option class provided that (i) it is among the 300 most actively traded multiply listed option classes, as ranked by National Cleared Volume at OCC, in its first full calendar month of trading and (ii) the underlying security is priced below $200 or the underlying index is at an index level below $200. Any option class added under this provision will be added on the first trading day of the month after it qualifies and will remain in the Penny Program for one full calendar year, after which it will be subject to the Annual Review described in Supplementary Material .01(b) to Options 3, Section 3. The Exchange may add any option class to the Penny Program, provided that (i) it is among the 75 most actively traded multiply listed option classes, as ranked by National Cleared Volume at OCC, in the past six full calendar months of trading and (ii) the underlying security is priced below $200 or the underlying index is at an index level below $200. Any option class added under this provision will be added on the first trading day of the second full month after it qualifies and will remain in the Penny Program for the rest of the calendar year, after which it will be subject to the Annual Review as described in Supplementary Material .01(b) to Options 3, Section 3. 
                        <E T="03">See</E>
                         Supplementary Material .01 to ISE Options 3, Section 3.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>40</SU>
                         
                        <E T="03">See</E>
                         Securities Exchange Act Release No. 88532 (April 1, 2020), 67 FR 19545, 19548 (April 7, 2020) (File No. 4-443) (Joint Industry Plan; Order Approving Amendment No. 5 to the Plan for the Purpose of Developing and Implementing Procedures Designed To Facilitate the Listing and Trading of Standardized Options To Adopt a Penny Interval Program) (“Penny Approval Order”).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>41</SU>
                         
                        <E T="03">Id.</E>
                         at 19548.
                    </P>
                </FTNT>
                <P>The Exchange believes that IBIT options has demonstrated that it has more than sufficient liquidity to garner an increased position and exercise limit of 250,000 contracts. The Exchange believes that any concerns related to manipulation and protection of investors are mollified by the significant liquidity provision in IBIT. The Exchange states that, as a general principle, increases in active trading volume and deep liquidity of the underlying securities do not lead to manipulation and/or disruption.</P>
                <P>
                    The Exchange believes that increasing the position (and exercise) limits for IBIT options would lead to a more liquid and competitive market environment for IBIT options, which will benefit customers that trade these options. Further, the reporting requirement for such options would remain unchanged. Thus, the Exchange will still require that each member organization that maintains positions in impacted options on the same side of the market, for its own account or for the account of a customer, report certain information to the Exchange. This information includes, but would not be limited to, the options' positions, whether such positions are hedged and, if so, a description of the hedge(s). Market-Makers would continue to be exempt from this reporting requirement, however, the Exchange may access Market-Maker position information.
                    <FTREF/>
                    <SU>42</SU>
                      
                    <PRTPAGE P="708"/>
                    Moreover, the Exchange's requirement that member organizations file reports with the Exchange for any customer who held aggregate large long or short positions on the same side of the market of 200 or more option contracts of any single class for the previous day will remain at this level and will continue to serve as an important part of the Exchange's surveillance efforts.
                    <SU>43</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>42</SU>
                         The Options Clearing Corporation (“OCC”) through the Large option Position Reporting (“LOPR”) system acts as a centralized service provider for TPH compliance with position reporting requirements by collecting data from each 
                        <PRTPAGE/>
                        TPH or TPH organization, consolidating the information, and ultimately providing detailed listings of each TPH's report to the Exchange, as well as Financial Industry Regulatory Authority, Inc. (“FINRA”), acting as its agent pursuant to a regulatory services agreement (“RSA”).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>43</SU>
                         
                        <E T="03">See</E>
                         Options 9, Section 16.
                    </P>
                </FTNT>
                <P>The Exchange also has no reason to believe that the growth in trading volume in IBIT will not continue. Rather, the Exchange expects continued options volume growth in IBIT as opportunities for investors to participate in the options markets increase and evolve. The Exchange believes that the current position and exercise limits in IBIT options are restrictive and will hamper the listed options markets from being able to compete fairly and effectively with the over-the-counter (“OTC”) markets. OTC transactions occur through bilateral agreements, the terms of which are not publicly disclosed to the marketplace. As such, OTC transactions do not contribute to the price discovery process on a public exchange or other lit markets. The Exchange believes that without the proposed changes to position and exercise limits for IBIT, market participants will find the 25,000 contract position limit an impediment to their business and investment objectives as well as an impediment to efficient pricing. As such, market participants may find the less transparent OTC markets a more attractive alternative to achieve their investment and hedging objectives, leading to a retreat from the listed options markets, where trades are subject to reporting requirements and daily surveillance.</P>
                <P>
                    The Exchange believes that the existing surveillance procedures and reporting requirements at the Exchange are capable of properly identifying disruptive and/or manipulative trading activity. The Exchange also represents that it has adequate surveillances in place to detect potential manipulation, as well as reviews in place to identify continued compliance with the Exchange's listing standards. These procedures monitor market activity via automated surveillance techniques to identify unusual activity in both options and the underlyings, as applicable. The Exchange also notes that large stock holdings must be disclosed to the Commission by way of Schedules 13D or 13G,
                    <SU>44</SU>
                    <FTREF/>
                     which are used to report ownership of stock which exceeds 5% of a company's total stock issue and may assist in providing information in monitoring for any potential manipulative schemes. Further, the Exchange believes that the current financial requirements imposed by the Exchange and by the Commission adequately address concerns regarding potentially large, unhedged positions in equity options. Current margin and risk-based haircut methodologies serve to limit the size of positions maintained by any one account by increasing the margin and/or capital that a member organization must maintain for a large position held by itself or by its customer.
                    <SU>45</SU>
                    <FTREF/>
                     In addition, Rule 15c3-1 
                    <SU>46</SU>
                    <FTREF/>
                     imposes a capital charge on member organizations to the extent of any margin deficiency resulting from the higher margin requirement.
                </P>
                <FTNT>
                    <P>
                        <SU>44</SU>
                         17 CFR 240.13d-1.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>45</SU>
                         
                        <E T="03">See</E>
                         Options 9, Section 3 regarding margin requirements.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>46</SU>
                         17 CFR 240.15c3-1.
                    </P>
                </FTNT>
                <HD SOURCE="HD3">2. Statutory Basis</HD>
                <P>
                    The Exchange believes that its proposal is consistent with Section 6(b) of the Act,
                    <SU>47</SU>
                    <FTREF/>
                     in general, and furthers the objectives of Section 6(b)(5) of the Act,
                    <SU>48</SU>
                    <FTREF/>
                     in particular, in that it is designed to prevent fraudulent and manipulative acts and practices, to promote just and equitable principles of trade, to foster cooperation and coordination with persons engaged in regulating, clearing, settling, processing information with respect to, and facilitating transactions in securities, to remove impediments to and perfect the mechanism of a free and open market and a national market system, and, in general, to protect investors and the public interest. Additionally, the Exchange believes the proposed rule change is consistent with the Section (6)(b)(5) 
                    <SU>49</SU>
                    <FTREF/>
                     requirement that the rules of an exchange not be designed to permit unfair discrimination between customers, issuers, brokers, or dealers.
                </P>
                <FTNT>
                    <P>
                        <SU>47</SU>
                         15 U.S.C. 78f(b).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>48</SU>
                         15 U.S.C. 78f(b)(5).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>49</SU>
                         15 U.S.C. 78(f)(b)(5).
                    </P>
                </FTNT>
                <P>The Exchange believes increasing the position (and exercise limits) for IBIT options from 25,000 to 250,000 contracts will remove impediments to and perfect the mechanism of a free and open market and a national market system, and, in general, protect investors and the public interest, because it will provide market participants with the ability to more effectively execute their trading and hedging activities. Also, increasing the position (and exercise) limits for IBIT options may allow Market-Makers to maintain their liquidity in these options in amounts commensurate with the continued high consumer demand in IBIT options market. The proposed higher position and exercise limit may also encourage other liquidity providers to continue to trade on the Exchange rather than shift their volume to OTC markets, which will enhance the process of price discovery conducted on the Exchange through increased order flow. The Exchange notes that a higher position and exercise limit would further allow institutional investors to utilize IBIT options for prudent risk management purposes.</P>
                <P>In addition, the Exchange believes that the current liquidity in shares of and options on IBIT will mitigate concerns regarding potential manipulation of IBIT and/or disruption of IBIT upon increasing the position limit. ISE's proposed position and exercise limit of 250,000 contracts on IBIT options is appropriate given the market capitalization and ADV of IBIT and designed to prevent fraudulent and manipulative acts and practices. If IBIT were compared to the 1,934 stocks that have position limits of 250,000 contracts to less than 500,000 contracts it would rank in the 88th percentile for market capitalization and the 99th percentile for ADV.</P>
                <P>
                    Additionally, the regression model performed by ISE demonstrates that the proposed position limit is half of the modeled limit given the liquidity of IBIT. Comparing IBIT's data relative to the market capitalization of the entire bitcoin market in terms of exercise risk and availability of deliverables, the Exchange was able to conclude that if a position limit of 250,000 contracts were considered, the exercisable risk would represent 2.89% 
                    <SU>50</SU>
                    <FTREF/>
                     of the shares outstanding of IBIT. Since IBIT has a creation and redemption process managed through the issuer (whereby Bitcoin is used to create IBIT shares), the position limit can be compared to the total market capitalization of the entire bitcoin market and in that case, the exercisable risk for options on IBIT would represent less than .072% of all bitcoin outstanding.
                    <SU>51</SU>
                    <FTREF/>
                     Comparing the proposed position limit to position limits for equivalent bitcoin futures position limits, the analysis demonstrated that the proposed 250,000 
                    <PRTPAGE P="709"/>
                    contracts for position and exercise limits is appropriate.
                </P>
                <FTNT>
                    <P>
                        <SU>50</SU>
                         This percentage is arrived at with this equation: (250,000 contract limit * 100 shares per option/866,040,000 shares outstanding).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>51</SU>
                         This number was arrived at with this calculation: ((250,000 limit * 100 shares per option * $54.02 settle) / (19,787,762 BTC outstanding * $94,830 BTC price)).
                    </P>
                </FTNT>
                <P>
                    Comparing a position limit of 250,000 for IBIT against other options on ETFs with an underling commodity, namely GLD, SLV and BITO, a position limit exercise in GLD represents 8.17% of the float of GLD, a position limit exercise in SLV represents 4.8% of the float of SLV, and a position limit exercise of BITO represents 23.22% of the float of BITO. In comparison, a 250,000 contract position limit in IBIT would represent 2.89% of the float of IBIT. Consequently, the 250,000 proposed IBIT options position limit is more conservative than the standard applied to GLD, SLV and BITO, and appropriate. Also, the Exchange notes that Cboe's proprietary CBTX and MBTX indices weight IBIT the highest (at 20%) in its index composition among the other ETFs that comprise the index.
                    <SU>52</SU>
                    <FTREF/>
                     The Exchange notes that today, these indexes have a position of 24,000 contracts which is much higher than the current position limits for IBIT options when considering the notional value of the indices.
                    <SU>53</SU>
                    <FTREF/>
                     These indexes are already trading with position and exercise limits that are higher than the lowest position limit for an industry index option.
                    <SU>54</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>52</SU>
                         
                        <E T="03">See https://www.cboe.com/tradable_products/bitcoin-etf-index-options?utm_source=mcae&amp;utm_medium=email&amp;utm_campaign=bitcoin_eft_options_launch.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>53</SU>
                         
                        <E T="03">See</E>
                         Cboe Rule 8.32(a). The Exchange notes that given the multiplier and notional value of CBTX, the index has a position and exercise limit that equates to 1,000,000 contracts of in kind exposure to IBIT, which is more than 40 times greater than the exposure for options on IBIT at the current 25,000 contract position and exercise limit.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>54</SU>
                         18,000 contracts is the lowest position limit for industry index options if the Exchange determines, at the time of a review conducted pursuant to subparagraph (2) of this paragraph (a), that any single underlying stock accounted, on average, for thirty percent (30%) or more of the index value during the thirty (30) -day period immediately preceding the review. 
                        <E T="03">See</E>
                         ISE Options 4A, Section 7. Further, Cboe Rule 8.32(a)(3) permits a limit of 31,500 contracts if the Exchange determines that the conditions specified in Rule 8.32(a)(1) and (2), which would require the establishment of a lower limit, have not occurred.
                    </P>
                </FTNT>
                <P>
                    ISE notes that IBIT is likely to trade in penny increments in January 2025, provided it is able to meet the applicable criteria.
                    <SU>55</SU>
                    <FTREF/>
                     The Commission noted that evidence contained in both the Exchanges' Report and the Cornerstone analysis demonstrates that the Penny Pilot has benefitted investors and other market participants in the form of narrower spreads.
                    <SU>56</SU>
                    <FTREF/>
                     The most actively traded options classes are included in the Penny Program based on certain objective criteria (trading volume thresholds and initial price tests). As noted in the Penny Approval Order, the Penny Program reflects a certain level of trading interest (either because the class is newly listed or a class that experience a significant growth in investor interest) to quote in finer trading increments, which in turn should benefit market participants by reducing the cost of trading such options.
                    <SU>57</SU>
                    <FTREF/>
                     If IBIT options were to enter the Penny Program, it will be among a select group of products that have achieved a certain level of liquidity that have garnered it the ability to trade in finer increments. The Exchange believes that if IBIT options were to trade in penny increments, failing to increase position and exercise limits once it started trading in finer increments, may artificially inhibit liquidity and create price inefficiency.
                </P>
                <FTNT>
                    <P>
                        <SU>55</SU>
                         The Exchange may add to the Penny Program a newly listed option class provided that (i) it is among the 300 most actively traded multiply listed option classes, as ranked by National Cleared Volume at OCC, in its first full calendar month of trading and (ii) the underlying security is priced below $200 or the underlying index is at an index level below $200. Any option class added under this provision will be added on the first trading day of the month after it qualifies and will remain in the Penny Program for one full calendar year, after which it will be subject to the Annual Review described in Supplementary Material .01(b) to Options 3, Section 3. The Exchange may add any option class to the Penny Program, provided that (i) it is among the 75 most actively traded multiply listed option classes, as ranked by National Cleared Volume at OCC, in the past six full calendar months of trading and (ii) the underlying security is priced below $200 or the underlying index is at an index level below $200. Any option class added under this provision will be added on the first trading day of the second full month after it qualifies and will remain in the Penny Program for the rest of the calendar year, after which it will be subject to the Annual Review as described in Supplementary Material .01(b) to Options 3, Section 3. 
                        <E T="03">See</E>
                         Supplementary Material .01 to ISE Options 3, Section 3.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>56</SU>
                         
                        <E T="03">See</E>
                         Securities Exchange Act Release No. 88532 (April 1, 2020), 85 FR 19545, 19548 (April 7, 2020) (File No. 4-443) (Joint Industry Plan; Order Approving Amendment No. 5 to the Plan for the Purpose of Developing and Implementing Procedures Designed To Facilitate the Listing and Trading of Standardized Options To Adopt a Penny Interval Program) (“Penny Approval Order”).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>57</SU>
                         
                        <E T="03">Id.</E>
                         at 19548.
                    </P>
                </FTNT>
                <P>Finally, as discussed above, the Exchange's surveillance and reporting safeguards continue to be designed to deter and detect possible manipulative behavior that might arise from increasing or eliminating position and exercise limits in certain classes. The Exchange believes that the current financial requirements imposed by the Exchange and by the Commission adequately address concerns regarding potentially large, unhedged positions in the options on the underlying securities, further promoting just and equitable principles of trading, the maintenance of a fair and orderly market, and the protection of investors.</P>
                <HD SOURCE="HD2">B. Self-Regulatory Organization's Statement on Burden on Competition</HD>
                <P>The Exchange does not believe that the proposed rule change will impose any burden on competition that is not necessary or appropriate in furtherance of the purposes of the Act.</P>
                <P>The Exchange's proposal does not burden intra-market competition because all Members would be permitted to trade IBIT options pursuant to the proposed position and exercise limit of 250,000 contracts. The Exchange believes that the proposed rule change will also provide additional opportunities for market participants to continue to efficiently achieve their investment and trading objectives for equity options on the Exchange.</P>
                <P>The Exchange does not believe that the proposed rule change will impose any burden on inter-market competition as the proposal is not competitive in nature. The Exchange expects that all option exchanges will adopt substantively similar proposals for adopting the additional position limit tiers, such that the Exchange's proposal would benefit competition. For these reasons, the Exchange does not believe that the proposed rule change will impose any burden on competition not necessary or appropriate in furtherance of the purposes of the Act.</P>
                <HD SOURCE="HD2">C. Self-Regulatory Organization's Statement on Comments on the Proposed Rule Change Received From Members, Participants, or Others</HD>
                <P>No written comments were either solicited or received.</P>
                <HD SOURCE="HD1">III. Date of Effectiveness of the Proposed Rule Change and Timing for Commission Action</HD>
                <P>
                    Within 45 days of the date of publication of this notice in the 
                    <E T="04">Federal Register</E>
                     or within such longer period up to 90 days (i) as the Commission may designate if it finds such longer period to be appropriate and publishes its reasons for so finding or (ii) as to which the self-regulatory organization consents, the Commission will:
                </P>
                <P>(A) by order approve or disapprove such proposed rule change, or</P>
                <P>(B) institute proceedings to determine whether the proposed rule change should be disapproved.</P>
                <HD SOURCE="HD1">IV. Solicitation of Comments</HD>
                <P>
                    Interested persons are invited to submit written data, views and arguments concerning the foregoing, including whether the proposed rule change is consistent with the Act. Comments may be submitted by any of the following methods:
                    <PRTPAGE P="710"/>
                </P>
                <HD SOURCE="HD2">Electronic Comments</HD>
                <P>
                    • Use the Commission's internet comment form (
                    <E T="03">https://www.sec.gov/rules/sro.shtml</E>
                    ); or
                </P>
                <P>
                    • Send an email to 
                    <E T="03">rule-comments@sec.gov.</E>
                     Please include file number SR-ISE-2024-62 on the subject line.
                </P>
                <HD SOURCE="HD2">Paper Comments</HD>
                <P>• Send paper comments in triplicate to Secretary, Securities and Exchange Commission, 100 F Street NE, Washington, DC 20549-1090.</P>
                <FP>
                    All submissions should refer to file number SR-ISE-2024-62. This file number should be included on the subject line if email is used. To help the Commission process and review your comments more efficiently, please use only one method. The Commission will post all comments on the Commission's internet website (
                    <E T="03">https://www.sec.gov/rules/sro.shtml</E>
                    ). Copies of the submission, all subsequent amendments, all written statements with respect to the proposed rule change that are filed with the Commission, and all written communications relating to the proposed rule change between the Commission and any person, other than those that may be withheld from the public in accordance with the provisions of 5 U.S.C. 552, will be available for website viewing and printing in the Commission's Public Reference Room, 100 F Street NE, Washington, DC 20549, on official business days between the hours of 10 a.m. and 3 p.m. Copies of the filing also will be available for inspection and copying at the principal office of the Exchange. Do not include personal identifiable information in submissions; you should submit only information that you wish to make available publicly. We may redact in part or withhold entirely from publication submitted material that is obscene or subject to copyright protection. All submissions should refer to file number SR-ISE-2024-62 and should be submitted on or before January 27, 2025.
                </FP>
                <SIG>
                    <P>
                        For the Commission, by the Division of Trading and Markets, pursuant to delegated authority.
                        <SU>58</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>58</SU>
                             17 CFR 200.30-3(a)(12).
                        </P>
                    </FTNT>
                    <NAME>Stephanie J. Fouse,</NAME>
                    <TITLE>Assistant Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31771 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8011-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">SECURITIES AND EXCHANGE COMMISSION</AGENCY>
                <DEPDOC>[Release No. 34-102057; File No. SR-OCC-2024-014]</DEPDOC>
                <SUBJECT>Self-Regulatory Organizations; The Options Clearing Corporation; Order Granting Approval of Proposed Rule Change, as Modified by Partial Amendment No. 1, by The Options Clearing Corporation Concerning Its Process for Adjusting Certain Parameters in Its Proprietary System for Calculating Margin Requirements During Periods When the Products It Clears and the Markets It Serves Experience High Volatility</SUBJECT>
                <DATE>December 30, 2024.</DATE>
                <HD SOURCE="HD1">I. Introduction</HD>
                <P>
                    On October 1, 2024, the Options Clearing Corporation (“OCC”) filed with the Securities and Exchange Commission (“Commission”) the proposed rule change SR-OCC-2024-014, pursuant to Section 19(b) of the Securities Exchange Act of 1934 (“Exchange Act”) 
                    <SU>1</SU>
                    <FTREF/>
                     and Rule 19b-4 
                    <SU>2</SU>
                    <FTREF/>
                     thereunder, to codify OCC's process for adjusting certain parameters in its proprietary system for calculating margin requirements during periods when the products OCC clears and the markets it serves experience high volatility.
                    <SU>3</SU>
                    <FTREF/>
                     The proposed rule change, as modified by Partial Amendment No. 1 (hereinafter, the “Proposed Rule Change”) was published for public comment in the 
                    <E T="04">Federal Register</E>
                     on October 9, 2024.
                    <SU>4</SU>
                    <FTREF/>
                     The Commission has received no comments regarding the Proposed Rule Change.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         15 U.S.C. 78s(b)(1).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         17 CFR 240.19b-4.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         
                        <E T="03">See</E>
                         Notice of Filing 
                        <E T="03">infra</E>
                         note 4, at 89 FR 81958.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         
                        <E T="03">See</E>
                         Securities Exchange Act Release No. 101246 (Oct. 3, 2024), 89 FR 81958 (Oct. 9, 2024) (File No. SR-OCC-2024-014) (“Notice of Filing”).
                    </P>
                </FTNT>
                <P>
                    On November 21, 2024, pursuant to Section 19(b)(2) of the Exchange Act,
                    <SU>5</SU>
                    <FTREF/>
                     the Commission designated a longer period within which to approve, disapprove, or institute proceedings to determine whether to disapprove the Proposed Rule Change.
                    <SU>6</SU>
                    <FTREF/>
                     For the reasons discussed below, the Commission is approving the Proposed Rule Change.
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         15 U.S.C. 78s(b)(2).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         
                        <E T="03">See</E>
                         Securities Exchange Act Release No. 101684 (Nov. 21, 2024), 89 FR 93693 (Nov. 27, 2024) (File No. SR-OCC-2024-014).
                    </P>
                </FTNT>
                <HD SOURCE="HD1">
                    II. Background 
                    <SU>7</SU>
                    <FTREF/>
                </HD>
                <FTNT>
                    <P>
                        <SU>7</SU>
                         Capitalized terms used but not defined herein have the meanings specified in OCC's Rules and By-Laws, available at 
                        <E T="03">https://www.theocc.com/about/publications/bylaws.jsp.</E>
                    </P>
                </FTNT>
                <P>
                    OCC is a central counterparty (“CCP”), which means that as part of its function as a clearing agency, it interposes itself as the buyer to every seller and the seller to every buyer for financial transactions. As the CCP for the listed options markets and for certain futures in the United States, OCC is exposed to the risk that one or more of its Clearing Members may fail to make a payment or to deliver securities. OCC addresses such risk exposure, in part, by requiring its Clearing Members to provide collateral, including margin collateral. Margin is the collateral that CCPs collect to cover potential changes in a member's positions over a set period of time. Typically, margin is designed to cover such exposures during normal market conditions, which means that margin collateral should be sufficient to cover exposures at least 99 out of 100 days.
                    <SU>8</SU>
                    <FTREF/>
                     OCC's methodology for calculating margin collateral—including daily and intra-day margin requirements for Clearing Members—is a collection of margin models collectively called the System for Theoretical Analysis and Numerical Simulations (“STANS”). The STANS Methodology Description is a document that comprehensively describes the material aspects of OCC's risk-based margin system, including its approach for calculating daily and intra-day margin requirements for its Clearing Members.
                    <SU>9</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>8</SU>
                         
                        <E T="03">See</E>
                         Securities Exchange Act Release No. 78961 (Sep. 28, 2016), 81 FR 70786, 70819 (Oct. 13, 2016) (“Standards for Covered Clearing Agencies”) (stating that a covered clearing agency generally should consider, among other things, “whether initial margin meets an established single-tailed confidence level of at least 99 percent with respect to the estimated distribution of future exposure[.]”).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>9</SU>
                         
                        <E T="03">See</E>
                         Securities Exchange Act Release No. 91079 (Feb. 8, 2021), 86 FR 9410 (Feb. 12, 2021) (File No. SR-OCC-2020-016) (“STANS Methodology Approval”).
                    </P>
                </FTNT>
                <P>
                    As a collection of models, STANS is subject to assumptions and limitations that are incorporated into STANS as margin model parameters. For example, OCC has a price return model that employs bounds, or “control sets” that are implemented under either regular or high volatility settings, for certain parameters that are calculated daily based on current market data.
                    <SU>10</SU>
                    <FTREF/>
                     OCC maintains authority under its rules to adjust member margin requirements to protect the respective interests of OCC, its Clearing Members, and the public. OCC has established an exception process for implementing, changing, and terminating certain of these margin model parameters in STANS to control margin requirements where such parameters cause STANS to produce inappropriate margin requirements 
                    <PRTPAGE P="711"/>
                    during periods of heightened volatility (the “high-volatility parameter controls”). While the STANS Methodology Description currently includes a brief discussion of the high-volatility parameter controls that OCC uses,
                    <SU>11</SU>
                    <FTREF/>
                     it does not provide a detailed description of OCC's actual process and governance for implementing, changing, and terminating the high-volatility parameter controls. As such, OCC is filing the Proposed Rule Change to codify and describe more fully in the STANS Methodology Description its process and governance surrounding the high-volatility parameter controls.
                </P>
                <FTNT>
                    <P>
                        <SU>10</SU>
                         
                        <E T="03">See</E>
                         Notice of Filing, notes 25-28 (describing the parameters to which bounds are applied).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>11</SU>
                         In the initial rule filing to introduce the STANS Methodology Description, OCC included a brief description of the high-volatility parameter controls discussion. 
                        <E T="03">See</E>
                         Securities Exchange Act Release No. 90763 (Dec. 21, 2020), 85 FR 85788, 85793 (Dec. 29, 2020) (File No. SR-OCC-2020-016) (“The STANS Methodology Description would also describe the controls that may be placed on the GJR-GARCH parameters after their initial calibration. GARCH volatility forecasting models can be very reactive in certain market environments. As a result, OCC may implement parameter controls for risk factors and classes of risk factors, which are subject to periodic review and approval by the [Model Risk Working Group].”).
                    </P>
                </FTNT>
                <P>
                    More specifically, OCC proposes to amend its existing Margin Policy to include material details regarding its high-volatility parameter control setting process.
                    <SU>12</SU>
                    <FTREF/>
                     Although the Proposed Rule Change would amend OCC's Margin Policy, OCC states that the proposal does not significantly change OCC's existing high-volatility parameter control setting practices,
                    <SU>13</SU>
                    <FTREF/>
                     which OCC indicates have been in use since at least 2020.
                    <SU>14</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>12</SU>
                         OCC also intends to update its internal Margin Setting and Maintenance procedure (Exhibit 3F to the Proposed Rule Change) to provide greater detail about its high-volatility parameter control process.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>13</SU>
                         
                        <E T="03">See</E>
                         Notice of Filing, 89 FR 81959.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>14</SU>
                         
                        <E T="03">See id.</E>
                         at 81961-62 (describing an instance when OCC applied the idiosyncratic control settings in 2021). Additionally, various exhibits to File No. SR-OCC-2024-014 indicate OCC's use of high-volatility parameter control settings since 2020. For example, confidential Exhibit B to that filing, which is an internal OCC memorandum addressing high-volatility parameter control settings, describes an instance on March 9, 2020 when OCC implemented the global control settings.
                    </P>
                </FTNT>
                <P>Proposed additions to the Margin Policy describing OCC's exception process for setting high-volatility parameter controls include the following: (1) setting and reviewing regular and high-volatility parameter control settings; (2) monitoring the volatility of products being cleared and markets served, and establishing thresholds to escalate the results of such monitoring to senior decisionmakers; and (3) internal governance for implementing and terminating high-volatility parameter control settings. The three sets of changes to OCC's Margin Policy are described in further detail below.</P>
                <HD SOURCE="HD2">A. Setting and Reviewing Regular and High-Volatility Parameter Control Settings</HD>
                <P>
                    STANS uses large-scale Monte Carlo simulations to calculate the margin requirements of OCC's Clearing Members. The methodology includes econometric models that incorporate a number of risk factors.
                    <SU>15</SU>
                    <FTREF/>
                     One of these econometric models, GARCH, is used to estimate the volatility of equity securities based on historical data. Over time, OCC has observed that the margin requirements produced by its GARCH model are strongly reactive to market movements and are considered to be “procyclical”—meaning that changes in margin requirements produced by the GARCH model may be positively correlated with the overall state of the market. OCC states that such procyclicality could inflate the margin requirements of OCC's Clearing Members beyond the related risk posed by Clearing Members' positions if it is not addressed during high-volatility periods in the market, and would potentially threaten the operational stability of those Clearing Members.
                    <SU>16</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>15</SU>
                         OCC defines a risk factor in STANS as a product or attribute whose historical data is used to estimate and simulate the risk for an associated product. The majority of risk factors utilized in STANS are the returns on individual equity securities.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>16</SU>
                         
                        <E T="03">See</E>
                         Notice of Filing, 89 FR 81960. For example, OCC states that its GARCH model produced forecasts for particular S&amp;P 500 Index (“SPX”) options that were four-fold larger than the comparable market index, leading to margin requirement increasing by 80% overnight, with some margin requirements increasing ten-fold. 
                        <E T="03">Id.</E>
                         OCC has attempted a number of approaches to mitigate the impact of procyclicality, including changes to its GARCH model. 
                        <E T="03">See</E>
                         Securities Exchange Act Release No. 84879 (Dec. 20, 2018), 83 FR 67392, 67393 (Dec. 28, 2018) (File No. SR-OCC-2018-014). OCC has also developed a new model to replace GARCH for simulating implied volatility for SPX-based options and volatility index futures. 
                        <E T="03">See</E>
                         Securities Exchange Act Release No. 95319 (July 19, 2022), 87 FR 44167 (July 25, 2022) (File No. SR-OCC-2022-001).
                    </P>
                </FTNT>
                <P>
                    As part of its current practice, OCC applies high-volatility parameter control settings to constrain the GARCH parameters temporarily during periods of high market volatility. OCC's price return model uses upper and lower bounds for parameters calculated daily based on market data. OCC's high-volatility parameter control settings consist of parameters that are bounded differently than regular control settings. These high-volatility parameter control settings, when applied to GARCH parameters after their initial calibration, mitigate the reactivity of the model volatility forecast and, in turn, generally prevent significant overestimation of Clearing Members' margin requirements.
                    <SU>17</SU>
                    <FTREF/>
                     Depending on the circumstances, OCC may apply control settings to individual risk factors (
                    <E T="03">i.e.,</E>
                     “idiosyncratic control settings”), or to all or a class of risk factors (
                    <E T="03">i.e.,</E>
                     “global control settings”).
                    <SU>18</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>17</SU>
                         
                        <E T="03">See</E>
                         Notice of Filing, 89 FR 81959. OCC also provides detailed examples in which high-volatility parameter control settings were implemented. 
                        <E T="03">Id.</E>
                         at 81962, notes 41-42.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>18</SU>
                         When OCC implements global control settings for a class or sector of risk factors, it is OCC's practice to blend the high volatility and regular control settings based on a weighted percentage between them. 
                        <E T="03">See</E>
                         Notice of Filing, 89 FR 81961. Such a “blended” or “weighted” approach allows OCC's risk managers, when appropriate, to select bounds that provide more conservative margin coverage when applying high volatility control settings globally across multiple risk factors. 
                        <E T="03">See id.</E>
                    </P>
                </FTNT>
                <P>
                    As part of the Proposed Rule Change, OCC proposes to amend its Margin Policy to describe the current exception process for setting and reviewing both regular and high-volatility parameter control settings. Specifically, the proposed addition to the Margin Policy would state that GARCH parameters may be temporarily constrained through the application of idiosyncratic or global control settings. The added language would state that OCC's Financial Risk Management team (“FRM”) maintains both regular and high-volatility parameter control sets, which it reviews on an at-least annual basis. FRM's review of the high-volatility parameter control sets assesses whether they effectively mitigate procyclicality while remaining appropriately risk-based. The new Margin Policy language would further state that OCC's Model Risk Working Group (“MRWG”) must approve any changes to the regular or high-volatility sets. The Proposed Rule Change would also provide further detail on the review of both regular and high-volatility parameter control sets.
                    <SU>19</SU>
                    <FTREF/>
                     These proposed changes to the Margin Policy describe current OCC processes that will remain unchanged.
                </P>
                <FTNT>
                    <P>
                        <SU>19</SU>
                         The proposed language states that in the case of the regular control set, the review assesses whether the GARCH parameter bounds are appropriately risk-based, including but not limited to assessing whether they align with the 95th percentile of the parameter calibrations over the prior review period; and, in the case of the high-volatility parameter control sets, the review assesses whether they effectively mitigate procyclicality while remaining appropriately risk-based, including but not limited to whether the bounds keep the day-over-day change in 2-day expected shortfall coverage within a factor of approximately 1.5, assuming price shocks based on observed returns for top risk factors.
                    </P>
                </FTNT>
                <PRTPAGE P="712"/>
                <HD SOURCE="HD2">B. Monitoring Volatility of Products and Markets Served</HD>
                <P>
                    As part of the Proposed Rule Change, OCC proposes to amend the Margin Calls and Adjustments section of the Margin Policy to include details about how OCC currently sets volatility controls. Specifically, the new Control Setting details would include information about OCC's current use of certain monitoring thresholds related to high market volatility, low market liquidity, and significant increases in position size or concentration (“CCA Monitoring Thresholds”).
                    <SU>20</SU>
                    <FTREF/>
                     The new details would state that the Quantitative Risk Management (“QRM”) team,
                    <SU>21</SU>
                    <FTREF/>
                     in collaboration with Stress Testing and Liquidity Risk Management, will perform a review of the CCA Monitoring Thresholds to ensure that they remain adequate to identify periods of high market volatility, low market liquidity, and significant increases in position size or concentration. Moreover, the new language would state that any changes to the CCA Monitoring Thresholds must be approved by the MRWG and the Stress Testing Working Group.
                </P>
                <FTNT>
                    <P>
                        <SU>20</SU>
                         The establishment of these CCA Monitoring Thresholds is described in OCC's internal Clearing Fund Methodology Policy and its internal Stress Test Reporting Procedure.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>21</SU>
                         FRM is the parent department of QRM, which is responsible for, among other things, monitoring the use and performance of risk models according to relevant procedures, maintaining risk tolerances and associated key risk indicators to measure and monitor risk models. 
                        <E T="03">See</E>
                         Securities Exchange Act Release No. 97484 (May 11, 2023), 88 FR 31549, 31550 (May 17, 2023) (File No. SR-OCC-2023-004).
                    </P>
                </FTNT>
                <P>OCC also proposes to amend the Margin Calls and Adjustments section to state that QRM shall perform a monthly sensitivity analysis of the margin model, but may review more frequently when CCA Monitoring Thresholds are breached.</P>
                <P>These proposed changes to the Margin Policy describe current OCC processes that will remain unchanged.</P>
                <HD SOURCE="HD2">C. Internal Governance for Implementing and Terminating High-Volatility Parameter Controls</HD>
                <P>As part of the Proposed Rule Change, OCC proposes to amend its Margin Policy to include details about its current internal governance process for implementing and terminating high-volatility parameter control settings. The new Margin Policy details would include descriptions of both idiosyncratic and global control settings, and the circumstances under which these settings may be used.</P>
                <P>
                    For example, for global control settings, FRM monitors market volatility on a daily basis, and escalates to the MRWG if a market volatility threshold is exceeded. As part of the escalation to the MRWG, FRM recommends whether global control settings should be applied to all risk factors or to a class of risk factors. MRWG approval is required for OCC to implement global control settings, and for OCC to revert back to regular control settings.
                    <SU>22</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>22</SU>
                         When OCC implements global control settings, MRWG evaluates and selects a control setting with different weightings between the regular control set and high-volatility parameter control set based on an assessment of which blended approach generates a coverage level that converges with the implied volatility of the SPX. Factors that the MRWG considers when determining whether to revert to regular control settings include, but are not limited to, whether SPX coverage rates produced under regular control settings have converged with the initial coverage rates when the global control settings were first implemented. 
                        <E T="03">See</E>
                         Notice of Filing, 89 FR 81961.
                    </P>
                </FTNT>
                <P>
                    Meanwhile, for idiosyncratic control settings, FRM monitors securities against thresholds for idiosyncratic price moves.
                    <SU>23</SU>
                    <FTREF/>
                     These thresholds may be a tiered structure that takes into account the type and magnitude of OCC's risk exposure to the security, the value of the security, the magnitude of the price move, and the coverage rates. When an idiosyncratic threshold is breached, FRM Officer approval is required for any implementation of idiosyncratic control settings for an individual risk factor. An FRM Officer may also approve idiosyncratic control settings based on additional considerations, including market moves, expected shortfall risk contribution, and changes in Clearing Member positions. Generally, the FRM Officer will approve the reversion back to regular control settings once market volatility lessens, but in exceptional circumstances, the FRM Officer has the discretion to apply the idiosyncratic control settings for a longer or shorter period of time.
                </P>
                <FTNT>
                    <P>
                        <SU>23</SU>
                         These “idiosyncratic thresholds” are defined in OCC's internal Margin Setting and Maintenance Procedure. OCC included a copy of this procedure as Exhibit 3F for the Proposed Rule Change.
                    </P>
                </FTNT>
                <P>The new language in the Margin Policy would also state that changes to the idiosyncratic thresholds require MRWG approval.</P>
                <P>These proposed changes to the Margin Policy describe current OCC processes that will remain unchanged.</P>
                <HD SOURCE="HD1">III. Discussion and Commission Findings</HD>
                <P>
                    Section 19(b)(2)(C) of the Exchange Act directs the Commission to approve a proposed rule change of a self-regulatory organization if it finds that such proposed rule change is consistent with the requirements of the Exchange Act and the rules and regulations thereunder applicable to such organization.
                    <SU>24</SU>
                    <FTREF/>
                     Under the Commission's Rules of Practice, the “burden to demonstrate that a proposed rule change is consistent with the Exchange Act and the rules and regulations issued thereunder . . . is on the self-regulatory organization [`SRO'] that proposed the rule change.” 
                    <SU>25</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>24</SU>
                         15 U.S.C. 78s(b)(2)(C).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>25</SU>
                         Rule 700(b)(3), Commission Rules of Practice, 17 CFR 201.700(b)(3).
                    </P>
                </FTNT>
                <P>
                    The description of a proposed rule change, its purpose and operation, its effect, and a legal analysis of its consistency with applicable requirements must all be sufficiently detailed and specific to support an affirmative Commission finding,
                    <SU>26</SU>
                    <FTREF/>
                     and any failure of an SRO to provide this information may result in the Commission not having a sufficient basis to make an affirmative finding that a proposed rule change is consistent with the Exchange Act and the applicable rules and regulations.
                    <SU>27</SU>
                    <FTREF/>
                     Moreover, “unquestioning reliance” on an SRO's representations in a proposed rule change is not sufficient to justify Commission approval of a proposed rule change.
                    <SU>28</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>26</SU>
                         
                        <E T="03">Id.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>27</SU>
                         
                        <E T="03">Id.</E>
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>28</SU>
                         
                        <E T="03">Susquehanna Int'l Group, LLP</E>
                         v. 
                        <E T="03">Securities and Exchange Commission,</E>
                         866 F.3d 442, 447 (D.C. Cir. 2017).
                    </P>
                </FTNT>
                <P>
                    After carefully considering the Proposed Rule Change, the Commission finds that the Proposed Rule Change is consistent with the requirements of the Exchange Act and the rules and regulations thereunder applicable to OCC. More specifically, the Commission finds that the Proposed Rule Change is consistent with Section 17A(b)(3)(F) of the Exchange Act 
                    <SU>29</SU>
                    <FTREF/>
                     and Rules 17Ad-22(e)(2) 
                    <SU>30</SU>
                    <FTREF/>
                     and 17Ad-22(e)(6) 
                    <SU>31</SU>
                    <FTREF/>
                     thereunder, as described in detail below.
                </P>
                <FTNT>
                    <P>
                        <SU>29</SU>
                         15 U.S.C. 78q-1(b)(3)(F).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>30</SU>
                         17 CFR 240.17Ad-22(e)(2).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>31</SU>
                         17 CFR 240.17Ad-22(e)(6).
                    </P>
                </FTNT>
                <HD SOURCE="HD2">A. Consistency With Section 17A(b)(3)(F) of the Exchange Act</HD>
                <P>
                    Section 17A(b)(3)(F) of the Exchange Act requires, among other things, that the rules of a clearing agency be designed to assure the safeguarding of securities and funds which are in the custody or control of the clearing agency or for which it is responsible.
                    <SU>32</SU>
                    <FTREF/>
                     Based on the review of the record, and for the reasons described below, OCC's proposed update to its Margin Policy in the manner described above is consistent with the safeguarding of securities and funds which are in OCC's custody or control or for which it is responsible.
                </P>
                <FTNT>
                    <P>
                        <SU>32</SU>
                         15 U.S.C. 78q-1(b)(3)(F).
                    </P>
                </FTNT>
                <PRTPAGE P="713"/>
                <P>
                    OCC's high-volatility parameter control settings provide an exception handling process for OCC to correct for procyclicality effects on the GARCH model calculation that may unreasonably inflate Clearing Members' margin requirements during periods of high market volatility.
                    <SU>33</SU>
                    <FTREF/>
                     The idiosyncratic control settings allow OCC to adjust Clearing Member margin requirements to be commensurate with the risk of the products, portfolios, or markets when an individual risk factor becomes volatile (
                    <E T="03">e.g.,</E>
                     reflecting genuine changes in the risk of the Clearing Member's products or portfolio, or the markets), rather than allowing the Clearing Member's margin requirement to diverge from observed market dynamics based on the reactivity of OCC's GARCH model. The global control settings offer the same benefit for periods during which all or a class of risk factors becomes volatile. Therefore, by setting and reviewing high-volatility parameter control settings, OCC is able to reduce the likelihood that Clearing Members would become operationally unstable or, potentially, default as the result of unreasonably high margin calls. This in turn further assures the safeguarding of Clearing Members' collateral by reducing the likelihood that OCC would be forced to charge losses from a defaulting Clearing Member to the Clearing Fund.
                </P>
                <FTNT>
                    <P>
                        <SU>33</SU>
                         Examples of unreasonably inflated margin requirements were included in backtesting data and analysis provided as part of OCC's confidential Exhibit 3C to File No. SR-OCC-2024-014. 
                        <E T="03">See</E>
                         Notice of Filing, 89 FR 81962, note 43.
                    </P>
                </FTNT>
                <P>OCC's use of CCA Monitoring Thresholds to monitor for market volatility is also consistent with the safeguarding of securities and funds which are in OCC's custody or control or for which it is responsible. The CCA Monitoring Thresholds are set and used for FRM to detect both high market volatility generally and high volatility of individual risk factors. When FRM observes that any of these thresholds are exceeded, FRM determines whether or not to recommend that OCC's high-volatility parameter control settings be implemented—either to MRWG that global controls should be implemented for market-wide volatility, or to the FRM Officer that idiosyncratic controls should be implemented for idiosyncratic volatility. OCC's monitoring and proper setting of these thresholds helps to lower the chances of a Clearing Member default resulting from margin calls that are significantly higher than necessary to account for the risk presented by the Clearing Member's products, portfolio, or the market, and thus assures the safeguarding of Clearing Members' collateral from any loss charges to OCC's Clearing Fund.</P>
                <P>
                    The high-volatility parameter control setting practices described in the Proposed Rule Change are designed to ensure that Clearing Member margin requirements remain commensurate with market risk in circumstances when the margin model reacts unreasonably to high market volatility. Indeed, the confidential backtesting data that OCC provided to the Commission 
                    <SU>34</SU>
                    <FTREF/>
                     shows that no account level exceedance has been attributed to OCC's implementation of high-volatility parameter control settings. Thus, the application of the high-volatility parameter control settings does not appear to have reduced OCC's ability to cover the risk posed by Clearing Members' positions. Additionally, the confidential information regarding model backtesting provided by OCC and reviewed by the Commission demonstrates that, overall, the use of high-volatility parameter control settings has not prevented OCC from maintaining a 2-day expected shortfall coverage level of 99%.
                    <SU>35</SU>
                    <FTREF/>
                     This demonstrates that, even with the use of the high-volatility parameter control settings, OCC's margin collateral remains sufficient to cover exposures at least 99 out of 100 days, as discussed above.
                    <SU>36</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>34</SU>
                         As stated in the Margin Policy, OCC monitors margin sufficiency by using its “business backtesting” process for monitoring account exceedances. OCC has provided responses to Commission requests for backtesting data and analysis as part of its confidential Exhibit 3C to File No. SR-OCC-2024-014. 
                        <E T="03">See</E>
                         Notice of Filing, 89 FR 81962, note 43.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>35</SU>
                         Notice of Filing, 89 FR 81962.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>36</SU>
                         
                        <E T="03">See supra</E>
                         note 8.
                    </P>
                </FTNT>
                <P>
                    For the foregoing reasons, the Proposed Rule Change is consistent with the requirements of Section 17A(b)(3)(F) of the Exchange Act.
                    <SU>37</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>37</SU>
                         15 U.S.C. 78q-1(b)(3)(F).
                    </P>
                </FTNT>
                <HD SOURCE="HD2">B. Consistency with Rule 17Ad-22(e)(2) under the Exchange Act</HD>
                <P>
                    Rule 17Ad-22(e)(2) under the Exchange Act requires that a covered clearing agency establish, implement, maintain and enforce written policies and procedures reasonably designed to, as applicable, provide for governance arrangements that, among other things, specify clear and direct lines of responsibility.
                    <SU>38</SU>
                    <FTREF/>
                     Based on the review of the record, and for the reasons described below, OCC's proposed update to its Margin Policy in the manner described above is consistent with Rule 17Ad-22(e)(2)(v).
                </P>
                <FTNT>
                    <P>
                        <SU>38</SU>
                         17 CFR 240.17Ad-22(e)(2)(v).
                    </P>
                </FTNT>
                <P>OCC's amendments to its Margin Policy describe the the arrangements governing the implemention, modification, and termination of high-volatility parameter controls. Defining the MRWG, QRM, FRM, and FRM Officer's roles and responsibilities in these processes specifies clear and direct lines of responsibility. Specifically, the added language to the Margin Policy describes the role of FRM in monitoring for both market and idiosyncratic volatility. It also describes the FRM's direct line of responsibility to either the MRWG for global control settings or the FRM Officer for idiosyncratic control settings, as well as the roles of MRWG and the FRM Officer in approving the eventual reversion back to regular control settings.</P>
                <P>
                    For the foregoing reasons, the Proposed Rule Change is consistent with Rule 17Ad-22(e)(2) under the Exchange Act.
                    <SU>39</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>39</SU>
                         17 CFR 240.17Ad-22(e)(2).
                    </P>
                </FTNT>
                <HD SOURCE="HD2">C. Consistency With Rule 17Ad-22(e)(6) Under the Exchange Act</HD>
                <P>
                    Rule 17Ad-22(e)(6) under the Exchange Act requires that a covered clearing agency establish, implement, maintain, and enforce written policies and procedures reasonably designed to cover, if the covered clearing agency provides central counterparty services, its credit exposures to its participants by establishing a risk-based margin system that, among other things, (1) considers, and produces margin levels commensurate with, the risks and particular attributes of each relevant product, portfolio, and market 
                    <SU>40</SU>
                    <FTREF/>
                     and (2) calculates sufficient margin to cover its potential future exposure to participants in the interval between the last margin collection and the close out of positions following a participant default.
                    <SU>41</SU>
                    <FTREF/>
                     Based on the review of the record, and for the reasons described below, OCC's proposed update to its Margin Policy in the manner described above is consistent with Rule 17Ad-22(e)(6).
                </P>
                <FTNT>
                    <P>
                        <SU>40</SU>
                         17 CFR 240.17Ad-22(e)(6)(i).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>41</SU>
                         17 CFR 240.17Ad-22(e)(6)(iii).
                    </P>
                </FTNT>
                <P>
                    As described above, the high-volatility parameter control settings provide a necessary exception process allowing OCC to mitigate a limitation of its GARCH models that have demonstrated extreme sensitivity to sudden spikes in volatility. Such reactivity can produce instability, and in certain instances, over- or underestimation of margin 
                    <PRTPAGE P="714"/>
                    requirements.
                    <SU>42</SU>
                    <FTREF/>
                     The confidential backtesting data that OCC provided to the Commission has shown that during instances of market volatility where OCC has employed either the idiosyncratic control settings or the global control settings, the control settings have limited Clearing Member margin requirements to be commensurate with market risk by countering procyclicality effects, while still ensuring that OCC is collecting appropriate margin to cover its exposure to relevant products, portfolios, and markets.
                    <SU>43</SU>
                    <FTREF/>
                     Ensuring that OCC maintains processes to counter procyclicality, in turn, allows for reduced margin requirements that, as described above, do not degrade backtesting coverage. Therefore, OCC is still able to calculate sufficient margin, while limiting the need for “destabilizing, procyclical changes.” 
                    <SU>44</SU>
                    <FTREF/>
                     Further, including such high-volatility parameter control settings reduces the likelihood that Clearing Members would be required to provide additional financial resources unnecessarily, which, in turn, could reduce the strain on such Clearing Members during stressed market conditions.
                </P>
                <FTNT>
                    <P>
                        <SU>42</SU>
                         For example, OCC's 2018 model would have increased aggregate margin requirements by 80 percent overnight in response to increased volatility observed on February 5, 2018. OCC stated that it believed that these margin requirements were unreasonable and procyclical. 
                        <E T="03">See</E>
                         Notice of Filing, 89 FR 81960; Securities Exchange Act Release No. 84879, at 83 FR 67392, 67393.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>43</SU>
                         OCC has provided responses to Commission requests for backtesting data and analysis as part of its confidential Exhibit 3C to File No. SR-OCC-2024-014. 
                        <E T="03">See</E>
                         Notice of Filing, 89 FR 81962, note 43.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>44</SU>
                         
                        <E T="03">See</E>
                         Standards for Covered Clearing Agencies, 81 FR 70819.
                    </P>
                </FTNT>
                <P>
                    Accordingly, the Proposed Rule Change is consistent with Rule 17Ad-22(e)(6) under the Exchange Act.
                    <SU>45</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>45</SU>
                         17 CFR 240.17Ad-22(e)(6).
                    </P>
                </FTNT>
                <HD SOURCE="HD1">IV. Conclusion</HD>
                <P>
                    On the basis of the foregoing, the Commission finds that the Proposed Rule Change is consistent with the requirements of the Exchange Act, and in particular, the requirements of Section 17A of the Exchange Act 
                    <SU>46</SU>
                    <FTREF/>
                     and the rules and regulations thereunder.
                </P>
                <FTNT>
                    <P>
                        <SU>46</SU>
                         In approving the Proposed Rule Change, the Commission has considered the proposed rule's impact on efficiency, competition, and capital formation. 
                        <E T="03">See</E>
                         15 U.S.C. 78c(f).
                    </P>
                </FTNT>
                <P>
                    <E T="03">It is therefore ordered,</E>
                     pursuant to Section 19(b)(2) of the Exchange Act,
                    <SU>47</SU>
                    <FTREF/>
                     that the proposed rule change, as modified by Partial Amendment No. 1 (SR-OCC-2024-014), be, and hereby is, approved.
                </P>
                <FTNT>
                    <P>
                        <SU>47</SU>
                         15 U.S.C. 78s(b)(2).
                    </P>
                </FTNT>
                <SIG>
                    <P>
                        For the Commission, by the Division of Trading and Markets, pursuant to delegated authority.
                        <SU>48</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>48</SU>
                             17 CFR 200.30-3(a)(12).
                        </P>
                    </FTNT>
                    <NAME>Stephanie J. Fouse,</NAME>
                    <TITLE>Assistant Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31610 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8011-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">SECURITIES AND EXCHANGE COMMISSION</AGENCY>
                <DEPDOC>[Release No. 34-102054; File No. SR-LTSE-2024-11]</DEPDOC>
                <SUBJECT>Self-Regulatory Organizations; Long-Term Stock Exchange, Inc.; Notice of Filing and Immediate Effectiveness of Proposed Rule Change To Establish Fees for Industry Members Related to Reasonably Budgeted CAT Costs of the National Market System Plan Governing the Consolidated Audit Trail for 2025</SUBJECT>
                <DATE>December 30, 2024.</DATE>
                <P>
                    Pursuant to Section 19(b)(1) of the Securities Exchange Act of 1934 (“Act”),
                    <SU>1</SU>
                    <FTREF/>
                     and Rule 19b-4 thereunder,
                    <SU>2</SU>
                    <FTREF/>
                     notice is hereby given that on December 20, 2024, Long-Term Stock Exchange, Inc. (“Exchange”) filed with the Securities and Exchange Commission (“Commission”) the proposed rule change as described in Item I below, which Item has been substantially prepared by the Exchange. The Exchange has designated this proposal for immediate effectiveness pursuant to Section 19(b)(3)(A) of the Act 
                    <SU>3</SU>
                    <FTREF/>
                     and Rule 19b-4(f) thereunder.
                    <SU>4</SU>
                    <FTREF/>
                     The Commission is publishing this notice to solicit comments on the proposed rule change from interested persons.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         15 U.S.C. 78s(b)(1).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         17 CFR 240.19b-4.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         15 U.S.C. 78s(b)(3)(A).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         17 CFR 240.19b-4(f). At any time within 60 days of the filing of the proposed rule change, the Commission summarily may temporarily suspend such rule change if it appears to the Commission that such action is necessary or appropriate in the public interest, for the protection of investors, or otherwise in furtherance of the purposes of the Act. If the Commission takes such action, the Commission will institute proceedings to determine whether the proposed rule change should be approved or disapproved.
                    </P>
                </FTNT>
                <HD SOURCE="HD1">I. Self-Regulatory Organization's Statement of the Terms of Substance of the Proposed Rule Change</HD>
                <P>
                    The Exchange proposes a rule change to establish fees for Industry Members 
                    <SU>5</SU>
                    <FTREF/>
                     related to reasonably budgeted CAT costs of the National Market System Plan Governing the Consolidated Audit Trail for 2025.
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         An “Industry Member” is defined as “a member of a national securities exchange or a member of a national securities association.” 
                        <E T="03">See</E>
                         LTSE Rule 11.610(u). 
                        <E T="03">See also</E>
                         Section 1.1 of the CAT NMS Plan. Unless otherwise specified, capitalized terms used in this rule filing are defined as set forth in the CAT NMS Plan and/or the CAT Compliance Rule. 
                        <E T="03">See</E>
                         Exchange Rule Series 11.600.
                    </P>
                </FTNT>
                <P>
                    The proposed rule change, including the Exchange's statement of the purpose of, and statutory basis for, the proposed rule change, is available on the Exchange's website at 
                    <E T="03">https://longtermstockexchange.com/,</E>
                     at the principal office of the Exchange, and on the Commission's website at 
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-LTSE-2024-11</E>
                    .
                </P>
                <HD SOURCE="HD1">II. Solicitation of Comments</HD>
                <P>
                    Interested persons are invited to submit written data, views, and arguments concerning the foregoing, including whether the proposed rule change is consistent with the Act.
                    <SU>6</SU>
                    <FTREF/>
                     Comments may be submitted electronically by using the Commission's internet comment form (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-LTSE-2024-11</E>
                    ) or by sending an email to 
                    <E T="03">rule-comments@sec.gov</E>
                    . Please include file number SR-LTSE-2024-11 on the subject line. Alternatively, paper comments may be sent to Secretary, Securities and Exchange Commission, 100 F Street NE, Washington, DC 20549-1090. All submissions should refer to file number SR-LTSE-2024-11. To help the Commission process and review your comments more efficiently, please use only one method. The Commission will post all comments on the Commission's internet website (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-LTSE-2024-11</E>
                    ). Do not include personal identifiable information in submissions; you should submit only information that you wish to make available publicly. We may redact in part or withhold entirely from publication submitted material that is obscene or subject to copyright protection. All submissions should refer 
                    <PRTPAGE P="715"/>
                    to file number SR-LTSE-2024-11 and should be submitted on or before January 27, 2025.
                </P>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         Copies of the submission, all subsequent amendments, all written statements with respect to the proposed rule change that are filed with the Commission, and all written communications relating to the proposed rule change between the Commission and any person, other than those that may be withheld from the public in accordance with the provisions of 5 U.S.C. 552, will be available for website viewing and printing in the Commission's Public Reference Room, 100 F Street NE, Washington, DC 20549, on official business days between the hours of 10 a.m. and 3 p.m. Copies of the filing also will be available for inspection and copying at the principal office of SRO.
                    </P>
                </FTNT>
                <SIG>
                    <P>
                        For the Commission, by the Division of Trading and Markets, pursuant to delegated authority.
                        <SU>7</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>7</SU>
                             17 CFR 200.30-3(a)(12).
                        </P>
                    </FTNT>
                    <NAME>Stephanie J. Fouse,</NAME>
                    <TITLE>Assistant Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31613 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8011-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">SECURITIES AND EXCHANGE COMMISSION</AGENCY>
                <DEPDOC>[Release No. 34-102061; File No. SR-MEMX-2024-49]</DEPDOC>
                <SUBJECT>Self-Regulatory Organizations; MEMX LLC; Notice of Filing and Immediate Effectiveness of Proposed Rule Change To Establish Fees for Industry Members Related to Reasonably Budgeted CAT Costs of the National Market System Plan Governing the Consolidated Audit Trail for 2025</SUBJECT>
                <DATE>December 31, 2024.</DATE>
                <P>
                    Pursuant to Section 19(b)(1) of the Securities Exchange Act of 1934 (“Act”),
                    <SU>1</SU>
                    <FTREF/>
                     and Rule 19b-4 thereunder,
                    <SU>2</SU>
                    <FTREF/>
                     notice is hereby given that on December 20, 2024, MEMX LLC (“Exchange”) filed with the Securities and Exchange Commission (“Commission”) the proposed rule change as described in Item I below, which Item has been substantially prepared by the Exchange. The Exchange has designated this proposal for immediate effectiveness pursuant to Section 19(b)(3)(A) of the Act 
                    <SU>3</SU>
                    <FTREF/>
                     and Rule 19b-4(f) thereunder.
                    <SU>4</SU>
                    <FTREF/>
                     The Commission is publishing this notice to solicit comments on the proposed rule change from interested persons.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         15 U.S.C. 78s(b)(1).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         17 CFR 240.19b-4.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         15 U.S.C. 78s(b)(3)(A).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         17 CFR 240.19b-4(f). At any time within 60 days of the filing of the proposed rule change, the Commission summarily may temporarily suspend such rule change if it appears to the Commission that such action is necessary or appropriate in the public interest, for the protection of investors, or otherwise in furtherance of the purposes of the Act. If the Commission takes such action, the Commission will institute proceedings to determine whether the proposed rule change should be approved or disapproved.
                    </P>
                </FTNT>
                <HD SOURCE="HD1">I. Self-Regulatory Organization's Statement of the Terms of Substance of the Proposed Rule Change</HD>
                <P>
                    The Exchange is filing with the Commission a proposed rule change to establish fees for Industry Members 
                    <SU>5</SU>
                    <FTREF/>
                     related to reasonably budgeted CAT costs of the National Market System Plan Governing the Consolidated Audit Trail (the “CAT NMS Plan” or “Plan”) for 2025. These fees would be payable to Consolidated Audit Trail, LLC (“CAT LLC” or the “Company”) and referred to as CAT Fee 2025-1, and would be described in a section of the Exchange's fee schedule entitled “Consolidated Audit Trail Funding Fees.” The fee rate for CAT Fee 2025-1 would be $0.000022 per executed equivalent share. CAT Executing Brokers will receive their first monthly invoice for CAT Fee 2025-1 in February 2025 calculated based on their transactions as CAT Executing Brokers for the Buyer (“CEBB”) and/or CAT Executing Brokers for the Seller (“CEBS”) in January 2025. CAT Fee 2025-1 is anticipated to be in place for six months, and is anticipated to recover approximately one-half of the costs set forth in the reasonably budgeted CAT costs for 2025. CAT LLC intends for CAT Fee 2025-1 to replace CAT Fee 2024-1 (which has a fee rate of $0.000035). The text of the proposed rule change is attached as Exhibit 5.
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         An “Industry Member” is defined as “a member of a national securities exchange or a member of a national securities association.” 
                        <E T="03">See</E>
                         Rule 4.5(u). 
                        <E T="03">See also</E>
                         Section 1.1 of the CAT NMS Plan. Unless otherwise specified, capitalized terms used in this rule filing are defined as set forth in the CAT NMS Plan and/or the CAT Compliance Rule. 
                        <E T="03">See</E>
                         Rule 4.5.
                    </P>
                </FTNT>
                <P>
                    The proposed rule change, including the Exchange's statement of the purpose of, and statutory basis for, the proposed rule change, is available at the principal office of the Exchange, and on the Commission's website at 
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-MEMX-2024-49.</E>
                </P>
                <HD SOURCE="HD1">II. Solicitation of Comments</HD>
                <P>
                    Interested persons are invited to submit written data, views, and arguments concerning the foregoing, including whether the proposed rule change is consistent with the Act.
                    <SU>6</SU>
                    <FTREF/>
                     Comments may be submitted electronically by using the Commission's internet comment form (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-MEMX-2024-49</E>
                    ) or by sending an email to 
                    <E T="03">rule-comments@sec.gov.</E>
                     Please include file number SR-MEMX-2024-49 on the subject line. Alternatively, paper comments may be sent to Secretary, Securities and Exchange Commission, 100 F Street NE, Washington, DC 20549-1090. All submissions should refer to file number SR-MEMX-2024-49. To help the Commission process and review your comments more efficiently, please use only one method. The Commission will post all comments on the Commission's internet website (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-MEMX-2024-49</E>
                    ). Do not include personal identifiable information in submissions; you should submit only information that you wish to make available publicly. We may redact in part or withhold entirely from publication submitted material that is obscene or subject to copyright protection. All submissions should refer to file number SR-MEMX-2024-49 and should be submitted on or before January 27, 2025.
                </P>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         Copies of the submission, all subsequent amendments, all written statements with respect to the proposed rule change that are filed with the Commission, and all written communications relating to the proposed rule change between the Commission and any person, other than those that may be withheld from the public in accordance with the provisions of 5 U.S.C. 552, will be available for website viewing and printing in the Commission's Public Reference Room, 100 F Street NE, Washington, DC 20549, on official business days between the hours of 10 a.m. and 3 p.m. Copies of the filing also will be available for inspection and copying at the principal office of SRO.
                    </P>
                </FTNT>
                <SIG>
                    <P>
                        For the Commission, by the Division of Trading and Markets, pursuant to delegated authority.
                        <SU>7</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>7</SU>
                             17 CFR 200.30-3(a)(12).
                        </P>
                    </FTNT>
                    <NAME>Stephanie J. Fouse,</NAME>
                    <TITLE>Assistant Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31767 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8011-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">SECURITIES AND EXCHANGE COMMISSION</AGENCY>
                <DEPDOC>[Release No. 34-102069; File No. SR-CboeEDGX-2024-088]</DEPDOC>
                <SUBJECT>Self-Regulatory Organizations; Cboe EDGX Exchange, Inc.; Notice of Filing and Immediate Effectiveness of Proposed Rule Change To Establish Fees for Industry Members Related to Reasonably Budgeted CAT Costs of the National Market System Plan Governing the Consolidated Audit Trail for 2025</SUBJECT>
                <DATE>December 31, 2024.</DATE>
                <P>
                    Pursuant to Section 19(b)(1) of the Securities Exchange Act of 1934 (“Act”),
                    <SU>1</SU>
                    <FTREF/>
                     and Rule 19b-4 thereunder,
                    <SU>2</SU>
                    <FTREF/>
                     notice is hereby given that on December 20, 2024, Cboe EDGX Exchange, Inc. (“Exchange”) filed with the Securities and Exchange Commission (“Commission”) the proposed rule change as described in Item I below, 
                    <PRTPAGE P="716"/>
                    which Item has been substantially prepared by the Exchange. The Exchange has designated this proposal for immediate effectiveness pursuant to Section 19(b)(3)(A) of the Act 
                    <SU>3</SU>
                    <FTREF/>
                     and Rule 19b-4(f) thereunder.
                    <SU>4</SU>
                    <FTREF/>
                     The Commission is publishing this notice to solicit comments on the proposed rule change from interested persons.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         15 U.S.C. 78s(b)(1).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         17 CFR 240.19b-4.
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         15 U.S.C. 78s(b)(3)(A).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         17 CFR 240.19b-4(f). At any time within 60 days of the filing of the proposed rule change, the Commission summarily may temporarily suspend such rule change if it appears to the Commission that such action is necessary or appropriate in the public interest, for the protection of investors, or otherwise in furtherance of the purposes of the Act. If the Commission takes such action, the Commission will institute proceedings to determine whether the proposed rule change should be approved or disapproved.
                    </P>
                </FTNT>
                <HD SOURCE="HD1">I. Self-Regulatory Organization's Statement of the Terms of Substance of the Proposed Rule Change</HD>
                <P>The Exchange proposes to amend its “Consolidated Audit Trail Funding Fees” fee schedule to establish the CAT Fee 2025-1 fee rate of $0.000022 per executed equivalent share.</P>
                <P>
                    The proposed rule change, including the Exchange's statement of the purpose of, and statutory basis for, the proposed rule change, is available on the Exchange's website at 
                    <E T="03">http://www.cboe.com/AboutCBOE/CBOELegalRegulatoryHome.aspx,</E>
                     at the principal office of the Exchange, and on the Commission's website at 
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-CboeEDGX-2024-088.</E>
                </P>
                <HD SOURCE="HD1">II. Solicitation of Comments</HD>
                <P>
                    Interested persons are invited to submit written data, views, and arguments concerning the foregoing, including whether the proposed rule change is consistent with the Act.
                    <SU>5</SU>
                    <FTREF/>
                     Comments may be submitted electronically by using the Commission's internet comment form (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-CboeEDGX-2024-088</E>
                    ) or by sending an email to 
                    <E T="03">rule-comments@sec.gov.</E>
                     Please include file number SR-CboeEDGX-2024-088 on the subject line. Alternatively, paper comments may be sent to Secretary, Securities and Exchange Commission, 100 F Street NE, Washington, DC 20549-1090. All submissions should refer to file number SR-CboeEDGX-2024-088. To help the Commission process and review your comments more efficiently, please use only one method. The Commission will post all comments on the Commission's internet website (
                    <E T="03">https://www.sec.gov/rules-regulations/self-regulatory-organization-rulemaking/national-securities-exchanges?file_number=SR-CboeEDGX-2024-088</E>
                    ). Do not include personal identifiable information in submissions; you should submit only information that you wish to make available publicly. We may redact in part or withhold entirely from publication submitted material that is obscene or subject to copyright protection. All submissions should refer to file number SR-CboeEDGX-2024-088 and should be submitted on or before January 27, 2025.
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         Copies of the submission, all subsequent amendments, all written statements with respect to the proposed rule change that are filed with the Commission, and all written communications relating to the proposed rule change between the Commission and any person, other than those that may be withheld from the public in accordance with the provisions of 5 U.S.C. 552, will be available for website viewing and printing in the Commission's Public Reference Room, 100 F Street NE, Washington, DC 20549, on official business days between the hours of 10 a.m. and 3 p.m. Copies of the filing also will be available for inspection and copying at the principal office of SRO.
                    </P>
                </FTNT>
                <SIG>
                    <P>
                        For the Commission, by the Division of Trading and Markets, pursuant to delegated authority.
                        <SU>6</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>6</SU>
                             17 CFR 200.30-3(a)(12).
                        </P>
                    </FTNT>
                    <NAME>Stephanie J. Fouse,</NAME>
                    <TITLE>Assistant Secretary.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31775 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8011-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">SMALL BUSINESS ADMINISTRATION</AGENCY>
                <DEPDOC>[Disaster Declaration #20701 and #20702; NORTH CAROLINA Disaster Number NC-20007]</DEPDOC>
                <SUBJECT>Presidential Declaration Amendment of a Major Disaster for the State of North Carolina</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>U.S. Small Business Administration.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Amendment 4.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>This is an amendment of the Presidential declaration of a major disaster for the State of North Carolina (FEMA-4827-DR), dated September 28, 2024.</P>
                    <P>
                        <E T="03">Incident:</E>
                         Tropical Storm Helene.
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Issued on December 20, 2024.</P>
                    <P>
                        <E T="03">Incident Period:</E>
                         September 25, 2024 through December 18, 2024.
                    </P>
                    <P>
                        <E T="03">Physical Loan Application Deadline Date:</E>
                         January 7, 2025.
                    </P>
                    <P>
                        <E T="03">Economic Injury (EIDL) Loan Application Deadline Date:</E>
                         June 30, 2025.
                    </P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        <E T="03">Visit the MySBA Loan Portal at https://lending.sba.gov</E>
                         to apply for a disaster assistance loan.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Alan Escobar, Office of Disaster Recovery &amp; Resilience, U.S. Small Business Administration, 409 3rd Street SW, Suite 6050, Washington, DC 20416, (202) 205-6734.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>The notice of the President's major disaster declaration for the State of North Carolina, dated September 28, 2024, is hereby amended to update the incident period for this disaster as beginning September 25, 2024 and continuing through December 18, 2024.</P>
                <P>All other information in the original declaration remains unchanged.</P>
                <EXTRACT>
                    <FP>(Catalog of Federal Domestic Assistance Number 59008)</FP>
                </EXTRACT>
                <SIG>
                    <NAME>Alejandro Contreras,</NAME>
                    <TITLE>Acting Deputy Associate Administrator, Office of Disaster Recovery &amp; Resilience.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31646 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8026-09-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">SMALL BUSINESS ADMINISTRATION</AGENCY>
                <DEPDOC>[Disaster Declaration #20543 and #20544; GEORGIA Disaster Number GA-20010]</DEPDOC>
                <SUBJECT>Presidential Declaration Amendment of a Major Disaster for the State of Georgia</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>U.S. Small Business Administration.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Amendment 2.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>This is an amendment of the Presidential declaration of a major disaster for the State of Georgia (FEMA-4821-DR), dated September 24, 2024.</P>
                    <P>
                        <E T="03">Incident:</E>
                         Tropical Storm Debby.
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Issued on December 26, 2024.</P>
                    <P>
                        <E T="03">Incident Period:</E>
                         August 4, 2024 through August 20, 2024.
                    </P>
                    <P>
                        <E T="03">Physical Loan Application Deadline Date:</E>
                         February 7, 2025.
                    </P>
                    <P>
                        <E T="03">Economic Injury (EIDL) Loan Application Deadline Date:</E>
                         June 24, 2025.
                    </P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        <E T="03">Visit the MySBA Loan Portal at https://lending.sba.gov</E>
                         to apply for a disaster assistance loan.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Alan Escobar, Office of Disaster Recovery &amp; Resilience, U.S. Small Business Administration, 409 3rd Street SW, Suite 6050, Washington, DC 20416, (202) 205-6734.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    The notice of the President's major disaster declaration for the State of Georgia, dated September 24, 2024, is hereby amended to extend the deadline for 
                    <PRTPAGE P="717"/>
                    filing applications for physical damages as a result of this disaster to February 7, 2025.
                </P>
                <P>All other information in the original declaration remains unchanged.</P>
                <EXTRACT>
                    <FP>(Catalog of Federal Domestic Assistance Number 59008)</FP>
                </EXTRACT>
                <SIG>
                    <NAME>Alejandro Contreras,</NAME>
                    <TITLE>Acting Deputy Associate Administrator, Office of Disaster Recovery &amp; Resilience.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31596 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8026-09-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">SMALL BUSINESS ADMINISTRATION</AGENCY>
                <DEPDOC>[Disaster Declaration #20720 and #20721; NORTH CAROLINA Disaster Number NC-20009]</DEPDOC>
                <SUBJECT>Presidential Declaration Amendment of a Major Disaster for Public Assistance Only for the State of North Carolina</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>U.S. Small Business Administration.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Amendment 3.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>This is an amendment of the Presidential declaration of a major disaster for Public Assistance Only for the State of North Carolina (FEMA-4827-DR), dated October 2, 2024.</P>
                    <P>
                        <E T="03">Incident:</E>
                         Tropical Storm Helene.
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Issued on December 20, 2024.</P>
                    <P>
                        <E T="03">Incident Period:</E>
                         September 25, 2024 through December 18, 2024.
                    </P>
                    <P>
                        <E T="03">Physical Loan Application Deadline Date:</E>
                         January 20, 2025.
                    </P>
                    <P>
                        <E T="03">Economic Injury (EIDL) Loan Application Deadline Date:</E>
                         July 2, 2025.
                    </P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        <E T="03">Visit the MySBA Loan Portal at https://lending.sba.gov</E>
                         to apply for a disaster assistance loan.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Alan Escobar, Office of Disaster Recovery &amp; Resilience, U.S. Small Business Administration, 409 3rd Street SW, Suite 6050, Washington, DC 20416, (202) 205-6734.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>The notice of the President's major disaster declaration for Private Non-Profit organizations in the State of North Carolina, dated October 2, 2024, is hereby amended to update the incident period for this disaster as beginning September 25, 2024 and continuing through December 18, 2024.</P>
                <P>All other information in the original declaration remains unchanged.</P>
                <EXTRACT>
                    <FP>(Catalog of Federal Domestic Assistance Number 59008)</FP>
                </EXTRACT>
                <SIG>
                    <NAME>Alejandro Contreras,</NAME>
                    <TITLE>Acting Deputy Associate Administrator, Office of Disaster Recovery &amp; Resilience.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31605 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8026-09-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">SMALL BUSINESS ADMINISTRATION</AGENCY>
                <DEPDOC>[Disaster Declaration #20711 and #20712; GEORGIA Disaster Number GA-20013]</DEPDOC>
                <SUBJECT>Presidential Declaration Amendment of a Major Disaster for the State of Georgia</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>U.S. Small Business Administration.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Amendment 11.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>This is an amendment of the Presidential declaration of a major disaster for the State of Georgia (FEMA-4830-DR), dated September 30, 2024.</P>
                    <P>
                        <E T="03">Incident:</E>
                         Hurricane Helene.
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Issued on December 26, 2024.</P>
                    <P>
                        <E T="03">Incident Period:</E>
                         September 24, 2024 through October 30, 2024.
                    </P>
                    <P>
                        <E T="03">Physical Loan Application Deadline Date:</E>
                         February 7, 2025.
                    </P>
                    <P>
                        <E T="03">Economic Injury (EIDL) Loan Application Deadline Date:</E>
                         June 30, 2025.
                    </P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        <E T="03">Visit the MySBA Loan Portal at https://lending.sba.gov</E>
                         to apply for a disaster assistance loan.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Alan Escobar, Office of Disaster Recovery &amp; Resilience, U.S. Small Business Administration, 409 3rd Street SW, Suite 6050, Washington, DC 20416, (202) 205-6734.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>The notice of the President's major disaster declaration for the State of Georgia, dated September 30, 2024, is hereby amended to extend the deadline for filing applications for physical damages as a result of this disaster to February 7, 2025.</P>
                <P>All other information in the original declaration remains unchanged.</P>
                <EXTRACT>
                    <FP>(Catalog of Federal Domestic Assistance Number 59008)</FP>
                </EXTRACT>
                <SIG>
                    <NAME>Alejandro Contreras,</NAME>
                    <TITLE>Acting Deputy Associate Administrator, Office of Disaster Recovery &amp; Resilience.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31597 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8026-09-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF STATE</AGENCY>
                <DEPDOC>[Public Notice: 12627; No. 2024-12]</DEPDOC>
                <SUBJECT>Determination Pursuant to the Foreign Missions Act</SUBJECT>
                <P>
                    Pursuant to the authority vested in the U.S. Secretary of State by the laws of the United States, including under the Foreign Missions Act, 22 U.S.C. 4301, 
                    <E T="03">et seq.</E>
                     (“the Act”), and delegated pursuant to U.S. Department of State Delegation of Authority No. 214, dated September 20, 1994, and after due consideration of matters related to the protection of the interests of the United States, as well as the benefits, privileges, and immunities provided to missions of the United States abroad, I hereby designate as a benefit for purposes of the Act exemption from charges assessed by the Metropolitan Transportation Authority of New York for entry into its designated “Congestion Relief Zone” for foreign missions and certain international organizations. This benefit extends to members and personnel of and representatives to such foreign missions and international organizations who enjoy certain tax-free privileges as determined by the Office of Foreign Missions and may be extended to vehicles bearing diplomatic and consular license plates issued by the Office of Foreign Missions.
                </P>
                <P>I determine that such exemption shall be provided to such foreign missions and international organizations on such terms and conditions as may be approved by the Office of Foreign Missions and that any state or local laws to the contrary are hereby preempted.</P>
                <P>This action is necessary to protect the interests of the United States, including with respect to fulfilling its international and domestic legal obligations and ensuring similar exemptions for U.S. missions and mission members abroad, and to facilitate relations between the United States and foreign states and relations between the United States and international organizations.</P>
                <P>The exemption from charges assessed by the Metropolitan Transportation Authority of New York for entry into its designated “Congestion Relief Zone” provided by this designation and determination shall apply to charges that have been or will be assessed against any foreign mission or international organization subject to this determination.</P>
                <SIG>
                    <NAME>Rebecca E. Gonzales,</NAME>
                    <TITLE>Director, Office of Foreign Missions, Department of State.</TITLE>
                </SIG>
            </PREAMB>
            <FRDOC>[FR Doc. 2024-31595 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4711-11-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <PRTPAGE P="718"/>
                <AGENCY TYPE="N">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <SUBAGY>Federal Motor Carrier Safety Administration</SUBAGY>
                <DEPDOC>[Docket No. FMCSA-2014-0215; FMCSA-2015-0323; FMCSA-2016-0008; FMCSA-2018-0028; FMCSA-2018-0053; FMCSA-2018-0056; FMCSA-2020-0050; FMCSA-2022-0045; FMCSA-2022-0046]</DEPDOC>
                <SUBJECT>Qualification of Drivers; Exemption Applications; Epilepsy and Seizure Disorders</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Federal Motor Carrier Safety Administration (FMCSA), Department of Transportation (DOT).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of renewal of exemptions; request for comments.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>FMCSA announces its decision to renew exemptions for 19 individuals from the requirement in the Federal Motor Carrier Safety Regulations (FMCSRs) that interstate commercial motor vehicle (CMV) drivers have “no established medical history or clinical diagnosis of epilepsy or any other condition which is likely to cause loss of consciousness or any loss of ability to control a CMV.” The exemptions enable these individuals who have had one or more seizures and are taking anti-seizure medication to continue to operate CMVs in interstate commerce.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Each group of renewed exemptions are applicable on the dates stated in the discussions below and will expire on the dates stated in the discussions below. Comments must be received on or before February 5, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may submit comments identified by the Federal Docket Management System Docket No. FMCSA-2014-0215, Docket No. FMCSA-2015-0323, Docket No. FMCSA-2016-0008, Docket No. FMCSA-2018-0028, Docket No. FMCSA-2018-0053, Docket No. FMCSA-2018-0056, Docket No. FMCSA-2020-0050, Docket No. FMCSA-2022-0045, or Docket No. FMCSA-2022-0046 using any of the following methods:</P>
                    <P>
                        • 
                        <E T="03">Federal eRulemaking Portal:</E>
                         Go to 
                        <E T="03">www.regulations.gov/,</E>
                         insert the docket number (FMCSA-2014-0215, FMCSA-2015-0323, FMCSA-2016-0008, FMCSA-2018-0028, FMCSA-2018-0053, FMCSA-2018-0056, FMCSA-2020-0050, FMCSA-2022-0045, or FMCSA-2022-0046) in the keyword box and click “Search.” Next, sort the results by “Posted (Newer-Older),” choose the first notice listed, and click on the “Comment” button. Follow the online instructions for submitting comments.
                    </P>
                    <P>
                        • 
                        <E T="03">Mail:</E>
                         Dockets Operations; U.S. Department of Transportation, 1200 New Jersey Avenue SE, West Building Ground Floor, Washington, DC 20590-0001.
                    </P>
                    <P>
                        • 
                        <E T="03">Hand Delivery:</E>
                         West Building Ground Floor, 1200 New Jersey Avenue SE, Washington, DC, 20590-0001 between 9 a.m. and 5 p.m. ET Monday through Friday, except Federal holidays.
                    </P>
                    <P>
                        • 
                        <E T="03">Fax:</E>
                         (202) 493-2251.
                    </P>
                    <P>
                        To avoid duplication, please use only one of these four methods. See the “Public Participation” portion of the 
                        <E T="02">SUPPLEMENTARY INFORMATION</E>
                         section for instructions on submitting comments.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Ms. Christine A. Hydock, Chief, Medical Programs Division, FMCSA, DOT, 1200 New Jersey Avenue SE, Washington, DC 20590-0001, (202) 366-4001, 
                        <E T="03">fmcsamedical@dot.gov.</E>
                         Office hours are from 8:30 a.m. to 5 p.m. ET Monday through Friday, except Federal holidays. If you have questions regarding viewing or submitting material to the docket, contact Dockets Operations, (202) 366-9826.
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P/>
                <HD SOURCE="HD1">I. Public Participation</HD>
                <HD SOURCE="HD2">A. Submitting Comments</HD>
                <P>If you submit a comment, please include the docket number for this notice (Docket No. FMCSA-2014-0215, Docket No. FMCSA-2015-0323, Docket No. FMCSA-2016-0008, Docket No. FMCSA-2018-0028, Docket No. FMCSA-2018-0053, Docket No. FMCSA-2018-0056, Docket No. FMCSA-2020-0050, Docket No. FMCSA-2022-0045, or Docket No. FMCSA-2022-0046), indicate the specific section of this document to which each comment applies, and provide a reason for each suggestion or recommendation. You may submit your comments and material online or by fax, mail, or hand delivery, but please use only one of these means. FMCSA recommends that you include your name and a mailing address, an email address, or a phone number in the body of your document so that FMCSA can contact you if there are questions regarding your submission.</P>
                <P>
                    To submit your comment online, go to 
                    <E T="03">www.regulations.gov/,</E>
                     insert the docket number (FMCSA-2014-0215, FMCSA-2015-0323, FMCSA-2016-0008, FMCSA-2018-0028, FMCSA-2018-0053, FMCSA-2018-0056, FMCSA-2020-0050, FMCSA-2022-0045, or FMCSA-2022-0046) in the keyword box and click “Search.” Next, sort the results by “Posted (Newer-Older),” choose the first notice listed, click the “Comment” button, and type your comment into the text box on the following screen. Choose whether you are submitting your comment as an individual or on behalf of a third party and then submit.
                </P>
                <P>
                    If you submit your comments by mail or hand delivery, submit them in an unbound format, no larger than 8
                    <FR>1/2</FR>
                     by 11 inches, suitable for copying and electronic filing. FMCSA will consider all comments and material received during the comment period.
                </P>
                <HD SOURCE="HD2">B. Viewing Comments</HD>
                <P>
                    To view comments go to 
                    <E T="03">www.regulations.gov.</E>
                     Insert the docket number (FMCSA-2014-0215, FMCSA-2015-0323, FMCSA-2016-0008, FMCSA-2018-0028, FMCSA-2018-0053, FMCSA-2018-0056, FMCSA-2020-0050, FMCSA-2022-0045, or FMCSA-2022-0046) in the keyword box and click “Search.” Next, sort the results by “Posted (Newer-Older),” choose the first notice listed, and click “Browse Comments.” If you do not have access to the internet, you may view the docket online by visiting Dockets Operations on the ground floor of the DOT West Building, 1200 New Jersey Avenue SE, Washington, DC 20590-0001, between 9 a.m. and 5 p.m. ET Monday through Friday, except Federal holidays. To be sure someone is there to help you, please call (202) 366-9317 or (202) 366-9826 before visiting Dockets Operations.
                </P>
                <HD SOURCE="HD2">C. Privacy Act</HD>
                <P>
                    In accordance with 49 U.S.C. 31315(b)(6), DOT solicits comments from the public on the exemption request. DOT posts these comments, without edit, including any personal information the commenter provides, to 
                    <E T="03">www.regulations.gov.</E>
                     As described in the system of records notice DOT/ALL 14 (Federal Docket Management System), which can be reviewed at 
                    <E T="03">https://www.transportation.gov/individuals/privacy/privacy-act-system-records-notices,</E>
                     the comments are searchable by the name of the submitter.
                </P>
                <HD SOURCE="HD1">II. Background</HD>
                <P>
                    Under 49 U.S.C. 31136(e) and 31315(b), FMCSA may grant an exemption from the FMCSRs for no longer than a 5-year period if it finds such exemption would likely achieve a level of safety that is equivalent to, or greater than, the level that would be achieved absent such exemption. The statutes also allow the Agency to renew exemptions at the end of the 5-year period. However, FMCSA grants medical exemptions from the FMCSRs for a 2-year period to align with the 
                    <PRTPAGE P="719"/>
                    maximum duration of a driver's medical certification.
                </P>
                <P>The physical qualification standard for drivers regarding epilepsy found in 49 CFR 391.41(b)(8) states that a person is physically qualified to drive a CMV if that person has no established medical history or clinical diagnosis of epilepsy or any other condition which is likely to cause the loss of consciousness or any loss of ability to control a CMV.</P>
                <P>
                    In addition to the regulations, FMCSA has published advisory criteria 
                    <SU>1</SU>
                    <FTREF/>
                     to assist Medical Examiners in determining whether drivers with certain medical conditions are qualified to operate a CMV in interstate commerce.
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         These criteria may be found in APPENDIX A TO PART 391—MEDICAL ADVISORY CRITERIA, section H. 
                        <E T="03">Epilepsy:</E>
                         § 391.41(b)(8), paragraphs 3, 4, and 5, which is available on the internet at 
                        <E T="03">https://www.gpo.gov/fdsys/pkg/CFR-2015-title49-vol5/pdf/CFR-2015-title49-vol5-part391-appA.pdf.</E>
                    </P>
                </FTNT>
                <P>The 19 individuals listed in this notice have requested renewal of their exemptions from the epilepsy and seizure disorders prohibition in § 391.41(b)(8), in accordance with FMCSA procedures. Accordingly, FMCSA has evaluated these applications for renewal on their merits and decided to extend each exemption for a renewable 2-year period.</P>
                <HD SOURCE="HD1">III. Request for Comments</HD>
                <P>Interested parties or organizations possessing information that would otherwise show that any, or all, of these drivers are not currently achieving the statutory level of safety should immediately notify FMCSA. The Agency will evaluate any adverse evidence submitted and, if safety is being compromised or if continuation of the exemption would not be consistent with the goals and objectives of 49 U.S.C. 31136(e) and 31315(b), FMCSA will take immediate steps to revoke the exemption of a driver.</P>
                <HD SOURCE="HD1">IV. Basis for Renewing Exemptions</HD>
                <P>In accordance with 49 U.S.C. 31136(e) and 31315(b), each of the 19 applicants has satisfied the renewal conditions for obtaining an exemption from the epilepsy and seizure disorders prohibition. The 19 drivers in this notice remain in good standing with the Agency, have maintained their medical monitoring and have not exhibited any medical issues that would compromise their ability to safely operate a CMV during the previous 2-year exemption period. In addition, the Agency has reviewed each applicant's certified driving record from their State Driver's Licensing Agency (SDLA). The information obtained from each applicant's driving record provides the Agency with details regarding any moving violations or reported crash data, which demonstrates whether the driver has a safe driving history and is an indicator of future driving performance. If the driving record revealed a crash, FMCSA requested and reviewed the related police reports and other relevant documents, such as the citation and conviction information. These factors provide an adequate basis for predicting each driver's ability to continue to safely operate a CMV in interstate commerce. Therefore, FMCSA concludes that extending the exemption for each renewal applicant for a period of 2 years is likely to achieve a level of safety equal to that existing without the exemption.</P>
                <P>In accordance with 49 U.S.C. 31136(e) and 31315(b), the following groups of drivers received renewed exemptions in the month of January and are discussed below.</P>
                <P>As of January 1, 2025, and in accordance with 49 U.S.C. 31136(e) and 31315(b), the following 11 individuals have satisfied the renewal conditions for obtaining an exemption from the epilepsy and seizure disorders prohibition in the FMCSRs for interstate CMV drivers:</P>
                <FP SOURCE="FP-1">Ricky Alegre (NJ)</FP>
                <FP SOURCE="FP-1">Thomas Avery (NY)</FP>
                <FP SOURCE="FP-1">Kenneth Boglia (NC)</FP>
                <FP SOURCE="FP-1">Jake Higginbotham (NV)</FP>
                <FP SOURCE="FP-1">Jordan Hyster (OH)</FP>
                <FP SOURCE="FP-1">Matthew Jacobson (PA)</FP>
                <FP SOURCE="FP-1">Everett Letourneau (ND)</FP>
                <FP SOURCE="FP-1">Kieth Maat (KS)</FP>
                <FP SOURCE="FP-1">Ty Martin (WV)</FP>
                <FP SOURCE="FP-1">Douglas Simms, Jr. (NC)</FP>
                <FP SOURCE="FP-1">Ronald Wagner (OH)</FP>
                <P>The drivers were included in docket number FMCSA-2014-0215, FMCSA-2015-0323, FMCSA-2016-0008, FMCSA-2018-0028, FMCSA-2018-0053, FMCSA-2018-0056, FMCSA-2020-0050, or FMCSA-2022-0045. Their exemptions are applicable as of January 1, 2025 and will expire on January 1, 2027.</P>
                <P>As of January 11, 2025, and in accordance with 49 U.S.C. 31136(e) and 31315(b), Dylan C. Hill (KS) has satisfied the renewal conditions for obtaining an exemption from the epilepsy and seizure disorders prohibition in the FMCSRs for interstate CMV drivers.</P>
                <P>This driver was included in docket number FMCSA-2016-0008. The exemption is applicable as of January 11, 2025 and will expire on January 11, 2027.</P>
                <P>As of January 25, 2025, and in accordance with 49 U.S.C. 31136(e) and 31315(b), the following seven individuals have satisfied the renewal conditions for obtaining an exemption from the epilepsy and seizure disorders prohibition in the FMCSRs for interstate CMV drivers:</P>
                <FP SOURCE="FP-1">Joseph Carlisle (IL)</FP>
                <FP SOURCE="FP-1">Samuel Collins (SC)</FP>
                <FP SOURCE="FP-1">Michael Day (AZ)</FP>
                <FP SOURCE="FP-1">Brian Graham (MN)</FP>
                <FP SOURCE="FP-1">Matthew Raymond (NY)</FP>
                <FP SOURCE="FP-1">Eric Stucky (NC)</FP>
                <FP SOURCE="FP-1">Thomas Weber (NY)</FP>
                <P>The drivers were included in docket number FMCSA-2022-0046. Their exemptions are applicable as of January 25, 2025 and will expire on January 25, 2027.</P>
                <HD SOURCE="HD1">V. Terms and Conditions</HD>
                <P>
                    The exemptions are extended subject to the following conditions: each driver must (1) remain seizure-free, maintain a stable treatment, and report to FMCSA within 24 hours if they experience a seizure during the 2-year exemption period; (2) submit to FMCSA annual reports from their treating physicians attesting to the stability of treatment and that the driver has remained seizure-free; (3) undergo an annual medical examination by a certified medical examiner, as defined by § 390.5T; (4) provide a copy of the annual medical certification to the employer for retention in the driver's qualification file, or keep a copy of their driver's qualification file if they are self-employed; (5) report to FMCSA the date, time, and location of any crashes, as defined in § 390.5T, within 7 days of the crash; (6) report to FMCSA any citations and convictions for disqualifying offenses under 49 CFR parts 383 and 391 to FMCSA within 7 days of the citation and conviction; and (7) submit to FMCSA annual certified driving records from their SDLA. The driver must also have a copy of the exemption when driving, for presentation to a duly authorized Federal, State, or local enforcement official. In addition, the driver must meet all the applicable commercial driver's license testing requirements. Each exemption will be valid for 2 years unless rescinded earlier by FMCSA. The exemption will be rescinded if: (1) the person fails to comply with the terms and conditions of the exemption; (2) the exemption has resulted in a lower level of safety than was maintained before it was granted; or (3) continuation of the exemption would not be consistent with the goals and objectives of 49 U.S.C. 31136(e) and 31315(b).
                    <PRTPAGE P="720"/>
                </P>
                <HD SOURCE="HD1">VI. Preemption</HD>
                <P>During the period the exemption is in effect, no State shall enforce any law or regulation that conflicts with this exemption with respect to a person operating under the exemption.</P>
                <HD SOURCE="HD1">VII. Conclusion</HD>
                <P>Based on its evaluation of the 19 exemption applications, FMCSA renews the exemptions of the aforementioned drivers from the epilepsy and seizure disorders prohibition in § 391.41(b)(8). In accordance with 49 U.S.C. 31136(e) and 31315(b), each exemption will be valid for 2 years unless revoked earlier by FMCSA.</P>
                <SIG>
                    <NAME>Larry W. Minor,</NAME>
                    <TITLE>Associate Administrator for Policy.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31759 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4910-EX-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <SUBAGY>Federal Motor Carrier Safety Administration</SUBAGY>
                <DEPDOC>[Docket No. FMCSA-2024-0165]</DEPDOC>
                <SUBJECT>Agency Information Collection Activities; Revision of an Approved Information Collection: Financial Responsibility Motor Carriers, Freight Forwarders, and Brokers</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Federal Motor Carrier Safety Administration (FMCSA), Department of Transportation (DOT).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice and request for comments.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>In accordance with the Paperwork Reduction Act of 1995, FMCSA announces its plan to submit the Information Collection Request (ICR) described below to the Office of Management and Budget (OMB) for its review and approval and invites public comment. FMCSA requests approval to renew an ICR titled, “Financial Responsibility Motor Carriers, Freight Forwarders, and Brokers.” The purpose of this ICR is to provide registered motor carriers, property brokers, and freight forwarders a means of meeting financial responsibility filing requirements. This ICR sets forth the financial responsibility documentation requirements for motor carriers, freight forwarders, and brokers as a result of Agency jurisdictional statutes.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Comments on this notice must be received on or before March 7, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may submit comments identified by Docket Number FMCSA-2024-0165 using any of the following methods:</P>
                    <P>
                        • 
                        <E T="03">Federal eRulemaking Portal:</E>
                          
                        <E T="03">https://www.regulations.gov.</E>
                         Follow the online instructions for submitting comments.
                    </P>
                    <P>
                        • 
                        <E T="03">Mail:</E>
                         Dockets Operations; U.S. Department of Transportation, 1200 New Jersey Avenue SE, West Building, Ground Floor, Washington, DC 20590-0001.
                    </P>
                    <P>
                        • 
                        <E T="03">Hand Delivery or Courier:</E>
                         Dockets Operations, U.S. Department of Transportation, 1200 New Jersey Avenue SE, West Building, Ground Floor, Washington, DC 20590-0001 between 9 a.m. and 5 p.m. ET, Monday through Friday, except Federal holidays. To be sure someone is there to help you, please call (202) 366-9317 or (202) 366-9826 before visiting Dockets Operations.
                    </P>
                    <P>
                        • 
                        <E T="03">Fax:</E>
                         (202) 493-2251.
                    </P>
                    <P>
                        To avoid duplication, please use only one of these four methods. See the “Public Participation and Request for Comments” portion of the 
                        <E T="02">SUPPLEMENTARY INFORMATION</E>
                         section for instructions on submitting comments.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Ana Alvarez, Financial Analyst, Office of Registration, Financial Responsibility Filings Division, DOT, FMCSA, 1200 New Jersey Avenue SE, West Building, 6th Floor, Washington, DC 20590-0001; (202) 366-0401; 
                        <E T="03">ana.alvarez@dot.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">Instructions</HD>
                <P>
                    All submissions must include the Agency name and docket number. For detailed instructions on submitting comments, see the Public Participation heading below. Note that all comments received will be posted without change to 
                    <E T="03">https://www.regulations.gov,</E>
                     including any personal information provided. Please see the Privacy Act heading below.
                </P>
                <HD SOURCE="HD1">Public Participation and Request for Comments</HD>
                <P>If you submit a comment, please include the docket number for this notice (FMCSA-2024-0165), indicate the specific section of this document to which your comment applies, and provide a reason for each suggestion or recommendation. You may submit your comments and material online or by fax, mail, or hand delivery, but please use only one of these means. FMCSA recommends that you include your name and a mailing address, an email address, or a phone number in the body of your document so FMCSA can contact you if there are questions regarding your submission.</P>
                <P>
                    To submit your comment online, go to 
                    <E T="03">https://www.regulations.gov/docket/FMCSA-2024-0165/document,</E>
                     click on this notice, click “Comment,” and type your comment into the text box on the following screen.
                </P>
                <P>
                    If you submit your comments by mail or hand delivery, submit them in an unbound format, no larger than 8
                    <FR>1/2</FR>
                     by 11 inches, suitable for copying and electronic filing.
                </P>
                <P>Comments received after the comment closing date will be included in the docket and will be considered to the extent practicable.</P>
                <HD SOURCE="HD1">Privacy Act</HD>
                <P>
                    In accordance with 5 U.S.C. 553(c), DOT solicits comments from the public to better inform its regulatory process. DOT posts these comments, including any personal information the commenter provides, to 
                    <E T="03">www.regulations.gov</E>
                     as described in the system of records notice DOT/ALL 14 (Federal Docket Management System (FDMS)), which can be reviewed at 
                    <E T="03">https://www.transportation.gov/individuals/privacy/privacy-act-system-records-notices.</E>
                     The comments are posted without edits and are searchable by the name of the submitter.
                </P>
                <HD SOURCE="HD1">Background</HD>
                <P>The Secretary of Transportation (Secretary) is authorized to register for-hire motor carriers of property and passengers under the provisions of 49 U.S.C. 13902, surface freight forwarders under the provisions of 49 U.S.C. 13903, and property brokers under the provisions of 49 U.S.C. 13904. These persons may conduct transportation services only if they are registered pursuant to 49 U.S.C. 13901. The Secretary has delegated authority pertaining to these registration requirements to the FMCSA (49 CFR 1.87) and the regulations implementing these requirements may be found at 49 CFR part 387. The registration remains valid only as long as these transportation entities maintain, on file with FMCSA, evidence of the required levels of financial responsibility pursuant to 49 U.S.C. 13906. FMCSA regulations governing the financial responsibility requirements for these entities are found at 49 CFR part 387. The information collected from these forms are summarized and displayed in the Licensing and Information system.</P>
                <HD SOURCE="HD2">Forms for Endorsements, Certificates of Insurance and Other Evidence of Bodily Injury and Property Damage Liability and Cargo Liability Financial Responsibility</HD>
                <P>
                    Forms BMC-91 and BMC-91X, titled “Motor Carrier Automobile Bodily Injury and Property Damage Liability Certificate of Insurance,” and Form 
                    <PRTPAGE P="721"/>
                    BMC-82, titled “Motor Carrier Bodily Injury Liability and Property Damage Liability Surety Bond Under 49 U.S.C. 13906,” provide evidence of the required coverage for bodily injury and property damage (BI &amp; PD) liability. A Form BMC-91X filing is required when a carrier's insurance is provided by multiple companies instead of just one. Form BMC-34, titled “Household Goods Motor Carrier Cargo Liability Certificate of Insurance,” and Form BMC-83, titled “Household Goods Motor Carrier Cargo Liability Surety Bond Under 49 U.S.C. 13906,” establish a carrier's compliance with the Agency's cargo liability requirements. Only household goods motor carriers are required to file evidence of cargo insurance with FMCSA (§ 387.303(c)). Form BMC-90, titled “Endorsement for Motor Carrier Policies of Insurance for Automobile Bodily Injury and Property Damage Liability Under Section 13906, Title 49 of the United States Code,” and Form BMC-32, titled “Endorsement for Motor Common Carrier Policies of Insurance for Cargo Liability Under 49 U.S.C. 13906,” are executed by the insurance company, attached to bodily injury and property damage or cargo liability insurance policy, respectively, and forwarded to the motor carrier or freight forwarder.
                </P>
                <HD SOURCE="HD2">Requirement To Obtain Surety Bond or Trust Fund Agreement</HD>
                <P>
                    Form BMC-84, titled “Broker's or Freight Forwarder's Surety Bond Under 49 U.S.C. 13906,” and Form BMC-85, titled “Broker's or Freight Forwarder's Trust Fund Agreement Under 49 U.S.C. 13906 or Notice of Cancellation of the Agreement,” are filed by brokers or freight forwarders to comply with the requirement that they must have a $75,000 surety bond or trust fund agreement in effect before FMCSA will issue property broker or freight forwarder operating authority registration. Both forms are being revised due to the implementation of the Broker and Freight Forwarder Financial Responsibility Final Rule (88 FR 78656, Nov. 16, 2023). As originally published in 2023, the rule had two compliance dates, January 16, 2025, and January 16, 2026. In anticipation of the January 16, 2025, compliance date, a 60-day 
                    <E T="04">Federal Register</E>
                     notice was published on August 1, 2024 (89 FR 62842). However, FMCSA has extended the compliance date of all requirements to January 16, 2026, creating a single compliance date for all provisions on the rule. This ICR updates the August 1 notice. The implementation of the Broker and Freight Forwarder Financial Responsibility Rule six months after the forms are set to expire necessitates the use of two versions of forms BMC-36, BMC-84, BMC-85. The first version of the forms will apply to the 6 months prior to the implementation of the rule on January 16, 2026. The second version will apply to the 2.5 years following the implementation of the Broker and Freight Forwarder Financial Responsibility Rule after January 16, 2026.
                </P>
                <HD SOURCE="HD2">Cancellation of Prior Filings</HD>
                <P>Form BMC-35, titled “Notice of Cancellation Motor Carrier Insurance under 49 U.S.C. 13906,” Form BMC-36, titled “Motor Carrier and Broker's Surety Bonds under 49 U.S.C. 13906 Notice of Cancellation,” and Form BMC-85, titled “Broker's or Freight Forwarder's Trust Fund Agreement Under 49 U.S.C. 13906 or Notice of Cancellation of the Agreement,” can be used to cancel prior filings. Forms BMC-36 and BMC-85 are being revised due to the implementation of the Broker and Freight Forwarder Financial Responsibility Final Rule's extended compliance date of January 16, 2026.</P>
                <HD SOURCE="HD2">Self-Insurance</HD>
                <P>Motor carriers can also apply to FMCSA to self-insure BI &amp; PD and/or cargo liability in lieu of filing certificates of insurance with the FMCSA, as long as the carrier maintains a satisfactory safety rating (see § 387.309.) Form BMC-40 is the application used by carriers to apply for self-insurance authority.</P>
                <P>
                    <E T="03">Title:</E>
                     Financial Responsibility Motor Carriers, Freight Forwarders, and Brokers.
                </P>
                <P>
                    <E T="03">OMB Control Number:</E>
                     2126-0017.
                </P>
                <P>
                    <E T="03">Type of Request:</E>
                     Revision of a currently approved ICR.
                </P>
                <P>
                    <E T="03">Respondents:</E>
                     For-hire Motor Carriers, Brokers, and Freight Forwarders.
                </P>
                <P>
                    <E T="03">Estimated Number of Respondents:</E>
                     200,147.
                </P>
                <P>
                    <E T="03">Estimated Time per Response:</E>
                     The estimated average burden per response for Form BMC-40 is 40 hours. The estimated average burden per response for forms BMC-34, 35, 82, 83, 91, and 91X is 10 minutes per form. In addition, form BMC-32 takes 10 minutes. Forms BMC 36, 84 and 85 are affected by the implementation of the Broker Freight Forward Financial Responsibility Rule. For the six months prior to the rule implementation the estimated average burden per response for these three forms is 10 minutes per form. For the remaining 2.5 year after the rule is implemented the estimated average burden per response for the revised forms is 12 minutes per form.
                </P>
                <P>
                    <E T="03">Expiration Date:</E>
                     June 30, 2025.
                </P>
                <P>
                    <E T="03">Frequency of Response:</E>
                     Certificates of insurance, surety bonds, and trust fund agreements are required when the transportation entity first registers with FMCSA and then when such coverages are changed or replaced by these entities. Notices of cancellation are required only when such certificates of insurance, surety bonds, and trust fund agreements are cancelled. The BMC-40 is filed only when a carrier seeks approval from FMCSA to self-insure its BI &amp; PD and/or cargo liability coverage.
                </P>
                <P>
                    <E T="03">Estimated Total Annual Burden:</E>
                     49,722. The annual burden was revised for Forms BMC-84, BMC-85, and BMC-36. The initial collection period for those forms is the six-month period prior to the compliance date of the Broker and Freight Forward Financial Responsibility Rule where the estimated average burden per response is 10 minutes. The second collection period is a revision for the 2.5 years following the January 16, 2026, rule compliance date where the estimated average burden per response is 12 minutes. The annual burden hours for the revised forms equal 2,249. The annual burden hours for the remaining forms are unchanged at 47,473.
                </P>
                <P>
                    <E T="03">Public Comments Invited:</E>
                     You are asked to comment on any aspect of this information collection, including: (1) whether the proposed collection is necessary for the performance of FMCSA's functions; (2) the accuracy of the estimated burden; (3) ways for FMCSA to enhance the quality, usefulness, and clarity of the collected information; and (4) ways that the burden could be minimized without reducing the quality of the collected information. The Agency will summarize or include your comments in the request for OMB's clearance of this ICR.
                </P>
                <SIG>
                    <DATED>Issued under the authority of 49 CFR 1.87.</DATED>
                    <NAME>Thomas P. Keane,</NAME>
                    <TITLE>Associate Administrator, Office of Research and Registration. </TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31550 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4910-EX-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <PRTPAGE P="722"/>
                <AGENCY TYPE="S">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <SUBAGY>Federal Motor Carrier Safety Administration</SUBAGY>
                <DEPDOC>[Docket No. FMCSA-2012-0154; FMCSA-2013-0121; FMCSA-2013-0124; FMCSA-2014-0384; FMCSA-2014-0386; FMCSA-2015-0328; FMCSA-2016-0002; FMCSA-2017-0057; FMCSA-2018-0135; FMCSA-2018-0137; FMCSA-2020-0028; FMCSA-2022-0034; FMCSA-2022-0035; FMCSA-2022-0036; FMCSA-2022-0037; FMCSA-2022-0038]</DEPDOC>
                <SUBJECT>Qualification of Drivers; Exemption Applications; Hearing</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Federal Motor Carrier Safety Administration (FMCSA), Department of Transportation (DOT).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of renewal of exemptions; request for comments.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>FMCSA announces its decision to renew exemptions for 25 individuals from the hearing requirement in the Federal Motor Carrier Safety Regulations (FMCSRs) for interstate commercial motor vehicle (CMV) drivers. The exemptions enable these hard of hearing and deaf individuals to continue to operate CMVs in interstate commerce.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Each group of renewed exemptions were applicable on the dates stated in the discussions below and will expire on the dates provided below. Comments must be received on or before February 5, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may submit comments identified by the Federal Docket Management System Docket No. FMCSA-2012-0154, Docket No. FMCSA-2013-0121, Docket No. FMCSA-2013-0124, Docket No. FMCSA-2014-0384, Docket No. FMCSA-2014-0386, Docket No. FMCSA-2015-0328, Docket No. FMCSA-2016-0002, Docket No. FMCSA-2017-0057, Docket No. FMCSA-2018-0135, Docket No. FMCSA-2018-0137, Docket No. FMCSA-2020-0028, Docket No. FMCSA-2022-0034; Docket No. FMCSA-2022-0035, Docket No. FMCSA-2022-0036, Docket No. FMCSA-2022-0037, or Docket No. FMCSA-2022-0038 using any of the following methods:</P>
                    <P>
                        • 
                        <E T="03">Federal eRulemaking Portal:</E>
                         Go to 
                        <E T="03">www.regulations.gov/,</E>
                         insert the docket number (FMCSA-2012-0154, FMCSA-2013-0121, FMCSA-2013-0124, FMCSA-2014-0384, FMCSA-2014-0386, FMCSA-2015-0328, FMCSA-2016-0002, FMCSA-2017-0057, FMCSA-2018-0135, FMCSA-2018-0137, FMCSA-2020-0028, FMCSA-2022-0034, FMCSA-2022-0035, FMCSA-2022-0036, FMCSA-2022-0037, or FMCSA-2022-0038).
                    </P>
                    <P>• In the keyword box and click “Search.” Next, sort the results by “Posted (Newer-Older),” choose the first notice listed, and click on the “Comment” button. Follow the online instructions for submitting comments.</P>
                    <P>
                        • 
                        <E T="03">Mail:</E>
                         Dockets Operations; U.S. Department of Transportation, 1200 New Jersey Avenue SE, West Building Ground Floor, Washington, DC 20590-0001.
                    </P>
                    <P>
                        • 
                        <E T="03">Hand Delivery:</E>
                         West Building Ground Floor, 1200 New Jersey Avenue SE, Washington, DC 20590-0001, between 9 a.m. and 5 p.m. ET Monday through Friday, except Federal Holidays.
                    </P>
                    <P>
                        • 
                        <E T="03">Fax:</E>
                         (202) 493-2251.
                    </P>
                    <P>
                        To avoid duplication, please use only one of these four methods. See the “Public Participation” portion of the 
                        <E T="02">SUPPLEMENTARY INFORMATION</E>
                         section for instructions on submitting comments.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Ms. Christine A. Hydock, Chief, Medical Programs Division, FMCSA, DOT, 1200 New Jersey Avenue SE, Room W64-224, Washington, DC 20590-0001, (202) 366-4001, 
                        <E T="03">fmcsamedical@dot.gov.</E>
                         Office hours are 8:30 a.m. to 5 p.m. ET Monday through Friday, except Federal holidays. If you have questions regarding viewing or submitting material to the docket, contact Dockets Operations, (202) 366-9826.
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">I. Public Participation</HD>
                <HD SOURCE="HD2">A. Submitting Comments</HD>
                <P>If you submit a comment, please include the docket number for this notice (Docket No. FMCSA-2012-0154, Docket No. FMCSA-2013-0121, Docket No. FMCSA-2013-0124, Docket No. FMCSA-2014-0384, Docket No. FMCSA-2014-0386, Docket No. FMCSA-2015-0328, Docket No. FMCSA-2016-0002, Docket No. FMCSA-2017-0057, Docket No. FMCSA-2018-0135, Docket No. FMCSA-2018-0137, Docket No. FMCSA-2020-0028, Docket No. FMCSA-2022-0034, Docket No. FMCSA-2022-0035, Docket No. FMCSA-2022-0036, Docket No. FMCSA-2022-0037, or Docket No. FMCSA-2022-0038), indicate the specific section of this document to which each comment applies, and provide a reason for each suggestion or recommendation. You may submit your comments and material online or by fax, mail, or hand delivery, but please use only one of these means. FMCSA recommends that you include your name and a mailing address, an email address, or a phone number in the body of your document so that FMCSA can contact you if there are questions regarding your submission.</P>
                <P>
                    To submit your comment online, go to 
                    <E T="03">www.regulations.gov/,</E>
                     insert the docket number (FMCSA-2012-0154, FMCSA-2013-0121, FMCSA-2013-0124, FMCSA-2014-0384, FMCSA-2014-0386, FMCSA-2015-0328, FMCSA-2016-0002, FMCSA-2017-0057, FMCSA-2018-0135, FMCSA-2018-0137, FMCSA-2020-0028, FMCSA-2022-0034, FMCSA-2022-0035, FMCSA-2022-0036, FMCSA-2022-0037, or FMCSA-2022-0038) in the keyword box and click “Search.” Next, sort the results by “Posted (Newer-Older),” choose the first notice listed, click the “Comment” button, and type your comment into the text box on the following screen. Choose whether you are submitting your comment as an individual or on behalf of a third party and then submit.
                </P>
                <P>
                    If you submit your comments by mail or hand delivery, submit them in an unbound format, no larger than 8
                    <FR>1/2</FR>
                     by 11 inches, suitable for copying and electronic filing. FMCSA will consider all comments and material received during the comment period.
                </P>
                <HD SOURCE="HD2">B. Viewing Comments</HD>
                <P>
                    To view comments go to 
                    <E T="03">www.regulations.gov.</E>
                     Insert the docket number (FMCSA-2012-0154, FMCSA-2013-0121, FMCSA-2013-0124, FMCSA-2014-0384, FMCSA-2014-0386, FMCSA-2015-0328, FMCSA-2016-0002, FMCSA-2017-0057, FMCSA-2018-0135, FMCSA-2018-0137, FMCSA-2020-0028, FMCSA-2022-0034, FMCSA-2022-0035, FMCSA-2022-0036, FMCSA-2022-0037, or FMCSA-2022-0038) in the keyword box and click “Search.” Next, sort the results by “Posted (Newer-Older),” choose the first notice listed, and click “Browse Comments.” If you do not have access to the internet, you may view the docket online by visiting Dockets Operations on the ground floor of the DOT West Building, 1200 New Jersey Avenue SE, Washington, DC 20590-0001, between 9 a.m. and 5 p.m. ET Monday through Friday, except Federal holidays. To be sure someone is there to help you, please call (202) 366-9317 or (202) 366-9826 before visiting Dockets Operations.
                </P>
                <HD SOURCE="HD2">C. Privacy Act</HD>
                <P>
                    In accordance with 49 U.S.C. 31315(b)(6), DOT solicits comments from the public on the exemption requests. DOT posts these comments, without edit, including any personal information the commenter provides, to 
                    <PRTPAGE P="723"/>
                    <E T="03">www.regulations.gov.</E>
                     As described in the system of records notice DOT/ALL 14 (Federal Docket Management System), which can be reviewed at 
                    <E T="03">https://www.transportation.gov/individuals/privacy/privacy-act-system-records-notices,</E>
                     the comments are searchable by the name of the submitter.
                </P>
                <HD SOURCE="HD1">II. Background</HD>
                <P>Under 49 U.S.C. 31136(e) and 31315(b), FMCSA may grant an exemption from the FMCSRs for no longer than a 5-year period if it finds such exemption would likely achieve a level of safety that is equivalent to, or greater than, the level that would be achieved absent such exemption. The statutes also allow the Agency to renew exemptions at the end of the 5-year period. FMCSA grants medical exemptions from the FMCSRs for a 2-year period to align with the maximum duration of a driver's medical certification.</P>
                <P>The physical qualification standard for drivers regarding hearing found in 49 CFR 391.41(b)(11) states that a person is physically qualified to drive a CMV if that person first perceives a forced whispered voice in the better ear at not less than 5 feet with or without the use of a hearing aid or, if tested by use of an audiometric device, does not have an average hearing loss in the better ear greater than 40 decibels at 500 Hz, 1,000 Hz, and 2,000 Hz with or without a hearing aid when the audiometric device is calibrated to American National Standard (formerly ASA Standard) Z24.5—1951.</P>
                <P>This standard was adopted in 1970 and was revised in 1971 to allow drivers to be qualified under this standard while wearing a hearing aid, (35 FR 6458, 6463 (Apr. 22, 1970) and 36 FR 12857 (July 8, 1971), respectively).</P>
                <P>The 25 individuals listed in this notice have requested renewal of their exemptions from the hearing standard in § 391.41(b)(11), in accordance with FMCSA procedures. Accordingly, FMCSA has evaluated these applications for renewal on their merits and decided to extend 24 individuals' exemption for a renewable 2-year period and one individual's exemption for a renewable 1-year period.</P>
                <HD SOURCE="HD1">III. Request for Comments</HD>
                <P>Interested parties or organizations possessing information that would otherwise show that any, or all, of these drivers are not currently achieving the statutory level of safety should immediately notify FMCSA. The Agency will evaluate any adverse evidence submitted and, if safety is being compromised or if continuation of the exemption would not be consistent with the goals and objectives of 49 U.S.C. 31136(e) and 31315(b), FMCSA will take immediate steps to revoke the exemption of a driver.</P>
                <HD SOURCE="HD1">IV. Basis for Renewing Exemptions</HD>
                <P>In accordance with 49 U.S.C. 31136(e) and 31315(b), each of the 25 applicants has satisfied the renewal conditions for obtaining an exemption from the hearing requirement. The 25 drivers in this notice remain in good standing with the Agency. In addition, the Agency has reviewed each applicant's certified driving record from their State Driver's Licensing Agency (SDLA). The information obtained from each applicant's driving record provides the Agency with details regarding any moving violations or reported crash data, which demonstrates whether the driver has a safe driving history and is an indicator of future driving performance. If the driving record revealed a crash, FMCSA requested and reviewed the related police reports and other relevant documents, such as the citation and conviction information. These factors provide an adequate basis for predicting each driver's ability to continue to safely operate a CMV in interstate commerce. Therefore, FMCSA concludes that extending the exemption for each of these drivers for a period of at most 2 years is likely to achieve a level of safety equal to that existing without the exemption.</P>
                <P>In accordance with 49 U.S.C. 31136(e) and 31315(b), the following groups of drivers received renewed exemptions in the month of January and are discussed below.</P>
                <P>As of January 15, 2025, and in accordance with 49 U.S.C. 31136(e) and 31315(b), Kevin Young has satisfied the renewal conditions for obtaining an exemption from the hearing requirement in the FMCSRs for interstate CMV drivers.</P>
                <P>The driver was included in docket number FMCSA-2022-0034. Their exemption is applicable as of January 15, 2025 and will expire on January 15, 2026.</P>
                <P>As of January 15, 2025, and in accordance with 49 U.S.C. 31136(e) and 31315(b), the following 15 individuals have satisfied the renewal conditions for obtaining an exemption from the hearing requirement in the FMCSRs for interstate CMV drivers:</P>
                <FP SOURCE="FP-1">Michael Arwood (TN)</FP>
                <FP SOURCE="FP-1">David Chappelear (TX)</FP>
                <FP SOURCE="FP-1">Jan Epitacio (CA)</FP>
                <FP SOURCE="FP-1">Jerry Jones (TX)</FP>
                <FP SOURCE="FP-1">Justin Kilgore (FL)</FP>
                <FP SOURCE="FP-1">Robert Knapp (MD)</FP>
                <FP SOURCE="FP-1">James Laughrey (KS)</FP>
                <FP SOURCE="FP-1">Kathy Miller (IA)</FP>
                <FP SOURCE="FP-1">Mayur Motiwale (ME)</FP>
                <FP SOURCE="FP-1">Sarah Nickell (IN)</FP>
                <FP SOURCE="FP-1">Lesley O'Rorke (IL)</FP>
                <FP SOURCE="FP-1">Gerson Ramirez (MT)</FP>
                <FP SOURCE="FP-1">Fernando Ramirez-Savon</FP>
                <FP SOURCE="FP-1">Willine Smith (MD)</FP>
                <FP SOURCE="FP-1">Dalton Taylor (OK)</FP>
                <P>The drivers were included in docket number FMCSA-2012-0154, FMCSA-2013-0121, FMCSA-2013-0124, FMCSA-2017-0057, FMCSA-2018-0137, FMCSA-2022-0035, FMCSA-2022-0036, or FMCSA-2022-0037. Their exemptions are applicable as of January 15, 2025 and will expire on January 15, 2027.</P>
                <P>As of January 22, 2025, and in accordance with 49 U.S.C. 31136(e) and 31315(b), the following six individuals have satisfied the renewal conditions for obtaining an exemption from the hearing requirement in the FMCSRs for interstate CMV drivers:</P>
                <FP SOURCE="FP-1">Hassan Abdi (MN)</FP>
                <FP SOURCE="FP-1">Jeffrey Daniel (NV)</FP>
                <FP SOURCE="FP-1">Jaymes Haar (IA)</FP>
                <FP SOURCE="FP-1">Andrew Hatch (IA)</FP>
                <FP SOURCE="FP-1">Marckenzie Loriston (FL)</FP>
                <FP SOURCE="FP-1">Carlos Sotelo Sanchez (CA)</FP>
                <P>The drivers were included in docket number FMCSA-2015-0328 or FMCSA-2020-0028. Their exemptions are applicable as of January 22, 2025 and will expire on January 22, 2027.</P>
                <P>As of January 30, 2025, and in accordance with 49 U.S.C. 31136(e) and 31315(b), the following three individuals have satisfied the renewal conditions for obtaining an exemption from the hearing requirement in the FMCSRs for interstate CMV drivers:</P>
                <P>Allen Carrasco (CA); Matthew Kaschalk (TN); and Erica Muhm (KY).</P>
                <P>The drivers were included in docket number FMCSA-2022-0038. Their exemptions are applicable as of January 30, 2025 and will expire on January 30, 2027.</P>
                <HD SOURCE="HD1">V. Terms and Conditions</HD>
                <P>
                    The exemptions are extended subject to the following conditions: each driver (1) must report to FMCSA any crashes as defined in § 390.5T, within 7 days of the crash; (2) must report to FMCSA any citations and convictions for disqualifying offenses under 49 CFR parts 383 and 391, within 7 days of the citation and conviction; (3) must submit to FMCSA annual certified driving records from their SDLA; and (4) is prohibited from operating a motorcoach or bus with passengers in interstate commerce. The driver must also have a copy of the exemption when driving, for presentation to a duly authorized Federal, State, or local enforcement 
                    <PRTPAGE P="724"/>
                    official. In addition, the driver must meet all the applicable commercial driver's license testing requirements. Each exemption will be valid for 2 years unless rescinded earlier by FMCSA. The exemption will be rescinded if: (1) the person fails to comply with the terms and conditions of the exemption; (2) the exemption has resulted in a lower level of safety than was maintained before it was granted; or (3) continuation of the exemption would not be consistent with the goals and objectives of 49 U.S.C. 31136(e) and 31315(b).
                </P>
                <HD SOURCE="HD1">VI. Preemption</HD>
                <P>During the period the exemption is in effect, no State shall enforce any law or regulation that conflicts with this exemption with respect to a person operating under the exemption.</P>
                <HD SOURCE="HD1">VII. Conclusion</HD>
                <P>Based upon its evaluation of the 25 exemption applications, FMCSA renews the exemptions of the aforementioned drivers from the hearing requirement in § 391.41(b)(11). In accordance with 49 U.S.C. 31136(e) and 31315(b), each exemption will be valid for 2 years unless revoked earlier by FMCSA.</P>
                <SIG>
                    <NAME>Larry W. Minor,</NAME>
                    <TITLE>Associate Administrator for Policy.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31758 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4910-EX-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <SUBAGY>Maritime Administration</SUBAGY>
                <DEPDOC>[Docket No. MARAD-2024-0163]</DEPDOC>
                <SUBJECT>Coastwise Endorsement Eligibility Determination for a Foreign-Built Vessel: Open Seas (Motor); Invitation for Public Comments</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Maritime Administration, DOT.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Secretary of Transportation, as represented by the Maritime Administration (MARAD), is authorized to issue coastwise endorsement eligibility determinations for foreign-built vessels which will carry no more than twelve passengers for hire. A request for such a determination has been received by MARAD. By this notice, MARAD seeks comments from interested parties as to any effect this action may have on U.S. vessel builders or businesses in the U.S. that use U.S.-flag vessels. Information about the requestor's vessel, including a brief description of the proposed service, is listed below.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Submit comments on or before February 5, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may submit comments identified by DOT Docket Number MARAD-2024-0163 by any one of the following methods:</P>
                    <P>
                        • 
                        <E T="03">Federal eRulemaking Portal:</E>
                         Go to 
                        <E T="03">https://www.regulations.gov.</E>
                         Search MARAD-2024-0163 and follow the instructions for submitting comments.
                    </P>
                    <P>
                        • 
                        <E T="03">Mail or Hand Delivery:</E>
                         Docket Management Facility is in the West Building, Ground Floor of the U.S. Department of Transportation. The Docket Management Facility location address is U.S. Department of Transportation, MARAD-2024-0163, 1200 New Jersey Avenue SE, West Building, Room W12-140, Washington, DC 20590, between 9 a.m. and 5 p.m., Monday through Friday, except on Federal holidays.
                    </P>
                </ADD>
                <NOTE>
                    <HD SOURCE="HED">Note:</HD>
                    <P> If you mail or hand-deliver your comments, we recommend that you include your name and a mailing address, an email address, or a telephone number in the body of your document so that we can contact you if we have questions regarding your submission.</P>
                </NOTE>
                <P>
                    <E T="03">Instructions:</E>
                     All submissions received must include the agency name and specific docket number. All comments received will be posted without change to the docket at 
                    <E T="03">www.regulations.gov,</E>
                     including any personal information provided. For detailed instructions on submitting comments, or to submit comments that are confidential in nature, see the section entitled Public Participation.
                </P>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Patricia Hagerty, U.S. Department of Transportation, Maritime Administration, 1200 New Jersey Avenue SE, Room W23-461, Washington, DC 20590. Telephone: (202) 366-0903. Email: 
                        <E T="03">patricia.hagerty@dot.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>As described in the application, the intended service of the vessel Open Seas is:</P>
                <P>
                    <E T="03">Intended Commercial Use of Vessel:</E>
                     Requester intends to offer passenger fishing charters.
                </P>
                <P>
                    <E T="03">Geographic Region Including Base of Operations:</E>
                     Western Alaska. Base of Operations: Soldotna, Alaska.
                </P>
                <P>
                    <E T="03">Vessel Length and Type:</E>
                     28′ Motor.
                </P>
                <P>
                    The complete application is available for review identified in the DOT docket as MARAD 2024-0163 at 
                    <E T="03">https://www.regulations.gov.</E>
                     Interested parties may comment on the effect this action may have on U.S. vessel builders or businesses in the U.S. that use U.S.-flag vessels. If MARAD determines, in accordance with 46 U.S.C. 12121 and MARAD's regulations at 46 CFR part 388, that the employment of the vessel in the coastwise trade to carry no more than 12 passengers will have an unduly adverse effect on a U.S.-vessel builder or a business that uses U.S.-flag vessels in that business, MARAD will not issue an approval of the vessel's coastwise endorsement eligibility. Comments should refer to the vessel name, state the commenter's interest in the application, and address the eligibility criteria given in section 388.4 of MARAD's regulations at 46 CFR part 388.
                </P>
                <HD SOURCE="HD1">Public Participation</HD>
                <HD SOURCE="HD2">How do I submit comments?</HD>
                <P>
                    Please submit your comments, including the attachments, following the instructions provided under the above heading entitled 
                    <E T="02">ADDRESSES</E>
                    . Be advised that it may take a few hours or even days for your comment to be reflected on the docket. In addition, your comments must be written in English. We encourage you to provide concise comments and you may attach additional documents as necessary. There is no limit on the length of the attachments.
                </P>
                <HD SOURCE="HD2">Where do I go to read public comments, and find supporting information?</HD>
                <P>
                    Go to the docket online at 
                    <E T="03">https://www.regulations.gov,</E>
                     keyword search MARAD-2024-0163 or visit the Docket Management Facility (see 
                    <E T="02">ADDRESSES</E>
                     for hours of operation). We recommend that you periodically check the Docket for new submissions and supporting material.
                </P>
                <HD SOURCE="HD2">Will my comments be made available to the public?</HD>
                <P>Yes. Be aware that your entire comment, including your personal identifying information, will be made publicly available.</P>
                <HD SOURCE="HD2">May I submit comments confidentially?</HD>
                <P>
                    If you wish to submit comments under a claim of confidentiality, you should submit the information you claim to be confidential commercial information by email to 
                    <E T="03">SmallVessels@dot.gov.</E>
                     Include in the email subject heading “Contains Confidential Commercial Information” or “Contains CCI” and state in your submission, with specificity, the basis for any such confidential claim highlighting or denoting the CCI portions. If possible, please provide a summary of your submission that can be made available to the public.
                </P>
                <P>
                    In the event MARAD receives a Freedom of Information Act (FOIA) request for the information, procedures described in the Department's FOIA regulation at 49 CFR 7.29 will be followed. Only information that is 
                    <PRTPAGE P="725"/>
                    ultimately determined to be confidential under those procedures will be exempt from disclosure under FOIA.
                </P>
                <HD SOURCE="HD1">Privacy Act</HD>
                <P>
                    Anyone can search the electronic form of all comments received into any of our dockets by the name of the individual submitting the comment (or signing the comment, if submitted on behalf of an association, business, labor union, etc.). For information on DOT's compliance with the Privacy Act, please visit 
                    <E T="03">https://www.transportation.gov/privacy.</E>
                </P>
                <EXTRACT>
                    <FP>(Authority: 49 CFR 1.93(a), 46 U.S.C. 55103, 46 U.S.C. 12121)</FP>
                </EXTRACT>
                <SIG>
                    <P>By Order of the Maritime Administrator.</P>
                    <NAME>T. Mitchell Hudson, Jr.,</NAME>
                    <TITLE>Secretary, Maritime Administration.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31604 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4910-81-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <SUBAGY>Maritime Administration</SUBAGY>
                <DEPDOC>[Docket No. MARAD-2024-0168]</DEPDOC>
                <SUBJECT>Request for Comments on the Renewal of a Previously Approved Collection: Maritime Administration Jones Act Vessel Availability Determinations</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Maritime Administration, DOT.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        The Maritime Administration (MARAD) invites public comments on our intention to request approval from the Office of Management and Budget (OMB) to renew an information collection in accordance with the Paperwork Reduction Act of 1995. The proposed collection OMB 2133-0545 (Maritime Administration (MARAD) Jones Act Vessel Availability Determinations) is used to collect information about the availability of qualified Jones Act vessels. Since the last renewal, there was a reduction in the public burden for this collection. We are required to publish this notice in the 
                        <E T="04">Federal Register</E>
                         to obtain comments from the public and affected agencies.
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Comments must be submitted on or before March 10, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may submit comments identified by Docket No. MARAD-2024-0168 through one of the following methods:</P>
                    <P>
                        • 
                        <E T="03">Federal eRulemaking Portal: www.regulations.gov.</E>
                         Search using the above DOT docket number and follow the online instructions for submitting comments.
                    </P>
                    <P>
                        • 
                        <E T="03">Mail or Hand Delivery:</E>
                         Docket Management Facility, U.S. Department of Transportation, 1200 New Jersey Avenue SE, West Building, Room W12-140, Washington, DC 20590, between 9 a.m. and 5 p.m., Monday through Friday, except on Federal holidays.
                    </P>
                    <P>
                        <E T="03">Instructions:</E>
                         All submissions must include the agency name and docket number for this rulemaking.
                    </P>
                </ADD>
                <NOTE>
                    <HD SOURCE="HED">Note:</HD>
                    <P>
                         All comments received will be posted without change to 
                        <E T="03">www.regulations.gov</E>
                         including any personal information provided.
                    </P>
                </NOTE>
                <P>
                    <E T="03">Comments are invited on:</E>
                     (a) whether the proposed collection of information is necessary for the Department's performance; (b) the accuracy of the estimated burden; (c) ways for the Department to enhance the quality, utility, and clarity of the information collection; and (d) ways that the burden could be minimized without reducing the quality of the collected information. The agency will summarize and/or include your comments in the request for OMB's clearance of this information collection.
                </P>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Lance Murray, 202-617-7792, Office of Cargo and Commercial Sealift, Maritime Administration, U.S. Department of Transportation, 1200 New Jersey Avenue SE, Washington, DC 20590, Email: 
                        <E T="03">Cargo.MARAD@dot.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P/>
                <P>
                    <E T="03">Title:</E>
                     Maritime Administration (MARAD) Jones Act Vessel Availability Determinations.
                </P>
                <P>
                    <E T="03">OMB Control Number:</E>
                     2133-0545.
                </P>
                <P>
                    <E T="03">Type of Request:</E>
                     Extension of a previously approved information collection.
                </P>
                <P>
                    <E T="03">Abstract:</E>
                     Pursuant to 46 U.S.C. 501(b), the Maritime Administrator is required to make determinations about the availability of qualified United States flag capacity to carry coastwise cargo in connection with all requests for waivers of the Jones Act (46 U.S.C. 55102). This information collection supports that mission.
                </P>
                <P>
                    <E T="03">Respondents:</E>
                     Coastwise qualified vessel owners, operators, charterers, brokers, and representatives.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Business or other for profit.
                </P>
                <P>
                    <E T="03">Estimated Number of Respondents:</E>
                     65.
                </P>
                <P>
                    <E T="03">Estimated Number of Responses:</E>
                     260.
                </P>
                <P>
                    <E T="03">Estimated Hours per Response:</E>
                     .75 Hrs.
                </P>
                <P>
                    <E T="03">Annual Estimated Total Annual Burden Hours:</E>
                     195.
                </P>
                <P>
                    <E T="03">Frequency of Response:</E>
                     Four Times Annually.
                </P>
                <EXTRACT>
                    <FP>(Authority: The Paperwork Reduction Act of 1995; 44 U.S.C. chapter 35, as amended; and 49 CFR 1.49.)</FP>
                </EXTRACT>
                <SIG>
                    <P>By Order of the Maritime Administrator.</P>
                    <NAME>T. Mitchell Hudson, Jr.,</NAME>
                    <TITLE>Secretary, Maritime Administration.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31601 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4910-81-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <SUBAGY>Maritime Administration</SUBAGY>
                <DEPDOC>[Docket No. MARAD-2024-0165]</DEPDOC>
                <SUBJECT>Coastwise Endorsement Eligibility Determination for a Foreign-Built Vessel: Skydancer (Sail); Invitation for Public Comments</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Maritime Administration, DOT.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Secretary of Transportation, as represented by the Maritime Administration (MARAD), is authorized to issue coastwise endorsement eligibility determinations for foreign-built vessels which will carry no more than twelve passengers for hire. A request for such a determination has been received by MARAD. By this notice, MARAD seeks comments from interested parties as to any effect this action may have on U.S. vessel builders or businesses in the U.S. that use U.S.-flag vessels. Information about the requestor's vessel, including a brief description of the proposed service, is listed below.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Submit comments on or before February 5, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may submit comments identified by DOT Docket Number MARAD-2024-0165 by any one of the following methods:</P>
                    <P>
                        • 
                        <E T="03">Federal eRulemaking Portal:</E>
                         Go to 
                        <E T="03">https://www.regulations.gov.</E>
                         Search MARAD-2024-0165 and follow the instructions for submitting comments.
                    </P>
                    <P>
                        • 
                        <E T="03">Mail or Hand Delivery:</E>
                         Docket Management Facility is in the West Building, Ground Floor of the U.S. Department of Transportation. The Docket Management Facility location address is U.S. Department of Transportation, MARAD-2024-0165, 1200 New Jersey Avenue SE, West Building, Room W12-140, Washington, DC 20590, between 9 a.m. and 5 p.m., Monday through Friday, except on Federal holidays.
                    </P>
                </ADD>
                <NOTE>
                    <HD SOURCE="HED">Note:</HD>
                    <P> If you mail or hand-deliver your comments, we recommend that you include your name and a mailing address, an email address, or a telephone number in the body of your document so that we can contact you if we have questions regarding your submission.</P>
                </NOTE>
                <P>
                    <E T="03">Instructions:</E>
                     All submissions received must include the agency name and 
                    <PRTPAGE P="726"/>
                    specific docket number. All comments received will be posted without change to the docket at 
                    <E T="03">www.regulations.gov,</E>
                     including any personal information provided. For detailed instructions on submitting comments, or to submit comments that are confidential in nature, see the section entitled Public Participation.
                </P>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Patricia Hagerty, U.S. Department of Transportation, Maritime Administration, 1200 New Jersey Avenue SE, Room W23-461, Washington, DC 20590. Telephone: (202) 366-0903. Email: 
                        <E T="03">patricia.hagerty@dot.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>As described in the application, the intended service of the vessel Skydancer is:</P>
                <P>
                    <E T="03">Intended Commercial Use of Vessel:</E>
                     Requester intends to offer passenger sailing charters.
                </P>
                <P>
                    <E T="03">Geographic Region Including Base of Operations:</E>
                     California. Base of Operations: Marina Del Rey, California.
                </P>
                <P>
                    <E T="03">Vessel Length and Type:</E>
                     57′ Monohull Sailboat.
                </P>
                <P>
                    The complete application is available for review identified in the DOT docket as MARAD 2024-0165 at 
                    <E T="03">https://www.regulations.gov.</E>
                     Interested parties may comment on the effect this action may have on U.S. vessel builders or businesses in the U.S. that use U.S.-flag vessels. If MARAD determines, in accordance with 46 U.S.C. 12121 and MARAD's regulations at 46 CFR part 388, that the employment of the vessel in the coastwise trade to carry no more than 12 passengers will have an unduly adverse effect on a U.S.-vessel builder or a business that uses U.S.-flag vessels in that business, MARAD will not issue an approval of the vessel's coastwise endorsement eligibility. Comments should refer to the vessel name, state the commenter's interest in the application, and address the eligibility criteria given in section 388.4 of MARAD's regulations at 46 CFR part 388.
                </P>
                <HD SOURCE="HD1">Public Participation</HD>
                <HD SOURCE="HD2">How do I submit comments?</HD>
                <P>
                    Please submit your comments, including the attachments, following the instructions provided under the above heading entitled 
                    <E T="02">ADDRESSES</E>
                    . Be advised that it may take a few hours or even days for your comment to be reflected on the docket. In addition, your comments must be written in English. We encourage you to provide concise comments and you may attach additional documents as necessary. There is no limit on the length of the attachments.
                </P>
                <HD SOURCE="HD2">Where do I go to read public comments, and find supporting information?</HD>
                <P>
                    Go to the docket online at 
                    <E T="03">https://www.regulations.gov,</E>
                     keyword search MARAD-2024-0165 or visit the Docket Management Facility (see 
                    <E T="02">ADDRESSES</E>
                     for hours of operation). We recommend that you periodically check the Docket for new submissions and supporting material.
                </P>
                <HD SOURCE="HD2">Will my comments be made available to the public?</HD>
                <P>Yes. Be aware that your entire comment, including your personal identifying information, will be made publicly available.</P>
                <HD SOURCE="HD2">May I submit comments confidentially?</HD>
                <P>
                    If you wish to submit comments under a claim of confidentiality, you should submit the information you claim to be confidential commercial information by email to 
                    <E T="03">SmallVessels@dot.gov.</E>
                     Include in the email subject heading “Contains Confidential Commercial Information” or “Contains CCI” and state in your submission, with specificity, the basis for any such confidential claim highlighting or denoting the CCI portions. If possible, please provide a summary of your submission that can be made available to the public.
                </P>
                <P>In the event MARAD receives a Freedom of Information Act (FOIA) request for the information, procedures described in the Department's FOIA regulation at 49 CFR 7.29 will be followed. Only information that is ultimately determined to be confidential under those procedures will be exempt from disclosure under FOIA.</P>
                <HD SOURCE="HD1">Privacy Act</HD>
                <P>
                    Anyone can search the electronic form of all comments received into any of our dockets by the name of the individual submitting the comment (or signing the comment, if submitted on behalf of an association, business, labor union, etc.). For information on DOT's compliance with the Privacy Act, please visit 
                    <E T="03">https://www.transportation.gov/privacy.</E>
                </P>
                <EXTRACT>
                    <FP>(Authority: 49 CFR 1.93(a), 46 U.S.C. 55103, 46 U.S.C. 12121)</FP>
                </EXTRACT>
                <SIG>
                    <P>By Order of the Maritime Administrator.</P>
                    <NAME>T. Mitchell Hudson, Jr.,</NAME>
                    <TITLE>Secretary, Maritime Administration.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31600 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4910-81-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <SUBAGY>Maritime Administration</SUBAGY>
                <DEPDOC>[Docket No. MARAD-2024-0164]</DEPDOC>
                <SUBJECT>Coastwise Endorsement Eligibility Determination for a Foreign-Built Vessel: Yes Dear (Motor); Invitation for Public Comments</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Maritime Administration, DOT.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Secretary of Transportation, as represented by the Maritime Administration (MARAD), is authorized to issue coastwise endorsement eligibility determinations for foreign-built vessels which will carry no more than twelve passengers for hire. A request for such a determination has been received by MARAD. By this notice, MARAD seeks comments from interested parties as to any effect this action may have on U.S. vessel builders or businesses in the U.S. that use U.S.-flag vessels. Information about the requestor's vessel, including a brief description of the proposed service, is listed below.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Submit comments on or before February 5, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may submit comments identified by DOT Docket Number MARAD-2024-0164 by any one of the following methods:</P>
                    <P>
                        • 
                        <E T="03">Federal eRulemaking Portal:</E>
                         Go to 
                        <E T="03">https://www.regulations.gov.</E>
                         Search MARAD-2024-0164 and follow the instructions for submitting comments.
                    </P>
                    <P>
                        • 
                        <E T="03">Mail or Hand Delivery:</E>
                         Docket Management Facility is in the West Building, Ground Floor of the U.S. Department of Transportation. The Docket Management Facility location address is U.S. Department of Transportation, MARAD-2024-0164, 1200 New Jersey Avenue SE, West Building, Room W12-140, Washington, DC 20590, between 9 a.m. and 5 p.m., Monday through Friday, except on Federal holidays.
                    </P>
                </ADD>
                <NOTE>
                    <HD SOURCE="HED">Note:</HD>
                    <P>If you mail or hand-deliver your comments, we recommend that you include your name and a mailing address, an email address, or a telephone number in the body of your document so that we can contact you if we have questions regarding your submission.</P>
                </NOTE>
                <P>
                    <E T="03">Instructions:</E>
                     All submissions received must include the agency name and specific docket number. All comments received will be posted without change to the docket at 
                    <E T="03">www.regulations.gov,</E>
                     including any personal information provided. For detailed instructions on submitting comments, or to submit comments that are confidential in 
                    <PRTPAGE P="727"/>
                    nature, see the section entitled Public Participation.
                </P>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Patricia Hagerty, U.S. Department of Transportation, Maritime Administration, 1200 New Jersey Avenue SE, Room W23-461, Washington, DC 20590. Telephone: (202) 366-0903. Email: 
                        <E T="03">patricia.hagerty@dot.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>As described in the application, the intended service of the vessel Yes Dear is:</P>
                <P>
                    <E T="03">Intended Commercial Use of Vessel:</E>
                     Requester intends to offer passenger day charters.
                </P>
                <P>
                    <E T="03">Geographic Region Including Base of Operations:</E>
                     East coast of Puerto Rico and Islands. Base of Operations: Fajardo, Puerto Rico.
                </P>
                <P>
                    <E T="03">Vessel Length and Type:</E>
                     28′ Motor.
                </P>
                <P>
                    The complete application is available for review identified in the DOT docket as MARAD 2024-0164 at 
                    <E T="03">https://www.regulations.gov.</E>
                     Interested parties may comment on the effect this action may have on U.S. vessel builders or businesses in the U.S. that use U.S.-flag vessels. If MARAD determines, in accordance with 46 U.S.C. 12121 and MARAD's regulations at 46 CFR part 388, that the employment of the vessel in the coastwise trade to carry no more than 12 passengers will have an unduly adverse effect on a U.S.-vessel builder or a business that uses U.S.-flag vessels in that business, MARAD will not issue an approval of the vessel's coastwise endorsement eligibility. Comments should refer to the vessel name, state the commenter's interest in the application, and address the eligibility criteria given in section 388.4 of MARAD's regulations at 46 CFR part 388.
                </P>
                <HD SOURCE="HD1">Public Participation</HD>
                <HD SOURCE="HD2">How do I submit comments?</HD>
                <P>
                    Please submit your comments, including the attachments, following the instructions provided under the above heading entitled 
                    <E T="02">ADDRESSES</E>
                    . Be advised that it may take a few hours or even days for your comment to be reflected on the docket. In addition, your comments must be written in English. We encourage you to provide concise comments and you may attach additional documents as necessary. There is no limit on the length of the attachments.
                </P>
                <HD SOURCE="HD2">Where do I go to read public comments, and find supporting information?</HD>
                <P>
                    Go to the docket online at 
                    <E T="03">https://www.regulations.gov,</E>
                     keyword search MARAD-2024-0164 or visit the Docket Management Facility (see 
                    <E T="02">ADDRESSES</E>
                     for hours of operation). We recommend that you periodically check the Docket for new submissions and supporting material.
                </P>
                <HD SOURCE="HD2">Will my comments be made available to the public?</HD>
                <P>Yes. Be aware that your entire comment, including your personal identifying information, will be made publicly available.</P>
                <HD SOURCE="HD2">May I submit comments confidentially?</HD>
                <P>
                    If you wish to submit comments under a claim of confidentiality, you should submit the information you claim to be confidential commercial information by email to 
                    <E T="03">SmallVessels@dot.gov.</E>
                     Include in the email subject heading “Contains Confidential Commercial Information” or “Contains CCI” and state in your submission, with specificity, the basis for any such confidential claim highlighting or denoting the CCI portions. If possible, please provide a summary of your submission that can be made available to the public.
                </P>
                <P>In the event MARAD receives a Freedom of Information Act (FOIA) request for the information, procedures described in the Department's FOIA regulation at 49 CFR 7.29 will be followed. Only information that is ultimately determined to be confidential under those procedures will be exempt from disclosure under FOIA.</P>
                <HD SOURCE="HD1">Privacy Act</HD>
                <P>
                    Anyone can search the electronic form of all comments received into any of our dockets by the name of the individual submitting the comment (or signing the comment, if submitted on behalf of an association, business, labor union, etc.). For information on DOT's compliance with the Privacy Act, please visit 
                    <E T="03">https://www.transportation.gov/privacy.</E>
                </P>
                <EXTRACT>
                    <FP>(Authority: 49 CFR 1.93(a), 46 U.S.C. 55103, 46 U.S.C. 12121)</FP>
                </EXTRACT>
                <SIG>
                    <P>By Order of the Maritime Administrator.</P>
                    <NAME>T. Mitchell Hudson, Jr.,</NAME>
                    <TITLE>Secretary, Maritime Administration. </TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31598 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4910-81-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <SUBAGY>Maritime Administration</SUBAGY>
                <DEPDOC>[Docket No. MARAD-2024-0167]</DEPDOC>
                <SUBJECT>Coastwise Endorsement Eligibility Determination for a Foreign-Built Vessel: Regenero (Sail); Invitation for Public Comments</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Maritime Administration, DOT.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Secretary of Transportation, as represented by the Maritime Administration (MARAD), is authorized to issue coastwise endorsement eligibility determinations for foreign-built vessels which will carry no more than twelve passengers for hire. A request for such a determination has been received by MARAD. By this notice, MARAD seeks comments from interested parties as to any effect this action may have on U.S. vessel builders or businesses in the U.S. that use U.S.-flag vessels. Information about the requestor's vessel, including a brief description of the proposed service, is listed below.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Submit comments on or before February 5, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may submit comments identified by DOT Docket Number MARAD-2024-0167 by any one of the following methods:</P>
                    <P>
                        • 
                        <E T="03">Federal eRulemaking Portal:</E>
                         Go to 
                        <E T="03">https://www.regulations.gov.</E>
                         Search MARAD-2024-0167 and follow the instructions for submitting comments.
                    </P>
                    <P>
                        • 
                        <E T="03">Mail or Hand Delivery:</E>
                         Docket Management Facility is in the West Building, Ground Floor of the U.S. Department of Transportation. The Docket Management Facility location address is U.S. Department of Transportation, MARAD-2024-0167, 1200 New Jersey Avenue SE, West Building, Room W12-140, Washington, DC 20590, between 9 a.m. and 5 p.m., Monday through Friday, except on Federal holidays.
                    </P>
                </ADD>
                <NOTE>
                    <HD SOURCE="HED">Note:</HD>
                    <P> If you mail or hand-deliver your comments, we recommend that you include your name and a mailing address, an email address, or a telephone number in the body of your document so that we can contact you if we have questions regarding your submission.</P>
                </NOTE>
                <P>
                    <E T="03">Instructions:</E>
                     All submissions received must include the agency name and specific docket number. All comments received will be posted without change to the docket at 
                    <E T="03">www.regulations.gov,</E>
                     including any personal information provided. For detailed instructions on submitting comments, or to submit comments that are confidential in nature, see the section entitled Public Participation.
                </P>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Patricia Hagerty, U.S. Department of Transportation, Maritime Administration, 1200 New Jersey Avenue SE, Room W23-461, Washington, DC 20590. Telephone: (202) 366-0903. Email: 
                        <E T="03">patricia.hagerty@dot.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <PRTPAGE P="728"/>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>As described in the application, the intended service of the vessel Regenero is:</P>
                <P>
                    <E T="03">Intended Commercial Use of Vessel:</E>
                     Requester intends to offer passenger cruises.
                </P>
                <P>
                    <E T="03">Geographic Region Including Base of Operations:</E>
                     Rhode Island, Maine, New York (excluding Great Lakes), Delaware, Maryland, North Carolina, South Carolina, Georgia, Florida (excluding Gulf coast). Base of Operations: Barrington, Rhode Island.
                </P>
                <P>
                    <E T="03">Vessel Length and Type:</E>
                     40.6′ Catamaran.
                </P>
                <P>
                    The complete application is available for review identified in the DOT docket as MARAD 2024-0167 at 
                    <E T="03">https://www.regulations.gov.</E>
                     Interested parties may comment on the effect this action may have on U.S. vessel builders or businesses in the U.S. that use U.S.-flag vessels. If MARAD determines, in accordance with 46 U.S.C. 12121 and MARAD's regulations at 46 CFR part 388, that the employment of the vessel in the coastwise trade to carry no more than 12 passengers will have an unduly adverse effect on a U.S.-vessel builder or a business that uses U.S.-flag vessels in that business, MARAD will not issue an approval of the vessel's coastwise endorsement eligibility. Comments should refer to the vessel name, state the commenter's interest in the application, and address the eligibility criteria given in section 388.4 of MARAD's regulations at 46 CFR part 388.
                </P>
                <HD SOURCE="HD1">Public Participation</HD>
                <HD SOURCE="HD2">How do I submit comments?</HD>
                <P>
                    Please submit your comments, including the attachments, following the instructions provided under the above heading entitled 
                    <E T="02">ADDRESSES</E>
                    . Be advised that it may take a few hours or even days for your comment to be reflected on the docket. In addition, your comments must be written in English. We encourage you to provide concise comments and you may attach additional documents as necessary. There is no limit on the length of the attachments.
                </P>
                <HD SOURCE="HD2">Where do I go to read public comments, and find supporting information?</HD>
                <P>
                    Go to the docket online at 
                    <E T="03">https://www.regulations.gov,</E>
                     keyword search MARAD-2024-0167 or visit the Docket Management Facility (see 
                    <E T="02">ADDRESSES</E>
                     for hours of operation). We recommend that you periodically check the Docket for new submissions and supporting material.
                </P>
                <HD SOURCE="HD2">Will my comments be made available to the public?</HD>
                <P>Yes. Be aware that your entire comment, including your personal identifying information, will be made publicly available.</P>
                <HD SOURCE="HD2">May I submit comments confidentially?</HD>
                <P>
                    If you wish to submit comments under a claim of confidentiality, you should submit the information you claim to be confidential commercial information by email to 
                    <E T="03">SmallVessels@dot.gov.</E>
                     Include in the email subject heading “Contains Confidential Commercial Information” or “Contains CCI” and state in your submission, with specificity, the basis for any such confidential claim highlighting or denoting the CCI portions. If possible, please provide a summary of your submission that can be made available to the public.
                </P>
                <P>In the event MARAD receives a Freedom of Information Act (FOIA) request for the information, procedures described in the Department's FOIA regulation at 49 CFR 7.29 will be followed. Only information that is ultimately determined to be confidential under those procedures will be exempt from disclosure under FOIA.</P>
                <HD SOURCE="HD1">Privacy Act</HD>
                <P>
                    Anyone can search the electronic form of all comments received into any of our dockets by the name of the individual submitting the comment (or signing the comment, if submitted on behalf of an association, business, labor union, etc.). For information on DOT's compliance with the Privacy Act, please visit 
                    <E T="03">https://www.transportation.gov/privacy.</E>
                </P>
                <EXTRACT>
                    <FP>(Authority: 49 CFR 1.93(a), 46 U.S.C. 55103, 46 U.S.C. 12121)</FP>
                </EXTRACT>
                <SIG>
                    <P>By Order of the Maritime Administrator.</P>
                    <NAME>T. Mitchell Hudson, Jr.,</NAME>
                    <TITLE>Secretary, Maritime Administration. </TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31606 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4910-81-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <SUBAGY>Maritime Administration</SUBAGY>
                <DEPDOC>[Docket No. MARAD-2024-0166]</DEPDOC>
                <SUBJECT>Coastwise Endorsement Eligibility Determination for a Foreign-Built Vessel: Serenity (Motor); Invitation for Public Comments</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Maritime Administration, DOT.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Secretary of Transportation, as represented by the Maritime Administration (MARAD), is authorized to issue coastwise endorsement eligibility determinations for foreign-built vessels which will carry no more than twelve passengers for hire. A request for such a determination has been received by MARAD. By this notice, MARAD seeks comments from interested parties as to any effect this action may have on U.S. vessel builders or businesses in the U.S. that use U.S.-flag vessels. Information about the requestor's vessel, including a brief description of the proposed service, is listed below.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Submit comments on or before February 5, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>You may submit comments identified by DOT Docket Number MARAD-2024-0166 by any one of the following methods:</P>
                    <P>
                        • 
                        <E T="03">Federal eRulemaking Portal:</E>
                         Go to 
                        <E T="03">https://www.regulations.gov.</E>
                         Search MARAD-2024-0166 and follow the instructions for submitting comments.
                    </P>
                    <P>
                        • 
                        <E T="03">Mail or Hand Delivery:</E>
                         Docket Management Facility is in the West Building, Ground Floor of the U.S. Department of Transportation. The Docket Management Facility location address is U.S. Department of Transportation, MARAD-2024-0166, 1200 New Jersey Avenue SE, West Building, Room W12-140, Washington, DC 20590, between 9 a.m. and 5 p.m., Monday through Friday, except on Federal holidays.
                    </P>
                </ADD>
                <NOTE>
                    <HD SOURCE="HED">Note:</HD>
                    <P> If you mail or hand-deliver your comments, we recommend that you include your name and a mailing address, an email address, or a telephone number in the body of your document so that we can contact you if we have questions regarding your submission.</P>
                </NOTE>
                <P>
                    <E T="03">Instructions:</E>
                     All submissions received must include the agency name and specific docket number. All comments received will be posted without change to the docket at 
                    <E T="03">www.regulations.gov,</E>
                     including any personal information provided. For detailed instructions on submitting comments, or to submit comments that are confidential in nature, see the section entitled Public Participation.
                </P>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Patricia Hagerty, U.S. Department of Transportation, Maritime Administration, 1200 New Jersey Avenue SE, Room W23-461, Washington, DC 20590. Telephone: (202) 366-0903. Email: 
                        <E T="03">patricia.hagerty@dot.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>
                    As described in the application, the intended service of the vessel Serenity is:
                    <PRTPAGE P="729"/>
                </P>
                <P>
                    <E T="03">Intended Commercial Use of Vessel:</E>
                     Requester intends to offer passenger cruises.
                </P>
                <P>
                    <E T="03">Geographic Region Including Base of Operations:</E>
                     New Jersey. Base of Operations: Brick, New Jersey.
                </P>
                <P>
                    <E T="03">Vessel Length and Type:</E>
                     55.8′ Motor Yacht.
                </P>
                <P>
                    The complete application is available for review identified in the DOT docket as MARAD 2024-0166 at 
                    <E T="03">https://www.regulations.gov.</E>
                     Interested parties may comment on the effect this action may have on U.S. vessel builders or businesses in the U.S. that use U.S.-flag vessels. If MARAD determines, in accordance with 46 U.S.C. 12121 and MARAD's regulations at 46 CFR part 388, that the employment of the vessel in the coastwise trade to carry no more than 12 passengers will have an unduly adverse effect on a U.S.-vessel builder or a business that uses U.S.-flag vessels in that business, MARAD will not issue an approval of the vessel's coastwise endorsement eligibility. Comments should refer to the vessel name, state the commenter's interest in the application, and address the eligibility criteria given in section 388.4 of MARAD's regulations at 46 CFR part 388.
                </P>
                <HD SOURCE="HD1">Public Participation</HD>
                <HD SOURCE="HD2">How do I submit comments?</HD>
                <P>
                    Please submit your comments, including the attachments, following the instructions provided under the above heading entitled 
                    <E T="02">ADDRESSES</E>
                    . Be advised that it may take a few hours or even days for your comment to be reflected on the docket. In addition, your comments must be written in English. We encourage you to provide concise comments and you may attach additional documents as necessary. There is no limit on the length of the attachments.
                </P>
                <HD SOURCE="HD2">Where do I go to read public comments, and find supporting information?</HD>
                <P>
                    Go to the docket online at 
                    <E T="03">https://www.regulations.gov,</E>
                     keyword search MARAD-2024-0166 or visit the Docket Management Facility (see 
                    <E T="02">ADDRESSES</E>
                     for hours of operation). We recommend that you periodically check the Docket for new submissions and supporting material.
                </P>
                <HD SOURCE="HD2">Will my comments be made available to the public?</HD>
                <P>Yes. Be aware that your entire comment, including your personal identifying information, will be made publicly available.</P>
                <HD SOURCE="HD2">May I submit comments confidentially?</HD>
                <P>
                    If you wish to submit comments under a claim of confidentiality, you should submit the information you claim to be confidential commercial information by email to 
                    <E T="03">SmallVessels@dot.gov.</E>
                     Include in the email subject heading “Contains Confidential Commercial Information” or “Contains CCI” and state in your submission, with specificity, the basis for any such confidential claim highlighting or denoting the CCI portions. If possible, please provide a summary of your submission that can be made available to the public.
                </P>
                <P>In the event MARAD receives a Freedom of Information Act (FOIA) request for the information, procedures described in the Department's FOIA regulation at 49 CFR 7.29 will be followed. Only information that is ultimately determined to be confidential under those procedures will be exempt from disclosure under FOIA.</P>
                <HD SOURCE="HD1">Privacy Act</HD>
                <P>
                    Anyone can search the electronic form of all comments received into any of our dockets by the name of the individual submitting the comment (or signing the comment, if submitted on behalf of an association, business, labor union, etc.). For information on DOT's compliance with the Privacy Act, please visit 
                    <E T="03">https://www.transportation.gov/privacy.</E>
                </P>
                <EXTRACT>
                    <FP>(Authority: 49 CFR 1.93(a), 46 U.S.C. 55103, 46 U.S.C. 12121)</FP>
                </EXTRACT>
                <SIG>
                    <P>By Order of the Maritime Administrator.</P>
                    <NAME>T. Mitchell Hudson, Jr.,</NAME>
                    <TITLE>Secretary, Maritime Administration.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31603 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4910-81-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <SUBAGY>National Highway Traffic Safety Administration</SUBAGY>
                <DEPDOC>[Docket No. NHTSA-2019-0129; Notice 2]</DEPDOC>
                <SUBJECT>Transamerica Tire Co. Ltd., Grant of Petition for Decision of Inconsequential Noncompliance</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>National Highway Traffic Safety Administration (NHTSA), Department of Transportation (DOT).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Grant of petition.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        Transamerica Tire Co. Ltd. (Transamerica) has determined that certain Transeagle ST tires manufactured by Shandong Yinbao Tyre (Yinbao) do not fully comply with Federal Motor Vehicle Safety Standard (FMVSS) No. 119, 
                        <E T="03">New Pneumatic Tires for Motor Vehicles with a GVWR of More than 4,536 kilograms (10,000 pounds) and Motorcycles.</E>
                         Transamerica, on behalf of Yinbao, filed a noncompliance report dated November 21, 2019. Transamerica petitioned NHTSA on November 25, 2019, and amended its petition on April 22, 2021, for a decision that the subject noncompliance is inconsequential as it relates to motor vehicle safety. This document announces the grant of Transamerica's petition.
                    </P>
                </SUM>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        Jayton Lindley, Office of Vehicle Safety Compliance, the National Highway Traffic Safety Administration (NHTSA), telephone (325) 655-0547, email 
                        <E T="03">Jayton.Lindley@dot.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">I. Overview</HD>
                <P>
                    Transamerica has determined that certain tires manufactured by Yinbao do not fully comply with paragraphs S6.5, specifically S6.5(b), of FMVSS No. 119, 
                    <E T="03">New Pneumatic Tires for Motor Vehicles with a GVWR of More than 4,536 kilograms (10,000 pounds) and Motorcycles</E>
                     (49 CFR 571.119). Transamerica, on behalf of Yinbao, filed a noncompliance report dated November 21, 2019, pursuant to 49 CFR part 573, 
                    <E T="03">Defect and Noncompliance Responsibility and Reports.</E>
                     Transamerica also petitioned NHTSA on November 25, 2019, for an exemption from the notification and remedy requirements of 49 U.S.C. Chapter 301 on the basis that this noncompliance is inconsequential as it relates to motor vehicle safety, pursuant to 49 U.S.C. 30118(d) and 30120(h) and 49 CFR part 556, 
                    <E T="03">Exemption for Inconsequential Defect or Noncompliance.</E>
                </P>
                <P>
                    Notice of receipt of Transamerica's petition was published with a 30-day public comment period in the 
                    <E T="04">Federal Register</E>
                     (86 FR 64593, November 18, 2021). No comments were received. To view the petition and all supporting documents log onto the Federal Docket Management System (FDMS) website at 
                    <E T="03">https://www.regulations.gov/.</E>
                     Then follow the online search instructions to locate docket number “NHTSA-2019-0129.”
                </P>
                <HD SOURCE="HD1">II. Tires Involved</HD>
                <P>Approximately 9,551 Transeagle ST radial tires, sizes ST235/85R16, ST235/80R16, and ST225/90R16, manufactured between September 23, 2017, and August 10, 2019, were reported by the manufacturer.</P>
                <HD SOURCE="HD1">III. Noncompliance</HD>
                <P>
                    Transamerica explains that the noncompliance is that the subject tires were inadvertently labeled with a Tire Identification Number (TIN) that contains an incorrect manufacturer's 
                    <PRTPAGE P="730"/>
                    code and, therefore, do not meet the requirements specified in paragraph S6.5(b) of FMVSS No. 119.
                </P>
                <P>For the tires that are the subject of this petition, what should be a 6 character manufacturer code contains an additional 7th character at the end of the labeled sequence, inadvertently producing a 14-character TIN instead of a 13-character TIN. Specifically, the subject tires were incorrectly marked with the code as “1BP TTFEFTL” whereas the manufacturer intended to mark the tires as follows:</P>
                <FP SOURCE="FP-1">• ST235/85R16: “1BP TTFEFT”</FP>
                <FP SOURCE="FP-1">• ST235/80R16: “1BP TFEFTL”</FP>
                <FP SOURCE="FP-1">
                    • ST225/90R16: “1BP TTFEF” 
                    <SU>1</SU>
                    <FTREF/>
                </FP>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         In its amended petition submitted on April 22, 2021, Transamerica acknowledges that this TIN which the manufacturer intended to use is also noncompliant because it does not contain six symbols as required. Because these tires are included in the scope of this petition, NHTSA does not need to further consider this fact in its analysis.
                    </P>
                </FTNT>
                <HD SOURCE="HD1">IV. Rule Requirements</HD>
                <P>Paragraphs S6.5 and S6.5(b) of FMVSS No. 119 include the requirements relevant to this petition. These requirements state that each tire shall be marked on one or both sidewalls with the TIN that meets the requirements of 49 CFR part 574. The TIN is comprised of 3 distinct codes totaling 13 characters. The first is the plant code, which uses 3 symbols, second is the manufacturer's code using exactly 6 symbols, and last is the date code, using 4 numbers to represent the week and year of production.</P>
                <HD SOURCE="HD1">V. Summary of Transamerica's Petition</HD>
                <P>The following views and arguments presented in this section, “V. Summary of Transamerica's Petition,” are the views and arguments provided by Transamerica and do not reflect the views of the Agency.</P>
                <HD SOURCE="HD2">Background</HD>
                <P>
                    On October 21, 2019, Transamerica received a letter from NHTSA explaining that NHTSA's Office of Vehicle Safety Compliance “has received information alleging that at least one of the tires manufactured by [Yinbao] and imported by [Transamerica] may not be in compliance with [FMVSS] No. 119.” Accordingly, the letter included a “photo showing a labeling failure on the tires branded Transeagle ST radial size 235/85R16.” Specifically, it is alleged that “[t]he tires appear to have an improper 14 character [TIN] instead of the 8-13 
                    <SU>2</SU>
                    <FTREF/>
                     character TIN required by FMVSS No. 119.”
                </P>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         NHTSA is clarifying the manufacturer's misunderstanding that an 8-13-character TIN would have been acceptable for these tires. Because the tires are marked with a 3-symbol plant code instead of a 2-symbol plant code, the TIN must conform to the 13-character format described in 49 CFR part 574.
                    </P>
                </FTNT>
                <P>Upon the receipt of NHTSA's inquiry, Transamerica conducted an investigation to determine the validity of the allegations and the universe of tires affected by such noncompliance. Transamerica found that a total number of 9,551 tires branded Transeagle ST radial tires size ST235/85R16, ST235/80R16, and ST225/90R16 contained an incorrect manufacturer's code in their TIN labels molded on the sidewall of the tires.</P>
                <HD SOURCE="HD2">Manufacturer's Arguments</HD>
                <P>Transamerica offers the following views and arguments in support of its petition:</P>
                <P>1. Transamerica says that, except for the incorrect manufacturer's code, all other information labeled on the tires is correct, including the manufacturer's assigned identification mark (typically referred to as plant code) as well as the week and year of manufacture (typically referred to as date code), and that the Transeagle ST tires otherwise comply with all applicable standards.</P>
                <P>2. Both Yinbao and Transamerica state that they are not aware of any crashes, injuries, customer complaints, or field reports in connection with this noncompliance.</P>
                <P>3. Transamerica claims that the inaccurate manufacturer's code would not affect either their or a consumers' ability to identify the tires should they be recalled for a performance related noncompliance.</P>
                <P>4. Transamerica states that they have taken measures to ensure that the tires can be registered correctly. There is a “Tire Registration” option on Transamerica's website where consumers can register their TIN and contact information. Transamerica has taken steps to ensure that the incorrect TINs with the additional characters can also be registered for any future recalls or warranty issues.</P>
                <P>5. Transamerica has already corrected the molds at the applicable manufacturing plant, such that no additional tires were fabricated with the noncompliance. Transamerica stated that they will also improve their internal processes to prevent future TIN errors.</P>
                <P>6. Transamerica states that NHTSA has previously granted petitions for inconsequential noncompliance where TIN information labels are incorrect or missing information and that granting this petition would be consistent with NHTSA's prior decisions on petitions involving tires labeled with inaccurate TIN information. Transamerica cites the following petitions:</P>
                <FP SOURCE="FP-1">• Michelin North America, Inc., Grant of Petition for Decision of Inconsequential Noncompliance, 81 FR 76412 (November 2, 2016)</FP>
                <FP SOURCE="FP-1">• Cooper Tire &amp; Rubber Company, Grant of Application for Decision of Inconsequential Noncompliance, 63 FR 29059 (May 27, 1998)</FP>
                <FP SOURCE="FP-1">• Tireco, Inc., Grant of Petition for Decision of Inconsequential Noncompliance, 80 FR 66614 (October 29, 2015)</FP>
                <FP SOURCE="FP-1">• Cooper Tire &amp; Rubber Company, Grant of Petition for Decision of Inconsequential Noncompliance, 71 FR 4397 (January 26, 2006)</FP>
                <FP SOURCE="FP-1">• Cooper Tire &amp; Rubber Company, Grant of Petition for Decision of Inconsequential Noncompliance, 82 FR 52966 (November 15, 2017).</FP>
                <FP SOURCE="FP-1">• Yokohama Tire Corporation, Grant of Petition for Decision of Inconsequential Noncompliance, 84 FR 64403 (November 21, 2019).</FP>
                <P>
                    Transamerica concludes by again contending that the subject noncompliance is inconsequential as it relates to motor vehicle safety and asking that its petition to be exempted from providing notification of the noncompliance, as required by 49 U.S.C. 30118, and a remedy for the noncompliance, as required by 49 U.S.C. 30120, be granted. Transamerica's complete petition and all supporting documents are available by logging onto the Federal Docket Management System (FDMS) website at: 
                    <E T="03">https://www.regulations.gov</E>
                     and following the online search instructions to locate the docket number listed in the title of this notice.
                </P>
                <HD SOURCE="HD1">VI. NHTSA's Analysis</HD>
                <P>
                    In determining inconsequentiality of a noncompliance, NHTSA focuses on the safety risk to individuals who experience the type of event against which a recall would otherwise protect.
                    <SU>3</SU>
                    <FTREF/>
                     In general, NHTSA does not consider the absence of complaints or injuries when determining if a noncompliance is inconsequential to safety. The absence of complaints does 
                    <PRTPAGE P="731"/>
                    not mean vehicle occupants have not experienced a safety issue, nor does it mean that there will not be safety issues in the future.
                    <SU>4</SU>
                    <FTREF/>
                     Further, because each inconsequential noncompliance petition must be evaluated on its own facts and determinations are highly fact-dependent, NHTSA does not consider prior determinations as binding precedent. Petitioners have the burden of persuading NHTSA that the noncompliance is inconsequential to safety.
                </P>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         
                        <E T="03">See Gen. Motors, LLC; Grant of Petition for Decision of Inconsequential Noncompliance,</E>
                         78 FR 35355 (June 12, 2013) (finding noncompliance had no effect on occupant safety because it had no effect on the proper operation of the occupant classification system and the correct deployment of an air bag); 
                        <E T="03">Osram Sylvania Prods. Inc.; Grant of Petition for Decision of Inconsequential Noncompliance,</E>
                         78 FR 46000 (July 30, 2013) (finding occupant using noncompliant light source would not be exposed to significantly greater risk than occupant using similar compliant light source).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         
                        <E T="03">See Morgan 3 Wheeler Limited; Denial of Petition for Decision of Inconsequential Noncompliance,</E>
                         81 FR 21663, 21666 (Apr. 12, 2016); 
                        <E T="03">see also United States</E>
                         v. 
                        <E T="03">Gen. Motors Corp.,</E>
                         565 F.2d 754, 759 (D.C. Cir. 1977) (finding defect poses an unreasonable risk when it “results in hazards as potentially dangerous as sudden engine fire, and where there is no dispute that at least some such hazards, in this case fires, can definitely be expected to occur in the future”).
                    </P>
                </FTNT>
                <P>NHTSA has evaluated the merits of the inconsequential noncompliance petition submitted by Transamerica and grants the petitioner's request for an exemption from the notification and remedy requirements of 49 U.S.C. 30118 and 49 U.S.C. 30120 based on the following:</P>
                <P>1. NHTSA believes, based on information provided by the manufacturer, that the tires otherwise meet the performance criteria of FMVSS No. 119 and that the subject labeling noncompliance likely has no effect on the operational safety and performance of the affected tires.</P>
                <P>2. NHTSA agrees that the additional characters in the TIN do not affect the ability of the manufacturer or consumer to identify the affected tires in the event of a recall. The agency has also verified with the manufacturer that the affected tires with additional characters in the TIN may be registered. Transamerica has also ensured that any future safety related recalls will include the incorrectly marked TIN numbers if needed.</P>
                <P>This grant exempts Transamerica from its obligations under 49 U.S.C. 30118 and 30120 to provide notification of, and a free remedy for, the noncompliance with FMVSS No. 119. However, erroneous TIN marking is also a violation of 49 CFR part 574. Grants of petitions for inconsequential noncompliance do not absolve entities subject to regulations other than the FMVSS from their obligations under those regulations. Although NHTSA has chosen not to do so in this instance, NHTSA may consider seeking civil penalties in the future for violations of part 574 by tire manufacturers and importers.</P>
                <HD SOURCE="HD1">VII. NHTSA's Decision</HD>
                <P>In consideration of the foregoing, NHTSA finds that Transamerica has met its burden of persuasion that the subject FMVSS No. 119 noncompliance in the affected tires is inconsequential to motor vehicle safety. Accordingly, Transamerica's petition is hereby granted and Transamerica is consequently exempted from the obligation of providing notification of, and a free remedy for, that noncompliance under 49 U.S.C. 30118 and 30120.</P>
                <P>NHTSA notes that the statutory provisions (49 U.S.C. 30118(d) and 30120(h)) that permit manufacturers to file petitions for a determination of inconsequentiality allow NHTSA to exempt manufacturers only from the duties found in sections 30118 and 30120, respectively, to notify owners, purchasers, and dealers of a defect or noncompliance and to remedy the defect or noncompliance. Therefore, this decision only applies to the subject tires that Transamerica no longer controlled at the time it determined that the noncompliance existed. However, the granting of this petition does not relieve tire distributors and dealers of the prohibitions on the sale, offer for sale, or introduction or delivery for introduction into interstate commerce of the noncompliant tires under their control after Transamerica notified them that the subject noncompliance existed.</P>
                <EXTRACT>
                    <FP>(Authority: 49 U.S.C. 30118, 30120; delegations of authority at 49 CFR 1.95 and 501.8)</FP>
                </EXTRACT>
                <SIG>
                    <NAME>Otto G. Matheke III,</NAME>
                    <TITLE>Director, Office of Vehicle Safety Compliance.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31753 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4910-59-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <SUBAGY>National Highway Traffic Safety Administration</SUBAGY>
                <DEPDOC>[Docket No. NHTSA-2024-0037]</DEPDOC>
                <SUBJECT>Uniform Procedures for State Highway Safety Grant Programs</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>National Highway Traffic Safety Administration (NHTSA), Department of Transportation (DOT).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of availability.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>This notice transmits the revised minimum performance measures that State Highway Safety Offices use in their triennial Highway Safety Plans.</P>
                </SUM>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P/>
                    <P>
                        <E T="03">For program issues:</E>
                         Barbara Sauers, Associate Administrator, Regional Operations and Program Delivery, National Highway Traffic Safety Administration; Telephone number: (202) 366-0144; Email: 
                        <E T="03">barbara.sauers@dot.gov.</E>
                    </P>
                    <P>
                        <E T="03">For legal issues:</E>
                         Megan Brown, Attorney Advisor, Litigation &amp; General Law, Office of the Chief Counsel, National Highway Traffic Safety Administration, 1200 New Jersey Avenue SE, Washington, DC 20590; Telephone number: (202) 366-1834; Email: 
                        <E T="03">Megan.Brown@dot.gov</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <HD SOURCE="HD1">Table of Contents</HD>
                <EXTRACT>
                    <FP SOURCE="FP-1">I. Background</FP>
                    <FP SOURCE="FP-1">II. Performance Measure Development</FP>
                    <FP SOURCE="FP-1">III. Comment Response</FP>
                    <FP SOURCE="FP-1">IV. Performance Measure Framework</FP>
                    <FP SOURCE="FP-1">V. Best Practices for Performance Management</FP>
                    <FP SOURCE="FP-1">VI. Applicability Date</FP>
                </EXTRACT>
                <HD SOURCE="HD1">I. Background</HD>
                <P>Roadway deaths are unacceptable and preventable and State Highway Safety Office (SHSO) officials have a critical role in eliminating crashes that result in deaths and serious injuries. Performance management is a vital tool for States to use in developing and implementing their highway traffic safety programs. Performance measures increase transparency and can help improve program outcomes by providing a greater understanding of how safety issues are being addressed with highway safety grant funds. This notice sets forth the revised minimum performance measures that SHSO will use in their triennial Highway Safety Plans (3HSP) to develop and implement their programs.</P>
                <P>
                    The highway safety grant program statute 
                    <SU>1</SU>
                    <FTREF/>
                     requires States to submit performance measures to support State safety goals and for each countermeasure strategy for programming funds that a State includes in its 3HSP. These performance measures must demonstrate constant or improved performance and provide documentation of the current safety levels for each performance measure, quantifiable performance targets for each performance measure, and a justification for each performance target.
                    <SU>2</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         23 U.S.C. 402(k)(4)(A).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         
                        <E T="03">Id.</E>
                    </P>
                </FTNT>
                <P>
                    NHTSA first established minimum performance measures in coordination with the Governor's Highway Safety Association (GHSA) in 2008.
                    <SU>3</SU>
                    <FTREF/>
                     Congress 
                    <PRTPAGE P="732"/>
                    mandated the use of performance measures for all States in MAP-21 and continued the requirements under the FAST Act and BIL. Under statute, NHTSA must develop minimum performance measures in consultation with GHSA.
                    <SU>4</SU>
                    <FTREF/>
                     Beginning with fiscal year (FY) 2010 HSPs, submitted to NHTSA in July 2009, all States and territories voluntarily agreed to include fourteen minimum performance measures. States were required to report targets beginning with their FY 2014 HSPs. In 2014, NHTSA and GHSA added a fifteenth measure addressing bicyclist fatalities.
                </P>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         “Traffic Safety Performance Measures for States and Federal Agencies” (DOT HS 811 025) (August 2008).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>4</SU>
                         23 U.S.C. 402(k)(4)(A).
                    </P>
                </FTNT>
                <P>This year, NHTSA, in consultation with GHSA, undertook the first comprehensive update of the minimum performance measures since they were originally published in 2008. This notice contains a description of that process and the resulting updated minimum performance measures.</P>
                <HD SOURCE="HD1">II. Performance Measure Development</HD>
                <P>NHTSA, in consultation with GHSA, identified a diverse and representative list of stakeholders from NHTSA, SHSOs, and other organizations. This step was crucial to ensuring that the engagement process included perspectives from various sectors and individuals who could offer valuable insights into the performance measures. Additionally, an expert panel consisting of members of GHSA and NHTSA provided input and direction to the overall process. The expert panel regularly met to discuss feedback from the stakeholders and to help develop this framework.</P>
                <P>Once stakeholders were identified, 57 listening sessions were held. There were 78 participants, comprised of representatives from NHTSA, GHSA, Federal Highway Administration (FHWA), National EMS Quality Alliance (NEMSQA), and additional State university research officials. Stakeholders shared their views on the effectiveness of the current core performance measures while suggesting opportunities for improvements.</P>
                <P>On August 21, 2024, NHTSA hosted a virtual public listening session, allowing all interested parties to share their insights both orally and through written submissions to the online docket. A summary of the comments and NHTSA's responses are below. NHTSA used the results of the stakeholder and public listening sessions to develop this updated performance measure framework.</P>
                <HD SOURCE="HD1">III. Comment Response</HD>
                <P>
                    On August 21, 2024, NHTSA hosted a virtual public listening session, allowing all interested parties to share their insights both orally and through written submissions to the online docket. Several speakers delivered remarks during the session. A total of eighteen written comments representing seventeen organizations were submitted online by GHSA, the American Association of State Highway and Transportation Officials (AAHSTO), the American Association of Motor Vehicle Administrators (AAMVA), Center for Policing Equity, Coalition for Cyclist, Detroit Greenways Coalition, Driving School Associations of the Americas, Georgia Governor's Office of Highway Safety, Health by Design, Fines and Fees Justice Center, Idaho Office of Highway Safety, National Safety Council, The League of American Bicyclists, The Policing Project at New York University School of Law, Who Poo App, and a joint comment by Vera Institute of Justice, Color of Change, and Center for American Progress. Complete comments may be viewed at regulations.gov.
                    <SU>5</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>5</SU>
                         
                        <E T="03">www.regulations.gov/document/NHTSA-2024-0037-0001/comment.</E>
                    </P>
                </FTNT>
                <P>
                    Several commenters 
                    <SU>6</SU>
                    <FTREF/>
                     submitted comments about NHTSA's programs and activities that fall outside the scope of this performance measure effort and will not be addressed further in this document. NHTSA appreciates those comments and will consider them where appropriate.
                </P>
                <FTNT>
                    <P>
                        <SU>6</SU>
                         AAMVA; Center for Policing Equity; Coalitions 4 Cyclists; Driving School Associations of the Americas; Fines and Fees Justice Center; Georgia Governor's Office of Highway Safety; Healthy By Design; National Safety Council; Policing Project at New York University School of Law; Vision Zero Network; Who Poo App; joint comment by Vera Institute of Justice, Color of Change, and the Center for American Progress.
                    </P>
                </FTNT>
                <P>
                    Many commenters submitted broad comments about the nature of NHTSA's performance measure program and how performance measures should be used. Several commenters 
                    <SU>7</SU>
                    <FTREF/>
                     recommended that NHTSA ensure that the Safe System Approach is integrated into DOT grants. NHTSA encourages States to adopt the Safe System approach and incorporate its principles into their performance management framework. AASHTO requested that the revisions to the minimum performance measures decrease associated burdens and costs on the State. The performance measure framework developed and laid out in this notice was developed to provide States with increased flexibility to use performance measures that are most useful to their program. That increased flexibility should decrease burden. In addition, NHTSA plans to deploy an electronic grants management system (eGrants) that SHSOs will use to submit the 3HSPs due on July 1, 2026. NHTSA expects that eGrants will further streamline the process for submitting and reporting on performance measure information provided to NHTSA. Finally, GHSA recommended that NHTSA create resources and provide technical assistance to States to empower States in better program-specific evaluations. NHTSA currently offers training to States through the Transportation Safety Institute (TSI) on program evaluation and NHTSA's Regional Offices are available to provide technical assistance.
                </P>
                <FTNT>
                    <P>
                        <SU>7</SU>
                         AASHTO; Fines and Fees Justice Center; GHSA; Idaho Office of Highway Safety; The League of American Bicyclists; National Safety Council; Vision Zero Network.
                    </P>
                </FTNT>
                <P>
                    Many commenters 
                    <SU>8</SU>
                    <FTREF/>
                     stressed the diversity and unique safety needs and priorities across States, and asked NHTSA to allow flexibility. The proposed framework allows States to select strategic core measures specific to their problem identification and to set other State-developed performance measures specific to their needs.
                </P>
                <FTNT>
                    <P>
                        <SU>8</SU>
                         AASHTO; Georgia Governor's Office of Highway Safety; GHSA.
                    </P>
                </FTNT>
                <P>
                    Healthy by Design argued that States should not be allowed to establish targets that anticipate an increase in fatalities. Conversely, AAMVA, the Georgia Governor's Office of Highway Safety, and GHSA all argued that the BIL's requirement for constant and improved performance has divorced performance targets from the data and has imposed penalties, such as increased oversight, on States that fail to meet their targets. AAMVA, AASHTO, and GHSA also argued that performance measures should be limited to areas where SHSOs have direct control over outcomes. As NHTSA has previously emphasized, 
                    <SU>9</SU>
                    <FTREF/>
                     NHTSA strongly disagrees that constant or improved performance targets are contrary to the data or that States lack the ability to influence safety numbers. Targets should reflect the outcomes that States expect to achieve after implementing their planned programs. If a projected outcome shows worsening safety levels, the State needs to change its planned program. Further, BIL requires States to submit only constant or improved performance measures, so NHTSA does not have the discretion to allow States to set worsening targets.
                </P>
                <FTNT>
                    <P>
                        <SU>9</SU>
                         87 FR 56756, 56767 (Sept. 15, 2022); 88 FR 7780, 7788 (Feb. 6, 2023).
                    </P>
                </FTNT>
                <P>
                    Some commenters suggested various combinations of required measures based on measures currently required by 
                    <PRTPAGE P="733"/>
                    both NHTSA and FHWA. GHSA and the Idaho Office of Highway Safety said that States should only be required to submit to NHTSA the five measures already required by FHWA.
                    <SU>10</SU>
                    <FTREF/>
                     In this new framework, NHTSA requires three of the FHWA measures (number of fatalities, rate of fatalities, and number of serious injuries) as universal core performance measures. Healthy by Design requested that the rate of serious injuries and number of non-motorized injuries be classified as core performance measures. Those two measures are program-dependent, and their use will vary by State. As such, they are classified as State-developed performance measures that States can include if they have relevant programs and countermeasures.
                </P>
                <FTNT>
                    <P>
                        <SU>10</SU>
                         Separately, the Idaho Office of Highway Safety also said that States should only be required to submit four of the five measures required by FHWA.
                    </P>
                </FTNT>
                <P>
                    Six commenters 
                    <SU>11</SU>
                    <FTREF/>
                     requested that NHTSA remove the activity measures that were included in the minimum performance measures established in 2008, and that NHTSA not include any measures that incentivize law enforcement quota systems. Center for Policing Equity requested that NHTSA not include any measures that incentivize law enforcement quota systems but asked that NHTSA include new activity measures specific to law enforcement activities, including non-traditional enforcement actions. The League of American Bicyclists requested that NHTSA add an activity measure related to interagency collaboration on priority issues. NHTSA has removed all activity measures requirements from this new performance measure framework. However, State-developed performance measures may include activity measures.
                </P>
                <FTNT>
                    <P>
                        <SU>11</SU>
                         AASHTO; Center for Policing Equity Fines and Fees Justice Center; Healthy by Design; League of American Bicyclists; Policing Project at New York University School of Law.
                    </P>
                </FTNT>
                <P>Various commenters requested specific performance measures. The Georgia Governor's Office of Highway Safety recommended that NHTSA include performance measures for all nationally prioritized program areas. Both the Policing Project at New York University School of Law and the joint comment of Vera Institute of Justice, Color of Change, and the Center for American Progress recommended that NHTSA include performance measures specific to details of pursuit by law enforcement and traffic stops. Healthy by Design recommended that NHTSA consider adding a measure related to geographic location and post-crash care injury severity and treatment. The League of American Bicyclists and Vision Zero Network both recommended a performance measure related to observed speeding behavior. The Georgia Governor's Office of Highway Safety recommended a measure of “suspected: distracted driving crashes.” In this update of the performance measure framework, NHTSA was guided in large part by a desire to provide States with flexibility to implement programs in response to their unique safety problems, while also maintaining a discrete set of universal and strategic core performance measures that prioritize national-level issues that are addressed by States. As a result, NHTSA did not create performance measures at the level of detail requested by these commenters. However, States may choose to create these and other performance measures as a State-developed performance measure.</P>
                <P>
                    Four commenters 
                    <SU>12</SU>
                    <FTREF/>
                     recommended that NHTSA add expanded measures relating to pedestrian and bicyclist safety, including separate non-motorist fatalities and serious injuries performance measures. The Idaho Office of Highway Safety, however, recommended that NHTSA remove the combined fatality and serious injury performance measure. In order to allow States flexibility to address the demonstrated safety problems in their State, NHTSA has identified non-motorist fatalities as a strategic core performance measure that is required for any State that has an identified non-motorist safety problem and countermeasure strategy. In addition, States may create a State-developed performance measure for other, more specific, non-motorist issues.
                </P>
                <FTNT>
                    <P>
                        <SU>12</SU>
                         Detroit Greenways Coalition; Healthy by Design; League of American Bicyclists; Vizion Zero Network.
                    </P>
                </FTNT>
                <P>
                    GHSA noted that if NHTSA opts to create a performance measure related to the grant program's statutory public participation and engagement requirements, that performance measure should be tied to the State's efforts to reach underrepresented communities, not how much funding those communities receive. The joint comment from Vera Institute of Justice, Color of Change, and the Center for American Progress recommended that NHTSA develop operational metrics of community engagement to assess level and type of engagement that went into the State's highway safety planning process. Section 402 places performance measures within the context of a State's safety levels.
                    <SU>13</SU>
                    <FTREF/>
                     As a result, NHTSA does not have authority to require States to provide performance measures related to public participation. That said, NHTSA notes that NHTSA assesses State efforts in public participation and engagement as part of the 3HSP review process and through the Annual Report.
                </P>
                <FTNT>
                    <P>
                        <SU>13</SU>
                         
                        <E T="03">See</E>
                         23 U.S.C. 402(k)(4)(A).
                    </P>
                </FTNT>
                <P>
                    AAMVA, AASHTO, and the Georgia Governor's Office of Highway Safety requested that NHTSA allow States to consider additional target-setting methods beyond the rolling average. The Georgia Governor's Office of Highway Safety and Idaho Office of Public Safety requested that States be allowed to choose whether to express a target in terms of annual totals, or a three-or five-year rolling average. Under the new framework, States have the flexibility to choose the time period that is most appropriate for their State provided the target covers the 3HSP period. See the “Additional Requirements” section for additional information. The Georgia Governor's Office of Highway Safety and Vision Zero Network argued that measures should be normalized by the appropriate denominator to show true progress (
                    <E T="03">e.g.,</E>
                     population, licensed drivers, or VMT), especially for States with significant population changes. This can be addressed by States in their development of State-developed performance measures.
                </P>
                <HD SOURCE="HD1">IV. Performance Measure Framework</HD>
                <HD SOURCE="HD2">Program-Driven Performance Measure Framework</HD>
                <P>In this document, NHTSA establishes an updated behavioral highway safety program-driven performance measure framework. This updated framework creates three categories of performance measures. Each of these categories are equally important and identifies required or recommended measures based on the State's program and the availability of standardized data. The three categories are:</P>
                <P>(1) Universal core performance measures—measures required for all States. These universal core performance measures cover problem areas for which all recipients currently include countermeasure strategies.</P>
                <P>(2) Strategic core performance measures—measures required for all States that have a corresponding countermeasure strategy in their 3HSP. These measures are required based on State-specific problem identification tied to countermeasure strategies.</P>
                <P>(3) State-developed performance measures—additional measures developed by States based on their specific problem identification and tied to their countermeasure strategies.</P>
                <P>
                    As described in more detail, above, there was a general consensus among 
                    <PRTPAGE P="734"/>
                    stakeholders for fewer required measures. However, some stakeholders sought specific additional measures to address emerging traffic safety issues within States. This program-driven performance measure framework system allows for both goals. Additionally, some performance measures are more (or less) relevant for some States than for others. For example, a State with large metropolitan areas may prioritize bicycle safety, while low-population rural States may have few bicyclist fatalities. This framework emphasizes a small set of universal performance measures that address problems faced by all States, while also including a set of strategic core performance measures that are required based on State-specific problem identification. It also offers increased flexibility and autonomy in programming State-specific priorities through the State-developed performance measures, as opposed to a one-size-fits-all approach. This framework lessens reporting burden by reducing the total number of measures required of all States while allowing the addition of measures relating to emerging issues specific to individual States. Flexibility and efficiency are increased by allowing States to focus on high-priority program areas to deploy resources to achieve the most significant reduction in fatalities and serious injuries.
                </P>
                <P>The new performance management framework is described below. Note that this does not change the underlying performance plan and reporting requirements in NHTSA's Uniform Procedures for State Highway Safety Grant Programs (23 CFR part 1300). The highway safety grant program statute (23 U.S.C. 402(k)(4)(A)) requires States to submit performance measures to support State safety goals and for each countermeasure strategy for programming funds that a State includes in its 3HSP.</P>
                <HD SOURCE="HD2">Universal Core Performance Measures</HD>
                <P>
                    The 
                    <E T="03">universal core performance measures</E>
                     (UC) are required for all States. These measures include:
                </P>
                <FP SOURCE="FP-1">UC-1 Number of fatalities</FP>
                <FP SOURCE="FP-1">UC-2 Number of serious injuries</FP>
                <FP SOURCE="FP-1">UC-3 Fatalities per vehicle miles travelled (VMT)</FP>
                <FP SOURCE="FP-1">UC-4 Number of unrestrained passenger vehicle occupant fatalities, all seat positions</FP>
                <FP SOURCE="FP-1">UC-5 Number of fatalities involving a driver or motorcycle operator with a BAC over your State's legal limit</FP>
                <FP SOURCE="FP-1">UC-6 Number of speeding-related fatalities</FP>
                <FP SOURCE="FP-1">UC-7 Number of pedestrian fatalities</FP>
                <HD SOURCE="HD2">Strategic Core Performance Measures</HD>
                <P>
                    Next, States must select 
                    <E T="03">strategic core performance measures</E>
                     from the below pre-set list if the State includes a corresponding countermeasure strategy in its 3HSP. These measures are based on State-specific problem identification tied to countermeasure strategies and were identified, in part, because relevant data sources are generally maintained across all states. These measures aim to reduce fatalities through problem identification and selected program areas tailored to address State needs. These measures include:
                </P>
                <FP SOURCE="FP-1">• Number of bicyclist and other cyclist fatalities</FP>
                <FP SOURCE="FP-1">• Number of motorcyclist fatalities </FP>
                <FP SOURCE="FP-1">• Number of drivers aged 20 or younger involved in fatal crashes</FP>
                <FP SOURCE="FP-1">• Number of drivers aged 65 and older involved in fatal crashes</FP>
                <FP SOURCE="FP-1">• Number of fatalities and serious injuries on rural roads</FP>
                <FP SOURCE="FP-1">• Number of roadside fatalities (first responders, tow-truck drivers, roadway crew)</FP>
                <HD SOURCE="HD2">State-Developed Performance Measures</HD>
                <P>
                    Lastly, States will include 
                    <E T="03">State-developed performance measures</E>
                     in their 3HSP. These measures will derive from State problem identification. They will be necessary to support countermeasure strategies for which there is no standardized measure of performance across all States and for which standardized datasets for all States do not yet exist. By incorporating these metrics, States can address localized challenges and enhance their overall traffic safety strategies. These are typically for program areas, countermeasure strategies, and topics that do not have a universal or strategic core measure that all States must track but may also be used in addition to existing measures. In these cases, a universal core measure is not sufficient on its own. This notice does not contain any required State-developed performance measures, but the examples below illustrate the types of performance measures that a State may choose to develop:
                </P>
                <FP SOURCE="FP-1">• Rate of serious injuries per 100 million VMT</FP>
                <FP SOURCE="FP-1">• Rate of combined fatalities and serious injuries per 100 million VMT</FP>
                <FP SOURCE="FP-1">
                    • Child Passenger Safety, 
                    <E T="03">e.g.,</E>
                     the number of improperly restrained child fatalities 
                </FP>
                <FP SOURCE="FP-1">
                    • Emergency Medical Services (EMS), 
                    <E T="03">e.g.,</E>
                     median response time for severely injured motor vehicle crash patient
                </FP>
                <FP SOURCE="FP-1">
                    • Drugged Driving, 
                    <E T="03">e.g.,</E>
                     toxicology results, percent of DUI cases tested for drugs other than alcohol
                </FP>
                <FP SOURCE="FP-1">
                    • Distracted driving, 
                    <E T="03">e.g.,</E>
                     observed cell phone/handheld electronic use for passenger vehicles, driver
                </FP>
                <FP SOURCE="FP-1">
                    • Traffic Records, 
                    <E T="03">e.g.,</E>
                     completeness, accuracy
                </FP>
                <HD SOURCE="HD2">Additional Requirements</HD>
                <P>
                    All performance measures must include a baseline documenting current safety levels, and a performance target that demonstrates constant or improved performance over the three-year period covered by the 3HSP with annual benchmarks to assist States in tracking performance.
                    <SU>14</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>14</SU>
                         23 CFR 1300.11(b)(3)(ii)(B).
                    </P>
                </FTNT>
                <P>A SHSO may express a target in terms of annual totals or three- or five-year rolling averages, depending on what is appropriate for their State. Below are examples of what this could look like using different time periods in the FY 2027-2029 3HSP.</P>
                <GPOTABLE COLS="5" OPTS="L2,tp0,i1" CDEF="s50,r50,r50,r50,r50">
                    <TTITLE> </TTITLE>
                    <BOXHD>
                        <CHED H="1">Total fatalities</CHED>
                        <CHED H="1">Current safety level</CHED>
                        <CHED H="1">2027 Benchmark</CHED>
                        <CHED H="1">2028 Benchmark</CHED>
                        <CHED H="1">2029 Target</CHED>
                    </BOXHD>
                    <ROW>
                        <ENT I="01">Annual</ENT>
                        <ENT>150 (2025 total)</ENT>
                        <ENT>145 (2027 total)</ENT>
                        <ENT>140 (2028 total)</ENT>
                        <ENT>135 (2029 total).</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">3-year average</ENT>
                        <ENT>155 (2023-2025 average)</ENT>
                        <ENT>150 (2025-2027 average)</ENT>
                        <ENT>145 (2026-2028 average)</ENT>
                        <ENT>140 (2027-2029 average).</ENT>
                    </ROW>
                    <ROW>
                        <ENT I="01">5-year average</ENT>
                        <ENT>160 (2021-2025 average)</ENT>
                        <ENT>155 (2023-2027 average)</ENT>
                        <ENT>150 (2024-2028 average)</ENT>
                        <ENT>145 (2025-2029 average).</ENT>
                    </ROW>
                </GPOTABLE>
                <P>For all fatality-based measures, FARS data will be used to determine if fatality-based targets are ultimately met. However, a SHSO may use State or FARS data to set the current safety level. And a SHSO may also use State data for the Performance Report section of the 3HSP and the Annual Report.</P>
                <HD SOURCE="HD1">V. Best Practices for Performance Management</HD>
                <P>
                    NHTSA encourages SHSOs to adopt a Safe System Approach and use robust 
                    <PRTPAGE P="735"/>
                    procedures to set performance targets. Performance measures set the stage for an informed discussion of State performance, barriers to improvement, potential countermeasure strategies, and the expected benefits of safety activities. SHSOs should expand and engage more diverse stakeholders when establishing performance targets. Considering the viewpoints of underserved and overrepresented communities is critical for setting performance targets.
                </P>
                <P>SHSOs should ensure that performance targets and measures are developed in cooperative partnerships based on data and objective information. The SHSO should use the most current available data to perform a trend analysis to help predict what is likely to happen. Using a data-driven decision process that accounts for the SHSO's programming and interventions helps maintain a focus on improvement. This approach helps make investment and policy decisions to achieve performance targets.</P>
                <P>NHTSA acknowledges that States face many other considerations when setting performance targets. Each performance target must be treated individually instead of applying the same formula or giving a blanket statement about what factors were considered for the entire process. For example, suppose a primary seat belt law was recently enacted in your State. In that case, the State could expect to have a higher decrease in unbelted fatalities compared to other types of fatalities.</P>
                <P>When setting targets, SHSOs should consider the following as part of their justification:</P>
                <FP SOURCE="FP-1">• Problem identification and trend analysis</FP>
                <FP SOURCE="FP-1">• What data sources were considered?</FP>
                <FP SOURCE="FP-1">• Which sociodemographic sources are considered?</FP>
                <FP SOURCE="FP-1">• How will the program, countermeasure strategy, and project selections adjustments help meet the target?</FP>
                <FP SOURCE="FP-1">• How were underserved and overrepresented communities considered?</FP>
                <FP SOURCE="FP-1">• How has the SHSO engaged with stakeholders?</FP>
                <FP SOURCE="FP-1">• Anticipated levels of effort</FP>
                <FP SOURCE="FP-1">• Economic conditions</FP>
                <FP SOURCE="FP-1">• Legislative changes</FP>
                <FP SOURCE="FP-1">• Political support</FP>
                <FP SOURCE="FP-1">• Has the State adopted the Safe System approach?</FP>
                <FP SOURCE="FP-1">• Other local considerations such as other transportation efforts, employment patterns, weather, demographic changes, and travel patterns</FP>
                <HD SOURCE="HD2">Illustrative Examples</HD>
                <P>
                    As a reminder, States are required to provide performance measures for every countermeasure strategy for programming funds in the 3HSP. Projects do not require specific performance measures but are instead associated with performance measures through their corresponding countermeasure strategy. This section provides context for when a State may need to submit a State-developed performance measure. For example, drugged or poly-substance impaired driving is listed as a State-developed performance measure because data is not consistently collected across States and territories, and State programs vary. NHTSA encourages States to look at ways to improve data collection related to drug impairment and testing. Suppose an SHSO includes a drug-impaired driving countermeasure strategy within the Impaired Driving program area. In that case, the State may not rely on the 
                    <E T="03">number of fatalities involving a driver or motorcycle operator with a BAC of .08 and above</E>
                     universal core performance measure as that measure is specific to alcohol-impaired driving. Instead, the SHSO must include a State-developed performance measure related to drugged driving. Other examples include if the SHSO has a Police Traffic Services program area that includes multiple topics such as speeding and distracted driving. In this example, the SHSO may not rely solely on the 
                    <E T="03">number of speeding-related fatalities</E>
                     performance measure. Rather, the SHSO may need to use a State-developed performance measure such as 
                    <E T="03">observed cell phone/handheld electronic, distracted driving fatalities,</E>
                     or another measure specific to the State's countermeasure strategies. Countermeasure strategies for topics such as traffic records may not rely on the 
                    <E T="03">universal core measures</E>
                     because none are relevant to traffic records. Instead, SHSOs will need to create a 
                    <E T="03">State-developed performance measure</E>
                     such as improvement in accuracy.
                    <SU>15</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>15</SU>
                         For additional guidance in setting performance measures related to traffic records system, see 
                        <E T="03">Traffic Records Data Quality Management Guide: Update to the Model Performance Measures for State Traffic Records Systems,</E>
                         DOT HS 813 544 (Mar 2024). 
                        <E T="03">Available online at https://crashstats.nhtsa.dot.gov/Api/Public/ViewPublication/813544.</E>
                    </P>
                </FTNT>
                <P>
                    Further, even for program areas and countermeasure strategies for which there is a 
                    <E T="03">universal</E>
                     or 
                    <E T="03">strategic core performance measure,</E>
                     SHSOs are strongly encouraged to also develop additional 
                    <E T="03">State-developed performance measures</E>
                     to more specifically address their problem ID when appropriate. For example:
                </P>
                <FP SOURCE="FP-1">
                    • In addition to UC-7 (
                    <E T="03">number of pedestrian fatalities</E>
                    ), a State could develop a separate measure for 
                    <E T="03">pedestrian fatalities for ages 18-34.</E>
                </FP>
                <FP SOURCE="FP-1">
                    • In addition to 
                    <E T="03">number of motorcyclist fatalities,</E>
                     a State could develop a separate measure for 
                    <E T="03">number of unhelmeted fatalities.</E>
                </FP>
                <FP SOURCE="FP-1">
                    • In addition to UC-4 (
                    <E T="03">number of unrestrained passenger vehicle occupant fatalities, all seat positions</E>
                    ), a State could develop a separate measure for 
                    <E T="03">observed seat belt use for passenger vehicles, front seat outboard passengers.</E>
                </FP>
                <FP SOURCE="FP-1">
                    • In addition to UC-5 (
                    <E T="03">number of fatalities involving a driver or motorcycle operator with a BAC over your State's legal limit</E>
                    ), a State could develop a separate measure for 
                    <E T="03">Number of fatalities in crashes involving a driver or motorcycle operator with a blood alcohol concentration (BAC) of .05 and above.</E>
                </FP>
                <HD SOURCE="HD1">VI. Applicability Date</HD>
                <P>SHSOs will submit performance measures aligning with this framework beginning with the 3HSP due to NHTSA on July 1, 2026, covering fiscal years 2027, 2028 and 2029.</P>
                <P>
                    <E T="03">Authority:</E>
                     49 CFR 1.95 and 501.8(i).
                </P>
                <SIG>
                    <P>Issued in Washington, DC.</P>
                    <NAME>Barbara Sauers,</NAME>
                    <TITLE>Associate Administrator, Regional Operations and Program Delivery.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31487 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <SUBAGY>National Highway Traffic Safety Administration</SUBAGY>
                <DEPDOC>[Docket No. NHTSA-2019-0042; Notice 2]</DEPDOC>
                <SUBJECT>Gillig, LLC, Grant of Petition for Decision of Inconsequential Noncompliance</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>National Highway Traffic Safety Administration (NHTSA), Department of Transportation (DOT).</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Grant of petition.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        Gillig LLC, determined that certain model year (MY) 2013-2019 Gillig Low Floor buses do not fully comply with Federal Motor Vehicle Safety Standard (FMVSS) No. 102, 
                        <E T="03">Transmission Shift Position Sequence, Starter Interlock, and Transmission Braking Effect.</E>
                         Gillig filed a noncompliance report dated April 1, 2019, and later amended the report on April 23, 2019. Gillig subsequently petitioned NHTSA on May 8, 2019, for a decision that the subject noncompliance is inconsequential as it 
                        <PRTPAGE P="736"/>
                        relates to motor vehicle safety. This notice announces the grant of Gillig's petition.
                    </P>
                </SUM>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Ahmad Barnes, Office of Vehicle Safety Compliance, the National Highway Traffic Safety Administration (NHTSA), (202) 366-7236.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P/>
                <P>
                    <E T="03">I. Overview:</E>
                     Gillig has determined that certain MY 2013-2019 Low Floor buses do not fully comply with paragraph S3.1.3 of FMVSS No. 102, 
                    <E T="03">Transmission Shift Position Sequence, Starter Interlock, and Transmission Braking Effect</E>
                     (49 CFR 571.102). Gillig filed a noncompliance report dated April 1, 2019, and later amended their report on April 23, 2019, pursuant to 49 CFR part 573, 
                    <E T="03">Defect and Noncompliance Responsibility and Reports.</E>
                     and subsequently petitioned NHTSA on May 8, 2019, for an exemption from the notification and remedy requirement of 49 U.S.C Chapter 301 on the basis that this noncompliance is inconsequential as it relates to motor vehicle safety, pursuant to 49 U.S.C. 30118(d) and 30120(h) and 49 CFR part 556, 
                    <E T="03">Exemption for Inconsequential Defect or Noncompliance.</E>
                </P>
                <P>
                    Notice of receipt of Gillig's petition was published with a 30-day public comment period, on September 20, 2019, in the 
                    <E T="04">Federal Register</E>
                     (84 FR 49624). No comments were received. To view the petition and all supporting documents log onto the Federal Docket Management System (FDMS) website at 
                    <E T="03">https://www.regulations.gov/.</E>
                     Then follow the online search instructions to locate docket number “NHTSA-2019-0042.”
                </P>
                <P>
                    <E T="03">II. Buses Involved:</E>
                     Approximately 925 MY 2013-2019 Gillig Low Floor buses, manufactured between December 23, 2013, and February 25, 2019, are potentially involved.
                </P>
                <P>
                    <E T="03">III. Noncompliance:</E>
                     Gillig explains that the noncompliance is that the subject buses are equipped with a starter interlock that allow starter operation while the transmission shift position is in a forward or reverse drive position and therefore, does not meet the requirements in paragraph S3.1.3 of FMVSS No. 102.
                </P>
                <P>
                    <E T="03">IV. Rule Requirements:</E>
                     Paragraph S3.1.3 of FMVSS No. 102 provides the requirements relevant to this petition. Except as provided in paragraphs S3.1.3.1 through S3.1.3.3, the engine starter shall be inoperative when the transmission shift position is in a forward or reverse drive position.
                </P>
                <P>
                    <E T="03">V. Summary of Gillig's Petition:</E>
                     The following views and arguments presented in this section, “V. Summary of Gillig's Petition,” are the views and arguments provided by Gillig and do not reflect the views of the Agency. Gillig described the subject noncompliance and contended that the noncompliance is inconsequential as it relates to motor vehicle safety.
                </P>
                <P>Gillig says that Allison Transmission Inc., (ATI) conducted an audit at Gillig's headquarters and discovered the noncompliance. In support of its petition, Gillig explains that “the potentially noncompliant condition occurs as follows: when the ignition switch is in the ON position, the engine is stopped, the shift selector is in the `Forward' or `Reverse' position, and the start button is depressed, the starter cranks the engine, but the transmission does not engage because, according to ATI, the shifter is in an inhibited state.” Gillig describes the inhibited state, “in a condition with ignition on/engine off, even if the transmission gear selector is moved to Drive or Reverse, the transmission shifter does not broadcast anything but Neutral to the transmission control unit”. Gillig says that “with the engine running, the vehicle operator must perform four separate actions in a specific sequence to engage the transmission and move the vehicle under power, specifically: (a) place foot on brake (b) select neutral (c) select a gear, and (d) remove foot from foot brake.” Gillig says that “because the transmission controller defaults the transmission to neutral after an engine start, there is no risk of unintentional vehicle movement” and therefore the subject noncompliance is inconsequential to motor vehicle safety.</P>
                <P>Gillig concluded that the subject noncompliance is inconsequential as it relates to motor vehicle safety and that its petition to be exempted from providing notification of the noncompliance, as required by 49 U.S.C. 30118, and a remedy for the noncompliance, as required by 49 U.S.C. 30120, should be granted.</P>
                <P>
                    <E T="03">VI. NHTSA's Analysis:</E>
                     The burden of establishing the inconsequentiality of a failure to comply with a 
                    <E T="03">performance requirement</E>
                     in an FMVSS—as opposed to a 
                    <E T="03">labeling requirement with no performance implications</E>
                    —is more substantial and difficult to meet. Accordingly, the Agency has not found many such noncompliances inconsequential.
                    <SU>1</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>1</SU>
                         
                        <E T="03">Cf. Gen. Motors Corporation: Ruling on Petition for Determination of Inconsequential Noncompliance,</E>
                         69 FR 19897, 19899 (Apr. 14, 2004) (citing prior cases where noncompliance was expected to be imperceptible, or nearly so, to vehicle occupants or approaching drivers).
                    </P>
                </FTNT>
                <P>
                    In determining inconsequentiality of a noncompliance, NHTSA focuses on the safety risk to individuals who experience the type of event against which a recall would otherwise protect.
                    <SU>2</SU>
                    <FTREF/>
                     In general, NHTSA does not consider the absence of complaints or injuries when determining if a noncompliance is inconsequential to safety. The absence of complaints does not mean vehicle occupants have not experienced a safety issue, nor does it mean that there will not be safety issues in the future.
                    <SU>3</SU>
                    <FTREF/>
                </P>
                <FTNT>
                    <P>
                        <SU>2</SU>
                         
                        <E T="03">See Gen. Motors, LLC; Grant of Petition for Decision of Inconsequential Noncompliance,</E>
                         78 FR 35355 (June 12, 2013) (finding noncompliance had no effect on occupant safety because it had no effect on the proper operation of the occupant classification system and the correct deployment of an air bag); 
                        <E T="03">Osram Sylvania Prods. Inc.; Grant of Petition for Decision of Inconsequential Noncompliance,</E>
                         78 FR 46000 (July 30, 2013) (finding occupant using noncompliant light source would not be exposed to significantly greater risk than occupant using similar compliant light source).
                    </P>
                </FTNT>
                <FTNT>
                    <P>
                        <SU>3</SU>
                         
                        <E T="03">See Morgan 3 Wheeler Limited; Denial of Petition for Decision of Inconsequential Noncompliance,</E>
                         81 FR 21663, 21666 (Apr. 12, 2016); 
                        <E T="03">see also United States</E>
                         v. 
                        <E T="03">Gen. Motors Corp.,</E>
                         565 F.2d 754, 759 (D.C. Cir. 1977) (finding defect poses an unreasonable risk when it “results in hazards as potentially dangerous as sudden engine fire, and where there is no dispute that at least some such hazards, in this case fires, can definitely be expected to occur in the future”).
                    </P>
                </FTNT>
                <P>
                    In evaluating the merits of the petition for inconsequentiality by Gillig, NHTSA has determined that this noncompliance is inconsequential to motor vehicle safety. Paragraph S3.1.3 of FMVSS No. 102 requires that the engine starter shall be inoperative while the transmission is in a forward or reverse position. In the subject vehicles, the starter is operational when a forward or reverse position is selected, which is noncompliant. Gillig contends that the subject vehicles are equipped with a shift controller interlock which is active when the propulsion system is on and prevents the vehicle from moving without the driver first performing a series of actions. The interlock prevents the forward or reverse gears from engaging until the transmission is first returned to its neutral position. Gillig also noted that the subject vehicles do not have a park position on the transmission selector which means the vehicles are likely to be started in either a forward or reverse gear. NHTSA agrees that subject Gillig vehicles shift interlock provides sufficient assurance of preventing unintended forward or rearward movement. More specifically, NHTSA agrees that because the transmission controller defaults the transmission to neutral after an engine start, there is no risk of unintentional vehicle movement. Consequently, the 
                    <PRTPAGE P="737"/>
                    interlock present here satisfies the intent of S3.1.3 of FMVSS No. 102, NHTSA finds that the noncompliance in the subject vehicles is inconsequential to safety.
                </P>
                <P>
                    <E T="03">VII. NHTSA's Decision:</E>
                     In consideration of the foregoing, NHTSA finds that Gillig has met its burden of persuasion that the subject FMVSS No. 102 noncompliance in the affected buses is inconsequential to motor vehicle safety. Accordingly, Gillig's petition is hereby granted and Gillig is consequently exempted from the obligation of providing notification of, and a free remedy for, that noncompliance under 49 U.S.C. 30118 and 30120.
                </P>
                <P>NHTSA notes that the statutory provisions (49 U.S.C. 30118(d) and 30120(h)) that permit manufacturers to file petitions for a determination of inconsequentiality allow NHTSA to exempt manufacturers only from the duties found in sections 30118 and 30120, respectively, to notify owners, purchasers, and dealers of a defect or noncompliance and to remedy the defect or noncompliance. Therefore, this decision only applies to the subject buses that Gillig no longer controlled at the time it determined that the noncompliance existed. However, the granting of this petition does not relieve vehicle distributors and dealers of the prohibitions on the sale, offer for sale, or introduction or delivery for introduction into interstate commerce of the noncompliant buses under their control after Gillig notified them that the subject noncompliance existed.</P>
                <EXTRACT>
                    <FP>(Authority: 49 U.S.C. 30118, 30120: delegations of authority at 49 CFR 1.95 and 501.8)</FP>
                </EXTRACT>
                <SIG>
                    <NAME>Otto G. Matheke III,</NAME>
                    <TITLE>Director, Office of Vehicle Safety Compliance.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31752 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4910-59-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF TRANSPORTATION</AGENCY>
                <DEPDOC>[DOT-OST-2024-0127]</DEPDOC>
                <SUBJECT>Solicitation for Annual Combating Human Trafficking in Transportation Impact Award</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Office of the Secretary of Transportation, U.S. Department of Transportation.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The annual Combating Human Trafficking in Transportation Impact Award (the award) is a component of the Department of Transportation's (DOT) Transportation Leaders Against Human Trafficking initiative that seeks to raise awareness among transportation stakeholders about human trafficking and increase training and prevention to combat the crime. The award serves as a platform for transportation stakeholders to creatively develop impactful and innovative counter-trafficking tools, initiatives, campaigns, and technologies that can be shared with the broader community to help stop human trafficking. The award is open to individuals and entities, including non-governmental organizations, transportation industry associations, research institutions, and State and local government organizations. Entrants compete for a cash award of up to $50,000 to be awarded to the individual(s) or entity selected for creating the most impactful counter-trafficking initiative or technology.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Submissions will be accepted from January 6, 2025 through 11:59 p.m. PST/2:59 a.m. EST on March 7, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        Additional information regarding the Department's counter-trafficking activities can be found at 
                        <E T="03">www.transportation.gov/stophumantrafficking.</E>
                    </P>
                    <P>
                        Additional information regarding the Department's counter-trafficking activities can be found at 
                        <E T="03">www.transportation.gov/stophumantrafficking.</E>
                         To register your intent to compete individually or as part of a team, visit 
                        <E T="03">www.transportation.gov/stophumantrafficking,</E>
                         email 
                        <E T="03">trafficking@dot.gov,</E>
                         or contact the Office of International Transportation and Trade at (202) 366-4398.
                    </P>
                </ADD>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P/>
                <P>
                    <E T="03">Award Approving Official:</E>
                     The Secretary of Transportation (Secretary).
                </P>
                <P>
                    <E T="03">Subject of Award Competition:</E>
                     The Combating Human Trafficking in Transportation Impact Award recognizes impactful, innovative, and shareable approaches to combating human trafficking in the transportation industry.
                </P>
                <HD SOURCE="HD1">Problem</HD>
                <P>As many as 27.6 million men, women, and children are held against their will and trafficked into forced labor and commercial sex. Transportation figures prominently in human trafficking enterprises when traffickers move victims, which uniquely positions the industry to combat the crime.</P>
                <HD SOURCE="HD1">Challenge</HD>
                <P>The Combating Human Trafficking in Transportation Impact Award is looking for the best innovators to develop original, impactful, unique, and shareable human trafficking tools, initiatives, campaigns, and technologies that can help stop these heinous crimes in the transportation industry.</P>
                <HD SOURCE="HD1">Eligibility</HD>
                <P>To be eligible to participate in the Combating Human Trafficking in Transportation Impact Award competition, private entities must be incorporated in and maintain a primary place of business in the United States, and individuals must be citizens or permanent residents of the United States. There is no charge to enter the competition.</P>
                <HD SOURCE="HD1">Rules, Terms, and Conditions</HD>
                <P>The following additional rules apply:</P>
                <P>1. Entrants shall submit a project to the competition under the rules promulgated by the Department in this Notice;</P>
                <P>2. Entrants must indemnify, defend, and hold harmless the Federal Government from and against all third-party claims, actions, or proceedings of any kind and from any and all damages, liabilities, costs, and expenses relating to or arising from participant's submission or any breach or alleged breach of any of the representations, warranties, and covenants of participant hereunder. Entrants are financially responsible for claims made by a third party;</P>
                <P>3. Entrants may not be a Federal entity, Federal employee acting within the scope of their employment, or a family member of a Federal Employee;</P>
                <P>4. Entrants may not be an employee or family member of an employee of the U.S. Department of Transportation;</P>
                <P>5. Entrants shall not be deemed ineligible because an individual used Federal facilities or consulted with Federal employees during a competition if the facilities and employees are made available to all individuals participating in the competition on an equitable basis;</P>
                <P>6. The entries cannot have been submitted in the same or substantially similar form in any other previous Federally sponsored promotion or Federally sponsored competition;</P>
                <P>7. Entrants previously awarded first place are not eligible to reenter for the same or substantially similar project;</P>
                <P>8. Entries which, in the Department's sole discretion, are determined to be substantially similar to another entity's entry submitted to this competition may be disqualified;</P>
                <P>
                    9. The competition is subject to all applicable Federal laws and regulations. Participation constitutes the entrants' full and unconditional agreement to these rules and to the Secretary's decisions, which are final and binding 
                    <PRTPAGE P="738"/>
                    in all matters related to this competition;
                </P>
                <P>10. Entries must be original, be the work of the entrant and/or nominee and must not violate the rights of other parties. All entries remain the property of the entrant. Each entrant represents and warrants that:</P>
                <P>• Entrant is the sole author and owner of the submission;</P>
                <P>• The entry is not the subject of any actual or threatened litigation or claim;</P>
                <P>• The entry does not and will not violate or infringe upon the intellectual property rights, privacy rights, publicity rights, or other legal rights of any third party; and</P>
                <P>• The entry does not and will not contain any harmful computer code (sometimes referred to as “malware,” “viruses,” or, “worms”).</P>
                <P>11. By submitting an entry in this competition, entrants agree to assume any and all risks and waive any claims against the Federal Government and its related entities (except in the case of willful misconduct) for any injury, death, damage, or loss of property, revenue or profits, whether direct, indirect, or consequential, arising from their participation in this competition, whether the injury, death, damage, or loss arises through negligence of otherwise. Provided, however, that by registering or submitting an entry, entrants and/or nominees do not waive claims against the Department arising out of the unauthorized use or disclosure by the agency of the intellectual property, trade secrets, or confidential information of the entrant;</P>
                <P>12. The Secretary or the Secretary's designees have the right to request additional supporting documentation regarding the application from the entrants and/or nominees;</P>
                <P>13. Each entrant grants to the Department, as well as other Federal agencies with which it partners, the right to use names, likeness, application materials, photographs, voices, opinions, and hometown and state for the Department's promotional purposes in any media, in perpetuity, worldwide, without further payment or consideration;</P>
                <P>14. If selected, the entrant and/or nominee must provide written consent granting the Department and any parties acting on their behalf, a royalty-free, non-exclusive, irrevocable, worldwide license to display publicly and use for promotional purposes the entry (“demonstration license”). This demonstration license includes posting or linking to the entry on Department websites, including the Competition website, and partner websites, and inclusion of the entry in any other media, worldwide;</P>
                <P>15. Applicants that are Federal grant recipients may not use Federal funds to develop submissions or to fund efforts in support of a submission;</P>
                <P>16. Federal contractors may not use Federal funds from a contract to develop submissions or to fund efforts in support of a submission; and</P>
                <P>17. The submission period begins on January 6, 2025. Submissions must be sent by 11:59 p.m. PST/2:59 a.m. EST on March 7, 2025. The timeliness of submissions will be determined by the time stamp of the Microsoft Form submission. Competition administrators assume no responsibility for lost or untimely submissions for any reason.</P>
                <HD SOURCE="HD1">Submission Requirements</HD>
                <P>
                    Applicants must submit entries using the following Microsoft Forms link: 
                    <E T="03">https://forms.office.com/g/XVPzafGs5G.</E>
                     Please contact 
                    <E T="03">trafficking@dot.gov</E>
                     for any submission issues via Microsoft Forms.
                </P>
                <P>
                    <E T="03">Expression of Interest:</E>
                     While not required, entrants are strongly encouraged to send brief expressions of interest to DOT prior to submitting entries. The expressions of interest should be sent by February 5, 2025 to 
                    <E T="03">trafficking@dot.gov,</E>
                     and include the following elements: (1) Name and title of entrant(s); (2) Telephone and email address; and (3) A synopsis of the concept, limited to no more than two pages.
                </P>
                <P>Please ensure your submission package includes EACH of the following twelve elements:</P>
                <HD SOURCE="HD2">1. Mode(s)</HD>
                <P>Specify which transportation mode(s) the proposal will focus on.</P>
                <HD SOURCE="HD2">2. Title</HD>
                <P>The proposal title.</P>
                <HD SOURCE="HD2">3. Entity</HD>
                <P>The name of the organization(s) being nominated, or the name(s) and title(s) of the individual(s) being nominated.</P>
                <HD SOURCE="HD2">4. Submitted By</HD>
                <P>Include name, title, phone, email, website URL, and mailing address.</P>
                <P>If the point of contact for the proposal is different, also specify their name, title, phone, and email.</P>
                <HD SOURCE="HD2">5. Background</HD>
                <P>Brief background regarding the submitting individual(s) or organization(s) that includes relevant counter-trafficking expertise.</P>
                <HD SOURCE="HD2">6. Partners</HD>
                <P>If applicable, list the partners who will be engaged in proposal development and/or implementation, including a brief background for each.</P>
                <HD SOURCE="HD2">7. Letters of Support</HD>
                <P>You may submit supporting letters, which may be from subject matter experts or industry, and may address the technical merit of the concept, originality, impact, practicality, measurability and/or applicability. Proposals with letters of support should include an itemized list with the name, title, and organization for each letter.</P>
                <HD SOURCE="HD2">
                    8. Proposal Description 
                    <E T="03">(1 Sentence)</E>
                </HD>
                <P>
                    A high-level description of the proposal including 
                    <E T="03">all</E>
                     deliverable(s).
                </P>
                <HD SOURCE="HD2">
                    9. Proposal Summary 
                    <E T="03">(1 Paragraph)</E>
                </HD>
                <P>A detailed synopsis of the proposal, including how efficacy will be measured and its anticipated impact.</P>
                <HD SOURCE="HD2">
                    10. Proposal Overview and Impact/Measurability 
                    <E T="03">(1-2 Pages)</E>
                </HD>
                <P>
                    A proposal description that presents a logical approach and workable solution to addressing the issue of human trafficking in the transportation industry. Include responses to the following questions: Is the concept unique? Are anticipated beneficiaries clearly identified? Were human trafficking survivors consulted in the proposal development and/or how will survivor input be included in implementation? Are anticipated resources and costs outlined in detail? Can the proposal be implemented in a way requiring a finite amount of resources (
                    <E T="03">e.g.,</E>
                     fixed costs, low or no marginal costs, and a clear path to implementation and scale beyond an initial investment)? For impact and measurability, include a description of how the proposal will be evaluated, and its potential impact on human trafficking in the transportation industry. 
                    <E T="03">Include responses to the following questions:</E>
                     How will the proposal's impact be measured? How will the proposal contribute to counter-trafficking efforts in the transportation sector? If not a national proposal, can the proposal be scaled nationally?
                </P>
                <HD SOURCE="HD2">
                    11. Supporting Documents 
                    <E T="03">(No Page Limit)</E>
                </HD>
                <P>
                    The paper(s) and/or technologies, programs, video/audio files, and other related materials, describing the proposal and addressing the selection criteria. As applicable, this can include a description of success of a previous or similar proposal and/or documentation of impact. DOT may request additional 
                    <PRTPAGE P="739"/>
                    information, including supporting documentation, more detailed contact information, releases of liability, and statements of authenticity to guarantee the originality of the work. Failure to respond in a timely manner may result in disqualification.
                </P>
                <HD SOURCE="HD2">12. Eligibility Statement</HD>
                <P>A statement of eligibility by private entities indicating that they are incorporated in and maintain a primary place of business in the United States, or a statement of eligibility by individuals indicating that they are citizens or permanent residents of the United States.</P>
                <HD SOURCE="HD1">Initial Screening</HD>
                <P>The Office of International Transportation and Trade (OITT) will initially review applications to determine that all required submission elements are included, and to determine compliance with eligibility requirements.</P>
                <HD SOURCE="HD1">Evaluation</HD>
                <P>After the Initial Screening, OITT, with input from the relevant Operating Administrations, will judge entries based on the factors described below: technical merit, originality, impact, practicality, measurability, and applicability. The Secretary will make the final selection. The Department reserves the right to not award the prize if the selecting officials believe that no submission demonstrates sufficient potential for sufficient transformative impact. The following factors will be given consideration:</P>
                <HD SOURCE="HD1">Technical Merit</HD>
                <P>• Does the proposal present a clear understanding of the issue of human trafficking in the transportation industry and utilizes a trauma-informed, victim-centered approach?</P>
                <P>• Does the proposal present a logical and workable solution and approach to addressing human trafficking in the transportation industry?</P>
                <P>• Were survivors of human trafficking consulted in the development of the proposal concept and is survivor input outlined in the description of proposal implementation?</P>
                <HD SOURCE="HD1">Originality</HD>
                <P>• Is the concept new or a variation of an existing idea?</P>
                <P>• Does the concept possess and clearly describe its unique merits?</P>
                <HD SOURCE="HD1">Impact/Measurability</HD>
                <P>• Can the proposal make a significant impact and/or contribution to the fight against human trafficking in the transportation industry?</P>
                <P>• Does the proposal clearly describe the breadth of impact?</P>
                <P>• Does the submission clearly outline how the proposal will be measured?</P>
                <P>• Will the proposal result in measurable improvements?</P>
                <HD SOURCE="HD1">Practicality</HD>
                <P>• Does the proposal clearly identify anticipated beneficiaries of the proposal?</P>
                <P>• Does the proposal clearly outline anticipated resources and all costs to be incurred by executing the concept?</P>
                <P>• Can the proposal be implemented in a way that requires a finite amount of resources (specifically, the submission has fixed costs, low or no marginal costs, and a clear path to implementation and scale beyond an initial investment)?</P>
                <HD SOURCE="HD1">Applicability</HD>
                <P>• Is the proposal national or can it be scaled nationally?</P>
                <HD SOURCE="HD1">Award</HD>
                <P>Up to three winning entries are expected to be announced. The first-place winner will receive up to a $50,000 cash prize. A plaque with the first-place winner(s) name and the date of the award will be on display at the U.S. Department of Transportation, and a display copy of the plaque(s) will be sent to the first-place award winner. Two additional plaques will be awarded to recognize the two runners up. At the Department's discretion, DOT may pay for invitational travel expenses to Washington, DC, for up to two individuals or representatives of the first-place winner and runners up, should selectees be invited to present their proposal(s) for DOT officials.</P>
                <P>
                    <E T="03">Authority:</E>
                     15 U.S.C. 3719 (America COMPETES Act).
                </P>
                <SIG>
                    <DATED>Issued in Washington, DC, on December 30, 2024.</DATED>
                    <NAME>Carol A. Petsonk,</NAME>
                    <TITLE>Assistant Secretary for Aviation and International Affairs.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31630 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4910-9X-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF THE TREASURY</AGENCY>
                <SUBAGY>Office of Foreign Assets Control</SUBAGY>
                <SUBJECT>Notice of OFAC Sanctions Action</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Office of Foreign Assets Control, Treasury.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) is publishing the names of one or more persons that have been placed on OFAC's Specially Designated Nationals and Blocked Persons List (SDN List) based on OFAC's determination that one or more applicable legal criteria were satisfied. All property and interests in property subject to U.S. jurisdiction of these persons are blocked, and U.S. persons are generally prohibited from engaging in transactions with them.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>
                        This action was issued on December 31, 2024. See 
                        <E T="02">SUPPLEMENTARY INFORMATION</E>
                         for relevant dates.
                    </P>
                </DATES>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>
                        OFAC: Associate Director for Global Targeting, 202-622-2420; Assistant Director for Sanctions Compliance, 202-622-2490 or 
                        <E T="03">https://ofac.treasury.gov/contact-ofac.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P/>
                <HD SOURCE="HD1">Electronic Availability</HD>
                <P>
                    The SDN List and additional information concerning OFAC sanctions programs are available on OFAC's website: 
                    <E T="03">https://ofac.treasury.gov.</E>
                </P>
                <HD SOURCE="HD1">Notice of OFAC Action</HD>
                <P>On December 31, 2024, OFAC determined that the property and interests in property subject to U.S. jurisdiction of the following persons are blocked under the relevant sanctions authorities listed below.</P>
                <BILCOD>BILLING CODE 4810-AL-P</BILCOD>
                <GPH SPAN="3" DEEP="576">
                    <PRTPAGE P="740"/>
                    <GID>EN06JA25.006</GID>
                </GPH>
                <GPH SPAN="3" DEEP="506">
                    <PRTPAGE P="741"/>
                    <GID>EN06JA25.007</GID>
                </GPH>
                <SIG>
                    <NAME>Lawrence M. Scheinert,</NAME>
                    <TITLE>Acting Deputy Director, Office of Foreign Assets Control.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31655 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 4810-AL-C</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="N">DEPARTMENT OF VETERANS AFFAIRS</AGENCY>
                <DEPDOC>[OMB Control No. 2900-0613]</DEPDOC>
                <SUBJECT>Agency Information Collection Activity: Recordkeeping at Flight Schools</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Veterans Benefits Administration, Department of Veterans Affairs.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>
                        Veterans Benefits Administration, Department of Veterans Affairs (VA), is announcing an opportunity for public comment on the proposed collection of certain information by the agency. Under the Paperwork Reduction Act (PRA) of 1995, Federal agencies are required to publish notice in the 
                        <E T="04">Federal Register</E>
                         concerning each proposed collection of information, including each proposed revision of a currently approved collection, and allow 60 days for public comment in response to the notice.
                    </P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Comments must be received on or before March 7, 2025.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        Comments must be submitted through 
                        <E T="03">www.regulations.gov.</E>
                    </P>
                </ADD>
                <FURINF>
                    <PRTPAGE P="742"/>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P/>
                    <P>
                        <E T="03">Program-Specific information:</E>
                         Nancy Kessinger, 202-632-8924, 
                        <E T="03">nancy.kessinger@va.gov.</E>
                    </P>
                    <P>
                        <E T="03">VA PRA information:</E>
                         Maribel Aponte, 202-461-8900, 
                        <E T="03">vacopaperworkreduact@va.gov.</E>
                    </P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>Under the PRA of 1995, Federal agencies must obtain approval from the Office of Management and Budget (OMB) for each collection of information they conduct or sponsor. This request for comment is being made pursuant to section 3506(c)(2)(A) of the PRA.</P>
                <P>With respect to the following collection of information, VBA invites comments on: (1) whether the proposed collection of information is necessary for the proper performance of VBA's functions, including whether the information will have practical utility; (2) the accuracy of VBA's estimate of the burden of the proposed collection of information; (3) ways to enhance the quality, utility, and clarity of the information to be collected; and (4) ways to minimize the burden of the collection of information on respondents, including through the use of automated collection techniques or the use of other forms of information technology.</P>
                <P>
                    <E T="03">Title:</E>
                     Recordkeeping at Flight Schools.
                </P>
                <P>
                    <E T="03">OMB Control Number:</E>
                     2900-0613. 
                    <E T="03">https://www.reginfo.gov/public/do/PRASearch</E>
                     (Once at this link, you can enter the OMB Control Number to find the historical versions of this Information Collection).
                </P>
                <P>
                    <E T="03">Type of Review:</E>
                     Revision of a currently approved collection.
                </P>
                <P>
                    <E T="03">Abstract:</E>
                     The State Approving Agencies that approve courses for VA training use these records to determine if courses offered by flight schools should be approved. VA representatives use the records to determine the accuracy of payments made to VA students at flight schools. Regulation do not require any reports, but it does only require the recordkeeping. Flight schools have the option to store these records electronically.
                </P>
                <P>
                    <E T="03">Affected Public:</E>
                     Businesses or other for Profit or Not for Profit Schools.
                </P>
                <P>
                    <E T="03">Estimated Annual Burden:</E>
                     1,316 hours.
                </P>
                <P>
                    <E T="03">Estimated Average Burden per Respondent:</E>
                     20 minutes.
                </P>
                <P>
                    <E T="03">Frequency of Response:</E>
                     Annual.
                </P>
                <P>
                    <E T="03">Estimated Number of Respondents:</E>
                     3,949.
                </P>
                <P>
                    <E T="03">Authority:</E>
                     44 U.S.C. 3501 
                    <E T="03">et seq.</E>
                </P>
                <SIG>
                    <NAME>Dorothy Glasgow,</NAME>
                    <TITLE>VA PRA Clearance Officer (Alt.), Office of Enterprise and Integration/Data Governance Analytics, Department of Veterans Affairs.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31628 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8320-01-P</BILCOD>
        </NOTICE>
        <NOTICE>
            <PREAMB>
                <AGENCY TYPE="S">DEPARTMENT OF VETERANS AFFAIRS</AGENCY>
                <SUBJECT>Solicitation of Nominations for Appointment to the Advisory Committee on Former Prisoners of War</SUBJECT>
                <AGY>
                    <HD SOURCE="HED">AGENCY:</HD>
                    <P>Department of Veterans Affairs.</P>
                </AGY>
                <ACT>
                    <HD SOURCE="HED">ACTION:</HD>
                    <P>Notice of solicitation for nominations.</P>
                </ACT>
                <SUM>
                    <HD SOURCE="HED">SUMMARY:</HD>
                    <P>The Department of Veterans Affairs (VA), Advisory Committee on Former Prisoners of War (the Committee or FPOW), is seeking nominations of qualified candidates to be considered for appointment as a member of the Committee.</P>
                </SUM>
                <DATES>
                    <HD SOURCE="HED">DATES:</HD>
                    <P>Nominations for membership on the Committee must be received no later than 5 p.m. EST on February 28, 2025. Packages received after this time will not be considered for the current membership cycle.</P>
                </DATES>
                <ADD>
                    <HD SOURCE="HED">ADDRESSES:</HD>
                    <P>
                        All nominations should be mailed to Outreach, Transition and Economic Development (OTED), Veterans Benefits Administration (VBA), Department of Veterans Affairs, 1800 G St., NW, Washington, DC 20006 or emailed to 
                        <E T="03">julian.wright2@va.gov.</E>
                         Please write Nomination for FPOW Membership in the subject line.
                    </P>
                </ADD>
                <FURINF>
                    <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                    <P>Julian Wright, Designated Federal Officer (DFO), OTED, Department of Veterans Affairs, 1800 G St., NW Washington, DC 20006, or telephone (202) 302-8629.</P>
                </FURINF>
            </PREAMB>
            <SUPLINF>
                <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                <P>In carrying out the duties set forth, the activities of the Committee include, but are not limited to:</P>
                <P>(1) Advising the Secretary on how VA can assist and represent FPOWs', including recommendations regarding expanding services and benefits to FPOWs' and related policy. Administrative, legislative and/or regulatory actions;</P>
                <P>(2) Advising the Secretary on incorporating lessons learned from current, and previous, successful family research and outreach efforts that measure the impact of provided care and benefits services on FPOWs;</P>
                <P>(3) Advising the Secretary on collaborating with family support programs within VA and engaging with other VA and non-VA advisory committees focused on specific demographics of FPOWs;</P>
                <P>(4) Advising the Secretary on working with interagency, intergovernmental, private/non-profit, community, and Veteran service organizations to identify and address gaps in services for FPOWs;</P>
                <P>(5) Providing such reports as the Committee deems necessary, but not less than one report per year, to the Secretary, through the DFO/VBA to describe the Committee's activities, deliberations, and findings, which may include but are not limited to: 1) identification of current challenges and recommendations for remediation related to access to care and benefits services of FPOWs; and 2) identification of current best practices in care and benefits delivery to FPOWs, and the impact of such best practices.</P>
                <P>
                    <E T="03">Authority:</E>
                     The Committee is authorized by statute, 38 U.S.C. 541 and operates in accordance with the provisions of the Federal Advisory Committee Act, as amended, 5 U.S.C. ch. 10. The Committee advises the Secretary on the following:
                </P>
                <P>(1) The administration of benefits for Veterans who are FPOWs, in the areas of compensation, health care, and rehabilitation.</P>
                <P>(2) The use of VA care and benefits services by FPOWs, and possible adjustments to such care and benefits services;</P>
                <P>(3) Factors that influence access to, quality of, and accountability for services and benefits for FPOWs.</P>
                <P>
                    <E T="03">Membership Criteria and Qualifications:</E>
                </P>
                <P>VA is seeking nominations for Committee membership. The Committee is composed of up to 12 members and several ex-officio members. The members of the Committee are appointed by the Secretary of Veteran Affairs from the general public, from various sectors and organizations, including but not limited to:</P>
                <P>(1) Veterans who are FPOWs</P>
                <P>(2) Appropriate representatives of Veterans who are FPOWs</P>
                <P>(3) Individuals who are recognized authorities in fields of pertinent to disabilities prevalent among FPOW, including authorities in epidemiology, mental health, nutrition, geriatrics, and internal medicine; and</P>
                <P>(4) Appropriate representatives of disabled Veterans.</P>
                <P>
                    In accordance with the Committee Charter, the Secretary shall determine the number, terms of service, and pay and allowances of Committee members. The term of service for any member may not exceed three years. The Secretary may reappoint any Committee member 
                    <PRTPAGE P="743"/>
                    for additional terms of service. To the extent possible, the Secretary seeks members who have diverse professional and personal qualifications including but not limited to subject matter experts in the areas described above. We ask that nominations include any relevant experience information so that VA can ensure diverse Committee membership.
                </P>
                <P>
                    <E T="03">Requirements for Nomination Submission:</E>
                     Nominations should be typed (one nomination per nominator). Nomination package should include:
                </P>
                <P>
                    (1) A letter of nomination that clearly states the name and affiliation of the nominee, the basis for the nomination (
                    <E T="03">i.e.</E>
                     specific attributes which qualify the nominee for service in this capacity), and a statement from the nominee indicating the willingness to serve as a member of the Committee;
                </P>
                <P>(2) The nominee's contact information, including name, mailing address, telephone numbers and email address;</P>
                <P>(3) The nominee's resume or curriculum vitae; and</P>
                <P>(4) A summary of the nominee's experience and qualifications relative to the membership considerations described above.</P>
                <P>Individuals selected for appointment to the Committee shall be invited to serve a two-year term. Committee members will receive a stipend for attending Committee meetings, including per diem and reimbursement for eligible travel expenses incurred.</P>
                <P>The Department makes every effort to ensure that the membership of its Federal advisory committees is fairly-balanced in terms of points of view represented. Every effort is made to ensure that a broad representation of geographic areas, gender, and racial and ethnic minority groups, and that the disabled are given consideration for membership. Appointments to this Committee shall be made without discrimination because of a person's race, color, religion, sex (including gender identity, transgender status, sexual orientation, and pregnancy), national origin, age, disability, or genetic information. Nominations must state that the nominee is willing to serve as a member of the Committee and appears to have no conflict of interest that would preclude membership. An ethics review is conducted for each selected nominee.</P>
                <SIG>
                    <DATED>Dated: December 31, 2024.</DATED>
                    <NAME>Jelessa M. Burney,</NAME>
                    <TITLE>Federal Advisory Committee Management Officer.</TITLE>
                </SIG>
            </SUPLINF>
            <FRDOC>[FR Doc. 2024-31625 Filed 1-3-25; 8:45 am]</FRDOC>
            <BILCOD>BILLING CODE 8320-01-P</BILCOD>
        </NOTICE>
    </NOTICES>
    <VOL>90</VOL>
    <NO>3</NO>
    <DATE>Monday, January 6, 2025</DATE>
    <UNITNAME>Presidential Documents</UNITNAME>
    <PRESDOCS>
        <PRESDOCU>
            <PROCLA>
                <TITLE3>Title 3—</TITLE3>
                <PRES>
                    The President
                    <PRTPAGE P="529"/>
                </PRES>
                <PROC>Proclamation 10877 of December 30, 2024</PROC>
                <HD SOURCE="HED">National Human Trafficking Prevention Month, 2025</HD>
                <PRES>By the President of the United States of America</PRES>
                <PROC>A Proclamation</PROC>
                <FP>Across the world, more than 27 million people, including thousands here at home, are subjected to the shameful, abhorrent abuse of human trafficking and forced labor. Human trafficking targets the most vulnerable in society and exploits them—denying their human rights, freedom, and dignity. It is a stain on our collective conscience and an affront to basic human dignity. During National Human Trafficking Prevention Month, we recommit to working to end human trafficking in America and around the globe.</FP>
                <FP>Any form of trafficking in people—from forced labor to sex trafficking—must not be tolerated, in the United States or anywhere around the world. That is why in 2021, I signed an updated National Action Plan (NAP) to Combat Human Trafficking, detailing my Administration's focus on prosecuting perpetrators, protecting survivors, and partnering with governments and organizations around the globe to end this scourge. The NAP also recognizes that human traffickers target people considered vulnerable in society—people from racial and ethnic minorities, women and girls, LGBTQI+ individuals, and others from marginalized backgrounds.</FP>
                <FP>Here at home, we have worked to crack down on human trafficking and combat gender-based violence in America. I remain proud that I first wrote the Violence Against Women Act as a United States Senator and I have worked to strengthen it ever since. That is why when I reauthorized it in 2022, I expanded Tribal court jurisdiction to prosecute non-Native sex traffickers. Furthermore, through my American Rescue Plan, my Administration delivered tens of thousands of housing vouchers to ensure people fleeing human trafficking or other violence have a safe home to go to. At the same time, we have been committed to working with survivors to support their path to recovery and healing, and improving our approach to preventing, identifying, and prosecuting these crimes. We have also taken steps to prevent trafficking in the United States by strengthening protections for vulnerable workers, including issuing new rules to improve worker protections and strengthen program integrity in temporary visa programs and releasing an updated version of the Department of State's Wilberforce “Know Your Rights” pamphlet.</FP>
                <FP>Around the world, we are also working with governments and organizations to put a stop to human trafficking. I signed the bipartisan Uyghur Forced Labor Prevention Act in 2021 and, from the moment the law took effect in 2022, Federal agencies have been working to ensure that no American imports are produced using forced labor. I signed the first-ever Presidential Memorandum to prioritize strong labor standards in our Nation's foreign policy as we work to build a world where our economic system gives predatory traffickers no safe harbor. In the 2024 Trafficking in Persons Report, the Department of State measured progress in 188 countries, including the United States, by deploying powerful technology tools to combat this scourge, and sanctioned over 240 individuals and entities for serious human rights abuses under the Global Magnitsky Sanctions Program.</FP>
                <FP>
                    During National Human Trafficking Prevention Month, I encourage Americans to learn the signs of human trafficking and share the National Human 
                    <PRTPAGE P="530"/>
                    Trafficking Hotline (888-373-7888), where one can report a tip or ask for help. Together, we can create a world where every person is treated with dignity and respect, lives free from fear, and can lead a life full of freedom and liberty.
                </FP>
                <FP>NOW, THEREFORE, I, JOSEPH R. BIDEN JR., President of the United States of America, by virtue of the authority vested in me by the Constitution and the laws of the United States, do hereby proclaim January 2025 as National Human Trafficking Prevention Month. I call upon businesses, civil society organizations, communities of faith, families, and all Americans to recognize the vital role we play in combating human trafficking and to observe this month with appropriate programs and activities aimed at preventing all forms of human trafficking.</FP>
                <FP>IN WITNESS WHEREOF, I have hereunto set my hand this thirtieth day of December, in the year of our Lord two thousand twenty-four, and of the Independence of the United States of America the two hundred and forty-ninth.</FP>
                <GPH SPAN="1" DEEP="80" HTYPE="RIGHT">
                    <GID>BIDEN.EPS</GID>
                </GPH>
                <PSIG> </PSIG>
                <FRDOC>[FR Doc. 2025-00078 </FRDOC>
                <FILED>Filed 1-3-25; 8:45 am]</FILED>
                <BILCOD>Billing code 3395-F4-P</BILCOD>
            </PROCLA>
        </PRESDOCU>
    </PRESDOCS>
    <VOL>90</VOL>
    <NO>3</NO>
    <DATE>Monday, January 6, 2025</DATE>
    <UNITNAME>Rules and Regulations</UNITNAME>
    <NEWPART>
        <PTITLE>
            <PRTPAGE P="745"/>
            <PARTNO>Part II</PARTNO>
            <AGENCY TYPE="P">Department of Housing and Urban Development</AGENCY>
            <CFR>24 CFR Parts 91, 92, 570, et al.</CFR>
            <TITLE>HOME Investment Partnerships Program: Program Updates and Streamlining; Final Rule</TITLE>
        </PTITLE>
        <RULES>
            <RULE>
                <PREAMB>
                    <PRTPAGE P="746"/>
                    <AGENCY TYPE="S">DEPARTMENT OF HOUSING AND URBAN DEVELOPMENT</AGENCY>
                    <CFR>24 CFR Parts 91, 92, 570, and 982</CFR>
                    <DEPDOC>[Docket No. FR-6144-F-03]</DEPDOC>
                    <RIN>RIN 2506-AC50</RIN>
                    <SUBJECT>HOME Investment Partnerships Program: Program Updates and Streamlining</SUBJECT>
                    <AGY>
                        <HD SOURCE="HED">AGENCY:</HD>
                        <P>Office of the Assistant Secretary for Community Planning and Development, Department of Housing and Urban Development, HUD.</P>
                    </AGY>
                    <ACT>
                        <HD SOURCE="HED">ACTION:</HD>
                        <P>Final rule.</P>
                    </ACT>
                    <SUM>
                        <HD SOURCE="HED">SUMMARY:</HD>
                        <P>HUD's HOME Investment Partnerships Program (HOME program or HOME) provides formula grants to States and units of general local government to fund a wide range of activities to produce and maintain affordable rental and homeownership housing and provides tenant-based rental assistance for low-income and very low-income households. This final rule revises the current HOME regulations to update, simplify, or streamline requirements, better align the program with other Federal housing programs, and implement recent amendments to the HOME statute. This final rule also includes minor revisions to the regulations for the Community Development Block Grant and Section 8 Housing Choice Voucher Programs consistent with the implementation of the changes to the HOME program. This final rule follows the publication of a proposed rule on May 29, 2024, and takes into consideration the comments received in response to that proposed rule.</P>
                    </SUM>
                    <DATES>
                        <HD SOURCE="HED">DATES:</HD>
                        <P>Effective February 5, 2025.</P>
                    </DATES>
                    <FURINF>
                        <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                        <P>
                            Virginia Sardone, Director, Office of Affordable Housing Programs, Office of Community Planning and Development, Department of Housing and Urban Development, 451 7th Street SW, Room 7160, Washington, DC 20410; telephone number (202) 708-2684 (this is not a toll-free number). HUD welcomes and is prepared to receive calls from individuals who are deaf or hard of hearing, as well as individuals with speech or communication disabilities. To learn more about how to make an accessible telephone call, please visit 
                            <E T="03">https://www.fcc.gov/consumers/guides/telecommunications-relay-service-trs.</E>
                        </P>
                    </FURINF>
                </PREAMB>
                <SUPLINF>
                    <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                    <P/>
                    <HD SOURCE="HD1">I. Background</HD>
                    <P>
                        The HOME program is authorized by title II of the Cranston-Gonzalez National Affordable Housing Act 
                        <SU>1</SU>
                        <FTREF/>
                         (“NAHA” or the “Act”) and has been in operation since 1992. The HOME program provides grants to States, local jurisdictions, and consortia of local jurisdictions (collectively, participating jurisdictions or PJs) and is used, often in partnership with local nonprofit groups, to fund a wide range of activities to build, buy, or rehabilitate affordable housing for rent or homeownership or to fund direct rental assistance to low-income people.
                        <SU>2</SU>
                        <FTREF/>
                         HOME program funds are awarded annually as formula grants to PJs. After the Department obligates funds to a PJ, the Department establishes a HOME Investment Trust Fund 
                        <SU>3</SU>
                        <FTREF/>
                         for each PJ, providing a line of credit that a PJ may draw upon as needed.
                    </P>
                    <FTNT>
                        <P>
                            <SU>1</SU>
                             42 U.S.C. 12721 
                            <E T="03">et seq.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>2</SU>
                             See HUD's HOME Investment Partnerships Program web page at 
                            <E T="03">https://www.hud.gov/program_offices/comm_planning/home.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>3</SU>
                             HUD's regulations for the HOME Investment Trust Fund can be found at 24 CFR 92.500.
                        </P>
                    </FTNT>
                    <P>
                        The HOME program is the largest Federal block grant to States and local governments designed exclusively to create affordable housing for low-income households. Each year, the HOME program allocates approximately $1.5 billion among States and approximately 600 localities nationwide. In fiscal year 2023, PJs completed 6,848 rental housing units and 4,051 homebuyer units, assisted 2,717 low-income homeowners to repair their homes, and provided tenant-based rental assistance to 13,016 low-income households. HOME funds are most often used as gap financing for rental projects, particularly for projects that have been awarded Low-Income Housing Credits (LIHTC).
                        <SU>4</SU>
                        <FTREF/>
                         As of late 2024, there are 237,767 HOME-assisted rental units operating in their periods of affordability (
                        <E T="03">i.e.,</E>
                         subject to ongoing HOME income and rent requirements).
                    </P>
                    <FTNT>
                        <P>
                            <SU>4</SU>
                             See 26 U.S.C. 42.
                        </P>
                    </FTNT>
                    <P>The HOME program is designed to reinforce several important values and principles of community development. First, the HOME program's flexibility empowers people and communities to design and implement strategies tailored to their own needs and priorities. Second, the HOME program's emphasis on consolidated planning expands and strengthens partnerships among all levels of government and the relationship with the private sector in the development of affordable housing. Third, the HOME program's technical assistance activities and set-aside for qualified Community Housing Development Organizations (CHDOs) help to build the capacity of, and partnerships, with these community-based nonprofit organizations. Fourth, the HOME program's requirement that PJs match 25 cents of every dollar in program funds helps mobilize community resources in support of affordable housing.</P>
                    <HD SOURCE="HD1">II. The Proposed Rule</HD>
                    <P>
                        On May 29, 2024, HUD published the “HOME Investment Partnerships Program: Program Updates and Streamlining” proposed rule (the proposed rule) in the 
                        <E T="04">Federal Register</E>
                        , available at 89 FR 46618. In the proposed rule, HUD proposed numerous changes to 24 CFR part 92. The proposed changes included significant revisions to the CHDO requirements, a change in the approach to HOME rents, simplified requirements for small-scale rental projects, enhanced flexibility in HOME tenant-based rental assistance (TBRA) programs, and simplified provisions and new flexibilities for community land trusts (CLTs). The proposed rule also proposed to significantly strengthen and expand tenant protections by requiring that a HOME tenancy addendum with a set of uniform tenant protections be appended to the leases of all tenants of HOME-assisted rental housing units. HUD also proposed requiring that a HOME tenancy addendum with a streamlined set of uniform tenant protections be appended to the leases of all tenants receiving TBRA. Additionally, HUD proposed to create incentives for meeting a more advanced property standard that incorporates green building standards, higher levels of energy efficiency, and innovative building techniques in new construction, reconstruction, and rehabilitation of housing. The proposed rule also sought to clarify the resale requirements for homeownership housing and proposed technical amendments and simplifications to conform provisions to certain changes made in the 2013 HOME Final Rule.
                        <SU>5</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>5</SU>
                             HOME Investment Partnerships Program: Improving Performance and Accountability; Updating Property Standards, (78 FR 44628, July 24, 2013).
                        </P>
                    </FTNT>
                    <P>
                        The proposed rule also included changes made by the Housing Opportunity Through Modernization Act of 2016: Implementation of Sections 102, 103, and 104 final rule, published in the 
                        <E T="04">Federal Register</E>
                         on February 14, 2023 (88 FR 9600) (the HOTMA Final Rule) and the Economic Growth Regulatory Relief and Consumer Protection Act: Implementation of National Standards for the Physical Inspection of Real Estate (NSPIRE) final rule, published in the 
                        <E T="04">Federal Register</E>
                          
                        <PRTPAGE P="747"/>
                        on May 11, 2023 (88 FR 30442) (the NSPIRE Final Rule). The proposed rule also proposed further revisions to the changes made to 24 CFR part 92 by the HOTMA and NSPIRE Final Rules. In addition, the proposed rule proposed updates to citations, in paragraphs where other changes are being made, to conform with recent changes to the Office of Management and Budget (OMB) regulations at 2 CFR part 200.
                    </P>
                    <P>See the proposed rule for a full description of all the HOME program proposed regulation changes associated with this rulemaking.</P>
                    <HD SOURCE="HD1">III. This Final Rule</HD>
                    <P>HUD reviewed and considered all public comments submitted in response to the proposed rule, which are summarized and addressed in the next section of this final rule. After considering the public comments received in response to the proposed rule, this final rule incorporates a majority of the proposed regulatory changes described in the proposed rule; however, in response to public comments received, HUD is making certain revisions to the HOME program regulations from those described in the proposed rule at this final rule stage. HUD is also making certain non-substantive revisions to the proposed regulatory text at this final rule stage.</P>
                    <P>In response to comments received during the proposed rule stage of this rulemaking, HUD is making the following revisions to the final rule:</P>
                    <HD SOURCE="HD2">24 CFR Part 91—Technical Revisions</HD>
                    <P>HUD is making certain technical revisions in 24 CFR part 91 to replace the term “affordability period” with “period of affordability.” These revisions are consistent with the technical revision proposed in 24 CFR part 92 to make the same terminology replacement. Further, these revisions are consistent with public comments HUD received noting that these revisions are appropriate.</P>
                    <HD SOURCE="HD2">24 CFR Part 92—Technical Revisions</HD>
                    <P>HUD is making certain technical revisions in 24 CFR part 92 to improve clarity and readability of certain language throughout the part. While HUD is not summarizing each of these technical changes because the changes are minor and non-substantive, a sampling of these revisions are described in the paragraphs that follow.</P>
                    <P>
                        The Department received comments indicating that it had not fully revised all references from “downpayment assistance” to “homeownership assistance.” The Department is revising §§ 92.203(d), 92.209(c)(2)(iv), 92.250(b)(4), 92.251(c)(3), 92.254(b)(1)(ii), 92.300(a)(6)(i), 92.351(a)(1), 92.504(c)(1)(i), and 92.504(c)(2)(i) accordingly. The Department declined to revise certain references in the regulation that were specific to the downpayment provided by a homebuyer (
                        <E T="03">e.g.,</E>
                         for purposes of the resale or recapture methods used in § 92.254).
                    </P>
                    <P>Commenters noted that there were a number of areas where the term “dwelling” had not been replaced by “housing.” Accordingly, the Department is revising §§ 92.219(a)(4), 92.254(a)(5)(ii)(A), and 92.258(a) to standardize the use of “housing.”</P>
                    <P>The Department noted several instances where it had not corrected the term “single-family” to read “single family.” Accordingly, the Department is revising §§ 92.220(a)(5)(ii), 92.254(a)(6), 92.504(c)(1)(i), and 92.504(c)(2)(i) to include the standardized term “single family.”</P>
                    <P>Several commenters noted that the Department failed to change all the references from “affordability period” to “period of affordability.” The Department has further revised the term for consistency in §§ 92.251(f), 92.252(d)(3), 92.254(a)(5)(ii)(B)(2), 92.258(c) and (d)(3), 92.359(f), and 92.508(c)(1) and (2).</P>
                    <P>The Department is also revising the first sentence of § 92.201(b)(3)(i) to clarify that States must require that State recipients use HOME funds in accordance with 24 CFR part 92. This is also stated in the written agreement section in § 92.504 and is a revision for consistency.</P>
                    <HD SOURCE="HD2">24 CFR 92.2 Definitions</HD>
                    <HD SOURCE="HD3">A. Commitment</HD>
                    <P>
                        As explained in greater detail in the preamble describing the revisions in § 92.209, the rental assistance contract requirements in the HOME tenant-based rental assistance program are being revised to require that the PJ enter into a rental assistance contract with the owner and the tenant, either as separate agreements or a single tri-party agreement. The Department is therefore revising the definition of 
                        <E T="03">Commit to a specific local project</E>
                         in paragraph (2)(iii) of the definition of 
                        <E T="03">Commitment</E>
                         to accurately state that the rental assistance contract, which is the committing document for HOME tenant-based rental assistance, is the contract with the “owner and the tenant” instead of the contract with the “owner or the tenant.”
                    </P>
                    <P>
                        A new paragraph (2)(ii)(C) was added under 
                        <E T="03">Commit to a specific local project</E>
                         in the definition of 
                        <E T="03">Commitment</E>
                         to provide the requirements for commitments to a family to acquire single family housing for homeownership that does not meet the PJ's property standards, as described in § 92.251(c)(3). The requirements include the same requirements for standard housing, 
                        <E T="03">i.e.,</E>
                         that the PJ (or State recipient or subrecipient) and the family must have executed a written agreement under which HOME assistance will be provided for the purchase of the single family housing, which requires the property title to be transferred to the family within six months of the agreement date. In addition, the paragraph will also require that the written agreement require the property to meet the standards in accordance with § 92.251(c)(3). This revision is being made because the current definition of Commit to a specific local project only contemplates that the homebuyer will be purchasing housing in standard condition and not housing that requires rehabilitation. This allows the written agreement to count as a commitment when it complies with the requirements in § 92.251(c)(3), thereby providing consistent application of the new rules permitting homebuyers to rehabilitate their units to meet property standards post-acquisition.
                    </P>
                    <HD SOURCE="HD3">B. Community Housing Development Organizations</HD>
                    <P>In response to public comments received, HUD is making multiple changes to paragraph (8)(i) of the definition of community housing development organization in § 92.2. Paragraph (8)(i) of the CHDO definition describes board membership requirements to maintain accountability to low-income community residents. Many commenters were concerned that the language of the proposed rule would reduce the accountability of CHDO boards. As described further in the following paragraphs, HUD is addressing the concerns expressed in the comments by strengthening the accountability structures.</P>
                    <P>
                        HUD is revising paragraph (8)(i) of the CHDO definition to add “low-income beneficiaries of HUD programs” as an explicitly named group of eligible board members to meet the accountability to low-income community residents board requirement. HUD recognizes that 42 U.S.C. 12704(6)(B) requires that a CHDO “maintain[], through significant representation on the organization's governing board and otherwise, accountability to low-income community residents and, to the extent practicable, low-income beneficiaries with regard to decisions on the design, siting, development, and management of 
                        <PRTPAGE P="748"/>
                        affordable housing . . . .” By adding “low-income beneficiaries of HUD programs” to the regulation, HUD believes it is more closely matching the intent of the statute and emphasizing that, whenever possible, board members of CHDOs should include low-income beneficiaries of HUD programs.
                    </P>
                    <P>HUD is also revising paragraph (8)(i) of the CHDO definition to use the term “designees of nonprofit organizations” instead of “authorized representatives of nonprofit organizations.” This revision of the term “designee” is being made because of confusion expressed by commenters regarding when a person is considered an “authorized representative.” HUD recognizes that the inconsistent terminology is confusing and believes that using a consistent term to describe individuals representing “low-income neighborhood organizations” and the “nonprofit organizations” described in paragraph (8)(i) brings additional clarity to paragraph (8)(i) of the CHDO definition.</P>
                    <P>HUD is further revising paragraph (8)(i) of the CHDO definition to specifically reference the designees of nonprofit organizations in the community that address the housing or supportive service needs of “low-income residents or residents of low-income neighborhoods.” This revision is in response to commenters who stated that HUD had not sufficiently connected the term “nonprofit organizations” to low-income residents of the community in paragraph (8)(i) of the CHDO definition. The commenters urged HUD to use clearer language to show that individuals representing organizations serving low-income persons, even if those persons do not live in low-income neighborhoods, should be able to meet the requirement that the CHDO board is accountable to low-income community residents. HUD believes this revision will better enable designees that directly serve low-income residents to be CHDO board members. In response to significant comment from the public, the Department is revising paragraph (8)(i) to prohibit an organization from being considered a CHDO if its service area is the entire State. Though the Department had proposed removing this restriction from the current regulation to better enable rural PJs and states to use their CHDO set-aside funds, the public comments were quite clear that allowing an organization to have a statewide service area was not the solution to addressing the shortage of CHDOs with capacity in rural areas.</P>
                    <P>In response to public comments received, HUD is also making multiple changes to paragraph (9) of the definition of community housing development organization in § 92.2. These specific changes are described in the paragraphs that follow.</P>
                    <P>HUD is revising the introductory text of paragraph (9) of the CHDO definition to add “Federal Home Loan Bank Affordable Housing Program (12 U.S.C. 1430) funds” to the list of housing programs that demonstrate a CHDO's capacity to carry out a housing project. This change is made in response to public comments to provide clarity because these grant funds are frequently layered with HOME funds in housing development projects.</P>
                    <P>HUD is revising paragraph (9)(i) of the CHDO definition by changing the first sentence of the paragraph to require that a CHDO have “paid employees” with housing development experience who will work directly on the HOME-assisted project. HUD is making this revision in response to public comments that correctly noted that the way the proposed rule phrased this portion of paragraph (9)(i) of the CHDO definition allowed a CHDO to have no paid employees at all and still meet the capacity requirement. HUD's intent with the proposed rule was to allow volunteers to supplement the capacity of paid employees, not to allow a CHDO to meet the capacity requirements while having no paid employees. HUD is making a similar revision in the last sentence of paragraph (9)(i) of the CHDO definition to read as “key, paid staff of the organization” for the same reasons.</P>
                    <P>HUD is further revising paragraph (9)(i) of the CHDO definition to add an additional sentence to clarify that where the paid employees of a CHDO alone do not demonstrate capacity, that experience can be supplemented with volunteer board members or officers. For additional clarity, HUD is also making minor revisions to paragraph (9)(i) of the CHDO definition to more directly state the requirement that a volunteer board member or officer may not be compensated by or have their services donated by another organization.</P>
                    <HD SOURCE="HD3">C. Community Land Trust</HD>
                    <P>In response to public comments received, HUD is making multiple changes from the proposed rule to the definition of CLT in § 92.2. These specific changes are described in the paragraphs that follow.</P>
                    <P>HUD is revising paragraph (1) of the CLT definition to read “[h]as as its primary purposes acquiring, developing, or holding land to provide housing that is permanently affordable to low-income persons.” Commenters noted that CLT ownership models vary nationwide and, while some CLTs do develop and maintain their properties, other CLTs acquire and hold properties as affordable housing in perpetuity but are not otherwise involved in maintenance or development work. HUD recognizes that its proposed definition was too narrow to consider many of these organizations as CLTs and is revising it accordingly. In addition, HUD's proposed rule stated that a CLT must have a primary purpose of serving both low- and moderate-income persons. After reviewing the comments and the various CLT models provided by commenters, HUD is revising the CLT definition to recognize that the primary purpose of a CLT participating in the HOME program must be to serve low-income persons. HUD is also making a similar change to remove “moderate-income” from paragraph (3) of the CLT definition.</P>
                    <HD SOURCE="HD3">D. Homeownership</HD>
                    <P>In response to public comments received, HUD is making certain changes to the definition of homeownership in § 92.2. Public commenters noted that the Department had not changed the term “dwelling” in the definition of homeownership in § 92.2. After considering the best way to clarify the requirement, the Department determined that it would be easier to replace to term “1-4 unit dwelling or in a condominium unit” with the term “single family housing,” which is defined as “a one-to four- unit residence, condominium unit, cooperative unit, combination of manufactured housing and lot, or manufactured housing lot.” The final rule text is clearer and uses a common term that is also defined in the regulation. It also provides additional clarity for homeownership projects involving manufactured homes, which are more explicitly referenced in the definition of single family housing. HUD believes that this clarifying change is therefore also responsive to comments requesting that HUD clarify the treatment of manufactured homes in HOME homeownership projects.</P>
                    <P>
                        HUD notes that in its review of the public comments, the Department identified significant confusion by some commenters about the time periods in the definition of CLT and homeownership in § 92.2 and the housing education and organizational support requirements in § 92.302. HUD is committed to better addressing the needs of CLTs and its revisions to the homeownership definition in § 92.2 clarify the intent of the definition and how it is meant to apply to HOME homeownership projects. The specific changes to the definition of 
                        <PRTPAGE P="749"/>
                        homeownership are described in the paragraphs that follow.
                    </P>
                    <P>HUD is revising paragraph (1) of the definition of homeownership to further clarify the explanatory text to state that the land upon which housing is located may be owned in fee simple or through a ground lease if the housing was owned in fee simple. The paragraph was also revised to give a rule of construction so that PJs and homeowners understand that the minimum term of a ground lease is the lowest time period if more than one condition applies. For example, if a ground lease was part of a CLT-developed project, the minimum term for the ground lease to be considered homeownership is 50 years, but if that CLT-developed project was in an insular area, the minimum term for the ground lease to be considered homeownership would be 40 years because the minimum term for a ground lease to be considered homeownership in insular areas is 40 years (See § 92.2(1)(ii)).</P>
                    <P>HUD is further revising paragraph (1) of the definition of homeownership to remove the latter portion of the introductory text of paragraph (1) that addressed 99-year ground leases. Paragraph (1) is instead being revised to create a new paragraph (1)(i) to make clear that a 99-year ground lease is one of multiple options for ground lease length. The original paragraphs (1)(i), (1)(ii), and (1)(iii) are being redesignated as (1)(ii), (1)(iii), (1)(iv), respectively.</P>
                    <P>HUD is also making other minor, non-substantive revisions to the introductory text and paragraph (1) to the definition of homeownership to improve the readability of the text.</P>
                    <HD SOURCE="HD3">E. Housing</HD>
                    <P>HUD is revising the definition of housing in § 92.2 to replace the term “dwellings” with “housing units.” Commenters noted that there were certain areas in the proposed rule where “dwelling” had not been replaced with the updated term. HUD is updating the housing definition to correct this issue.</P>
                    <HD SOURCE="HD3">F. Single Room Occupancy (SRO) Housing</HD>
                    <P>
                        HUD is revising the definition of 
                        <E T="03">single room occupancy</E>
                         (SRO) housing in § 92.2 to replace the term “dwelling” with “housing.” Commenters noted that there were certain areas in the proposed rule where “dwelling” had not been replaced with the updated term. HUD is updating the SRO housing definition to correct this issue.
                    </P>
                    <HD SOURCE="HD3">G. American Dream Downpayment Initiative References</HD>
                    <P>The Department intended to remove all American Dream Downpayment Initiative (ADDI) regulations as part of this rulemaking. Unfortunately, the Department inadvertently retained language in the definition of “State” that described deviations between the term “State” in the HOME program and in the ADDI program. The Department is revising the definition of “State” to remove all ADDI-related language in this final rule.</P>
                    <HD SOURCE="HD2">24 CFR 92.3—Applicability of 2025 Regulatory Changes</HD>
                    <P>In response to the proposed rule, HUD received comments requesting that the Department specify the effective date of the regulatory changes associated with this final rule. To address these comments, HUD is revising § 92.3 to provide the applicable effective dates for the regulatory changes associated with this final rule instead of the applicable effective dates associated with the 2013 regulatory revisions. The header is being revised to describe the applicability of 2025 regulatory changes.</P>
                    <P>The introductory language of § 92.3 is being replaced by a provision explaining that the regulations in 24 CFR part 92 apply based on when an income determination is made or when the HOME funds for the project were committed. The provision goes on to explain that projects where the HOME funds were committed before a certain date may be subject to previous versions of these regulations. The provision also explains that the intent of § 92.3 is to provide instruction regarding which version of these regulations applies to which project based on when the funds were committed.</P>
                    <P>Paragraph § 92.3(a) is being replaced with a new paragraph (a). Paragraph (a) establishes the effective date for the 2025 final rule. The paragraph explains that the final rule is applicable to projects for which HOME funds are committed on or after February 5, 2025. The paragraph goes on to state that a PJ must perform income determinations in accordance with § 92.203 after February 5, 2025.</P>
                    <P>Paragraph § 92.3(b) is being revised to explain that while the effective date of the rule is 30 days after publication, PJs are permitted to continue to comply with the HOME regulations as they existed immediately before the effective date for commitments made up to one year after the rule's effective date. This allows PJs time to change their policies and procedures, forms, and systems, so that they can effectively implement the provisions of the final rule.</P>
                    <P>Paragraph (c) describes how the income regulations will be implemented for existing tenants and new projects that are coming online. This is because the income requirements of § 92.203 are applied to tenants of existing projects pursuant to their written agreements. The Department wants to clarify that for up to one year after the effective date of the rule, PJs may calculate income in accordance the income requirements that the PJs was implementing immediately prior to the publication of the final rule. This allows PJs to transition to determining income in accordance with the new requirements, as many income reexaminations may be underway when the rule becomes effective.</P>
                    <P>In some cases, PJs may wish to amend existing written agreements to take advantage of certain flexibilities or impose new requirements. While most of the rule may be applied immediately on the effective date, the Department is clarifying that certain provisions may not be implemented when a commitment has already been issued for a project. These relevant provisions are listed in § 92.3(d)(1) through (5).</P>
                    <P>Section 92.3(d)(1) explains that the written agreement cannot be revised to allow for certain predevelopment costs as well as certain project related soft costs currently contained in § 92.206(d)(2) to be reimbursed in accordance with the newly revised § 92.206(d)(1) if the HOME funds were committed to the project prior to the effective date of the final rule. Commitments were made after underwriting the project with assumptions that these costs were not going to be paid with HOME funds and the Department determined that the written agreements should not be amended to include those costs as payable from HOME when it was not the source that had already been identified to pay for the cost.</P>
                    <P>
                        Similarly, § 92.3(d)(2) states that the new flexibility to obtain a higher maximum per-unit subsidy increase should only be included for projects where funds were committed to the project after the effective date of the final rule. While the Department fully supports green building requirements, the Department determined that projects with current commitments should not undergo additional underwriting and cost allocation. When a PJ committed HOME funds to projects before the effective date of the rule, they underwrote and sized the assistance based on the assumption that the maximum per-unit subsidy was the 
                        <PRTPAGE P="750"/>
                        limit in effect. The Department believes that this should continue to be the case and that current projects should not be amended. If a PJ were to amend its written agreement with an owner to add the new requirements at a later time, it can be disruptive, cause delays in production of badly needed affordable housing units and is not the behavior that the Department is attempting to incentivize by providing the increase in maximum per-unit subsidy.
                    </P>
                    <P>Section 92.3(d)(3) states that the revised dollar thresholds for periods of affordability in § 92.252 and § 92.254 will not apply to projects where the PJs had already committed HOME funds. Similar to paragraphs (d)(1) and (2), a PJ already agreed with an owner on the applicable periods of affordability, just like they had agreed to a maximum per-unit subsidy, or which type of funds were used to pay which costs. To allow the owner and PJ the ability to reduce the period of affordability for a project that has already been agreed upon through amending the written agreement would be perverse and counter to the purposes of the Act.</P>
                    <P>Section 92.3(d)(4) states that the new tenant protection provisions cannot be imposed upon owners that are already under a current written agreement or tenants and owners under a current rental assistance contract or receiving security deposit assistance. Owners should have appropriate notice before imposing substantial changes in landlord-tenant relations. The HOME program provides development subsidies to owners to build affordable housing but does not provide ongoing operations assistance. Owners must consider the costs of compliance in determining whether to participate in the HOME program. This includes the costs of complying with tenant protections. Moreover, the Department received numerous comments indicating that imposing the tenant protections on current owners would amount to a regulatory taking. While the Department does not believe that this is the case and would strenuously object to any characterization of improving tenant protections as a form of taking or violation of an owner's due process rights, the Department does believe it is important to establish clear compliance requirements within the written agreement between the PJ and the owner, and to allow those requirements to remain consistent for the life of the agreement. To prevent potential litigation and loss of affordable housing, the Department is requiring that the new and revised tenant protections provided in § 92.253 only be effective for projects with commitments of up to one year after the effective date of the rule and not be applied to projects with commitments prior to the effective date of the rule.</P>
                    <P>Finally, § 92.3(d)(5) was added to state that the revisions to the role of CHDOs in owning, developing, and sponsoring affordable housing in § 92.300 only apply to projects where the PJ committed CHDO set-aside funds on or after the effective date of the final rule. The new flexibilities in § 92.300 should be used for new projects. If a PJ has already entered into an agreement with a CHDO to own, develop, or sponsor a project, then it is inappropriate for the PJ to amend the agreement and enter into an agreement with a new party because of the new flexibilities provided in § 92.300. The Department is expanding the way in which CHDOs can be involved in a HOME project but is not encouraging PJs to terminate or significantly restructure existing CHDO projects.</P>
                    <P>The Department also believes that it may be helpful to place the date and the triggering action into a chart to better assist PJs, owners, and the public in understanding when the 2025 final rule's requirements are applicable.</P>
                    <HD SOURCE="HD2">24 CFR 92.201 Distribution of Assistance</HD>
                    <P>The Department is also revising the first sentence of § 92.201(b)(3)(i) to clarify that States must require State recipients use HOME funds in accordance with part 92. This is also stated in the written agreement section in § 92.504 and is a revision for consistency.</P>
                    <HD SOURCE="HD2">24 CFR 92.203 Income Determinations</HD>
                    <P>The Department is making a technical revision to the first sentence of § 92.203(a) to remove the dash between “income” and “eligible” to maintain consistent usage of the term. The Department is revising the “must” to a “may” in § 92.203(a)(1) in response to public comments recommending that HUD allow PJs to always retain the right to determine annual income in accordance with the process described in paragraphs (b)-(e). This change will allow PJs the choice of accepting the income determinations made in Federal or State project-based rental subsidy programs instead of requiring PJs to accept those determinations.</P>
                    <P>In response to public comments, the Department is revising the language in § 92.203(a) to create a new paragraph (a)(3) and redesignate the current paragraph (a)(3) as paragraph (a)(4). The new paragraph (a)(3) provides additional burden relief for PJs and owners by expanding a safe harbor that is currently located in § 92.203(b)(1)(iii). The current safe harbor in § 92.203(b)(1)(iii) is limited to government programs and not forms of public assistance, which is a broader term that encompasses tax credits and other forms of assistance that are not “programs.” The Department uses this broader term “public assistance” in the safe harbor provisions in 24 CFR 5.609(c)(3) for 1937 Act programs but does not use this term in the current HOME regulations. The current safe harbor in HOME regulations cannot be used for initial annual income and eligibility determinations, or in calculating annual income for a family in years 6, 12, and 18 of a HOME rental housing project's period of affordability. The safe harbor also cannot be used for individuals applying for or renewing tenant-based rental assistance.</P>
                    <P>Public commenters recommended that PJs be able to accept income determinations made under other forms of public assistance, including LIHTC income determinations for families living in tax credit units. The Department recognizes the utility in expanding the safe harbor to include other forms of government assistance and allowing its use for initial annual income determinations or annual income determinations made in years 6, 12, and 18 of a HOME rental housing project's period of affordability as well as for individuals entering into or renewing a new rental assistance contract for tenant-based rental assistance. Therefore, the Department is moving the safe harbor into paragraph (a) as a new paragraph (a)(3) to enable a PJ to use the information for initial annual income and subsequent income determinations for HOME rental housing tenants as well as for tenant-based rental assistance. The Department is also expanding the applicability of the safe harbor to include an annual income determination made under another form of Federal, State, or local public assistance. Accordingly, the Department is also removing § 92.203(b)(1)(iii) and revising the last sentence in paragraph (b)(1) to indicate that there are only two methods of determining income under paragraph (b)(1).</P>
                    <P>
                        The Department provides several examples to enhance the public's understanding of the types of assistance that could be accepted under the new paragraph (a)(3). These examples include TANF, Medicaid, LIHTC, and local rental subsidy programs. These programs all calculate annual income but do not make the adjustments that are made in HUD programs that are subject to 24 CFR 5.611.
                        <PRTPAGE P="751"/>
                    </P>
                    <P>To obtain the relief of the safe harbor under new § 92.203(a)(3), the PJ must be able to obtain a statement that indicates the family size and income. This can be provided by an administrator of a Federal, State, or local form of public assistance, even if that administrator is not the administrator at the Federal or State level. The Department considered whether to allow, as the current safe harbor provision in § 92.203(b)(1)(iii) does, a government administrator to provide a PJ with a statement indicating that the family's income does not exceed the current dollar limit for very low-income or low-income families for the family size of the tenant. The Department decided against including this language.</P>
                    <P>The Department drafted this safe harbor partly in response to public comments requesting that the Department accept a statement made by an administrator of public assistance without further review of income documentation for the tenant. The Department agrees that it is possible to use a statement from a government administrator to determine income, though verification is left to PJ policies and procedures. However, the Department decided that if it was expanding the safe harbor to enable PJs to accept a statement, then the statement must contain a statement of family size and income and not just a statement that the family was below the applicable income limit for the family's size. This is especially true because, in many cases, the PJ must still calculate adjusted income in accordance with paragraph (f). To provide the maximum amount of burden relief to both the PJs and tenant, and best address the concerns of the commenter, the statement must have the family's annual income on it so that the PJ need only adjust the income (if applicable) from a known amount of annual income. Accordingly, the Department is also removing § 92.203(b)(1)(iii) and revising the last sentence in paragraph (b)(1) to indicate that there are only two methods of determining income under paragraph (b)(1).</P>
                    <P>The Department is requiring in the new § 92.203(a)(3) that the statement accepted by the PJ must be for an income determination made within the previous 12-month period. This aligns with how similar safe harbor provisions are used in other HUD programs, such as the safe harbor in 24 CFR 5.609(c)(3) that is used for certain programs governed under the U.S. Housing Act of 1937. The Department considered whether to provide a shorter period, such as the 6-month requirement under § 92.203(e)(2) for income determinations made prior to providing homeownership or tenant-based rental assistance to a family. However, after consideration of the comment and how to align this safe harbor with other safe harbors in HUD regulations, HUD has determined that 6 months is inappropriate. When a family applies to a PJ for assistance and the PJ determines the family's income, there is a reasonable expectation that this income examination is close in time to when the family will receive the HOME assistance from the PJ. When a person was determined income eligible with these other forms of public assistance, it may not be at the same time as when the PJ's tenant-based rental assistance program waiting list opens up for the public to apply or when a person is next up on an owner's waiting list. To establish a shorter period in which the income determination will remain valid for purposes of the new safe harbor would therefore disadvantage those families and PJs and so the Department chose to allow income determinations made within a 12-month period to qualify for purposes of the safe harbor at § 92.203(a)(3).</P>
                    <P>As part of the revisions made to lift and expand the safe harbor in § 92.203(a)(3), the Department is making conforming changes to paragraph (b)(2) and adding paragraph (b)(3) to explain that only families applying for homeownership activities must calculate income using 2 months of source documents. Before paragraph (a)(3) was added, both families applying for homeownership assistance and families applying for or receiving tenant-based rental assistance were required to solely use source documents. However, with the expansion of the safe harbor to tenants applying for, renewing, or for assisted families required to enter into a new rental assistance contract, the Department had to make conforming changes to explain how income is calculated for tenant-based rental assistance. The new paragraph (b)(3) does this by explaining that, for families applying for or receiving tenant-based rental assistance, the PJ may determine annual income in accordance with the new safe harbor provision or through the use of source documents. The paragraph also clarifies that income will be calculated at the times specified in § 92.209(e)(3), which provides explicit instructions on when income must be determined for a family applying for or receiving tenant-based rental assistance.</P>
                    <P>The Department received negative comments on § 92.203(e)(2). While the Department is declining to revise the six-month limit on when income is valid, the Department recognizes that the provision itself could be clearer. The Department is therefore clarifying that a PJ is not required to redetermine income for a family unless 6 months have elapsed since the PJ determined the family is income eligible. The term “re-examine” is confusing given that the provision is about determining a family's income eligibility in advance of being provided assistance. This is different than when income is reexamined for families living in a rental housing project or families entering into or renewing a rental assistance contract. As the Department is revising income reexamination provisions for small-scale rental housing and in the context of tenant-based rental assistance, the Department believes it is important to remain consistent and is therefore revising this provision as well.</P>
                    <P>Paragraph 92.203(e)(2) is also being clarified to explain that when the regulation refers to “HOME assistance,” the regulation means homeownership assistance and tenant-based rental assistance. In the HOME regulations, the term “HOME assistance” is used in a variety of contexts. The term means the assistance provided to a subrecipient, State recipient, or contractor to run all or a portion of a PJ's HOME program; the assistance provided to a developer, owner, or sponsor to develop a HOME rental or homeownership project; assistance provided to a family for tenant-based rental assistance; homeownership assistance provided to a family to purchase and/or rehabilitate a home; or assistance provided to a CHDO. The Department believed it was important to clarify which type of assistance is meant in the provision given the various ways in which the term is used. Paragraph (e)(2) was also revised with a clarifying edit to say that a family “is income eligible” instead of “qualifying as income eligible.” This is a non-substantive revision for readability.</P>
                    <P>
                        The Department is revising § 92.203(f)(1)(ii) to remove two references to § 92.252(a)(2)(iii), which is being removed by this rulemaking. The Department is also revising § 92.203(f)(2) to make corresponding revisions now that PJs are given the option of accepting a public housing agency, owner, or rental subsidy provider's determination of the family's adjusted income under that program's rules instead of being required to do so under § 92.203(a)(1). This change is in response to public comments, as described earlier in this preamble.
                        <PRTPAGE P="752"/>
                    </P>
                    <HD SOURCE="HD2">24 CFR 92.206 Eligible Project Costs</HD>
                    <P>In response to public comments, HUD is making certain changes to § 92.206(d) regarding related soft costs that may be considered eligible project costs. The Department proposed and received comments requesting that HUD allow environmental reviews or other environmental studies or assessments to be reimbursable costs incurred prior to the commitment of funds to a project. Commenters requested that the provision be expanded to also include environmental fees, which the Department agrees can be included in the provision. The comments urged the Department to also consider expanding the types of costs that would be allowed to be incurred to include “pre-development” and other related soft costs.</P>
                    <P>In response to the comments, HUD is making changes to paragraph (d)(1) to expand the project soft costs that may be incurred prior to a commitment. The final rule moves certain soft costs from paragraph (d)(2) into paragraph (d)(1), including costs to process and settle financing for the project, such as private lender origination fees, credit reports, fees for title evidence, legal fees, private appraisal fees, and fees for independent cost estimates. By moving these soft costs into paragraph (d)(1), HUD is allowing the costs to be paid so long as they were incurred no more than 24 months before the date of commitment and included in the written agreement committing the funds. Note that “legal fees” is a more expansive term than the current term “attorney's fees” and the Department is intentionally expanding the term to be more inclusive of the different legal costs that are associated with a project in response to public comment.</P>
                    <P>The Department determined that soft costs contained in the other provisions in paragraph (d) could not be moved into paragraph (d)(1) as there is no reasonable expectation that such costs would occur prior to commitment of HOME funds. Those provisions include building permits, which can only be obtained after completion of the HUD environmental review; fees for recordation and filing of legal documents, as recordation of documents related to an acquisition, rehabilitation, or new construction contract should occur after commitment of HOME funds; and building or developer fees, as those fees should not be earned or chargeable to the HOME grant for work performed prior to the environmental review and commitment of the HOME funds to a project.</P>
                    <P>
                        In response to public comment, HUD is also revising § 92.206 to add “accounting fees”, “filing fees for zoning or planning review and approval”, and “other lender-required third-party reporting fees” to paragraph (d)(1). The Department added these fees, as recommended by the commenter, because the Department agrees that these fees, which are generally incurred prior to applying to a PJ for HOME assistance, are directly related to meeting underwriting and construction feasibility criteria that are required in the definition of § 92.2 
                        <E T="03">Commitment.</E>
                         They may be payable with HOME funds if a PJ agrees to pay these costs in the written agreement.
                    </P>
                    <HD SOURCE="HD2">24 CFR 92.208 Eligible Community Housing Development Organization (CHDO) Operating Expense and Capacity Building Costs</HD>
                    <P>The public comments indicated confusion over the proposed use of capacity building funds for CHDOs. The new § 92.208(c) describes how PJs may provide HOME assistance to CHDOs for operating costs under § 92.300(a). The paragraph is not intended to describe the use of capacity building funds, which is described in the previous paragraph at § 92.208(b). HUD inadvertently included reference to “capacity building costs” in the proposed § 92.208(c) and understands that this may have led to confusion for commenters. Consequently, HUD is removing the reference to “capacity building costs” in § 92.208(c) to eliminate this confusion.</P>
                    <HD SOURCE="HD2">24 CFR 92.209 Tenant-Based Rental Assistance: Eligible Costs and Requirements</HD>
                    <P>The Department revised § 92.209(c)(3) to correct the term “tenant-based rental assistance” in the third sentence of the paragraph. The regulation had previously read “tenant-based assistance.” This is a non-substantive change.</P>
                    <P>The Department made several revisions to § 92.209(e) in response to public comment. The Department redesignated § 92.209(e) as § 92.209(e)(2) and revised the provision as described below. The Department also revised the header for paragraph (e) to describe the rental assistance contract more broadly and not just the term rental assistance contract. The Department then made four new subsections.</P>
                    <P>The first subsection, § 92.209(e)(1), defines the parties to the rental assistance contract, which is also the header for this provision. Based on public comment to specific solicitation of comment #10, the Department is requiring the PJ to have a rental assistance contract with both the owner and the tenant. This can take the form of a single tri-party agreement or two separate agreements. There is precedent for this model in HUD programs. In the Housing Choice Voucher program, the tenant has an agreement with the public housing agency where the tenant agrees to the rules of the program (See Form HUD-52646), and the owner has an agreement with the public housing where the owner agrees to the terms of the housing assistance payments agency (See Form HUD-52641). The Department also believes that this is the best method for the PJ to enforce HOME requirements on tenant and owner alike.</P>
                    <P>The Department revised the redesignated § 92.209(e)(2) to provide that a rental assistance contract does not need to start on the first day of the lease so long as the contract commences at the beginning of the first month in which tenant-based rental assistance is provided. The Department revised the provision to decouple the execution of the rental assistance contract from the tenant lease because with the imposition of the tenancy addendum, which must be executed and attached to the tenant lease, the need for the rental assistance contract to begin on the first day of the lease is significantly lessened. This is because the terms of the HOME tenant-based rental assistance tenancy addendum will control in the event of a conflict between the preexisting lease and the tenancy addendum, and therefore the risk that the lease would contain prohibited lease terms or would otherwise not comply with the HOME program requirements is eliminated. The Department is also revising this requirement in response to public comments that stated that it disadvantages families to require that the rental assistance contract begin on the first day of the lease because current very low-income tenants would have to break their lease to obtain rental assistance, which is not always possible. The Department does not wish to disadvantage tenants that are housing insecure or rent burdened by requiring they enter a new lease in order to receive tenant-based rental assistance under HOME.</P>
                    <P>
                        The Department also revised the redesignated § 92.209(e)(2) to explain that a rental assistance contract can be amended subject to the availability of funds. This revision is made in response to a public commenter that requested HUD explain whether an amendment to a rental assistance contract would require a new income determination. The Department is drawing a distinction 
                        <PRTPAGE P="753"/>
                        between new contracts, amendments, and renewals of rental assistance contracts first in paragraph (e)(2) and then further in the new paragraphs (e)(3) and (e)(4).
                    </P>
                    <P>The new § 92.209(e)(3) explains under what conditions a contract may be amended or renewed. The new § 92.209(e)(3)(i) explains that all parties must consent to an amendment to the rental assistance contract. The new § 92.209(e)(3)(i)(A) explains that a rental assistance contract may be amended because the lease between the family and owner has been amended or renewed, as long as the lease term or amount charged under the lease are the only terms of the contract being changed. The new § 92.209(e)(3)(i)(B) explains that amendments to the rental assistance contract may extend the original term of the rental assistance contract up to 24 months from the original date of execution, which is the maximum term allowable under § 92.209(e)(2). The new § 92.209(e)(3)(i)(C) also allows for the amendment of the rental assistance contract when a family is moving within the same building or development, but the parties to the lease, family size, and the number of bedrooms are all the same. With respect to § 92.209(e)(3)(i)(C), the Department believes these are reasonable restrictions on tenants and owners, as changes to the parties to a lease, family size, and the number of bedrooms in a unit are all significant enough such that allowing a PJ to amend an existing rental assistance contract is not appropriate, and the PJ should instead be required to enter into a new rental assistance contract with the family and owner.</P>
                    <P>The new § 92.209(e)(3)(ii) explains that, subject to the availability of HOME funds, a rental assistance contract may be renewed after the expiration of its initial term. The new § 92.209(e)(3)(iii) explains that in all other instances, the PJ must enter a new rental assistance contract with the family and owner in accordance with § 92.209(e). This includes when family size changes, when the family moves to a different address with a different owner, or when the number of bedrooms in the unit changes.</P>
                    <P>The Department explains the differences between when a new contract must be entered, when a contract can be amended, or when a contract can be renewed primarily to provide greater clarity in tenant-based rental assistance requirements as well as to explain when an income determination must be performed. The new paragraph (e)(4) whose header is “initial and subsequent income determinations” explains that a PJ must perform an income examination each time a new rental assistance contract is entered into (see § 92.209(e)(4)(i)) or renewed (see § 92.209(e)(4)(iii)). The Department believes that this change is appropriate because it permits PJs to amend current rental assistance contracts to extend their term to the maximum 24-month period without requiring additional income examination, providing burden relief to tenants receiving tenant-based rental assistance. The Department declines to extend this burden relief to new rental assistance contracts or renewals as material terms of the lease or the number of persons in the housing are changing (in the case of new rental assistance contracts) or the rental assistance contract is being extended for more than twenty-four months (in the case of renewals). In these situations, income should be redetermined because it factors so heavily into the sizing of the rental assistance.</P>
                    <P>
                        The Department is adding a new § 92.209(e)(4)(iv) to explain that if a family is participating in a HOME lease-purchase program and receiving tenant-based rental assistance, then the family's income will only be determined at the time of execution of the lease purchase agreement. This is because the statute states that a family must be income-eligible at the time the lease-purchase agreement is signed,
                        <SU>6</SU>
                        <FTREF/>
                         and because this will better enable tenants to save up for the purchase of the housing in accordance with the lease-purchase agreement and the HOME lease-purchase program. This type of treatment is only when the family is participating in a HOME lease-purchase program and not for other non-HOME lease-purchase programs because those programs may have different rules and restrictions, and their program design may vary significantly from HOME requirements. In those instances where a family is receiving tenant-based rental assistance and participating in a lease-purchase program, the family's income will be examined when the family enters into the rental assistance contract and again if the family's assistance is renewed.
                    </P>
                    <FTNT>
                        <P>
                            <SU>6</SU>
                             See 42 U.S.C. 12745(b)(2)(B).
                        </P>
                    </FTNT>
                    <P>The Department is revising § 92.209(g) to refer to § 92.253 instead of specific paragraphs within § 92.253. This is because § 92.253 has been revised to directly state its applicability to tenant-based rental assistance and the requirements of the HOME tenant-based rental assistance tenancy addendum. The Department is also revising § 92.209(h)(3)(ii) to better identify the Section 8 Housing Choice Voucher Program payment standard that may be used by a PJ, which is the payment standard established in 24 CFR 982.503(a) through (c) and not the exception payment standard established in 24 CFR 982.503(d). The exception payment standard is, by its nature, an exception to the rule and the Department has not allowed its use in HOME in the past. This change is therefore just a clarification of HUD's existing interpretation of the HOME and Section 8 regulations.</P>
                    <P>The Department also made clarifying revisions to § 92.209(j)(6) to use the language “[s]urety bonds, security deposit insurance, or instruments similar to surety bonds or security deposit insurance . . .” instead of the proposed phrasing of “[s]urety bonds or security deposit insurance and similar instruments . . . .” HUD believes that this revision improves the clarity and readability of the paragraph.</P>
                    <P>Consistent with changes made throughout the section, the Department is revising the last two sentences of paragraph (k) to reference paragraph (e) and making technical revisions. The current provision requires that a PJ enter into an agreement with either the owner or the family. The final rule will require that the PJ enter into an agreement with the owner and the family.</P>
                    <HD SOURCE="HD2">24 CFR 92.210 Troubled HOME-Assisted Rental Housing Projects</HD>
                    <P>In response to public comment that suggested the Department was establishing an unreasonably high bar to evidence that a HOME project is no longer financially viable and able to obtain the relief in § 92.210, the Department has revised and reorganized § 92.210(a).</P>
                    <P>The first sentence in the paragraph remains unchanged from the proposed rule. Revised § 92.210(a)(1) now states that a project is not financially viable through the period of affordability if one of the conditions in § 92.210(a)(1)(i)-(iii) exists.</P>
                    <P>
                        In response to public comments, the Department provides in § 92.210(a)(1)(i) that a project is no longer financially viable through the period of affordability if the project's operating costs exceed its operating revenue considering project reserves. The Department has revised this sentence to remove the term “significantly” and to make this and the other conditions listed in § 92.210(a)(1)(i)-(iii) be independent conditions. In § 92.210(a)(1)(ii), the Department is creating a new condition that the project is no longer financially viable through the period of affordability if an owner is 
                        <PRTPAGE P="754"/>
                        unable to pay for necessary capital repair costs or ongoing expenses for the project. In the proposed rule, the owner being unable to pay for necessary capital repair costs was another condition that needed to be satisfied instead of an independent condition. However, given the comments, the Department believed it was best to expand the ground to include inability to pay operating expenses and to make the ground an independent ground for demonstrating that a project is no longer financially viable through the period of affordability.
                    </P>
                    <P>Lastly, if project reserves are insufficient to operate the project, then the Department also believes that the project is no longer financially viable through the period of affordability and is therefore making that a separate ground for relief under § 92.210(a)(1)(iii). The Department also revised § 92.210(a)(3) to clarify that HUD may approve the actions in § 92.210(b) and (c) to “strategically preserve the affordability of a rental project.” The Department had proposed to add the modifier “in preserving affordability” at the end of the sentence in the proposed rule but believes it is better for readability to move the language to describe the type of preservation action that is occurring for troubled housing rental housing projects under § 92.210. Similarly, the Department is revising § 92.210 to explain that the PJ may be permitted to reduce the “total” number of HOME-assisted units or change the designation of the units. This is a non-substantive clarifying change.</P>
                    <HD SOURCE="HD2">24 CFR 92.212 Pre-Award Costs</HD>
                    <P>The Department revised § 92.212(b)(2) to clarify the provision. The provision, as proposed, had initially stated that, if a given year's appropriation were not timely, then a PJ may incur administrative and planning costs as of the earlier of the beginning of their program year or the date that HUD receives the PJ's consolidated plan. The provision then defined when an appropriation was not timely as when it occurs less than ninety days before a PJ's program year start date.</P>
                    <P>After further consideration, the Department decided that it is inappropriate to characterize appropriations as timely or not timely in a regulation. The Department also believed this language detracted from the overall clarity of the provision. Instead, the last sentence is being deleted and the first sentence is being revised to state that in any year in which an appropriation is less than 90 days from a PJ's program start date, the PJ may incur administrative and planning costs as of the earlier of the beginning of their program year or the date that HUD receives the PJ's consolidated plan. This is a clearer sentence that doesn't characterize the timeliness of appropriations and it aligns with the related final rule text in § 570.200(h)(3).</P>
                    <HD SOURCE="HD2">24 CFR 92.214 Prohibited Activities and Fees</HD>
                    <P>For certain paragraphs in § 92.214, HUD made clarifying revisions to use the language “[s]urety bonds, security deposit insurance, or instruments similar to surety bonds or security deposit insurance . . .” instead of the proposed phrasing of “[s]urety bonds or security deposit insurance and similar instruments . . . .” HUD believes that this revision improves the clarity and readability of the paragraph. In response to public comment, HUD also clarified that HOME rental housing project owners may not charge tenants fees for normal wear and tear.</P>
                    <HD SOURCE="HD2">24 CFR 92.219 Recognition of Matching Contribution</HD>
                    <P>HUD is revising § 92.219(a)(4) to replace the term “dwelling” with the term “housing.” HUD is making this revision to standardize the use of the term “housing” in part 92 and in response to commenters that noted that the Department failed to make this terminology replacement in the proposed rule. The Department also made technical revisions to § 92.221(b)(1) to remove a dash, add section symbols, and add the word “through” when citing §§ 92.218 through 92.221.</P>
                    <P>
                        The Department is making conforming regulatory revisions to § 92.219(b)(2)(ii) and (iii) to remove the pinpoint citations to § 92.253(a)-(c) and (d)(2) and replace them with more general citations to the tenant protection provisions, as the provisions have moved and are now contained in the applicable tenancy addendum (HOME rental housing tenancy addendum, HOME TBRA tenancy addendum, and HOME security deposit assistance tenancy addendum). The Department also made non-substantive revisions to § 92.253(b)(2)(ii) for readability and to reduce confusion. The revised provision explains that the written agreement must impose and enumerate all requirements applicable to the project, including affordability requirements in §§ 92.252 or 92.254 (as applicable based on the type of project being carried out), any applicable tenant protections due to operation of a rental housing project (or lease-purchase project), any applicable property standards based on the type of project (
                        <E T="03">e.g.,</E>
                         new construction, rehabilitation, acquisition, etc.), and income determination requirements that apply to the family through § 92.203. The revisions of the section should make it easier for PJs to know what items are necessary for the written agreement, but no substantive changes were made from the current requirements.
                    </P>
                    <HD SOURCE="HD2">24 CFR 92.250 Maximum Per-Unit Subsidy Amount, Underwriting, and Subsidy Layering</HD>
                    <P>The Department received comments stating that a five percent increase in the maximum per-unit subsidy was insufficient to cover the associated costs with meeting nationally recognized green building standards. In response, the Department is increasing the percentage in the final rule up to ten percent in § 92.250(c). The Department understands that many commenters requested increases that were significantly higher, especially in the context of rehabilitation. The estimates provided by commenters ranged significantly from ten percent to well over twenty-five percent depending upon the market, the standard the project owner is attempting to meet, and whether the project was new construction or rehabilitation. The Department understands that rehabilitation of existing housing units and meeting significantly higher energy efficiency thresholds than what is required under section 212(e) of the Act can add significantly higher costs. However, the Department must balance the benefits from more sustainable, energy-efficient housing against the potential that fewer units will be created or fewer families served if the subsidy increased beyond ten percent. Given the level of annual appropriations that the HOME program receives, the Department believes it can only move to ten percent at this time but will reevaluate in the future.</P>
                    <HD SOURCE="HD2">24 CFR 92.251 Property Standards and Inspections</HD>
                    <HD SOURCE="HD3">A. Carbon Monoxide and Smoke Detection</HD>
                    <P>
                        In response to public comments on carbon monoxide and smoke detection, including comments received in response to specific solicitation of comment #3, which requested comment from the public on new requirements for smoke alarms, the Department is making revisions to § 92.251(a)(3)(vi), § 92.251(b)(1)(xi), § 92.251(c)(3), and § 92.251(f)(1)(iv).
                        <PRTPAGE P="755"/>
                    </P>
                    <P>
                        First, the Department is adding the carbon monoxide requirement applicable to the Section 8 voucher program as a new requirement for the HOME program at § 92.251(a)(3)(vi)(A), § 92.251(b)(1)(xi)(A), and § 92.251(f)(1)(iv)(A), which HUD will more fully describe through a publication in the 
                        <E T="04">Federal Register</E>
                        . The Department is also revising § 92.251(c)(3) to reference the requirement at § 92.251(b)(1)(xi)(A) and revising § 92.251(f)(1)(i) to clarify that the carbon monoxide requirements in 24 CFR 5.703 do not apply because the ones in § 92.251(f)(1)(iv)(A) apply instead.
                    </P>
                    <P>Second, the Department is adding smoke detection requirements to § 92.251(a)(3)(vi)(B), § 92.251(b)(1)(xi)(B), and § 92.251(f)(1)(iv)(B). The Department is also revising § 92.251(c)(3) to reference the requirement in § 92.251(b)(1)(xi)(B). The revised smoke detection requirements are tailored to the type of HOME activity and work being performed, based on public comments and informed by implementation considerations.</P>
                    <P>
                        For new construction projects under § 92.251(a)(3)(vi)(B)(
                        <E T="03">1</E>
                        ), a hardwired smoke detector must be installed on each level of each housing unit, in or near each sleeping area in each housing unit, in the basement of each housing unit, and in each common area of a project. However, a hardwired smoke alarm is not required in crawl spaces or unfinished attics of housing units. In addition, a hardwired smoke detector must also be installed within 21 feet of any door to a sleeping area measured along a path of travel and, where a smoke alarm installed outside a sleeping area is separated from an adjacent living area by a door, a smoke alarm must also be installed on the living area side of the door. The Department believes that it is appropriate to require that the smoke alarm be hardwired, as HOME funds are being used in the new construction of the projects and therefore the building designs and electrical systems can be tailored to meet the HOME requirements.
                    </P>
                    <P>
                        In response to HUD's consideration of public comments, the Department added § 92.251(a)(3)(vi)(B)(
                        <E T="03">4</E>
                        ) to establish that following the relevant specifications of either the International Code Council (ICC) or the National Fire Protection Association (NFPA) Standard 72 satisfies the requirements of § 92.251(a)(3)(vi)(B). Originally, the Department considered only codifying installation in accordance with the NFPA Standard 72 but received comments urging the Department to make its revisions consistent with the U.S. Housing Act of 1937, as amended by the Consolidated Appropriations Act, 2023 (Pub. L. 117-328, div. AA, title VI, § 601)). The Consolidated Appropriations Act, 2023 requires that units occupied by tenants living in public housing, living in units and receiving Section 8 Housing Choice Vouchers, or living in unit that receives project-based assistance comply with the applicable codes and standards published by the International Code Council or the National Fire Protection Association and the requirements of the National Fire Protection Association Standard 72 or any successor standard. Therefore, the Department is codifying § 92.251(a)(3)(vi)(B)(
                        <E T="03">4</E>
                        ) to allow property compliance with either standard for new construction in the HOME program which is consistent with other HUD programs.
                    </P>
                    <P>
                        The Department also added paragraph (a)(3)(vi)(B)(
                        <E T="03">2</E>
                        ) to require that smoke alarms have an alarm system designed for hearing-impaired persons. The Department is adding this language to ensure that individuals with hearing impairments are adequately warned in the event of smoke or a fire. The addition of this paragraph also makes the requirements of this section more consistent with the requirements contained in the Consolidated Appropriations Act, 2023.
                    </P>
                    <P>
                        The Department also added paragraph (a)(3)(vi)(B)(
                        <E T="03">3</E>
                        ) to describe that the Secretary may establish additional standards related to § 92.251(a)(3)(vi)(B) through a publication in the 
                        <E T="04">Federal Register</E>
                        .
                    </P>
                    <P>Additionally, the Department considered requiring hardwired smoke detectors for rehabilitation projects but understood that rehabilitation projects may require different considerations. As a result, while the Department is adopting the same requirements from § 92.251(a)(3)(vi)(B) for § 92.251(b)(1)(xi)(B). In addition, the Department is also adding § 92.251(b)(1)(xi)(B)(4), which will allow a PJ to provide a written exception to an owner to allow the owner to install a smoke detector that uses 10-year non rechargeable, nonreplaceable primary batteries as long as the smoke detector is sealed, tamper-resistant, contains a means to silence the alarm, and otherwise complies with the requirements of this section. This relief may only be provided where the use of hardwired smoke detectors places an undue financial burden on the owner or is infeasible. It is the PJ's responsibility for making and documenting this determination for their records. The Department is declining to define the terms “undue financial burden” or “infeasible” because it believes that PJs should have the flexibility to develop their own standards and to make their own determinations based on the fact-specific circumstances.</P>
                    <P>
                        For homeownership activities, the Department is revising § 92.251(c)(3) to require that housing acquired for homeownership meet the same carbon monoxide and smoke detection requirements required under § 92.251(b)(1)(xi). And, similar to the exception that the Department is allowing at § 92.251(b)(1)(xi)(B), the Department is allowing a PJ to provide a written exception to an owner to allow the owner to install a smoke detector that uses 10-year non rechargeable, nonreplaceable primary batteries as long as the smoke detector is sealed, tamper-resistant, contains a means to silence the alarm, and otherwise complies with the requirements of this section. The Department is also requiring that the same grounds which justify an exemption from being required to use hardwired smoke detectors, 
                        <E T="03">i.e.,</E>
                         undue financial burden, be the applicable grounds in § 92.251(c)(3).
                    </P>
                    <P>Finally, as for the ongoing property standards for existing rental housing projects and the property standards for tenant-based rental assistance, the Department is creating new requirements in § 92.251(f)(1)(iv)(B), which will mandate that smoke detectors meet the standards in 24 CFR 5.703(b) and (d). These are the NSPIRE smoke detection standards that apply to the Section 8 program and elsewhere. The Department believes it is appropriate to treat existing rental housing and units with tenants receiving tenant-based rental assistance the same as those receiving Section 8 HCV assistance or project-based Section 8 assistance, as these programs are sufficiently similar.</P>
                    <P>
                        For these existing rental housing units and units with tenants receiving tenant-based rental assistance, the inside area must include at least one battery-operated or hard-wired smoke detector, in proper working condition, on each level of the property. For the unit, there must be at least one battery-operated or hard-wired smoke detector, in proper working condition on each level of the unit, inside each bedroom, within 21 feet of any door to a bedroom measured along a path of travel, and where a smoke detector installed outside a bedroom is separated from an adjacent living area by a door, a smoke detector must also be installed on the living area side of the door. Additionally, if the unit is occupied by any hearing-
                        <PRTPAGE P="756"/>
                        impaired person, the smoke detectors must have an alarm system designed for hearing-impaired persons. For both the inside area of the building and the unit, the Secretary is able to establish additional standards through 
                        <E T="04">Federal Register</E>
                         publication.
                    </P>
                    <HD SOURCE="HD3">B. Accepting NSPIRE Inspections</HD>
                    <P>
                        The Department is revising § 92.251(b)(1)(viii)(A), § 92.251(f)(3)(i)(B), and § 92.251(f)(4)(ii) in response to commenters that stated HUD should not restrict the acceptance of NSPIRE inspections to only those made under another HUD program. The Department understands that there are other projects using non-HUD funding, such as LIHTC projects, that may use inspections to the NSPIRE standards to demonstrate compliance with the requirements for those funding sources. The Department will allow a PJ to accept inspections to the NSPIRE standards or another alternative inspection standard HUD may establish through 
                        <E T="04">Federal Register</E>
                         publication. The inspections must be in satisfaction of another funding source's requirements and conducted within the timeframes established for the applicable regulations.
                    </P>
                    <HD SOURCE="HD3">C. Meeting Property Standards After Acquisition of Homeownership Housing</HD>
                    <P>In response to comment, the Department is revising § 92.251(c)(3)(ii)(C) and adding § 92.251(c)(3)(ii)(D) to give PJs the ability to provide homebuyers an extension of the six-month deadline for bringing a substandard homeownership unit into compliance with the PJ's property standards.</P>
                    <P>While the Department strongly encourages PJs to provide homeownership assistance to homebuyers purchasing housing that already meets their property standards, this is not always possible. Because there will be times where homebuyers wish to purchase properties that do not meet the PJ's property standards, the Department is revising its regulations to be flexible enough to allow PJs and homebuyers to bring a unit up to the PJ's property standards after purchase.</P>
                    <P>The Department continues to believe that six months is the appropriate amount of time to provide a homebuyer to comply with a PJ's property standards. However, every construction project is different, and each jurisdiction has local requirements for permitting. In the past, due to national emergencies or disasters, homebuyers have also been affected by materials shortages. Therefore, in light of the variety of factors that can affect even minor repairs needed to bring a unit up to a PJ's property standards, the Department's revisions to § 92.251(c)(3)(ii)(C) and addition of § 92.251(c)(3)(ii)(D) will allow PJs to provide homebuyers an extension lasting up to 12 months from the date of acquisition with HOME funds to bring their unit up to the PJ's property standards. If an extension is granted, the PJ must inspect the unit within 12 months of acquisition and determine that it meets the PJ's property standards.</P>
                    <HD SOURCE="HD3">D. Clarifying the Application of Property Standards</HD>
                    <P>In response to public comments requesting clear requirements for when a unit must be inspected under the new construction property standards and when a unit must be inspected under the PJ's rehabilitation standards, the Department is adding a new § 92.251(d) that explains that if a project includes both rehabilitation of housing units and either new construction or reconstruction of housing units, then the PJ must apply the rehabilitation standards to the housing units that are rehabilitated and the new construction requirements to housing that is either newly constructed or reconstructed.</P>
                    <HD SOURCE="HD3">E. Sample Size for Property Inspections</HD>
                    <P>The Department solicited comment on the correct sample size for HOME project inspections in specific solicitation #4 of the proposed rule. After considering the comments received in response to this solicitation, the Department developed a chart that will provide greater clarity on how many units must be inspected in a project based on the number of HOME-assisted units within the project. Accordingly, the Department is revising § 92.251(f)(3)(iii) to require that inspections be performed in accordance with the chart. The Department is also adding clarifying text to indicate that the PJ must inspect the inspectable areas for each building containing HOME-assisted units and not just the units themselves.</P>
                    <P>
                        To determine the appropriate sample size for each project, the Department started with its minimum requirement that four units be inspected for all projects that have up to twenty units. This is because all units in small-scale housing (1-4 unit projects) must be inspected once every three years, and projects of a larger size should not be required to inspect fewer units than a small-scale housing project. This is counter to the statutory intent of the monitoring flexibilities provided for small-scale housing projects.
                        <SU>7</SU>
                        <FTREF/>
                         Additionally, the Department examined other sampling techniques in response to public comment, including the LIHTC and NSPIRE sampling methods (see 26 CFR 1.42-5 for LIHTC and 88 FR 43379 and 43380 for NSPIRE). The Department found that even with the four-unit minimum sample size requirement for projects with up to twenty units, HOME was still less burdensome than other programs and required fewer units to be inspected than did other programs.
                    </P>
                    <FTNT>
                        <P>
                            <SU>7</SU>
                             See 42 U.S.C. 12756(c).
                        </P>
                    </FTNT>
                    <P>The Department has therefore adopted its proposal for a 20 percent sample for projects containing between twenty and one hundred and thirty HOME units. Then, in response to comments requesting that the Department provide burden relief similar to that provided in LIHTC or HUD programs subject to NSPIRE, the Department adopted the sampling method that it uses under NSPIRE for projects containing greater than one hundred and thirty units. The Department believes that this approach strikes the correct balance by providing burden relief for smaller and larger projects while still requiring an appropriate amount of unit inspections occur. It also provides a clearer standard for PJs because the unit sampling for the inspection is not required to be based on a statistically valid sample.</P>
                    <HD SOURCE="HD3">F. Miscellaneous Revisions to § 92.251</HD>
                    <P>The Department is adding State and local requirements back into § 92.251(a)(3)(iii), which lists the various standards that housing must, where relevant, meet with respect to disaster mitigation. The Department believed it had provided clarifying technical revisions to this section, but did not mean to remove any additional requirements not contained in State and local codes or ordinances from the list of applicable standards. The Department also did not intend to change the meaning of that provision in any other way.</P>
                    <P>
                        The Department is revising paragraph (a)(3)(iv) to make the requirement described in that paragraph more consistent with the requirements in § 92.504(c). Instead of requiring that a PJ ensure construction contracts and documents describe the work to be undertaken, the PJ must require this to be the case. This non-substantive change will increase clarity and will make the language in paragraph (a)(3)(iv) consistent with that of the monitoring requirements provided in the written agreement provisions in 
                        <PRTPAGE P="757"/>
                        § 92.504 and of the cost principles contained in 2 CFR part 200, subpart E.
                    </P>
                    <P>
                        The Department is revising § 92.251(a)(3)(vii) to state that the green building standards will be published through a 
                        <E T="04">Federal Register</E>
                         publication.
                    </P>
                    <P>Similar to how the Department is revising § 92.251(a)(3)(iv) to make the requirements in this section more consistent with the requirements in § 92.504(c), the Department is also revising § 92.251(b)(2). Instead of requiring a PJ to “ensure” that construction meet the PJ's rehabilitation standards, the PJ must “require” this to be the case. This is already required in other regulations including the monitoring requirements provided in the written agreement provisions in § 92.504 and the cost principles contained in 2 CFR part 200, subpart E, and so is a non-substantive change made to increase clarity. § 92.251(b)(1)(vi) is being revised to align the language with the same language contained in § 92.251(a)(2)(iii).</P>
                    <HD SOURCE="HD2">24 CFR 92.252 Qualification as Affordable Housing: Rental Housing</HD>
                    <P>In response to public comment, the Department has determined that the rent limits do not apply to Federal, State, or local rental assistance or subsidy payments and is revising the third sentence of § 92.252(a) accordingly. The Department also revised the first sentence of § 92.252(a)(1) to state that if a family is participating in a program where the person pays thirty percent of their monthly adjusted income or ten percent of their monthly income as a contribution to rent, then the maximum rent due from the family is the family's contribution under that program. Commenters requested clarity on whether an owner could accept the full contract rent for a tenant in a HOME-assisted rental housing unit that was also receiving Section 8 or other forms of rental assistance even if the tenant was low-income and governed by the High HOME Rent provisions of § 92.252(a)(1).</P>
                    <P>After careful consideration, the Department determined that the changes in the Housing and Economic Recovery Act of 2008 (HERA) (Pub. L. 110-289, 122 Stat. 2654, approved July 30, 2008) not only revised the Section 8 statute, but fundamentally changed the relationship between the two programs. It is clear from HERA that the HOME Rent Limits were not meant to apply to recipients of Section 8 assistance or similar recipients of rental assistance or living in subsidized units. Prior to the passage of HERA, the only way that the Secretary was permitted to increase the rent limits was provided by 42 U.S.C. 12745(a)(1)(A). After passage of HERA, HUD determined the Secretary could also make such determination based upon misalignment between HOME rent requirements and the rent requirements of Section 8 and other similar rental assistance or subsidy programs. The Secretary determined that this change is appropriate and promotes greater alignment between the HOME program and HUD's other rental assistance programs and is revising § 92.252(a)(1) and § 92.252(a)(2) accordingly. Where a family is participating in a program where the family pays as a contribution toward rent no more than thirty percent of the family's monthly adjusted income or ten percent of the family's monthly income, then the maximum rent due from the family is the family's contribution, regardless of whether the family is occupying a High or Low HOME Rent unit. Thus, under the HOME program as changed by HERA, the HOME-assisted rental housing project owner may now accept the rent due from the tenant and the assistance or subsidy payment made under the applicable assistance or subsidy program.</P>
                    <P>The Department is revising § 92.252(a)(2)(i) to clearly reference the fair market rent being described in § 92.252(a)(1)(i) and to revise the term “fair market value” to “fair market rent” to more accurately describe the rent. § 92.252(a)(2)(ii) is also being revised to more accurately state that the rent contribution of the family in a Low HOME rent unit is 30 percent of the family's adjusted income. This is not a substantive change from the proposed rule or the current regulatory text, but it is a more accurate description of the Low HOME rent applicable to a family.</P>
                    <P>In response to comments about aligning with LIHTC on income and rents, the Department is adding the statutory language contained in 42 U.S.C. 12745(a)(1)(B)(ii) into the new § 92.252(a)(2)(iii). The provision will state that if a HOME-assisted unit “is a LIHTC unit and has rents not greater than the gross rent for rent-restricted residential units as determined under section 42(g)(2) of title 26” then it shall be a Low HOME Rent unit.</P>
                    <P>The Department is revising § 92.252(a)(3)(i) and (ii) to add explicit reference to how the zero-bedroom fair market rent is determined. This rent is established under 24 CFR part 888. In revising the rent limits, the Department also realized the requirement in § 92.252(a)(3)(ii), which currently requires that SRO units without sanitary or food preparation facilities meet the occupancy requirements of Low HOME rent units, could be identified in plain language. Instead of referring to the occupancy requirements, the provision is being revised to explain that the units are to be occupied by very low-income tenants. This is a non-substantive change to provide a clearer regulation.</P>
                    <P>In response to public comments received, HUD is clarifying in § 92.252(b) that “cable and broadband” are not included in utility allowances. Commentors asked for clarity regarding whether broadband is a utility and whether tenants can be required to pay for cable and broadband as a condition of occupying a HOME-assisted rental housing unit. The Department agrees the regulation could be clearer and included language in § 92.252(b) to clarify that in addition to telephone, “cable and broadband” are not included in utility allowances.</P>
                    <P>
                        Paragraph § 92.252(b) was also revised to add the term “applicable” when describing local public housing authority utility allowances. The Department understands multiple public housing authorities may serve a particular geographic location (
                        <E T="03">e.g.,</E>
                         State, county, city, etc.) and the Department believes that the public housing authority providing Section 8 project-based voucher assistance (if the project is assisted) or the one serving the jurisdiction that the PJ believes is most reflective of the utility consumption in the community in which the project is located should be the one used for the HOME project.
                    </P>
                    <P>The Department is making a non-substantive change to replace the word “ensure” with “require” in § 92.252(c). This change better explains the requirement that PJs must not allow owners to charge tenants in excess of the rents in § 92.252.</P>
                    <P>
                        The Department is revising the dollar thresholds that define the periods of affordability in § 92.252(d) in response to public comments. Commenters stated that the thresholds had not been adjusted for inflation and the increase in the cost of construction. The Department agrees that the thresholds have not been revised since 1991 and must be revised to account for the increase in costs.
                        <FTREF/>
                        <SU>8</SU>
                          
                        <E T="03">See</E>
                         42 U.S.C. 12745(a)(1)(E) of the Act. requires that HOME projects “will remain affordable, according to binding commitments satisfactory to the Secretary, for the remaining useful life of the property, as determined by the Secretary, without regard to the term of the mortgage or to transfer of ownership, or for such other period that the Secretary determines is the longest feasible period of time 
                        <PRTPAGE P="758"/>
                        consistent with sound economics and the purposes of this Act . . .” The Department cannot adjust the thresholds to fully account for the differences in inflation 
                        <SU>9</SU>
                        <FTREF/>
                         because the Department must balance the need for adjusting the periods of affordability to account for the increase in costs (
                        <E T="03">i.e.,</E>
                         sound economics) with the purposes of the Act, which are to produce and maintain affordable housing units.
                        <SU>10</SU>
                        <FTREF/>
                         Given the significant decrease in appropriations that the HOME program has had in both real and inflation-adjusted dollars since the inception of the current dollar thresholds, the Department can only revise the thresholds to partially account for the increase of costs.
                        <SU>11</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>8</SU>
                             The HOME thresholds came into effect in 1991 (see 56 FR 65312-01).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>9</SU>
                             By one measure, the Consumer Price Index, the dollar has increased by over 200% since the establishment of the dollar thresholds used to determine the period of affordability for the HOME program. See the CPI Inflation Calculator at 
                            <E T="03">https://data.bls.gov/cgi-bin/cpicalc.pl?cost1=1%2C000%2C000.00&amp;year1=199201&amp;year2=202310.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>10</SU>
                             See 42 U.S.C. 12722(1) and (7).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>11</SU>
                             In 1992, the Department was appropriated $1,500,000,000 for HOME, the first year of annual appropriations for the program. (See 105 STAT. 744 for Pub. L. 102-139). For Fiscal Year 2024, the Department received $1,250,000,000 for HOME. In current dollars, this is a decrease in investment in affordable housing of only $250,000,000 but when using the Consumer Price Index to calculate the inflation-adjusted decrease, it is a decrease of over 50% of the initial investment made in affordable housing.
                        </P>
                    </FTNT>
                    <P>Accordingly, the Department will revise the initial threshold for rehabilitation or acquisition of existing housing per-unit amount of HOME funds from $15,000 to $25,000. If the per-unit cost of rehabilitation and/or acquisition of existing housing is below $25,000, then the minimum period of affordability for each HOME-assisted housing unit is five years. The Department is revising the second threshold from $40,000 to $50,000. If the per-unit cost of rehabilitation and/or acquisition of existing housing is from $25,000 to $50,000, then the minimum period of affordability shall be ten years for each HOME-assisted rental housing unit. For rehabilitation and/or acquisition of existing housing, if the per-unit cost is over $50,000 for each HOME-assisted rental housing unit, then the minimum period of affordability is fifteen years.</P>
                    <P>While the Department is revising the dollar thresholds for the periods of affordability involving rehabilitation and/or acquisition, the Department has chosen to maintain the period of affordability for new construction and for rehabilitation involving refinancing. The Department believes that the useful life of the property or the longest feasible period of time is consistent with sound economics and the purposes of this Act is still twenty years for HOME rental housing projects involving new construction. Similarly, the Department believes that properties where rehabilitation involves refinancing should also continue to be subject to a period of affordability of fifteen years, as the refinancing and rehabilitation of the property to the PJ's rehabilitation standards should adequately extend its useful life to a period of fifteen years. If the rehabilitation and refinancing action cannot ensure that the property remains capable of operating as affordable housing for a period of fifteen years, then the project is not feasible or furthering the purposes of the Act.</P>
                    <P>The Department is revising the first sentence of § 92.252(g) and § 92.252(g)(3) to include reference to the new safe harbor in § 92.203(a)(3). This revision allows a PJ to use the safe harbor in § 92.203(a)(3) in the calculation of both initial and annual income determinations instead of using source documents, as required in § 92.203(b)(1)(i). The Department is also revising the first sentence of § 92.252(g) to reference income provisions for HOME tenant-based rental assistance tenants, which have been moved to § 92.203(b)(3) from § 92.203(b)(2).</P>
                    <P>The Department is revising § 92.252(g)(1) to provide a chart clarifying the alternative income reexamination cycle for small-scale rental projects that a PJ may permit. The Department is also revising § 92.252(g)(2) to specify that rental projects, including small-scale projects, must reexamine tenant income using source documentation every sixth year of the period of affordability.</P>
                    <P>The Department is revising § 92.252(h)(2)(i) for readability by striking “section 42” and instead stating that over-income tenants subject to the rent restrictions under section 42 of the Internal Revenue Code of 1986 must pay a rent that complies “with that section.” This is clearer and less wordy. The Department is adding a new paragraph § 92.252(h)(2)(iii) that will explain that rent limits do not apply to rental assistance or subsidy payments under any Federal, State, or local rental assistance or subsidy program. This is because when tenants become over-income in certain rental assistance programs, such as the Housing Choice Voucher program, the tenant still pays a percentage of their rent, such as thirty percent of their rent, up to the contract rent for the housing unit. This means that there may still be subsidy or assistance from the rental assistance provider until the tenant is paying the full contract rent. If owners were unable to accept this rent, then it would undermine the purposes of HERA, as explained earlier for High and Low HOME Rents. As such, the Department providing the same clarification it did in paragraph § 92.252(a), which is that the rent does not include the rental assistance provided by the rental assistance or subsidy provider.</P>
                    <P>Paragraph § 92.252(i) was revised similar to other provisions to state that surety bonds, security deposit insurance, or instruments similar to surety bonds and security deposit insurance may not be used in lieu of or in addition to a security deposit in HOME-assisted units. This is a clarifying change for readability and not a substantive change from the proposed rule.</P>
                    <HD SOURCE="HD2">24 CFR 92.253 Tenant Protections and Selection</HD>
                    <P>The Department is making significant changes to its tenant protection provisions in response to public comment. Based on comments received as part of the specific solicitation of comment #10, the Department has chosen to create three tenancy addenda for the HOME program, one for each type of HOME rental activity (rental housing, tenant-based rental assistance, security deposit assistance only). The requirements for each addendum shall be provided in paragraphs (b)-(d) accordingly. The Department is also reorganizing the tenant protections regulations by removing the current security deposit and termination of tenancy provisions found in paragraphs (c) and (d) and instead placing them directly into the applicable tenancy addendum. The Department believes these changes allow HUD to tailor the protections to the form of assistance being received under the HOME program and should decrease any potential chilling effects that an addendum may have on private owners accepting tenants with HOME tenant-based rental or security deposit assistance.</P>
                    <P>
                        The Department also believes reorganizing the tenant protections to include the security deposit requirements and termination of tenancy provisions into the applicable tenancy addenda for rental housing and tenant-based rental assistance is more legally supportable and consistent with other HUD programs. Section 42 U.S.C. 12755(a)(1) provides an explicit congressional delegation of authority to the Secretary to determine the terms and conditions of leases in the HOME program. Security deposit requirements and termination of tenancy provisions are material terms to a lease and other 
                        <PRTPAGE P="759"/>
                        HUD programs include specific provisions addressing each in their tenancy addenda, including in the Section 8 voucher programs.
                        <SU>12</SU>
                        <FTREF/>
                         The Department believes this is the most legally sound way of requiring PJs and owners to comply with the tenant protections and that it will better enable beneficiaries of HUD programs to assert their legal rights and defenses. Commenters had also specifically requested that the Department add the security deposit provisions within the tenancy addendum, as those are traditionally contained in a lease, and the Department agrees.
                    </P>
                    <FTNT>
                        <P>
                            <SU>12</SU>
                             See HUD Form 52641A for the Housing Choice Voucher Program Tenancy Addendum and Form HUD 52530.c for the Section 8 Project-based Voucher Program Tenancy Addendum.
                        </P>
                    </FTNT>
                    <P>Accordingly, the Department is revising paragraph § 92.253(a) by adding a “(1)” after lease contents and redesignating § 92.253(a)(1)-(4) as § 92.253(a)(1)(i)-(iv). Paragraph § 92.253(a)(1)(iv)(A) shall also be revised to require that a lease of a tenant in HOME rental housing include the HOME rental housing tenancy addendum described in § 92.253(b). Paragraph § 92.253(a)(1)(iv)(B) is being added and shall require that a lease of a tenant in HOME tenant-based rental assistance include the HOME tenant-based rental assistance tenancy addendum described in paragraph § 92.253(c).</P>
                    <P>A separate paragraph § 92.253(a)(2) is being added and shall provide the lease requirements for security deposit assistance only recipients. After reviewing the comments received as part of the solicitation of public comment, the Department determined that it was not appropriate to require that tenants and owners use the HOME tenant-based rental assistance tenancy addendum. Security deposit assistance is fundamentally different than other forms of assistance under the HOME program. It is a one-time form of assistance that is inherently short-term in nature. The assistance is primarily intended as a form of emergency assistance for families whose primary barrier to obtaining housing is the security deposit. Many times, this assistance is also paired with long-term assistance in other programs that comes with their own protections. The HOME tenant-based rental assistance tenancy addendum contemplates a contractual relationship between the PJ and the owner because of the updated rental assistance contract requirements contained in § 92.209(e). Security deposit assistance, in contrast, is of limited duration, lasting only the issuance of the initial assistance.</P>
                    <P>Instead of requiring the HOME tenant-based rental assistance tenancy addendum, the Department is requiring a security deposit assistance tenancy addendum. Paragraph § 92.253(a)(2) shall require a written lease between the tenant and the owner that is for a period of not less than 1 year, unless by mutual agreement between the tenant and the owner, a shorter period is specified. This mirrors the requirements for both rental housing and tenant-based rental assistance. Likewise, to determine that the HOME security deposit assistance tenancy addendum is included in the lease, the owner must also provide the PJ with a written lease before security deposit assistance is provided. This mirrors the new requirements for both rental housing and tenant-based rental assistance. Then, the paragraph requires that the lease contain the HOME security deposit assistance tenancy addendum in paragraph (d) of this section.</P>
                    <P>The Department received a significant amount of comment on its proposed tenant protections that represented a spectrum of participants in the HOME program including PJs, owners, CHDOs, tenant rights and advocacy organizations, fair housing and civil rights organizations, and associations. These comments ranged from unqualified support to complete opposition. The Department considered the comments and determined that the vast majority of its proposed text was appropriate for a rental housing tenancy addendum. However, based on public comment and the reorganization of the regulation, the Department did make a number of revisions since the proposed rule stage.</P>
                    <P>The introductory text in § 92.253(b) has been clarified to indicate that the tenancy addendum being described is the HOME “rental housing” tenancy addendum. The second sentence was also revised to include addenda from local affordable housing programs in addition to other Federal or State affordable housing programs. The Department did not intend to inadvertently exclude HOME-assisted tenants from receiving other forms of local affordable housing assistance and believes this revision is responsive to public comments that warned HUD not to create conflicts with local programs. Paragraph (b)(1)(ii)(A) is being revised to clarify that with respect to maintenance and repairs to a housing unit, the owner shall provide tenants with written expected timeframes for maintaining or repairing units as soon as practicable. A written record is more protective of a participating jurisdiction, owner, and tenant alike, as it provides each clear evidence of when work is expected to occur.</P>
                    <P>The Department is revising paragraph (b)(2)(i) because while it is true that a family may reside in the unit with a foster child, foster adult, or live-in aide, the family must still comply with all applicable occupancy requirements when living in HOME-assisted rental housing. The Department did not intend to preempt or override State or local occupancy laws or HUD's own occupancy restrictions in other programs whose assistance may be combined with HOME assistance, such as Section 8 project-based rental assistance. The Department notes that any reasonable accommodations must still be made in accordance with all applicable laws regarding nondiscrimination and accessibility. In § 92.253(b)(5), the owner is separately agreeing not to interfere with or retaliate against the tenant for asserting their rights, which include the right to request a reasonable accommodation for a live-in aide. In § 92.253(b)(8), the owner is also agreeing to operate HOME rental housing in accordance with all applicable nondiscrimination and equal opportunity requirements pursuant to § 92.350. As a result, the Department does not believe that this revision will negatively impact tenant protections. This revision was made in response to public comments that requested HUD reexamine the tenant protections to determine that they did not conflict with State or local law or with other Federal programs.</P>
                    <P>The Department is revising the term “dwelling” to “housing” in § 92.253(b)(2)(iii), (b)(2)(iii)(A), and (b)(2)(iii)(C). The Department is also revising § 92.253(b)(2)(iii)(C) in response to public comment urging HUD to require that owners provide tenants with written notice of the date, time, and purpose of the owner's entry if the owner must enter the housing without advance notification when there is reasonable cause to believe that an emergency requiring entry to the unit exists. The commenter was supportive of this approach and believed it would be protective for the tenant. The Department agrees and believes this provision will improve communication between owners and tenants of HOME-rental housing.</P>
                    <P>
                        In response to public comment, the Department is revising § 92.253(b)(3)(i) to require that owners provide tenants with written accessible notice of the specific grounds for proposed adverse actions by the owner against the tenant before taking such actions. The 
                        <PRTPAGE P="760"/>
                        Department had proposed to provide this as simply a notification requirement. One commenter recommended that instead, the Department revise the provision to make the adverse action itself contingent upon providing the tenant notice. The Department believes this is a sensible approach and that it may enable tenants to assert any rights or protections prior to the imposition of any charges or other adverse actions. In revising § 92.253(b)(3)(i), the Department is also clarifying that the notification of the adverse action must be translated if required for the tenant to understand the notice. Tenants and owners have an existing landlord-tenant relationship and so it should not be overly burdensome to ensure that tenants are able to read the written notice in a language they can understand. Similar changes were made to § 92.253(c)(3)(i).
                    </P>
                    <P>The Department is also revising § 92.253(b)(3)(ii) to more clearly state when tenants must be notified of changes in the ownership and management of the rental housing project. Paragraph § 92.253(b)(3)(ii)(A) will specify that an owner must notify tenants within 30 calendar days of the impending sale or foreclosure of a rental housing project. Paragraph § 92.253(b)(3)(ii)(B) specifies that owners must notify tenants within five business days of a change in ownership. These requirements were both in the proposed rule. The Department added as a new requirement that owners not only notify tenants within five business days of any changes in ownership but also any changes in property management companies managing the property as § 92.253(b)(3)(ii)(C). This change, being made to was in response to public comments that believed that such notification should include property managers and not just owners. Property managers have significant involvement in the operation of the property and are agents or employees acting on behalf of HOME rental housing owners. When an owner obtains a different property management company, it can have significant impacts on the daily life of tenants. The Department believes it is important to keep tenants informed in advance of such impacts and that this improved communication may help both owners and tenants. Similar additions are made to § 92.253(c)(3)(ii).</P>
                    <P>The Department is revising § 92.253(b)(4)(v) to narrow the instances in which a tenant must pay an owner's attorney fees or other legal costs as part of a court proceeding. In the proposed rule, the Department proposed language to allow payment of such costs if the tenant loses the court proceeding. In response to public comment stating that the Department should examine local and State laws to determine that the tenant protections in § 92.253 are not in conflict with such requirements, the Department determined that this provision may conflict with State or local laws that would not permit payment of attorney's fees or other legal costs, even if the tenant were to lose the matter. Moreover, as courts hearing landlord-tenant disputes are making findings of fact and law based on the individual circumstances of each case, it should be up to those courts to determine whether tenants should pay these costs. Therefore, the revised requirement will state that a tenant is only required to pay the owner's attorney fees or other legal costs if the tenant loses the court proceeding and the court orders the tenant to pay those costs.</P>
                    <P>The Department is significantly revising § 92.253(b)(5) to address a number of comments received about the effectiveness of the provisions in protecting tenants. First, the heading for the section is being revised to explicitly include “unreasonable interference” to be clear that unreasonable interference with the tenant's safety or peaceful enjoyment of their property is a subject of the provision and that the provision is not only prohibiting retaliation. Commenters reasonably believed that the section was only describing retaliation because the heading did not specify otherwise. Similarly, unreasonable interference is now being separately prohibited in § 92.253(b)(5)(i). The terminology is also being revised from the proposed rule to remove the term “comfort” and instead state “tenant's safety or peaceful enjoyment of a rental unit or the common areas of the rental housing project.” The Department recognizes that there is significant landlord-tenant case law on the term “peaceful enjoyment” and that it is a far more recognized term than “enjoyment.” The Department believes this change will improve the ability for courts to determine the meaning of the provision in relation to their jurisdictions and governing law. The revision to address common areas also reflects consistency with protections in § 92.253 that allow tenants reasonable access to and use of the common areas of the project (see § 92.253(b)(2)(iv)).</P>
                    <P>The Department then revised § 92.253(b)(5)(ii) to prohibit an owner from retaliating against a tenant for taking any action allowable under the lease and applicable law. The rule provides a variety of actions that a tenant may take under a lease and the Department believes that retaliating against a tenant for using any of these protections is a breach of the lease and of the owner's written agreement with the participating jurisdiction. Section 92.253(b)(5)(iii) provides a list of actions that evidence unreasonable interference or retaliation against a tenant. The Department stresses that this language is providing examples and that it is not a limited list. The actions taken are the same actions that were prohibited in the proposed rule, but the list has been redesignated § 92.253(b)(5)(iii)(A)-(E), and § 92.253(b)(5)(iii)(B) has been revised to add a parenthetical to give an example of what it means to be increasing obligations of a tenant in a manner that is not in accordance with 24 CFR part 92. The example given is of new or increased monetary obligations, such as the addition of new or increased fees. This is just an example of monetary obligations but nonmonetary obligations like new property rules could also be considered retaliatory acts under this regulation under the right circumstances.</P>
                    <P>In response to public comments requesting that the Department specify the consequences of unreasonably interfering with a tenant's safety or peaceful enjoyment or retaliating against a tenant for exercising a right under their lease or the law, the Department has added a new § 92.253(b)(5)(iv). This new provision explains that if an owner unreasonably interferes or retaliates against a tenant, then the owner is violating the lease, the HOME program requirements, and their written agreement with the participating jurisdiction. While the Department has no authority to require that a participating jurisdiction establish a grievance process, the participating jurisdiction is required to address any regulatory violations in accordance with the applicable provisions contained in § 92.504(a) and (c). This applicability is made clearer by adding explicit cross references.</P>
                    <P>
                        The Department is also revising § 92.253(b)(5)(ii) of the proposed rule, which is being revised and redesignated as § 92.253(b)(6). The new § 92.253(b)(6) has a revised header that explains that the section is describing the exercise of rights under tenancy. The revised first sentence explains that the tenant can exercise any right of tenancy or protection under their lease and other applicable Federal, State, or local tenant protections. Then the Department redesignated § 92.253(b)(5)(ii)(A)(C) as § 92.253(b)(6)(i) through (iii) and revised § 92.253(b)(6)(ii) to also allow for a tenant to report lease violations in 
                        <PRTPAGE P="761"/>
                        addition to requesting enforcement of the lease or any tenant protections. The Department believes that reporting such lease violations are inherent in requesting enforcement but believes that it is best to be explicit, given that the provision is also contained in the lease addendum.
                    </P>
                    <P>The Department redesignated the proposed § 92.253(b)(6) and (7) as § 92.253(b)(7) and (8). In response to public comments, the Department also redesignated § 92.253(c) as § 92.253(b)(9). The same provision will also be included in § 92.253(c)(9). This provision, which provides the requirements for security deposits, should be contained in the tenancy addenda and not contained in a standalone regulation. As explained earlier in this preamble, the Department has clear authority to specify the terms and conditions of the lease under 42 U.S.C. 12755 and security deposits are a material term of the lease. Therefore, the Department is moving the security deposit provisions from a standalone section of the regulation and instead making the language a part of each HOME tenancy addendum. The Department is also revising § 92.253(b)(9) to state that “Surety bonds, security deposit insurance, and instruments similar to surety bonds or security deposit insurance may not be used in lieu of or in addition to a security deposit.” This is a non-substantive clarification of the text.</P>
                    <P>Similarly, one of the most important provisions of a lease concerns termination of tenancy. The Department understands how central these terms are to a lease and is also including termination of tenancy provisions in the lease addendum. Section 92.253(d)(1) of the proposed rule and all its contents are being redesignated as § 92.523(b)(10)(i)-(v) and being revised.</P>
                    <P>Section 92.253(b)(10)(i) is being revised from the proposed rule to clarify that good cause includes serious or repeated violation of the “material” terms and conditions of the lease. The Department adds the word “material” because good cause is a higher standard and minor lease violations, especially when easily curable or already cured, should not provide the basis for a termination of tenancy or refusal to renew tenancy in a HOME rental housing project. The Department still believes that serious or repeated violations of the material terms of the lease, such as nonpayment of rent or intentionally damaging the project, can form the basis of a termination of tenancy or refusal to renew.</P>
                    <P>Section 92.253(b)(10)(i) is also being revised to add a provision that states that an owner is permitted to terminate the tenancy of any tenant or household member or refuse to renew the lease of a tenant of rental housing assisted with HOME funds if the owner is permitted to do so pursuant to the provisions contained in 24 CFR part 5, subpart I; 24 CFR 882.511; or 24 CFR 982.310. This change is in response to public comments and to maintain consistency across HUD programs. Owners with tenants assisted under programs that are subject to these lease provisions must be allowed to terminate tenancy in accordance with the U.S. Housing Act of 1937 (42 U.S.C. 1437f) and the Department is allowing for a consistent approach for termination of tenancy under the HOME program for those assisted tenants.</P>
                    <P>Section 92.253(b)(10)(i)(A) is being revised from the proposed rule. The provision will state that refusal to purchase a HOME rental housing unit is not good cause to terminate a tenancy. The provision will provide an exception for when a family fails to purchase housing pursuant to a lease-purchase agreement. This was in response to public comment, which pointed out that owners must be able to sell units when the tenant fails to purchase the home in accordance with their lease-purchase agreement. The Department agrees and allows for this to be good cause to terminate a tenancy.</P>
                    <P>Section 92.253(b)(10)(i)(B) is being restructured to specify other good cause and then list each ground individually. This was done to improve readability of this section. Two grounds for good cause were added and one was significantly revised.</P>
                    <P>
                        The first form of good cause being added to § 92.253(b)(10)(i)(B)(
                        <E T="03">1</E>
                        ) is when a tenant or household member is a direct threat to the safety of the tenants or employees of the housing or an imminent and serious threat to the property, which is a statutory ground that commenters requested be considered in the termination of tenancy or refusal to renew.
                        <SU>13</SU>
                        <FTREF/>
                         The Department agrees that owners should be able to terminate tenancy for this reason and is adding this as a specific ground. The Department requires owners to maintain records to demonstrate that they complied with the tenant protections provisions, including records demonstrating there is a reasonable basis to determine that a person constituted a direct threat to safety of the tenants or employees of the housing or an imminent and serious threat to the property. This could include specific threats or acts that took place on the project site, against other families living in the project, or against any employees or staff of the owner. The Department believes that posing a direct threat to the safety of tenants or employees is a high bar and not satisfied easily. Similarly, forming the basis for an imminent and serious threat to the property is a higher bar than just describing past negligent acts alone, and brings with it an expectation that there is a specific or credible threat or act made by the tenant or household member against the property.
                    </P>
                    <FTNT>
                        <P>
                            <SU>13</SU>
                             42 U.S.C. 12755(b) states: “An owner shall not terminate the tenancy or refuse to renew the lease of a tenant of rental housing assisted under this subchapter except for serious or repeated violation of the terms and conditions of the lease, for violation of applicable Federal, State, or local law, or for other good cause. Any termination or refusal to renew must be preceded by not less than 30 days by the owner's service upon the tenant of a written notice specifying the grounds for the action. Such 30-day waiting period is not required if the grounds for the termination or refusal to renew involve a direct threat to the safety of the tenants or employees of the housing, or an imminent and serious threat to the property (and the termination or refusal to renew is in accordance with the requirements of State or local law).”
                        </P>
                    </FTNT>
                    <P>
                        The second form of good cause added to § 92.253(b)(10)(i)(B)(
                        <E T="03">5</E>
                        ) allows an owner to terminate a tenant's tenancy terminated if the tenant fails to purchase the housing within the timeframes listed in the tenant's lease-purchase agreement. The intent of a lease-purchase program is for the tenant to purchase the unit. If the unit cannot be purchased pursuant to the lease-purchase agreement within 36 months, then the owner must be able to sell the unit to an eligible homebuyer to effectuate the intent of the homeownership development project. The Department has revised § 92.254(a)(7) to further enable owners to sell homeownership units that fail to be purchased pursuant to their lease-purchase agreement and though those changes are not interdependent with the tenant protections provisions contained in § 92.253, the Department is maintaining consistency between the requirements.
                    </P>
                    <P>
                        One form of good cause was substantively revised since the proposed rule is contained in the newly redesignated § 92.253(b)(10)(i)(B)(
                        <E T="03">2</E>
                        ). This form of good cause was revised to state that other good cause includes when a tenant unreasonably refuses to provide the owner access to the unit to allow the owner to repair the unit. The provision originally contained language permitting termination of tenancy or refusal to renew tenancy if the tenant creates a documented nuisance under applicable State or local law. The comments received for that provision were decidedly negative and there were significant concerns that this provision 
                        <PRTPAGE P="762"/>
                        was not only inconsistent with the rest of the tenant protections but counterproductive to the overall tenant protection scheme by providing an often-used avenue for discrimination. The Department agrees with commenters and is removing the provision, thereby clarifying that owners may not justify termination of tenancy on outdated or discriminatory concepts of nuisance but instead must rely upon good cause.
                    </P>
                    <P>Section 92.253(d)(1)(i)(D) is being redesignated and revised as § 92.253(b)(10)(i)(C). The provision is also being revised directly in response to public comment. The public was concerned that the meaning of a record of conviction of a crime that bears directly on the tenant's continued tenancy was too vague to be an appropriate legal standard to apply to landlord-tenant relationships. The commenters believed that the Department should be more specific to ensure the regulation and protections are applied correctly. The Department agrees. Based on the public comment, the Department is revising the language to specify that the violations of applicable Federal, State, or local law must be for convictions of a crime that directly threatens the health, safety, or right to peaceful enjoyment of the premises by other tenants in the project. The Department continues to believe that termination of tenancy is a fact-specific matter and that it is impossible to provide an exhaustive list of all the grounds or considerations that one must consider prior to termination. Criminal convictions may impact continued tenancy but only to the extent that such convictions interfere with the rights of others who live in the project. Minor violations of law that do not impact people living in the housing should not form the basis for terminating tenancy or refusing to renew a lease in the HOME program.</P>
                    <P>Paragraph § 92.253(d)(1)(ii) is being redesignated as § 92.253(b)(10)(ii) and revised. The first and second sentence are revised to only provide 30 days' notice prior to termination of tenancy or refusal to renew, and to specify that the 30-day requirement does not apply to the statutory grounds for termination relating to tenants that are a direct threat to the safety of the tenants or employees of the housing or an imminent and serious threat to the property. The Department received overwhelmingly negative comments from the public on the negative effects of requiring a longer notice period before termination or refusal to renew. Some commenters explained the variation of eviction timeframes across the country. Others explained how adding an additional 30 days to the notice period impacted the average eviction process and the average owner in their jurisdiction. Organizations that represented owners and affordable housing managers described how these changes negatively impact the financial feasibility of current and future HOME projects. There were commenters who supported the change, and most indicated that it would better assist tenants in curing or preventing termination of tenancy. The Department also considered what it had done in other programs and the effort to make a consistent 30 day notice standard. On the whole, when the Department considered the potential negative ramifications and how the extension to 60 days was inconsistent with other Departmental efforts, the Department decided to withdraw the proposal to extend the notice period to 60 days and is revising the paragraph accordingly. Paragraphs § 92.253(d)(1)(iii) through (v) are redesignated as § 92.253(b)(10)(iii) through (v). Paragraph § 92.253(d)(1)(v) is also being revised to specify that an owner may not create a hostile living environment or refuse to provide a reasonable accommodation to cause a tenant to terminate their tenancy. The proposed rule had initially just stated that the owner cannot refuse to make a reasonable accommodation, but changes are now being made to cover situations where an owner refuses to permit a lawful reasonable accommodation with the intent of constructively evicting a person.</P>
                    <P>A new paragraph (c) is being added to § 92.253. This section will provide the tenancy addendum requirements for the HOME tenant-based rental assistance program. The opening paragraph mirrors the opening paragraph for § 92.253(b) and specifies that the terms of the HOME tenant-based rental assistance tenancy addendum shall prevail over any conflicting provisions of the lease. The terms and conditions of the written lease, the HOME tenant-based rental assistance tenancy addendum, the VAWA addendum listed in § 92.253(a), and any addendum required by another Federal, State, or local affordable housing program are the sole and entire agreement between the owner and the tenant and no prior or contemporaneous oral or written representation or agreement between the owner or tenant shall have legal effect. This is the same as the new rental housing requirements and provides sufficient protections to ensure that the owner does not later claim that the tenant agreed to something that would be prohibited under the tenant protections or applicable law. Paragraph § 92.253(c) also states that the HOME tenant-based rental assistance tenancy addendum shall terminate upon termination of the rental assistance contract. Initially, the Department had proposed that the lease terminate upon termination of the rental assistance contract but determined that it was best left to the owner and tenant as to when the lease shall terminate. Instead, the tenancy addendum shall terminate, as the tenant is no longer being assisted with HOME tenant-based rental assistance. Then the paragraph provides the same list of tenant protections contained in the HOME rental housing tenancy addendum paragraph (b) except for:</P>
                    <P>1. The provision in § 92.253(b)(1)(iii) which requires an owner to repair a life-threatening deficiency impacting the tenant, and requires, if the repairs cannot be completed on the day the life-threatening deficiency is identified, the owner to promptly relocate the tenant into housing that is decent, safe, sanitary, and in good repair and that provides the same or a greater level of accessibility, or other physically suitable lodging, at no additional cost to the tenant, until the repairs are completed. The Department recognizes that this type of provision may have a chilling effect on owner participation in the tenant-based rental assistance program and is removing the requirement. If participating jurisdictions wish to provide this requirement as part of the rental assistance contract, then they still retain discretion to do so.</P>
                    <P>2. Section 92.253(b)(2)(v) allowing tenants to organize, create tenant associations, convene meetings, distribute literature, and post information. This provision may have a chilling effect on owners and may deter participation in the tenant-based rental assistance program. Though the Department believes that tenants should have the right to organize tenant associations, rental assistance provided through HOME tenant-based rental assistance is not of the same durable nature as development subsidies provided to owners and developers producing HOME rental housing. Requiring that owners allow organizing activities when the participating jurisdiction has far fewer incentives to encourage owners to comply disadvantages tenants and participating jurisdictions who are already contending with source of income discrimination in many jurisdictions.</P>
                    <P>
                        3. Paragraph § 92.253(c)(9)(iii) will permit tenants that are already in a lease 
                        <PRTPAGE P="763"/>
                        before they enter into a rental assistance contract to have fulfilled the security deposit requirements of paragraph § 92.253(c)(9) even if the family used an instrument prohibited under paragraph (c)(9)(i). This was due to comment that rightly explained that tenants under a lease may have already used surety bonds, security deposit insurance, or instruments similar to surety bonds and security deposit insurance before they ever received HOME tenant-based rental assistance. While the Department does not encourage the use of these instruments and has determined that they are neither legally security deposits nor is their use advantageous to either owners or tenants, the Department does not want to penalize tenants or place obstacles in the way of tenants attempting to use tenant-based rental assistance.
                    </P>
                    <P>Other than the above-described protections, § 92.253(c)(1)-(9) is substantively the same as § 92.253(b)(1)-(9). The Department believes that this is appropriate. Recipients of tenant-based rental assistance should have substantively the same protections as tenants in HOME-assisted rental housing.</P>
                    <P>The Department did want to highlight that for the retaliation provision contained in § 92.253(c)(5)(iv), the Department understands that participating jurisdictions may have limited leverage to require that owners unreasonably interfering with or retaliating against individuals with HOME tenant-based rental assistance stop their actions. The participating jurisdiction must use their best judgment about how to address such circumstances, including balancing the needs of the tenant to the continued tenant-based rental assistance and the participating jurisdiction's obligation to enforce compliance with the owner's rental assistance contract with the participating jurisdiction. However, the Department is declining to remove this protection, as it is a meaningful and necessary tenant protection for all the reasons given in the proposed rule.</P>
                    <P>The termination of tenancy provisions that were contained in paragraph § 92.253(d)(2) are being revised and redesignated from the proposed rule to be included in § 92.253(c)(10). First, just as in the HOME rental housing termination provisions in § 92.253(b)(10)(i), the tenant-based rental assistance provisions are being included in a new paragraph § 92.253(c)(10)(i) that states that an owner may not terminate the tenancy of any tenant or household member or refuse to renew the lease of a tenant with tenant-based rental assistance, except for serious or repeated violation of the material terms and conditions of the lease; for violation of applicable Federal, State, or local law; for completion of the tenancy period for transitional housing or failure to follow any required transitional housing supportive services plan; or for other good cause. This mirrors the HOME rental housing section but does not include the additional specific grounds that allows owners to terminate the tenancy of any tenant or household member or refuse to renew the lease of a tenant of rental housing assisted with HOME funds if the owner is permitted to do so pursuant to the provisions contained in 24 CFR part 5, subpart I; 24 CFR 882.511; or 24 CFR 982.310. This is because the Department has determined that this is not applicable to the recipients of HOME tenant-based rental assistance, who would not be living in units receiving subsidy or assistance under the Section 8 program.</P>
                    <P>Similar to § 92.253(b)(10)(i)(A), § 92.253(c)(10)(i)(A) also states that an increase in the tenant's income or assets, the amount or type of income or assets the tenant possesses does not constitute good cause. The section also states that except in the case of a lease-purchase agreement, other good cause also does not include refusal of the tenant to purchase the housing. These protections are substantively the same as the HOME rental housing protections.</P>
                    <P>
                        The provisions on good cause in § 92.253(c)(10)(i)(B) differ from the proposed rule in several respects. Section 92.253(d)(2)(i)(A) and (B) of the proposed rule are being redesignated as § 92.253(c)(10)(i)(B)(
                        <E T="03">2</E>
                        ) and (
                        <E T="03">3</E>
                        ). Section 92.253(c)(10)(i)(B)(
                        <E T="03">1</E>
                        ) is added and is substantively the same as the statutory grounds for termination of tenancy and refusal to renew that were added to § 92.253(b)(10)(i)(B)(
                        <E T="03">1</E>
                        ). If a tenant or household member constitutes a direct threat to the safety of tenants or employees of the housing or an imminent and serious threat to the property, an owner must have the ability to terminate the tenancy or refuse to renew the lease. For the reasons given earlier in this preamble, this is a high standard to meet, and the owner must be able to document how they arrived at this determination. Section 92.253(d)(2)(i)(C) is being revised and redesignated as § 92.253(c)(10)(i)(B)(
                        <E T="03">4</E>
                        ). The sentence shall now only describe when a tenant unreasonably refuses to provide an owner with access to repair the unit. Section 92.253(d)(2)(i)(D) of the proposed rule is being redesignated as § 92.253(c)(10)(i)(B)(
                        <E T="03">5</E>
                        ). Section 92.253(d)(2)(i)(E) of the proposed rule, which provided the termination of the rental assistance contract as grounds for termination of the tenant lease is being removed. The Department received negative comments on this provision and recognizes that this is a decision best left to the owner and the tenant. After the rental assistance contract expires, the tenancy addendum will also terminate. The owner may continue to lease the unit to the tenant under the terms of the tenant lease. Section 92.253(d)(2)(i)(F) introductory text and (d)(2)(i)(F)(
                        <E T="03">1</E>
                        ) of the proposed rule are being combined and redesignated as § 92.253(c)(10)(i)(B)(
                        <E T="03">6</E>
                        ). Section 92.253(d)(2)(i)(F)(
                        <E T="03">2</E>
                        ) is likewise being revised for readability and redesignated as § 92.253(c)(10)(i)(B)(
                        <E T="03">7</E>
                        ).
                    </P>
                    <P>
                        The Department added a new ground for good cause in response to public comment. Section 92.253(c)(10)(i)(B)(
                        <E T="03">8</E>
                        ) states that if a tenant fails to purchase a housing unit within the timeframes of a tenant's lease purchase agreement, then this shall be good cause to terminate the tenancy. Commenters requested that this be a ground for termination because otherwise, the owner would be required to continue to rent to the family, even though the family would be in breach of their lease purchase agreement. This would disadvantage owners who wished to sell the homeownership units after a tenant fails to purchase the housing and would disincentivize lease-purchases.
                    </P>
                    <P>Section 92.253(d)(2)(ii) is being redesignated as § 92.253(c)(10)(ii) and revised to remove the 5-business day requirement for the owner to notify the participating jurisdiction that it has served a notice to vacate to a tenant. This is because the new tenant-based rental assistance rental assistance requirements require the owner and participating jurisdiction to have a rental assistance contract (see § 92.209(e)). Therefore, instead of requiring a time period in the regulation, the regulation will defer to the rental assistance contract or the participating jurisdiction's policies and procedures to govern the issuance of notice to the participating jurisdiction. The citation in the last sentence was also revised because of the redesignation of the paragraph.</P>
                    <P>
                        Paragraphs § 92.253(d)(2)(iii) and (iv) are being redesignated as § 92.253(c)(10)(iii) and (iv) without change. Paragraph § 92.253(d) is being added to add security deposit assistance tenancy addendum requirements. The addendum shall prevail over conflicting terms of the lease. The terms and conditions of the written lease, the HOME security deposit assistance tenancy addendum, and any addendum required by another Federal, State, or 
                        <PRTPAGE P="764"/>
                        local affordable housing program shall constitute and contain the sole and entire agreement between the owner and the tenant. The security deposit assistance tenancy addendum shall prohibit the prohibited lease terms that are currently contained in § 92.253(b)(1)-(9), except that § 92.253(d)(8) shall be revised to state that a tenant is only obligated to pay costs if the tenant loses and the court so orders, consistent with the revisions made in § 92.253(b)(4)(v) and § 92.253(c)(4)(v).
                    </P>
                    <P>Paragraph § 92.253(e)(4) is being revised to specify that participating jurisdictions must not exclude an applicant with Federal, State, or local tenant-based rental assistance. The proposed rule did not prohibit discriminating against a person because they were receiving local rental assistance, just State and Federal tenant-based rental assistance. In response to comment and consistent with HUD's position that source of income discrimination must end, the Department is adding this prohibition to the tenant selection regulations.</P>
                    <P>Paragraph § 92.253(e)(5) is being revised to remove the requirement that HUD approve alternative waiting list procedures for small-scale housing projects. The Department believes that this is best left to participating jurisdictions. The Department reminds participating jurisdictions and owners that all Federal, State, and local nondiscrimination requirements, including the Violence Against Women Act (VAWA), continue to apply to tenant selection, and any approved waiting list procedures must comply with all applicable requirements.</P>
                    <P>Paragraph § 92.253(f) is being revised to require that the notification of an environmental, health, or safety hazard be in writing. The paragraph is also being revised to require that when an owner becomes aware of such hazards, the owner must notify both the participating jurisdiction and the tenants instead of just the tenants. This was requested by commenters and will allow tenants to find out as quickly as possible if a hazard is affecting their unit or project. The paragraph is also being revised to add a sentence to explain that when an owner or participating jurisdiction has notified the tenants, this satisfies the requirement for the other party.</P>
                    <HD SOURCE="HD2">24 CFR 92.254 Qualification as Affordable Housing: Homeownership</HD>
                    <HD SOURCE="HD3">A. Allowing Over-Income In-Place Tenants To Purchase Their Homes</HD>
                    <P>The Department has determined that the Secretary may permit the period of affordability for a project to be terminated earlier than the time periods specified in § 92.252 under the circumstances described in detail below. The Department is revising § 92.254, which currently prohibits over-income in-place tenants from purchasing their units. This is in response to public comment requesting that in-place HOME tenants who are no longer income eligible be permitted to purchase their housing units, including when former tax credit projects are converting to homeownership housing units.</P>
                    <P>It is consistent with the statutory language of the Act, as well as the purposes of the Act, to allow in-place HOME tenants who have saved up for a downpayment to use that downpayment to purchase the unit that they are currently occupying. Developing stable homeownership models where tenants can live in a housing unit, work towards increasing their income from very-low income to moderate-income, and eventually purchase their unit is not only consistent with the intent of the drafter of the Act but in furtherance of it. As such, the Department is revising § 92.254(a)(3) to add a sentence s allowing HOME-assisted housing to be purchased by an in-place tenant pursuant to § 92.255 if the homebuyer's family was low-income at the time the homebuyer's family began occupying the HOME rental housing unit. This is similar to how families that entered into lease-purchase agreements may purchase their housing so long as they were income-eligible when they entered into their lease-purchase agreement. The Department believes this is in furtherance of the purposes of the Act and will increase homeownership opportunities for HOME-assisted tenants.</P>
                    <HD SOURCE="HD3">B. Meeting Property Standards Post-Acquisition</HD>
                    <P>The Department is revising § 92.254(a)(3) to provide clearer language that explicitly authorizes a participating jurisdiction to assist a family even if the homeownership unit does not meet the property standards at acquisition, provided that the written agreement between the participating jurisdiction and the homebuyer requires the property to meet the standards within the period specified in § 92.251(c)(3)(ii) and funding is secured to complete the rehabilitation necessary to comply with the standards. This ensures consistency between the requirements in § 92.251(c)(3) and § 92.254.</P>
                    <HD SOURCE="HD3">C. Change in Start of Period of Affordability</HD>
                    <P>
                        The Department revised § 92.254(a)(4) in response to public comments. Commenters had objected to beginning the period of affordability upon project completion. For homeownership projects, project completion means that all necessary title transfer requirements and construction work have been performed; the project complies with the requirements of this part (including the property standards under § 92.251); the final drawdown of HOME funds has been disbursed for the project; and the project completion information has been entered into the disbursement and information system established by HUD.
                        <SU>14</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>14</SU>
                             See 24 CFR 92.2 
                            <E T="03">project completion.</E>
                        </P>
                    </FTNT>
                    <P>
                        The Department understands that requiring that a homebuyer's resale or recapture period only begin to run after the participating jurisdiction completes all the information in the disbursement and information system can disadvantage homebuyers, especially for multiple address projects where completion of the information in the disbursement and information system can only occur after all housing units in the project meet the requirements in 24 CFR part 92. The Department is changing the provision to instead require the period of affordability begin after execution of the instrument that requires recapture of the HOME investment or recordation of the resale restrictions against the property. The Department is further conditioning the execution of the instrument that requires recapture of the HOME investment or recordation of the resale restrictions against the property upon both meeting the property standards in § 92.251(c)(3) and the transfer of the property title to the homebuyer. The Department believes these are reasonable restrictions because the property must meet the property standards at the time of purchase, or within 6 months after purchase, if permitted by the participating jurisdiction (with the ability to extend up to 12 months after purchase). If the property does not meet the standards within the required time period under § 92.251(c)(3), then the participating jurisdiction would have to repay the investment, and the housing would not be a HOME-assisted homeownership 
                        <PRTPAGE P="765"/>
                        unit (and thus should not have resale or recapture provisions applied to it).
                    </P>
                    <HD SOURCE="HD3">D. Change in Period of Affordability for Homeownership</HD>
                    <P>The Department revised the threshold for the periods of affordability in the table § 92.254(a)(4) consistent with the periods of affordability in § 92.252(d)(4). When the homeownership assistance provided on a per-unit basis is under $25,000, the period of affordability shall be for a minimum of 5 years. When the homeownership assistance is $25,000 to $50,000, then the minimum period of affordability shall be 10 years. If the amount of homeownership assistance is above $50,000, the minimum period of affordability shall be 15 years.</P>
                    <P>
                        The Department believes that it is important to increase the thresholds for the periods of affordability for the reasons given earlier. The Department considered that since 1990, the House Price Index has increased by over 300%.
                        <SU>15</SU>
                        <FTREF/>
                         The need for HOME homeownership assistance outpaced inflation, as measured by the Consumer Price Index, and has been a driver in increasing the amount of HOME homeownership assistance that is provided per family assisted over the course of the HOME program's history. However, given that the appropriations for the HOME program have decreased by over 50% in inflation-adjusted dollars since the 1992 HOME appropriation of $1,500,000,000,
                        <SU>16</SU>
                        <FTREF/>
                         and the need to maintain affordable homeownership units in accordance with the purposes of the Act,
                        <SU>17</SU>
                        <FTREF/>
                         the Department adjusted the thresholds to be consistent with the revisions made in § 92.252.
                    </P>
                    <FTNT>
                        <P>
                            <SU>15</SU>
                             See U.S. Developmental Index; Not Seasonally Adjusted, which is an excel sheet within the Federal Housing Finance Agency Housing Price Index Datasets: 
                            <E T="03">https://www.fhfa.gov/data/hpi/datasets?tab=additional-data.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>16</SU>
                             By one measure, the Consumer Price Index, the dollar has increased by over 200% since the establishment of the dollar thresholds used to determine the period of affordability for the HOME program. See the CPI Inflation Calculator at 
                            <E T="03">https://data.bls.gov/cgi-bin/cpicalc.pl?cost1=1%2C000%2C000.00&amp;year1=199201&amp;year2=202310.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>17</SU>
                             See 42 U.S.C. 12722(1) and (7).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">E. Edit for Consistency in 92.504</HD>
                    <P>Consistent with § 92.504, the Department is revising the first sentence of § 92.254(a)(5)(ii)(A) to state that recapture provisions must “require” that the PJ recoups all or a portion of the HOME assistance to the homebuyers if the housing does not continue to be the principal residence of the family for the duration of the period of affordability. The Department states this as a requirement in other parts of the rule and is clarifying the provision here for consistency. A similar revision is made in § 92.254(g)(3).</P>
                    <HD SOURCE="HD3">F. Revising Lease-Purchase Provisions of 24 CFR 92.254(a)(7)</HD>
                    <P>The Department considered a variety of comments on its revisions to lease-purchase regulations in § 92.254(a)(7). After careful consideration of the challenges owners encounter when the family fails to purchase the property pursuant to the lease-purchase agreement, the Department is substantially revising § 92.254(a)(7). The Department is revising the introductory sentence of the provision to explain that acquisition, rehabilitation or new construction of housing to be sold to eligible low-income homebuyers for lease-purchase is allowable.</P>
                    <P>
                        The next provision § 92.254(a)(7)(i) explains the statutory requirement of 42 U.S.C. 12745(b)(2)(B) that a homebuyer must qualify as a low-income family at the time the lease-purchase agreement is signed. The regulation is being revised to provide standalone requirements for lease-purchases within the section. As a result, HUD revised the regulation to clarify that the current regulation's requirements that income determinations be made based on the income of all people living in the homeownership unit are applicable to lease-purchases.
                        <SU>18</SU>
                        <FTREF/>
                         The Department is also clarifying in § 92.254(a)(7)(i) that if a family is also receiving HOME tenant-based rental assistance, the PJ is not required to reexamine the family's income during the term of the lease-purchase agreement. The Department has received comments that it should reduce income examination when it is not necessary, and that the Department should move to triennial income examination. While the Department declined to move to such an income cycle for the reasons given in the preamble to § 92.209 and in the applicable responses to public comment, the Department realized that HOME lease-purchase programs are different. The Act clearly states that a family's income is to be determined at the signing of the HOME lease-purchase agreement 
                        <SU>19</SU>
                        <FTREF/>
                         and does not require that income be reexamined prior to the purchase. When a PJ pairs their tenant-based rental assistance with a HOME-assisted lease-purchase program, the aim is to allow the family to accumulate money for a downpayment and to better position themselves for sustainable homeownership when they acquire the housing. By eliminating the requirement that the family's income be reexamined during the term of the lease-purchase agreement, the requirement is more consistent with the Act, the rule better enables families to save up for the purchase of the home, and it provides burden relief to PJs that would otherwise be required to reexamine the tenant's income after 24 months from the date of execution of the rental assistance contract.
                    </P>
                    <FTNT>
                        <P>
                            <SU>18</SU>
                             See 24 CFR 92.254(a)(3).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>19</SU>
                             See 42 U.S.C. 12745(b)(1)(B).
                        </P>
                    </FTNT>
                    <P>Paragraph § 92.254(a)(7)(ii) explains that the owner and homebuyer must execute a lease-purchase agreement prior to the family occupying the unit and that the lease-purchase program must require the family to purchase the housing within 36 months of the execution of the lease-purchase agreement. The provision also retains language from the proposed rule explaining that owners and homebuyers that have entered into a lease-purchase agreement are subject to the affordability requirements in the homeownership section unless the housing is not purchased within the timeframes described in § 92.254(a)(7) in accordance with the lease-purchase agreement.</P>
                    <P>The Department is adding § 92.254(a)(7)(iii) in response to public comments that requested that owners be able to sell units to an eligible homebuyer if the family that entered into the lease-purchase agreement fails to purchase the housing pursuant to the agreement. The new § 92.254(a)(7)(iii) provides that if the first homebuyer does not acquire the housing, then the owner may sell the housing to an eligible low-income homebuyer within 48 months of execution of the lease-purchase agreement. This provides owners 12 months from the expiration of a 36-month lease-purchase agreement to find another eligible low-income homebuyer and sell the homeownership unit. The regulation also permits the PJ to provide homeownership assistance to the next homebuyer identified for the unit but prohibits the owner from entering into another lease-purchase agreement for the housing.</P>
                    <P>
                        The Department has concluded that owners should have another chance to sell the unit as a homeownership unit instead of being required to operate the housing as rental housing if the lease-purchase agreement fails to end in the sale of the housing. However, since the lease-purchase did not succeed the first time, the Department is prohibiting owners from using the lease-purchase model on a second attempt to sell the housing. The owner must default to the rules that apply in a typical homeownership development project.
                        <PRTPAGE P="766"/>
                    </P>
                    <P>
                        Section 92.254(a)(7)(iv) has been amended accordingly to provide owners with additional time to sell the housing once it has failed to be sold through a lease-purchase agreement by allowing owners 48 months to complete the sale and transfer the title to an eligible low-income homebuyer (
                        <E T="03">i.e.,</E>
                         36 months for lease-purchase under a lease-purchase agreement and 12 months to sell the housing from the expiration of the 36-month lease-purchase agreement). This change to allow 12 months to sell the housing from the expiration of the 36-month lease-purchase agreement is consistent with the Department's extension of the period in which an owner may sell homeownership housing from 9 months to 12 months (see § 92.254(a)(3)).
                    </P>
                    <P>The Department inadvertently omitted paragraph (a)(8) in the publication of the proposed rule. It was not the Department's intent to delete paragraph (a)(8), and the Department noted some confusion over the use of this provision in the public comments. In the final rule, the Department is retaining the language from § 92.254(a)(8) from the current rule without change.</P>
                    <P>In response to public comment explaining that it is very difficult to purchase housing with a right of first refusal, bring the property into compliance with the PJ's property standards, and resell it to an eligible homebuyer within 6 months, the Department is revising § 92.254(b)(1)(i) and § 92.254(b)(3)(ii) to allow PJs and CLTs with up to 12 months to sell the housing to the next eligible low-income homebuyer.</P>
                    <HD SOURCE="HD2">G. Preserving Affordability of HOME Projects</HD>
                    <P>The Department is adding an additional clarifying sentence to § 92.254(b)(2)(v) to explain that while sales proceeds can be used to reimburse up to one-hundred percent of the administrative funds used by a PJ to preserve the affordability, any sales proceeds exceeding that amount shall be program income for the PJ.</P>
                    <HD SOURCE="HD2">H. Assisting Homebuyers in Projects Developed by Community Land Trusts</HD>
                    <P>In response to public comments requesting that CLTs or PJs be allowed to assist homebuyers when a CLT exercises a right of first refusal or preemptive purchase rights in accordance with § 92.254(b)(3), the Department is revising § 92.254(b)(3)(iv) to explicitly permit the PJ to provide homeownership assistance to the next eligible homebuyer. PJ always has the flexibility to assist a homebuyer through a homeownership assistance program, regardless of whether the unit the homebuyer wishes to purchase was originally purchased by another HOME-assisted homebuyer. Since the Department is revising § 92.254(b)(3)(iv) to explicitly permit PJs to assist the next homebuyer, the Department is also clarifying both § 92.254(b)(3)(iii) and (iv) to state that if a homebuyer is provided assistance by the PJ, the period of affordability shall be calculated in accordance with § 92.254(b)(1)(iii) and § 92.254(b)(1)(iv), and if no additional assistance is provided to the homebuyer, then the period of affordability shall be equal to remaining period of affordability on the property.</P>
                    <P>However, the Department does not believe the statute permits the PJ to award HOME funds to the CLT to provide homeownership assistance to the next eligible homebuyer. The statute specifically states that when HOME “funds provided in prior and subsequent appropriations acts that were or are used by community land trusts for the development of affordable homeownership housing pursuant to section 215(b) of such Act,” then the community land trusts could retain the right to purchase the housing without violating the period of affordability requirements contained in section 215(b)(3)(A). This type of relief was to allow for a unit to temporarily cease to be used as affordable housing, as long as the housing was rededicated to that purpose shortly thereafter. It did not establish a new eligible activity or new eligible costs but gave CLTs the ability to exercise their purchase rights without violating the affordability requirements and triggering repayment of the HOME investment by the PJ. As such, the Department is revising the regulation to allow the PJ to assist the next eligible homebuyer.</P>
                    <HD SOURCE="HD2">24 CFR 92.255 Purchase of HOME Units by In-Place Tenants</HD>
                    <P>
                        The Department received public comments requesting that in-place HOME tenants who are no longer income eligible still be permitted to purchase their housing units. While regulations currently do not permit over-income in-place tenants to purchase their units, the Department has determined that the Secretary may permit the period of affordability for a project to be terminated earlier under certain circumstances. 
                        <E T="03">See</E>
                         42 U.S.C. 12742(a)(1)(E) (noting that rental housing qualifies as affordable housing under this subchapter only if the housing will remain affordable, according to binding commitments satisfactory to the Secretary, for the remaining useful life of the property).
                    </P>
                    <P>The Department believes that it is consistent with the purposes of the Act to allow in-place HOME tenants who have saved up for a downpayment to use that downpayment to purchase the unit that they are currently occupying. Developing stable homeownership models where tenants can live in a housing unit, work towards increasing their income from very-low income to moderate-income, and eventually purchase their unit is not only consistent with the intent of the Act but in furtherance of it.</P>
                    <P>As such, the Department is revising § 92.255(b) to state that if the tenant's family is no longer low-income at the time of the purchase, then the family may still purchase the home. The provision is also being revised to state that the family must occupy the housing as their principal residence in accordance with § 92.254(a)(3) and must agree to the imposition of resale restrictions on the housing, in accordance with § 92.254(a)(5), for the remaining period of affordability of the housing unit. By adding these requirements, it ensures that the intent of the Act is fulfilled because the family, which began their participation in the HOME program as low- or very low-income, must own and occupy the housing for the full period of affordability or be subject to the very same resale restrictions that all other income-eligible families must comply with in the event that the family sells or transfers the property within the housing's original period of affordability.</P>
                    <P>Paragraph § 92.255(c) is similarly revised to explain that though an in-place HOME tenant may purchase their unit even if the tenant's family is no longer low-income, additional HOME funds cannot be provided to assist that family because the family is not income eligible for homeownership assistance.</P>
                    <HD SOURCE="HD2">24 CFR 92.300 Set-Aside for Community Housing Development Organizations (CHDOs)</HD>
                    <P>
                        In the proposed rule, HUD proposed to revise the text of § 92.300. The Department is making further revisions to § 92.300(a)(2) to clarify that rental housing owned by a CHDO is rental housing if it is “leased” to low-income tenants. The Department had inadvertently removed necessary words from the provision in the proposed rule and is clarifying text. HUD also determined that it is necessary to further revise the text of § 92.300(a)(2) and (3) in order to clarify when a community housing development organization is 
                        <PRTPAGE P="767"/>
                        considered to be an owner of rental housing. The Department is clarifying that if a community housing development organization has site control of a project through a long-term ground lease, such lease must run for the full period of affordability in § 92.252. If an owner does not have site control for the entire period of affordability, then they do not really own the housing for the full period of affordability and cannot enforce 24 CFR part 92 requirements in accordance with this section. Accordingly, § 92.300(a)(2) and (3) are being revised to more clearly explain the ground lease requirements that must be met for a community housing development organization to be considered an owner of rental housing.
                    </P>
                    <P>In response to public comments, HUD is also making additional changes to § 92.300(a)(3). HUD received public comments requesting that 92.300(a)(3) more clearly describe how a community housing development organization is intended to be in charge of the development process when it acts as a “developer” under that provision. The Department is adding a clarifying sentence that explains that the requirement that a CHDO be in charge of all aspects of the development must be evidenced by an enforceable written agreement between the CHDO and the other entities sharing responsibility in the development of the housing. The Department also provided examples of different types of written agreements that may meet the requirements, including joint venture agreements and master development agreements.</P>
                    <P>Additionally, multiple commenters questioned whether the Department's removal of the requirement that rental housing developed by a CHDO be owned by the CHDO during development and for the full period of the affordability would allow a loophole for CHDOs to sell CHDO developed units to for-profit organizations. The Department recognized that this provision could inadvertently be used for that purpose. As a result, the Department revised § 92.300(a)(3) to require that the housing be owned by a CHDO unless the PJ documents that that the CHDO no longer has the capacity to own and manage the housing for the full period of affordability and there are no other CHDOs with capacity to own and manage the project for the full period of affordability. If the PJ authorizes the transfer of the housing, then it may only be sold to a nonprofit. By requiring that the PJ attempt to find another CHDO to own the housing unless the PJ cannot identify a CHDO that is capable of owning and managing the housing in accordance with the requirements of part 92 for the full period of affordability, the regulation is more consistent with the purposes of the Act and the intent of the CHDO set-aside. It also provides adequate safeguards to ensure that the CHDO set-aside is not being used for the enrichment of private for-profit businesses.</P>
                    <P>The Department is withdrawing its proposed language for the first sentence of § 92.300(a)(4)(i), which would have barred wholly-owned for-profit CHDO subsidiaries from being considered a CHDO or valid CHDO subsidiary for purposes of meeting the CHDO project set-aside requirements. The Department recognizes that this is a model that CHDOs may be using and does not wish to reduce the ways CHDOs can participate in HOME projects.</P>
                    <P>Commenters welcomed changing the term “downpayment assistance” to “homeownership assistance” in § 92.300(a)(6)(i) and elsewhere. Many commenters noted that the new term is broader and could include assistance for closing costs and mortgage rate buy-downs. The Department believes that it in addition to changing the term “downpayment assistance” to “homeownership assistance,” it will also be helpful to revise § 92.300(a)(6)(i) to provide additional examples of the kinds of homeownership assistance that CHDOs can provide.</P>
                    <HD SOURCE="HD2">24 CFR 92.353 Displacement, Relocation, and Acquisition</HD>
                    <P>The Department is revising the reference to § 92.253(d) in § 92.353(c)(2)(ii)(A) to remove the pinpoint citation, as the termination of tenancy provisions are now contained in § 92.253(b)(10) and § 92.253(c)(10).</P>
                    <HD SOURCE="HD2">24 CFR 92.356 Conflict of Interest</HD>
                    <P>HUD is clarifying language in § 92.356(d)(1). The Department recognizes that there may be some confusion over what constitutes a “combination” of conflict of interest disclosure methods provided in the proposed rule. The Department is clarifying in the final rule that a disclosure of a conflict of interest is a combination of “at least two” of the communication methods provided in paragraph (d)(1).</P>
                    <HD SOURCE="HD2">24 CFR 92.504 Participating Jurisdiction Responsibilities; Written Agreements</HD>
                    <P>The Department made revisions to § 92.504(c)(1)(v) and § 92.504(c)(2)(xii) to revise the written agreement requirements to require that for projects involving rental housing, tenant-based rental assistance, or security deposit assistance, the written agreement between the PJ and the State Recipient or Subrecipient, as applicable, must require that the HOME tenancy addendum that applies to the type of project is used for all HOME-assisted units or tenants. The Department is also making technical revisions to § 92.504(c)(3)(ii)(A) to revise the first sentence to read in the singular instead of the plural. This was done to be consistent with the rest of the surrounding provisions.</P>
                    <P>The Department is revising § 92.504(c)(3)(i) to add the requirement contained in § 92.206(d)(1) into the written agreement between the PJ and the owner of HOME rental housing. Paragraph § 92.206(d)(1) requires that if HOME funds will be reimbursing expenses that were incurred no more than twenty-four months before the date of the commitment, the written agreement must explicitly permit the use of the funds for those purposes.</P>
                    <P>The Department is making technical corrections to § 92.504(c)(3)(ii)(A) to read in the singular instead of the plural, consistent with how the rest of § 92.504(c)(3) is written. The Department is also adding a new sentence to the end of the paragraph that explicitly requires that the written agreement contain the option the PJ selected for calculating income in accordance with § 92.203(b)(1). This information should already have been included in the written agreement pursuant to § 92.203 but the Department is now including this language in the written agreement provisions for consistency.</P>
                    <P>The Department is making technical edits to § 92.504(c)(5)(i)(A) to add parenthesis around examples of allowable forms of assistance that a PJ may provide a homebuyer, homeowner, or tenant or owner receiving tenant-based rental assistance.</P>
                    <P>The Department made technical revisions to § 92.504(c)(5)(iii) to add the word “assistance” after “security deposit” to align with provisions in § 9.253(d) that describe security deposit assistance. The Department is also making a minor technical edit to § 92.504(c)(6)(i)(A) to add a comma after the regulatory citation to § 92.300(a)(2)-(5).</P>
                    <P>
                        The Department is revising § 92.504(c)(6)(i)(B) in response to public comments questioning whether the Department was proposing to change the treatment of recaptured funds in CHDO homeownership projects. The Department is clarifying that PJs may permit CHDOs to retain recaptured funds for additional HOME projects pursuant to the written agreement. The Department is also adding a descriptive 
                        <PRTPAGE P="768"/>
                        header to the section 
                        <E T="03">Retaining proceeds and recaptured funds.</E>
                    </P>
                    <P>
                        The Department recognized that it permits CHDOs to provide homeownership assistance to families as part of HOME homeownership housing developed by the CHDO. This amount of assistance is limited to 10 percent of the overall amount of HOME funds provided to the project. The Department is adding § 92.504(c)(6)(i)(B)(
                        <E T="03">2</E>
                        ) to more clearly establish the written agreement requirements for the provision of this assistance. The agreement must provide the amount of funds for homeownership assistance, the number of homebuyers to receive the assistance, any matching contributions, and the period of the agreement. The 10 percent limitation is also added, as is the requirement that the CHDO's agreement with the homebuyer meet the written agreement requirements in § 92.504(c)(5)(i) that apply to agreements providing HOME homeownership assistance to eligible homebuyers.
                    </P>
                    <HD SOURCE="HD2">24 CFR 92.505 Applicability of Uniform Administrative Requirements</HD>
                    <P>The Department revised § 92.505 to explain that 2 CFR 200.344 is applicable to HOME as provided in § 92.507. Originally, the Department had said that 2 CFR 200.344 was not applicable to HOME PJs, State recipients, and subrecipients but this is confusing because § 92.507 does make most of 2 CFR 200.344 applicable to them. By adding the caveat that 2 CFR 200.344 is not applicable, except as provided in § 92.507, this clarifies that it is applicable and that § 92.507 will explain how.</P>
                    <HD SOURCE="HD2">24 CFR 92.507 Closeout</HD>
                    <P>In the proposed rule, HUD proposed to revise § 92.507 in order to specify the procedures and actions that must be completed by a PJ and HUD to close out a grant. In this final rule, the Department is further revising § 92.507 for clarity and consistency with 2 CFR part 200. The Department is adding a second sentence to the introductory provision in § 92.507. This explains that the requirements of 2 CFR 200.344 apply to closeouts in the HOME program, with the exception where such requirements conflict with the requirements in § 92.507. The Department was concerned that its language was confusing because in various parts of § 92.507, such as in § 92.507(b)(10)(v) and (vi), the regulation requires that PJs comply with 2 CFR 200.344. By adding this sentence, the Department is clarifying that PJs must follow 2 CFR 200.344 unless it conflicts with the HOME regulations.</P>
                    <P>The Department is revising § 92.507(a)(1) to clarify that HUD will close out a grant after the period of performance has ended instead of when HUD determines that PJ has completed all required activities and closeout actions. HUD is not limiting its discretion here, given under separate legal authorities (including the Act, individual appropriations laws, and provisions within 2 CFR part 200) to close out a HOME grant. Additional clarification is also being added to specify that the PJ must complete all required activities and closeout activities for the grant, as required by HUD. The revised provision directly states the PJ's closeout responsibilities under the HOME program.</P>
                    <P>The Department is revising § 92.507(a)(2) to explain that to prepare for closeout, before the end of the budget period of the grant, the PJ shall review all eligible activities under the grant and reconcile its accounts by drawing funds down in a timely manner and refunding the proper accounts of any previously disbursed balances of unobligated cash paid in advance. This is clearer language that is more legally accurate than the proposed rule, which did not explain that these actions were to prepare for closeout, did not condition each provision on being taken during the budget period, and did not specify how refunds would be performed in sufficient detail.</P>
                    <P>The Department is redesignating § 92.507(a)(2)(ii) of the proposed rule by redesignating it as paragraph (a)(3) and by explaining that after the end of the grant budget period, no additional activities may be undertaken with that particular HOME grant and that there are no additional eligible costs incurred after the budget period. The provision also explains that unused funds shall be returned to the U.S. Treasury by HUD, and that the PJ must promptly refund any unused grant funds not authorized to be retained in accordance with HUD's instructions. These clarifications more directly state the requirements and the conditions without using problematic terminology like “recapture” which has a different statutory meaning in the HOME program than in appropriations law.</P>
                    <P>
                        The Department is revising § 92.507(a)(4)(ii) in order to remove a reference to FAPIIS and instead add a reference to 
                        <E T="03">SAM.gov</E>
                        , the current system being used for reporting. The Department is revising § 92.507(b)(2) to state that a PJ must demonstrate that it has fulfilled all programmatic and administrative requirements for the project (
                        <E T="03">i.e.,</E>
                         property inspections, obtaining certificates of occupancy, 
                        <E T="03">etc.</E>
                        ) within the period of performance in accordance with 2 CFR 200.344(a). The proposed rule's provision stated that the PJ must complete all activities for which the funds were expended. This may have been confusing to the PJs as HOME funds are not to be used after the budget period. As such, HUD revised the language to appropriately characterize the PJ's actions as providing HUD with information demonstrating it has completed all the programmatic and administrative requirements within the period of performance and not that HUD was allowing for completion of activities after the budget period had expired.
                    </P>
                    <P>The Department is revising § 92.507(b)(3) to remove the word “remaining” when characterizing the data to be entered into the computerized disbursement and information system established by HUD. This was for clarity. Similarly, the Department is revising both paragraph (b)(5) and (b)(10) to improve the grammatical structure of each provision by removing “the participating jurisdiction must.” This is because the lead-in sentence in § 92.507(b) already states that the PJ must take the following actions to close out a grant and therefore it is unnecessary to repeat the words in those provisions.</P>
                    <P>The Department is revising § 92.507(b)(10)(i) to specify that instead of cancelling the unused grant funds, those funds shall be returned to the U.S. Treasury. This is clearer language and more directly states the mechanics of what is occurring during closeout. Paragraph § 92.507(b)(10)(iv) and § 92.507(c)(6) are both being revised to include both a State and a consortium in the list of entities that qualify as a PJ. If a jurisdiction is not a PJ as a metropolitan city, urban county, State, consortium, or consortium member when it receives program income, recaptured funds, or repayments in accordance with § 92.503, then the funds are not subject to the requirements of 24 CFR part 92. The proposed rule inadvertently excluded States and consortia, both of which are types of PJs. The Department is also revising § 92.507(c)(8) to remove the parenthetical citation at the end because it was unnecessary and confusing.</P>
                    <P>
                        The Department is making a technical revision to § 92.507(b)(10)(viii) to specify that the PJ's certification acknowledges that future monitoring by HUD will occur, “including” that findings of noncompliance may be taken into account by HUD as unsatisfactory performance of the PJ and in any risk-based assessment of any future grant 
                        <PRTPAGE P="769"/>
                        award under the HOME program in the future.
                    </P>
                    <P>The Department also revised the reference to recordkeeping requirements in 2 CFR part 200 that are applicable to PJs to “2 CFR 200.345, as applicable.” The provision references applicable provisions in 2 CFR 200.337 through 2 CFR 200.345, as had been provided in the proposed rule, and therefore is a non-substantive change.</P>
                    <HD SOURCE="HD2">24 CFR 92.508 Recordkeeping</HD>
                    <P>The Department is revising the first sentence to § 92.508(a)(3)(vii) to state that PJs must maintain records demonstrating that each rental housing project met the affordability and income targeting requirements of § 92.252 for the required period or met the requirements in § 92.255 for conversion to homeownership for in-place tenants. This aligns with changes made to § 92.254(a) and § 92.255(b) and provides a recordkeeping requirement that contemplates conversion of rental housing units to homeownership units for in-place tenants in accordance with § 92.255.</P>
                    <P>Consistent with changes made by the Department to other sections requiring that there be a minimum level of tenant protections for families receiving security deposit assistance, HUD is adding “security deposit assistance” to § 92.508(a)(3)(ix) to require that the PJ maintain records demonstrating that each family receiving such assistance had a lease that included a HOME security deposit assistance addendum in accordance with § 92.253(d).</P>
                    <HD SOURCE="HD2">24 CFR 570.200 General Policies</HD>
                    <P>In the proposed rule, HUD proposed to revise the introductory text of § 570.200(h). However, HUD's proposed revisions would have decoupled the effective date of a grant agreement from a grantee's program year start date and would have subjected many grantees to pre-award costs on an annual basis. After considering public comments, HUD has determined the need to maintain the connection between the grant agreement effective date and program year start dates to reserve pre-award costs to those incurred before a program year start date and, therefore, is retaining the existing introductory text to § 570.200(h). Instead, HUD is adding a new § 570.200(h)(3) to make the effective date of the grant agreement, in a year when an annual appropriation occurs less than ninety days before a grant recipient's program year start date, the earlier of either the program year start date or the date that the consolidated plan is received by HUD. This change better aligns CDBG with the new HOME program regulation at § 91.212(b)(2) and continues practices implemented through annual waivers.</P>
                    <HD SOURCE="HD1">IV. Public Comments</HD>
                    <HD SOURCE="HD2">General Comments</HD>
                    <HD SOURCE="HD3">A. Comments in Support for the Proposed Rule</HD>
                    <P>Multiple commenters expressed general support for the regulatory proposals described in the proposed rule. Commenters stated that they support the regulatory proposals described in the proposed rule because they will simplify and align programs to create more affordable housing for persons needing housing assistance. One commenter stated that the proposed rule's changes would improve housing stability of low-income households. Another said it would promote program flexibility, HUD's mission, and clarity and alignment with other Federal programs. One commenter expressed support for the proposed rule because it will make the HOME program more accessible and user-friendly in rural places. One commenter stated that they support the proposed changes because they may lead to shorter waiting periods to receive housing. Another commenter stated that the proposed rule would help to more effectively use resources to narrow the racial homeownership and wealth gaps.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for reviewing and is moving forward with a final rule.
                    </P>
                    <HD SOURCE="HD3">B. The Rule Increases Program Alignment</HD>
                    <P>Commenters supported HUD's proposed changes to streamline HOME program requirements to align with the CDBG and Section 8 programs because the commenter believes it would ensure consistency with the implementation of changes to the HOME program.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for reviewing the proposed rule. The Department further aligned the HOME regulations with the CDBG and Section 8 programs in this final rule.
                    </P>
                    <HD SOURCE="HD3">C. The Rule Should Be Revised To Account for Manufactured Housing</HD>
                    <P>One commenter urged HUD to explicitly address manufactured homes and manufactured home communities in the rule and guidance. The commenter's suggestions included explicitly clarifying that manufactured homes are a permissible HOME housing type, that manufactured housing titled as real property or personal property are eligible for HOME assistance, that permissible land tenure types include manufactured home on land that is owned by the homeowner or leased in manufactured home communities, that manufactured home communities are explicitly named as permissible for affordable housing preservation, that non-profit shared-equity cooperatives are explicitly named as being eligible for HOME funding as is the water and sewer infrastructure they own.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Manufactured homes and lots are explicitly included in the definition of “housing” in § 92.2. To be considered a homeowner for purposes of the HOME program, a manufactured homeowner must only have a ground lease as long as the period of affordability required in accordance with § 92.254.
                        <SU>20</SU>
                        <FTREF/>
                         This is more flexible than the 50-year ground lease required to constitute homeownership on Indian trust lands and land held by CLTs, and is the most flexible definition of homeownership in the HOME program.
                    </P>
                    <FTNT>
                        <P>
                            <SU>20</SU>
                             See paragraph (1) of the definition of homeownership in 24 CFR 92.2.
                        </P>
                    </FTNT>
                    <P>While the Department is not explicitly revising its regulations to change the definition of homeownership for manufactured homeowners, HUD notes that if manufactured home communities structure their ground leases or ownership in accordance with the HOME homeownership requirements, then purchasers may be eligible under the HOME regulations. When designing their HOME programs, participating jurisdictions are required to consider the housing needs within their jurisdiction, including the needs of those who own or wish to purchase a manufactured home.</P>
                    <HD SOURCE="HD3">D. The Rule Is More Burdensome</HD>
                    <P>Another commenter stated that, while supportive of some of the rule's proposed changes, the proposed rule would increase administrative burden and that this adds to other administrative costs from Section 3, BABA, and VAWA.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department believes that the requirements contained in this final rule will reduce burden and compliance will be less costly than the current requirements. The Department understands that Section 3; Build America, Buy America; and Violence Against Women Act requirements each may add different requirements on HUD grantees. These requirements may change the way that the participating jurisdiction contracts for goods and services, or how the participating jurisdiction assist survivors of domestic violence, dating violence, sexual assault, stalking, or human trafficking. However, these requirements are not within the scope of this rulemaking. The 
                        <PRTPAGE P="770"/>
                        Department will continue to assess ways to further reduce the burdens of compliance with various independent statutory requirements.
                    </P>
                    <HD SOURCE="HD3">E. HUD Should Further Streamline the Requirements of the HOME Program</HD>
                    <P>A commenter stated that HUD's rulemaking should seek to further streamline the HOME program and reduce regulatory and compliance burdens because these burdens detract from the value of limited resources provided to HOME-assisted projects.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department agrees with the commenter and engaged in further streamlining of HOME requirements including but not limited to income examinations, physical condition inspections, and rent determinations.
                    </P>
                    <HD SOURCE="HD3">F. Legislative Reform Necessary</HD>
                    <P>Commenters supported legislative reform of modernization of the HOME program overall or particular statutory provisions. One commenter recommended that HUD continue to work with Congress to develop and pass legislation to reauthorize and further modernize the HOME program.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for sharing their view and notes that it also has called for legislative reform of HOME in recent HUD Budget Requests.
                    </P>
                    <HD SOURCE="HD3">G. Technical Assistance, Training, and Guidance</HD>
                    <P>Several commenters requested technical assistance, guidance, or training on various topics in the regulation.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department agrees with commenters that it must provide significant training, guidance, and technical assistance on this final rule to assist participating jurisdictions and other program participants comply with new requirements and exercise new flexibilities.
                    </P>
                    <HD SOURCE="HD2">Streamlining Terminology</HD>
                    <HD SOURCE="HD3">A. Replacing “Downpayment Assistance” With “Homeownership Assistance”</HD>
                    <P>Commenters supported HUD's proposal to change the definition of “downpayment assistance” to “homeownership assistance.” Two commenters said this change would provide participating jurisdictions and HUD regional offices with the clarity needed to understand the full breadth of homeownership-related activities that are allowable using HOME funding in addition to downpayment assistance. One commenter said that this change would increase affordable housing supply by facilitating the use of HOME funds by developers to construct or rehabilitate owner-occupied housing. One commenter suggested that a clear assertion that HOME covers more than downpayment assistance alone will more easily allow affordable housing developers to use these funds to construct or rehabilitate more owner-occupied housing, adding more units to a dwindling affordable supply.</P>
                    <P>One commenter stated that HUD has several instances where the term “downpayment assistance” is used instead of “homeowner assistance” despite the noted substitution, which has resulted in confusion. The commenter noted the following instances of “downpayment assistance” appearing in several other locations within the text of the rule including §§ 92.203(d); 92.209(c)(2)(iv); 92.250(b)(4); § 92.251(c)(3); 92.300(a)(6)(i); 92.351(a)(1); 92.504(c)(1)(i); 92.504(c)(2)(i).</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for reviewing and is moving forward with this change. In examining the regulation and comments, the Department determined that there were numerous instances where the term “downpayment assistance” persisted and has made revisions to the term in §§ 92.203, 92.209, 92.250, 92.251, 92.300, 92.351, and 92.504.
                    </P>
                    <HD SOURCE="HD3">B. Replacing “Dwelling” With “Housing”</HD>
                    <P>A commenter stated that they support the proposed change of replacing the term “dwelling” with “housing” for the HOME program, TBRA program, and income targeting for homeownership.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for reviewing. HUD will move forward with replacing the term “dwelling” with “housing” where the Department determines that this is accurate terminology. The Department did note that in relation to HOME regulations implementing the Uniform Relocation Assistance and Real Property Acquisition Policies Act (URA) (42 U.S.C. 4601 
                        <E T="03">et seq.</E>
                        ), and its regulations at 49 CFR part 24, as amended, and Section 104(d) of the Housing and Community Development Act (42 U.S.C. 5304(d)) and its regulations at 24 CFR part 42, the term “dwelling” is more consistent with the underlying statutory and regulatory terminology and will be maintaining the usage of the term in that area of the HOME regulations. Similarly, the Department will be retaining the use of this terminology in relation to accessibility requirements, which refer to applicable definitions outside of 24 CFR part 92. In performing its review, the Department determined there were additional areas whether the term “housing” was more appropriate than “dwelling” including in §§ 92.2, 92.219, 92.253, 92.254, and 92.258. The Department is revising these regulations accordingly.
                    </P>
                    <HD SOURCE="HD3">C. Replacing “Affordability Period” With “Period of Affordability”</HD>
                    <P>Commenters supported HUD's proposed definition of “period of affordability.” One commenter supported the consistent use of the term but noted that the old term persists in certain places in the regulation.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for reviewing and is moving forward with the revised term “period of affordability.” The Department has also revised the remaining references to “affordability period” to read as “period of affordability” to maintain consistent terminology.
                    </P>
                    <HD SOURCE="HD3">D. Replacing “Single-Family” With “Single Family”</HD>
                    <P>One commenter thanked the Department for streamlining the term single family while another commenter noted places where certain terminology was not corrected.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department noted that there were instances in which the term was not corrected and is making changes to § 92.2. and § 92.220.
                    </P>
                    <HD SOURCE="HD2">§ 92.2—Commitment Definition</HD>
                    <HD SOURCE="HD3">A. General Support</HD>
                    <P>One commenter supported changing the language of the definition of “commitment” from “official” to “officials” And from “downpayment assistance” to homeownership assistance.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the commenter's support and will move forward with these changes.
                    </P>
                    <HD SOURCE="HD3">B. Paragraph (2) of the Commitment Definition—Commit to a Specific Local Project—Opposition to Requirement To Secure All Project Financing Before Commitment</HD>
                    <P>
                        One commenter stated that HUD should consider revising paragraph (2)(i) of the definition of “commitment” in § 92.2 because requiring applicants to secure all project funding before receiving a commitment of HOME funds is overly burdensome, particularly for nonprofit developers. The commenter explained that this upfront secured funding requirement could result in fewer applications for HOME funding and should be removed. The commenter also suggested expanding the meaning 
                        <PRTPAGE P="771"/>
                        of construction to include incurring typical pre-development costs such as architectural and engineering costs.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Commenters urged HUD to revise the definition of 
                        <E T="03">commit to a specific local project</E>
                         by removing the requirement that all project financing be secured before commitment. The Department did not propose a change to these requirements and declines to make these proposed changes at the final rule stage. HUD believes these requirements to be essential to ensuring that HOME funds are not committed to and used for projects that have not secured all the financing necessary to enable the project to be successfully and timely completed. The Department is not defining construction or expanding the meaning of construction to include pre-development activities such as architectural and engineering costs. The type of costs that the commenter is describing are project-related soft costs.
                    </P>
                    <P>Under the current regulation, project related soft costs, which include architectural and engineering costs, may be reimbursed if they are incurred not more than 24 months before the date that HOME funds are committed to the project and the participating jurisdiction expressly permits HOME funds to be used to pay these costs in the written agreement committing the funds to the project. The proposed rule added the cost of environmental reviews and studies to this provision.</P>
                    <P>The Department received several comments on HUD's revision to § 92.206(d)(1) to allow HUD environmental review or other environmental studies or assessments to be reimbursable costs incurred prior to when funds were committed to a project. Those commenters urged the Department to consider expanding the types of costs that would be allowed to be incurred to include “pre-development” or other related soft costs. The Department agrees with the commenters and is expanding the project soft costs that may be incurred prior to a commitment to include costs to process and settle financing for the project, including private lender origination fees, credit reports, fees for title evidence, legal fees, private appraisal fees, and fees for independent cost estimates. These were all contained in paragraph (d)(2) but will now be deleted from paragraph (d)(2) and added to paragraph (d)(1). While the Department is moving these provisions to paragraph (d)(2), the Department determined that several provisions could not be moved because there is no reasonable expectation that they should occur prior to commitment. These provisions include obtaining building permits, which require HUD environmental review; fees for recordation and filing of legal documents, as recorded documents relating to an acquisition, rehabilitation, or new construction project should occur after commitment of HOME funds; and builders or developers fees, as those fees should not be earned and chargeable to the HOME grant for work performed prior to the environmental review and commitment of the HOME funds to the project.</P>
                    <P>Additionally, because of specific public comment, the Department also added “accounting fees”, “filing fees for zoning or planning review and approval”, and “other lender-required third-party reporting fees” to paragraph (d)(1). By moving or adding the soft costs into paragraph (d)(1), HUD is allowing the above-described costs to be paid as long as they were incurred no more than 24 months before the date of commitment, and they were included in the written agreement committing the funds.</P>
                    <HD SOURCE="HD3">C. Paragraph (2) of the Commitment Definition—Commit to a Specific Local Project—Opposition to Requirement That Construction Must Be Scheduled To Start Within Twelve Months of the Agreement Date</HD>
                    <P>Commenters urged HUD to lengthen the time between commitment and the start of construction from the current 12 months. One commenter proposed extending the timeframe to 24 months because of the extensive backlog of construction work and the loss of available and qualified contractors. Another commenter stated that HUD's 12-month timeline could be challenging if the construction cycle is tied to hard costs or providing additional guidance for circumstances in which the 12-month deadline is missed.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the commenter's review of the proposed rule and this recommendation. The Department did not propose a change to the 12-month time period between the date of the written agreement and the start of construction on a HOME-assisted project. The 12-month requirement has been in the commitment definition since 1991 and ensures that HOME funds are not prematurely committed to projects that are not ready to move to construction. HUD declines to adopt the suggested change. In addition, HUD notes that the 12 months is not a deadline; the current rule states that a participating jurisdiction must have a reasonable expectation that construction will begin within 12 months when committing HOME funds to a specific local project. This expectation can be demonstrated by the construction schedule appended to the written agreement committing the funds.
                    </P>
                    <HD SOURCE="HD2">§ 92.2—Community Housing Development Organization Definition</HD>
                    <HD SOURCE="HD3">A. General Comments</HD>
                    <P>Many commenters supported the changes and stated that the proposed rule would create more opportunities for nonprofits to become CHDOs, expand the nonprofit affordable housing delivery system, expand the capacity of CHDOs, and make it easier for participating jurisdictions to use their CHDO set-aside funds. Other comments expressed concern about or opposition to HUD's proposed changes, particularly changes aimed at increasing eligible CHDOs in rural areas. One commenter stated that, despite having concerns about certain HUD proposals, it appreciates HUD's efforts to make CHDO designation easier to attain and retain particularly in areas with few or no CHDOs. Another commenter stated that while the commenter is supportive of the proposed changes that would create opportunities for organizations to participate in housing development and build their own capacity, HUD should consider additional policy safeguards to preserve the purpose of the set-aside and ensure that unintended consequences, such as bad actors meeting the letter of the requirements but “not the spirit of the designation,” do not outweigh the benefits. One commenter stated that it appreciates HUD's effort to expand options for meeting the low-income board requirement but does not believe it will make a significant difference in the number of organizations that will seek the CHDO designation. The commenter stated that meeting the 15 percent CHDO set-aside requirement will continue to be a challenge for many participating jurisdictions irrespective of the proposed changes.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD believes that there are appropriate safeguards in place in the final rule because the designees of nonprofit organizations that may serve on the board only count towards the one-third board representation requirement if they represent organizations that “address the housing or supportive service needs of low-income residents or residents of low-income neighborhoods.” This connection to the community, and the list of examples HUD provides to further elaborate on the types of groups and the role they must play within the community, demonstrate that the intent 
                        <PRTPAGE P="772"/>
                        is not to water down a CHDO's ties to the community but to strengthen them. Promoting board representation for victim service providers, homeless providers, organizations involved in promoting or defending civil rights, disability advocates, and other organizations that directly serve the community will serve to strengthen CHDOs' boards and provide needed input from hard-to-reach groups.
                    </P>
                    <HD SOURCE="HD3">B. Include Cooperatives as Eligible for CHDOs</HD>
                    <P>One commenter suggested that HUD expand CHDO eligibility to affordable housing cooperative corporations because affordable housing cooperatives, including resident owned manufactured housing community cooperatives, meet the goals of CHDOs to advance resident and community engagement as cooperative boards are made up of their resident owners who govern and manage the cooperative. The commenter further explained that cooperatives would benefit from eligibility as CHDOs by gaining greater access to CHDO sponsors. The commenter stated that if affordable housing cooperatives are not granted status as CHDOs directly, then it is imperative that they are granted access to work with a CHDO nonprofit 501(c)(3) sponsor to access set-aside funds that can create lasting affordable housing.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the comments and notes that nothing in the existing HOME regulations or in the proposed rule would prohibit a cooperative housing corporation from being designated as a CHDO as long as the organization can meet the definition of CHDO. The Department has also significantly changed the ways that CHDOs can be involved in a development project in § 92.300 and believes that it provides additional opportunities for affordable housing cooperatives to partner with CHDOs on CHDO set-aside projects.
                    </P>
                    <HD SOURCE="HD3">C. Paragraph (4) of CHDO Definition—Align Definition of CHDO in 24 CFR 92.2 and the Definition of Community-Based Development Organization in 24 CFR 570.204</HD>
                    <P>One commenter recommended that the regulations relating to CHDOs align more closely with the community-based development organization regulations through the CDBG program.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department is limited by statute in how closely it can align the definitions of CHDO and community-based development organization. By regulation, a CHDO qualifies as a community-based development organization if it is designated as a CHDO by the participating jurisdiction, has a geographic area of operation of no more than one neighborhood, and has received HOME funds under 24 CFR 92.300 or is expected to receive HOME funds as described in and documented in accordance with 24 CFR 92.300(e) (See 24 CFR 570.204(c)(2)). This safe harbor is provided in recognition that if an organization meets all the requirements of 
                        <E T="03">community housing development organization</E>
                         in § 92.2, then the organization will have met the statutory requirements in 42 U.S.C. 5305(a)(15). This is because the statutory definition of CHDO is more restrictive than the statutory and regulatory definition of a community-based development organization. It is because of these statutory and programmatic differences that a community-based development organization cannot automatically qualify as a CHDO.
                    </P>
                    <P>Under the HCDA statute and CDBG regulations, community-based development organizations include local development corporations, which can be for-profit entities (See 42 U.S.C. 5305(a)(15)) and 24 CFR 570.204(c)(1)(iii)). Under NAHA, CHDOs must be nonprofit organizations (42 U.S.C. 12704(6)). Community-based development organizations can also perform economic development activities under the CDBG program, and thus the organizations will have more expansive purposes and scopes than CHDOs, which are required to have among their purposes the provision of affordable housing. The difference in eligible activities also means that community-based development organizations can have different types of representation on their boards, including businesses serving low-income communities (24 CFR 570.204(c)(1)(iv)). Thus, after a careful examination of the two sets of statutory and regulatory requirements, the Department has determined that no change to further align the definitions should be made at this time.</P>
                    <HD SOURCE="HD3">D. Paragraph (4) of CHDO Definition—Tax Exempt Status</HD>
                    <P>One commenter supported the change to the CHDO definition that clarifies the options for meeting the requirement that a CHDO must be exempt from taxation.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the comment and is adopting the language in paragraph 4 of the CHDO definition at § 92.2 without change.
                    </P>
                    <HD SOURCE="HD3">E. Paragraph (5) of CHDO Definition—General Support for Changes to Limitations on Public Officials on a CHDO's Governing Board</HD>
                    <P>Commenters were broadly supportive of the proposed change narrowing the individuals who would count toward the one-third limitation on governing board membership from “any governmental entity” to “officials or employees of the participating jurisdiction or governmental entity that created the community housing development organization.” Commenters stated that the proposed change would provide more flexibility to nonprofit organizations in meeting the board requirements while maintaining the freedom from governmental control of CHDOs intended by statute. One commenter stated that the change would help CHDOs create boards with expertise in the field of affordable housing, while appropriately addressing conflict of interest considerations that may arise. Another commenter stated that the change will facilitate resource-sharing between CHDOs and governmental entities such as councils of governments, Tribal entities, and regional planning commissions in rural communities.</P>
                    <P>Commenters also supported the proposal to clarify that no governmental entity, not only the one that created the CHDO, may appoint more than one-third of the CHDO's board members, as well as the language clarifying that not only may the board members appointed by a government entity not appoint the remaining two-thirds of a CHDO's board members, the board members who are officials or employees of the governmental entity that created the CHDO may not appoint any of the remaining two-thirds board members.</P>
                    <P>One commenter recommended that HUD emphasize that the one-third public official restriction on board membership does not apply to all CHDOs, only those CHDOs that were created by a governmental entity. The commenter stated that this would involve promulgating a Notice clarifying the new and correct interpretation of this paragraph, and an intense training and communication plan to educate participating jurisdictions across the country.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for sharing their views. HUD is adopting the proposed rule language without change. The Department also agrees that its guidance should be clearer that, while all CHDOs must be free from governmental control, the one-third limitation on public 
                        <PRTPAGE P="773"/>
                        officials only applies to CHDOs that were created by the participating jurisdiction or another governmental entity. For CHDOs not created by a governmental entity, the participating jurisdiction must determine that the CHDO is not a governmental entity and is not controlled by a governmental entity.
                    </P>
                    <HD SOURCE="HD3">F. Paragraph (5) of CHDO Definition—Opposition to Public Officials on a CHDO's Governing Board</HD>
                    <P>A commenter questioned why HUD would require a CHDO to include elected officials on the CHDO board. The commenter stated that requiring CHDOs to include elected officials on the CHDO board would constitute a conflict of interest because elected officials approve the funding for HOME projects. The commenter stated that a CHDO would have to turn to neighboring communities to select elected officials for the CHDO board to avoid any conflict.</P>
                    <P>
                        HUD Response: The commenter incorrectly believes that HUD is requiring CHDOs to include elected public officials on the CHDO governing board. HUD revised paragraph (5) of the 
                        <E T="03">Community Housing Development Organization</E>
                         definition in § 92.2 to make the existing limitation on public officials and employees of a governmental entity on the CHDO governing board less restrictive should a CHDO choose to include public officials on the governing board.
                    </P>
                    <HD SOURCE="HD3">G. Paragraph (5) of CHDO Definition—Limitation on Public Officials on a CHDO's Governing Board—Volunteer Members Planning or Zoning Commissions</HD>
                    <P>One commenter recommended that HUD allow volunteer members of planning or zoning commissions or other local advisory boards to serve as CHDO board members and not count against the public sector limit.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD is not adopting this recommendation. Whether a volunteer member of a planning or zoning commission or other local advisory board may count towards the public sector limit depends upon a variety of factors including whether the organization the person is volunteering for created the CHDO, whether the person is considered an employee or official, whether the entity is considered part of the participating jurisdiction, 
                        <E T="03">etc.</E>
                         It is likely that many volunteer members of planning or zoning commissions or other local advisory boards may not count towards the limits described in paragraph (5) of the definition of 
                        <E T="03">community housing development organization</E>
                         contained in § 92.2.
                    </P>
                    <HD SOURCE="HD3">H. Paragraph (5) of CHDO Definition—Statutory Basis for Limitation on Public Officials on a CHDO's Governing Board</HD>
                    <P>One commenter was supportive of changes to the CHDO board but also encouraged HUD to go further and fully address the “public officials” issue. The commenter disputed that there was a statutory basis for limiting participation of public officials or employees of governmental entities from being board members of CHDOs. The commenter believed that it was entirely at HUD's discretion whether to include this language in its regulations, or not, and how to interpret it.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         When the Act was created, CHDOs, which had existed prior to the Act, were nonprofit, private sector organizations that had deep ties to the community. The Congressional findings of the Act explicitly stated that CHDOs are nonprofit organizations acting in the private sector.
                        <SU>21</SU>
                        <FTREF/>
                         If a governmental entity creates a CHDO, then it is consistent with the purposes and findings of the Act to place a reasonable limitation on the public sector board membership of the CHDO. This limitation is necessary to ensure that the CHDO is not simply an affiliate or an alter ego of a governmental entity but a robust community-based nonprofit organization with capacity to develop, sponsor, and own affordable housing in the jurisdiction. The Department is moving forward with its revisions to paragraph (5).
                    </P>
                    <FTNT>
                        <P>
                            <SU>21</SU>
                             42 U.S.C. 12721.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">I. Paragraph (5) of CHDO Definition—Further Narrow Limitation on Public Officials on a CHDO's Governing Board</HD>
                    <P>Another commenter suggested that HUD could further reduce barriers to meeting low-income representation and public official requirements by counting only elected or appointed officials toward the public official limitation and permit civil service employees to serve on CHDO boards, subject to a conflict of interest policy.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department believes that it has struck the correct balance in its new final rule requirements and is not adopting this recommendation. The limits in paragraph (5) of the definition of 
                        <E T="03">community housing development organization</E>
                         only apply when the CHDO was created by a governmental entity and the civil service employee is working for the governmental entity that created the organization or the participating jurisdiction that is funding the organization. This is already a narrow subset of all cases. Even when the limit in paragraph (5) of the definition of 
                        <E T="03">community housing development organization</E>
                         applies, HUD regulations are not barring the person's representation but stating that the person counts towards the limit and cannot be an officer or employee of the organization in order to consider the organization a CHDO.
                    </P>
                    <HD SOURCE="HD3">J. Paragraph (5) of CHDO Definition—Low-Income Public Officials on a CHDO's Governing Board</HD>
                    <P>Commenters suggested that HUD should revise the rule to state that if an appointed official or employee of a participating jurisdictions lives in a low-income community and is themselves low-income, they will be allowed to be counted toward the low-income representation on the board of the CHDO and not count as a public official. One commenter stated the regulation should explicitly state that this applies in rural areas or areas where significant low-income representation does not exist.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         If a person meets the definition of low-income under § 92.2 or lives within a low-income community, then under paragraph (8)(i) of § 92.2 
                        <E T="03">Community housing development organization,</E>
                         the person would be included in the one-third representation requirement. If a CHDO is created by a governmental entity, no more than one-third of its board may be officials or employees of the participating jurisdiction providing HOME funds to the CHDO or the governmental entity that created the CHDO. In the commenter's example, if the CHDO was created by a governmental entity, and the person was an employee or official of the participating jurisdiction funding the CHDO or the governmental entity that created it, then the person would also count towards the one-third limitation under paragraph (5) of the definition of 
                        <E T="03">community housing development organization</E>
                         in § 92.2. These are independent requirements and serve to prevent potential abuses. The Department would also note that under the commenter's recommended approach, the entire board of an organization created by a governmental entity could be employees or officials so long as they were low-income or lived in low-income neighborhoods. This is not the intent of the drafters of the Act in creating the set-aside requirement and the Department is declining the commenters' recommendations.
                        <PRTPAGE P="774"/>
                    </P>
                    <HD SOURCE="HD3">K. Paragraph (5) of CHDO Definition—Further Limit Public Officials on a CHDO's Governing Board to Officials or Employees Administering HOME Assistance</HD>
                    <P>One commenter that is a State participating jurisdiction stated that it supports the proposal to narrow public officials to the participating jurisdiction but questioned what unit of government is considered the participating jurisdiction. The commenter asked whether all State employees would be considered part of the participating jurisdiction or whether the limitation would apply to the lead agency, the consolidated planning partners or the administrator of the HOME grant. The commenter recommended that the language be updated to apply the limitation only to employees of the entity that administers the HOME funding.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         In the scenario raised by this commenter, the participating jurisdiction is the State, and the limitation would apply to officials and employees of any State agencies, not solely officials and employees of the agency that administers the State's HOME grants. HUD declines to change the regulation so that only employees of the agency that administers the HOME funds for the participating jurisdiction count towards the one-third limitation or the prohibition against being an officer or employee of a CHDO. This change would be inconsistent with the statutory intent that CHDOs not be controlled by the participating jurisdiction. An official or employee of a participating jurisdiction, even when not affiliated with the specific agency administering HOME assistance, is still potentially subject to the influence of that participating jurisdiction. Consequently, when they serve on a CHDO board, HUD believes that they should count toward the one-third limitation on public sector participation on the board of a CHDO created by a participating jurisdiction.
                    </P>
                    <HD SOURCE="HD3">L. Paragraph (8) of CHDO Definition—Support for Inclusion of “Designees” of Low-Income Neighborhood Organizations</HD>
                    <P>
                        Several commenters supported the proposed change to expand the CHDO low-income board representation requirement under paragraph (8)(i) of the definition of 
                        <E T="03">community housing development organization</E>
                         to include “designees” of low-income neighborhood organizations rather than only the elected representatives of such organization, stating that the change is helpful and will widen the pool from which CHDOs may find board members. A commenter who supported the proposed changes stated that they would be particularly helpful for communities with rising incomes where board members who previously qualified as residents of a low-income neighborhood may now be residents of a middle-income neighborhood.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the comments and is adopting this change.
                    </P>
                    <HD SOURCE="HD3">M. Paragraph (8) of CHDO Definition—Difference Between “Designee” and “Authorized Representative”</HD>
                    <P>Multiple commenters asked that HUD clarify or provide examples in the final rule of the difference between a “designee” and an “authorized representative,” as used in paragraph (8)(i) of its proposals regarding nonprofit representatives on CHDO boards because the proposed rule implies a difference that is not explained. Another commenter noted that there is some ambiguity in the term “authorized representatives” in paragraph (8)(i) and encouraged HUD to broaden the scope of the language as it could be construed to mean only individuals who have legal authority to bind the nonprofit.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department recognizes that using two different terms “designee” and “authorized representative” created confusion because low-income neighborhood organizations and nonprofit organizations that address housing or supportive services needs of residents of low-income-neighborhoods may have similar corporate structures and organizational requirements. The Department believes that the term “designee” is the appropriate term. A low-income neighborhood organization or a nonprofit organization that addresses the housing or supportive service needs of low-income residents or residents of low-income-neighborhoods can designate one or more persons to serve on the board of a CHDO. Accordingly, the Department has revised paragraph (8)(i) of the definition of CHDO to read “designees of nonprofit organizations in the community that address the housing or supportive service needs of low-income residents or residents of low-income neighborhoods . . . .”
                    </P>
                    <HD SOURCE="HD3">N. Paragraph (8) of CHDO Definition—Support for Inclusion of Authorized Representatives of Nonprofit Organizations in the Community That Address the Housing or Supportive Service Needs of Residents of Low-Income Neighborhoods</HD>
                    <P>Many commenters stated that they support the proposals to permit authorized representatives of local non-profit organizations and members of low-income neighborhood organizations to meet the CHDO board requirements for low-income residents. One commenter stated that representatives from organizations who serve low-income persons, even when an organization's focus is on a topic other than housing, should count towards the low-income representation. Other commenters objected to the proposed rule's addition of “authorized representatives of nonprofit organizations” to the definition of CHDOs in § 92.2, citing concerns about accountability and connection of a CHDO board to the low-income neighborhood. One commenter stated that relaxing the requirement for direct community involvement on CHDO boards would dilute the intended impact of the designation as a means for maintaining accountability to low-income community residents because authorized representatives from nonprofit organizations are not required to reside in the neighborhood nor be low-income themselves. The commenter recommended that HUD remove the “authorized representative” option for meeting the CHDO board member eligibility requirement. Another commenter stated that the expanded definition is not community-centered and does not truly connect the governance of the CHDO to the community.</P>
                    <P>One commenter stated that although they were not firmly opposed to the change, they were concerned about the potential of the proposed changes to water down the representation of low-income people in CHDO governance, which is an important source of accountability. The commenter urged the Department to consider the possibility of layering using a tandem requirement to preserve the opportunities for low-income people to participate in this process.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department is moving forward with language allowing for designees of nonprofit organizations in the community that address the housing or supportive service needs of low-income community residents or residents of low-income neighborhoods to count towards the one-third board 
                        <PRTPAGE P="775"/>
                        membership requirement in paragraph (8)(i) of the definition of 
                        <E T="03">community housing development organization</E>
                         in § 92.2.
                        <SU>22</SU>
                        <FTREF/>
                         The Department believes that designees of nonprofit organizations that house or provide supportive services to low-income residents or residents of low-income neighborhoods are accountable to the people they serve, understand the challenges they face, and are in a position to represent the beneficiaries of their services in making decisions on the design, siting, development, and management of affordable housing, in accordance with 42 U.S.C. 12704(6)(B).
                    </P>
                    <FTNT>
                        <P>
                            <SU>22</SU>
                             See earlier preamble discussion on why the Department is using the term “designee.”
                        </P>
                    </FTNT>
                    <P>Designees of nonprofit organizations that address the housing or supportive service needs of low-income community residents or residents of low-income neighborhoods may not always live in low-income neighborhoods or be low-income, but they directly serve those that are, including persons with disabilities, victims of domestic violence, homeless persons, people suffering from food insecurity, and victims of civil rights violations. Their participation strengthens the board of CHDOs because these organizations have deep ties to the community and the people they serve. Far from watering down the requirements for board members, the Department believes that this better enables CHDOs to retain subject matter experts that better understand the community being served by the CHDO.</P>
                    <HD SOURCE="HD3">O. Paragraph (8) of CHDO Definition—Building More Equity Into Governing Boards</HD>
                    <P>One commenter stated that it was concerned about recruitment and retention of low-income residents for board membership and understands HUD's proposal to relax board member restrictions, but would appreciate further consideration/guidance toward instilling equity in board member criteria requirements because this impacts board member representativeness. The commenter stated that this relaxation may eventually have potentially negative effects on low-income tenants residing in the affordable housing development. The commenter further stated that a board that is technically allowed per HUD requirements may not be representative of the community it serves.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the comment and recognizes the tension inherent in simplifying qualification requirements to increase the number of organizations that can qualify as CHDOs and maintaining accountability to the low-income neighborhood where a project is located. HUD believes that the requirement in paragraph (8)(ii) that a CHDO have a formal process for low-income program beneficiaries to advise the organization in its decisions regarding the design, siting, development, and management of affordable housing helps maintain accountability to low-income tenants residing in projects. HUD is attempting to build equity in this by including “designees of nonprofit organizations in the community that address the housing or supportive service needs of low-income residents or residents of low-income neighborhoods, including homeless providers, Fair Housing Initiatives Program (FHIP) providers, Legal Aid, disability rights organizations, and victim service providers.”
                    </P>
                    <P>HUD has determined that the entities used as examples in this section each assist protected classes including persons with disabilities; survivors of domestic violence, dating violence, stalking, sexual assault, and human trafficking; and persons suffering from various forms of discrimination. By clarifying how FHIPs, Legal Aid organizations, and other civil rights organizations can count towards representation, HUD is advancing equity in CHDO board composition. Moreover, the Department believes that each hold a connection to the community and will make CHDOs more representative of the community and the needs of low-income residents within the community.</P>
                    <HD SOURCE="HD3">P. Paragraph (8) of CHDO Definition—Examples of Nonprofit Organizations That Address the Housing or Supportive Service Needs of Residents of Low-Income Neighborhoods</HD>
                    <P>Commenters requested that HUD clarify in the final rule or supplemental guidance whether the list of community serving organizations included in the proposed rule is organizations from which authorized representatives can qualify for the low-income portion of the CHDO board is exhaustive or illustrative in nature. Some commenters urged HUD to be as expansive as possible in identifying the types of organizations included in this provision. Some commenters suggested other types of organizations that should be specifically listed in the regulation, including health and behavioral healthcare providers, healthcare organizations, food pantries, workforce development organizations, Native American- and Tribal-serving organizations, and faith-based organizations. Commenters stated that the inclusion of faith-based institutions could further HUD's goals of supporting CHDOs in rural areas. One commenter cited the historically significant relationship between faith-based organizations and housing development organizations, especially in rural areas.</P>
                    <P>One commenter recommended against the HOME program rule listing out specific organizations that meet the low-income representative requirement for CHDO boards. The commenter stated that if HUD wishes to include a specific list of organizations, then HUD should make sure the list explicitly states that the listed organizations are just examples of organizations that qualify to meet the low-income representative requirement for CHDO boards.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the recommendations made by the commenters. The Department believes the current list of examples of nonprofit organizations that address housing or supportive service needs of low-income residents or residents of low-income-neighborhoods in paragraph (8)(i) of the definition of CHDO in § 92.2 is sufficient for the public to understand what type of organizations meet this requirement. Some of the commenters' recommendations, like faith-based organizations, are already explicitly mentioned in HOME regulations.
                        <SU>23</SU>
                        <FTREF/>
                         Many of the other organizations that commenters mention will qualify if they meet the nonprofit requirements and provide needed housing or supportive services to community residents. The Department will provide additional implementation guidance on the new CHDO requirements.
                    </P>
                    <FTNT>
                        <P>
                            <SU>23</SU>
                             See paragraph (10) of the definition of 
                            <E T="03">community housing development organization</E>
                             in 24 CFR 92.2.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">Q. Paragraph (8) of CHDO Definition—Reduce Low-Income Board Membership Requirements</HD>
                    <P>
                        Commenters encouraged HUD to reduce the low-income board requirement below the current one-third or eliminate the low-income representation requirement altogether. One commenter stated that expanding low-income board eligibility to include “designees of low-income neighborhood organizations” will not increase nonprofit interest in becoming CHDOs because nonprofit organizations do not want to make significant changes to their board composition. One commenter who supported the proposed changes also recommended reducing the low-income board representation from 
                        <PRTPAGE P="776"/>
                        one-third to 10 or 15 percent, stating that this would still constitute significant representation by low-income community residents.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department believes that the one-third board representation requirement is consistent with the statutory intent in 42 U.S.C. 12704(6)(B), which requires that CHDOs maintain accountability to low-income community residents through “significant” representation on the organization's governing board and “to the extent practicable, to low-income beneficiaries with regard to decisions on the design, siting, development, and management of affordable housing.” Reducing the percentage or eliminating the requirement would not be consistent with the intent of the Act and would decrease the CHDO's connection with the people they serve. The Department is declining to change the one-third board representation requirement.
                    </P>
                    <HD SOURCE="HD3">R. Paragraph (8) of CHDO Definition—Meeting the Low-Income Representation Requirement in Rural Communities</HD>
                    <P>A commenter stated that in their rural service area there are no low-income neighborhood organizations and that one of their board members works at a nonprofit as the school district's homeless liaison and family support specialist. The commenter stated that because there are no low-income neighborhoods in the school district, the noted board member would not count toward the one-third low-income representation. The commenter suggested that HUD consider using tandem requirements to preserve the opportunities for low-income people to participate in this process. Another commenter with a rural service area suggested that the language in paragraph (8)(i) of § 92.2 be changed to “. . . authorized representatives of nonprofit organizations in the community that address the housing or supportive service needs of low-income residents of the CHDO's service area . . . .”</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department recognizes the challenges in rural communities where nonprofit organizations may be providing supportive services to low-income individuals but may not be serving in a low-income community. The Department believes that it has sufficiently broadened paragraph (8) to account for designees of nonprofit organizations that serve low-income residents within the community that the CHDO serves. This should address the commenter's concerns and better enable people who serve low-income community residents to represent their interests on the board of a CHDO.
                    </P>
                    <HD SOURCE="HD3">S. Paragraph (8) of CHDO Definition—The Use of the Term “Residents of Low-Income Neighborhoods” Is Too Limiting</HD>
                    <P>Another commenter also suggested that HUD reconsider the phrasing “residents of low-income neighborhoods” because it suggests that service organizations who are regional or whose clients are not defined by the clients' neighborhood of residence are not eligible. The commenter stated that agencies that are included in this criterion necessarily have regional footprints, and the residents they serve are defined by some income or other “need” characteristic, not the income level of the neighborhood in which the client lives.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department agrees that the phrasing of “residents of low-income neighborhoods” could be read as too narrow and does not fully capture the statutory intent of the definition contained in 42 U.S.C. 12704(6). 42 U.S.C. 12704(6)(B) requires that a CHDO be a nonprofit organization that “maintains, through significant representation on the organization's governing board and otherwise, accountability to low-income community residents and, to the extent practicable, low-income beneficiaries with regard to decisions on the design, siting, development, and management of affordable housing . . .” HUD has determined that adding “low-income beneficiaries of HUD programs,” to the list of individuals that may count towards the one-third board membership requirement contained in paragraph (8)(i) of the definition of CHDO in § 92.2 can partly address the commenter's concern while also being more consistent with the statutory requirement. HUD believes this will address the commenter's concerns because status as a low-income beneficiary of HUD programs is not connected to the immediate geography of the person served. HUD encourages CHDOs, to the greatest extent practicable, to include low-income beneficiaries of HUD programs because their inclusion will lead to increased accountability. HUD recognizes that not all HOME rental projects and not all people served by HUD programs reside in low-income communities and believes that this addition will make this representation more inclusive. HUD encourages siting projects outside of areas of concentrated poverty but still wants accountability to the beneficiaries of the program served. Therefore, HUD believes this change is a meaningful revision. HUD would note that while HUD is proposing this revision to make it clearer that beneficiaries of HUD programs can count towards the representation requirements, the Department would like to clarify that the term “other low-income community residents” is already part of the regulation and the term “community” can be considered a multi-county area. So, it is very possible that many of the people the commenter described may already be eligible to count towards the one-third board representation requirement contained in paragraph (8)(i) of the definition of CHDO in § 92.2.
                    </P>
                    <P>The Department is also addressing the commenter's concerns by expanding the type of designees of nonprofit organizations to include nonprofit organizations that serve “low-income residents” instead of organizations serving “residents of low-income neighborhoods.” Therefore, in the example the commenter gave, if the person was a designee of a nonprofit organization that provided services to a low-income resident of the CHDO's community, then the person would be able to count towards the one-third board representation requirement in paragraph (8) of the definition of CHDO.</P>
                    <HD SOURCE="HD3">T. Paragraph (8) of CHDO Definition—Lived Experience Should Count Towards Low-Income Board Representation Requirements</HD>
                    <P>Commenters stated that HUD should consider individuals who are not low-income but have previous lived experience as a low-income person or a homeless person to qualify as a low-income community resident for the purposes of meeting the requirement for one-third low-income representation on the CHDO governing board. These commenters stated that the changes in circumstance, such as increases in income, do not eliminate such a board member's lived experience, which make them a valuable representative of the interests of low-income people and places.</P>
                    <P>
                        Other commenters recommended that HUD revise the regulation to permit individuals who joined the board as a low-income community resident to retain that designation even if their income rises above the low-income level. Some commenters stated that HUD should provide a grace period in such cases because it is difficult for CHDOs to replace board members when their eligibility as a low-income representative unexpectedly ends. Similarly, a commenter suggested that if a board member moves or has their home address re-designated into a different census tract, HUD should allow a grace period not to exceed the lesser of their board term or five years 
                        <PRTPAGE P="777"/>
                        for that board member to continue to qualify as living in a low-income community. Commenters suggested grace periods of varying length, including three years and 10 years.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department agrees that current lived experience should count towards board representation requirement and has expanded the list of people that can count towards the one-third board representation requirement in paragraph (8) of the definition of CHDO to include low-income beneficiaries of HUD programs. HUD also considered whether persons with former lived experience of being low-income or homeless should qualify towards the requirement that an organization's governing board maintain accountability to low-income community residents and low-income beneficiaries. Unfortunately, the Department believes that this does not satisfy the statutory requirement that board members be connected and answerable to low-income community residents because they might not appropriately account for the present challenges impacting low-income persons in the community being served. The Department also considered providing a set time period in which a person could qualify as a low-income board member regardless of whether the board member's income increased. The Department believed that doing so could lead to a result where individuals who were not low-income, no longer lived in low-income communities, and had no ties or accountability structures to the low-income community would be counted towards the board representation requirement. This is not consistent with the intent of the Act and does not provide accountability to the people that the CHDO serves. As a result, the Department has declined to make the commenters' recommended revisions.
                    </P>
                    <HD SOURCE="HD3">U. Paragraph (8) of CHDO Definition—Expanding the Definition of “Community” To Be Statewide</HD>
                    <P>Some commenters supported the proposed change to allow the definition of the community to include the entire State because it would address challenges rural communities face in meeting the governing board and staff capacity requirements and increase the usage of CHDO set-aside funds in rural areas. One commenter stated that HUD's proposed rule would benefit rural organizations that have experienced negative impacts from the existing high standards in the definition of CHDO in HUD's regulations.</P>
                    <P>Many commenters raised concerns or strongly objected to expanding community to mean the entire State. These commenters believed it would weaken the connection of a CHDO to the low-income community being served. One commenter noted that the proposed change would disincentivize State participating jurisdictions from working to build the capacity of local groups, which is antithetical to the intent of the CHDO set-aside requirement. One commenter expressed concern regarding the change to allow Statewide CHDOs, particularly for very large and geographically diverse States such as California, and recommended HUD allow State participating jurisdictions the flexibility to evaluate the capacity of CHDOs to serve the entire State, especially rural and underserved areas of the State. Commenters stated that the proposed change went too far in permitting rural CHDOs to qualify based on board representation from the areas being served. Several commenters stated the proposed change would inappropriately characterize all rural areas as equal for purposes of low-income representation. One commenter stated that under the proposed regulation, a Statewide CHDO could develop a board with no low-income presence, accountability, or connection with the community served. Another commenter asked HUD to consider the tension between the need to drive more CHDO dollars to rural communities and the need to build capacity and provide opportunities for smaller rural-serving CHDOs when moving forward with the consideration of Statewide CHDOs.</P>
                    <P>Commenters stated that while they recognized the critical need for more CHDOs in rural areas, they were concerned that the proposed change would result in small community-based organizations having to compete for CHDO set-aside funds with large, high-capacity Statewide organizations. One commenter stated that small, rural CHDOs would be disadvantaged by their greater need for capacity building funding. Commenters stated that if HUD adopts the proposed change, it should also implement mechanisms to ensure that Statewide CHDOs consider local community input and priorities in the rural communities they serve and consider how to ensure smaller organizations are not wholly cut out from accessing CHDO resources.</P>
                    <P>Some commenters recommended that HUD allow CHDOs with Statewide service areas to be eligible as CHDOs but only award project dollars to CHDOs (located anywhere in the State) with at least three years of service to the community in which the project is located, as opposed to one year of service anywhere in the State.</P>
                    <P>Commenters noted that the regulations already allow for rural communities to be defined as a multi-county area. One such commenter stated that 42 U.S.C. 12704 prohibits participating jurisdictions from requiring such a CHDO with such a community to have board representation from each of its counties. The commenter stated that there is currently no regulatory barrier for a CHDO to claim as its community every county in a State with the exception of areas within a Metropolitan Statistical Area; the barrier that exists is participating jurisdictions' interpretation of “multi-county.” The commenter suggested that a better proposal would be for HUD to direct the most expansive interpretation of “multi-county”, and to allow individual Statewide participating jurisdictions to apply for waivers from the existing regulation to create Statewide CHDOs only if needed.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the many thoughtful comments submitted by many commenters on both sides of this difficult issue. While HUD remains concerned about the challenges many participating jurisdictions have in identifying and sustaining CHDOs that serve rural areas, it has decided not to adopt the change to the definition of community in paragraph (8) of the CHDO definition. The Department is persuaded by commenters that adopting this proposal would impair or eliminate the accountability of CHDOs to the low-income communities being served with CHDO set-aside funds and would negatively affect small rural CHDOs by putting them in competition with larger Statewide organizations with more capacity but less connection to the low-income community being served.
                    </P>
                    <P>
                        HUD appreciates commenter suggestions that if the proposal were to be adopted, the Department should impose mechanisms to help ensure that Statewide CHDOs consider local community input, require a longer history of serving a specific rural community, or mitigate the disadvantage that smaller rural CHDOs would have in comparison to Statewide organizations in competing for CHDO set-aside funds. However, the Department recognizes that the qualification of nonprofit organizations as CHDOs is already substantially regulated and believes that additional regulation would be counterproductive. Instead, HUD considers the adoption of other proposed changes to the CHDO definition in paragraphs (8) and (9) of § 92.2, to the developer and sponsor roles at § 92.300(a)(2) and (3), and the elimination of the proposed revision of 
                        <PRTPAGE P="778"/>
                        the definition of community in § 92.2 to be a middle ground that will hopefully increase the availability of CHDOs to serve rural areas without diminishing the accountability of those CHDOs to the low-income communities being served.
                    </P>
                    <P>In response to the commenter that stated that 42 U.S.C. 12704 prohibits a participating jurisdiction from requiring a CHDO serving rural areas to have board representation from each of its counties, HUD notes that this interpretation of the Act is incorrect. The Act prohibits HUD, not participating jurisdictions, from requiring that an organization must have representation from each county in its service area to be designated as a CHDO. Because HOME is a block grant program, participating jurisdictions have discretion to establish requirements for their programs and select projects as they choose through requests for proposals or other legally permissible methods. Consequently, participating jurisdictions can establish their own requirements for designating or awarding funds to CHDOs that are more stringent and take into account these types of considerations.</P>
                    <HD SOURCE="HD3">V. Paragraph (9) of CHDO Definition—Using Volunteers To Demonstrate Capacity</HD>
                    <P>Some commenters supported the proposed change in paragraph (9)(i) that would permit the capacity and experience of volunteers who will work directly on a HOME-assisted project and are officers or board members to be considered as part of demonstrated capacity. Commenters stated that the proposed change would make it easier for organizations to qualify as CHDOs.</P>
                    <P>One commenter suggested that HUD not limit volunteers to board members as they considered this limitation unnecessary. The commenter noted that if there are concerns about dependability or ongoing capacity, then the standard should be broadened to also include “contracted volunteers.”</P>
                    <P>Other commenters that supported the proposed change suggested that HUD consider imposing guardrails on volunteer capacity such as applying a limit on the period that the experience of a volunteer official or board member may be counted toward a CHDO's capacity. Some commenters recommended a three-year limit. One commenter stated that prolonged reliance on officials and board members will harm an organization when it comes to meeting development capacity requirements, especially because nonprofits have high staff turnover. The commenter stated that this will affect the ability of nonprofits to train new staff on HOME requirements and place the burden of such education on the participating jurisdiction.</P>
                    <P>One commenter stated that they had serious concerns about volunteers serving on a board in meeting the capacity requirements for an organization. The commenter stated they had these concerns because a volunteer will generally not dedicate the same time and effort as an employee. The commenter also stated that the proposed change would allow for people to create shell organizations that have a representative board who are also real estate professionals and have that qualify as a CHDO organization.</P>
                    <P>A commenter noted that the definition of CHDO in § 92.2(9) states that “the nonprofit organization must have employees or volunteers,” which appears to allow an organization with volunteers and no employees to be designated as a CHDO. The commenter requested that HUD clarify whether this language was intentional or unintentional. The commenter stated further that HUD could refine the language to add clarity on the relationship between “employees” and the nonprofit seeking CHDO designation.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing the rule. The Department especially thanks the commenter that informed the Department that the provision as drafted in the proposed rule could have allowed a CHDO to meet the capacity requirement without paid staff. This was not what the Department intended. The Department is revising paragraph (9)(i) of the definition of CHDO. The Department believes that requiring paid staff and then allowing their capacity to be supplemented by volunteers strikes an appropriate balance. The Department also believes this addresses commenters who requested that there be guardrails or time limitations.
                    </P>
                    <P>Under the final rule, CHDOs must maintain paid staff that will manage the development process. CHDOs can also rely upon board members and officers of the organization with significant development experience because those board members and officers have more lasting ties to the organization than typical volunteers, who may only be volunteering for individual projects or for a limited time.</P>
                    <P>The Department is also declining to allow the use of a “contracted volunteer,” which is an amorphous term that could lead to abuse or indirect control of a CHDO by a for-profit entity, or lead to determining that an organization lacks the capacity when the person demonstrating capacity is not contracted for the full development cycle. Even if the volunteer is contracted for the amount of time overlaps with the development cycle for a particular project, the ties of contracted volunteer service are not nearly as strong or as binding as paid staff, board members, or officers. Typically, the consequences are far less significant if a contracted volunteer ends their volunteer term early, while volunteer board members and officers have terms of office, and the organization generally has mechanisms for replacement of former officers or board members written into their organizational documents to ensure proper governance.</P>
                    <HD SOURCE="HD3">W. Paragraph (9) of CHDO Definition—Experience With Other Funding Sources and Programs</HD>
                    <P>Commenters stated that they support the proposed rule language that would broaden the requirement that an organization have demonstrated staff capacity for carrying out projects assisted with HOME funds to include housing projects funded with other Federal funds, LIHTC, or local and State affordable housing programs. One commenter expressed support because the proposed change would help small rural CHDOs meet organizational capacity requirements.</P>
                    <P>Commenters also requested that HUD explicitly include experience with the New Markets Tax Credits and Federal Home Loan Bank Affordable Housing Program.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department agrees with commenters that the list of types of programs or forms of assistance could be broadened and that experience in the Federal Home Loan Bank Affordable Housing Program is sufficient to demonstrate capacity. The Department is therefore adding this program to this list of programs that demonstrate capacity in paragraph (9) of the definition of CHDO in § 92.2. The Department is declining to add experience with the New Market Tax Credits as these credits are exclusively for non-residential uses and experience in commercial development alone is not sufficient to demonstrate experience with the challenges of housing development.
                    </P>
                    <HD SOURCE="HD3">X. Paragraph (9) of CHDO Definition—Use of Donated Labor, Consultants, and Others</HD>
                    <P>
                        Commenters made suggestions regarding other individuals whose experience should be counted toward a CHDO's capacity. Commenters recommended that the final rule permit 
                        <PRTPAGE P="779"/>
                        the experience of staff from affiliated entities, parent companies, for-profit developers, public housing authorities, and regional planning commissions whose services are donated to the CHDO be considered as capacity of a CHDO. One commenter stated that HUD should clarify the difference between donated time and volunteer time. Several commenters also recommended that CHDOs be allowed to demonstrate capacity and experience through the use of consultants and non-employee compensation.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department does not believe that donated labor is sufficient to meet the statutory requirement in 42 U.S.C. 12704(6)(C) that a CHDO have staff with demonstrated capacity to own, develop, or sponsor a HOME project. The CHDO itself must be capable of participating in the housing development process. When an organization relies upon the expertise of donated labor or individuals who work for affiliated organizations, those individuals lack lasting ties to the organization and may only be donated for individual projects or for a limited time. The donated labor also may lead to situations where organizations that are not CHDOs exercise outsized influence over CHDO projects, thereby potentially undermining the purposes of the Act.
                    </P>
                    <P>The Department does allow the use of a consultant in the first year that a CHDO is provided HOME funds; paragraph (9)(i) reads as follows: “[f]or its first year of funding as a community housing development organization, an organization may satisfy [the capacity] requirement through a contract with a consultant who has housing development experience to train appropriate key paid staff of the organization.” The Department believes that it is appropriate to retain this provision but is adding clarification that the staff that are to be trained must be paid staff, as per the Department's earlier comment response on the importance of paid staff in demonstrating capacity to develop HOME projects.</P>
                    <HD SOURCE="HD3">Y. Revise the CHDO Definition To Enable Participation of More Resident-Owned Communities</HD>
                    <P>One commenter who supported the flexibility provided to CHDOs in the proposed rule stated that the changes do not allow resident-owned communities to qualify as CHDOs. The commenter stated that such communities cannot meet the 501(c)(3) status and demonstrated capacity requirements, even though they fully meet the intent of CHDOs. The commenter stated that resident-owned manufactured housing communities are owned by predominantly low-income community members organized to govern and preserve their communities and have flourished for 40 years due to a system of professional technical assistance, training, and ongoing business coaching. The commenter urged HUD to support capacity building systems for resident-owned communities and other eligible manufactured housing communities.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the comments and agrees that using HOME funds, including CHDO set-aside funds, for manufactured housing communities presents some challenges. The Act requires that to qualify as a CHDO, an organization must be a non-profit organization. The regulations implement that statutory provision through a requirement that a CHDO have tax-exempt status evidenced by a 501(c)(3), 501(c)(4), or section 905 designation from the Internal Revenue Service. In addition, the Act and the Consolidated and Further Continuing Appropriations Act of 2012 (Pub. L. 112-55) and the Consolidated and Further Continuing Appropriations Act of 2013 (Pub. L. 113-6) require that a CHDO have staff with demonstrated capacity to undertake HOME-assisted housing activities. These requirements do not apply to HOME funds outside of the CHDO set-aside making those funds possibly a better fit for such projects. The Department provides a broad range of technical assistance through its Community Compass demand-response system, which can be of assistance in developing approaches to use HOME funds to assist manufactured home communities.
                    </P>
                    <HD SOURCE="HD2">§ 92.2—Community Land Trust Definition</HD>
                    <HD SOURCE="HD3">A. General Comments on the Definition</HD>
                    <P>Several commenters expressed support for HUD's proposed definition of the term “community land trust” with many commenters noting that the proposed definition allows for flexibility in the composition of the organizational board and governance of community land trusts across the country. One commenter specifically noted that the proposed definition does not specify the structure of the community land trust's governing board yet retains the nonprofit purpose, the centrality of land, the lasting affordability, and codifies the preemptive purchase rights of community land trusts to prevent the loss of units to the open market.</P>
                    <P>Two commenters support the elevation of the term “community land trust” to the definition section of the regulation noting that the placement makes it clear that the definition applies throughout the HOME program.</P>
                    <P>Two commenters noted the importance of community land trusts to the affordable housing market noting that community land trusts help families bridge the gap between rental housing and homeownership, benefit residents of color in communities facing displacement, increase resilience against climate extremes, pass lower property taxes through to the project or end user, and are a dedicated partner for local government funding for affordable housing. Several commenters also stated that the proposed definition will enable more community land trusts to participate in the HOME program, while two commenters noted that rural community land trusts in particular would be encouraged to participate in the HOME program. Two commenters also added that the proposed changes would allow community land trusts to fully realize the benefits of the HOME program and the right to a preemptive purchase option provided in 2016.</P>
                    <P>Several commenters expressed concern about or opposition to HUD's proposed definition of community land trust.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department is moving forward with including a definition of community land trust in § 92.2. The definition of community land trust better enables these organizations to participate in the HOME program in the manner envisioned by the Act and the drafters of the Consolidated Appropriations Act, 2016.
                        <SU>24</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>24</SU>
                             The Consolidated Appropriations Act, 2016 Public Law 114-113, div. L, title II, Dec. 18, 2015, 129 Stat. 2878 said that notwithstanding the affordability requirements contained in section 215(b)(3)(A) of the Act [42 U.S.C. 12745(b)(3)(A)], community land trusts may “hold and exercise purchase options, rights of first refusal or other preemptive rights to purchase the housing to preserve affordability, including but not limited to the right to purchase the housing in lieu of foreclosure.”
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">B. Opposition to the Definition Over Concerns of Conflict With Environmental Requirements</HD>
                    <P>One commenter asked if HUD's proposal regarding community land trusts would violate other HUD requirements, including the environmental review process requirement that prevents proposed projects from being built too close to other low-income housing.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The commenter is mistaken. There are no low-income 
                        <PRTPAGE P="780"/>
                        housing concentration requirements as part of the HOME environmental review process. Section 92.202(b) requires that new rental housing meet the site and neighborhood requirements contained in 24 CFR 983.57(e)(2) and (3) but those requirements are not applicable to homeownership projects that are developed by community land trusts.
                    </P>
                    <HD SOURCE="HD3">C. Add “Membership” or “Community-Governed” to the Organizational Requirements of Community Land Trusts</HD>
                    <P>Two commenters objected to the proposed definition noting that HUD should add the phrase “membership or community-governed” to the definition to reflect the community governance structure inherent in community land trusts. The commenters added that HUD should address the underlying concerns about participating jurisdictions' difficulty determining the legitimacy of the governing models through education.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department understands the commenter's concern but does not believe that adding additional community governance structures to the definition of community land trusts in § 92.2 is appropriate at this time. Community land trusts may also attempt to meet the definition of CHDO in § 92.2, and own, develop, or sponsor HOME projects in accordance with § 92.300. Adding additional community governance requirements in addition to those contained in § 92.2 or § 92.300 may create too high of a bar for participation in the HOME program.
                    </P>
                    <P>
                        Moreover, community land trust governance structures vary from State to State, based upon State laws and local models. In the materials that various commenters provided and in the State laws that were reviewed in the preparation of the proposed rule text, the board requirements and best practices varied significantly. Given the wide variety of community land trust models operating over a significant period of time throughout the nation, the Department does not wish to inadvertently narrow the definition or eliminate consideration of an organization that would have met the intent of the drafters of the Act or the Consolidated Appropriations Act, 2016.
                        <SU>25</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>25</SU>
                             The Consolidated Appropriations Act, 2016 Public Law 114-113, div. L, title II, Dec. 18, 2015, 129 Stat. 2878 said that notwithstanding the affordability requirements contained in section 215(b)(3)(A) of the Act [42 U.S.C. 12745(b)(3)(A)], community land trusts may “hold and exercise purchase options, rights of first refusal or other preemptive rights to purchase the housing to preserve affordability, including but not limited to the right to purchase the housing in lieu of foreclosure.”
                        </P>
                    </FTNT>
                    <P>The Department is committed to making it easier for participating jurisdictions to support CHDOs and better implement statutory provisions that enable community land trusts to participate in the HOME program.</P>
                    <HD SOURCE="HD3">D. The Definition of Community Land Trusts Is Too Restrictive</HD>
                    <P>Another commentor objected to HUD's proposed definition of community land trust as too restrictive, stating that the proposed definition could disqualify many community land trusts from using the additional tools that the revised rule would provide. The commenter stated that the use of the phrase “development and maintenance” would exclude community land trusts that carry out non-development activities such as land acquisition and noted that few community land trusts provide maintenance services, which are generally the responsibility of the owner. The commenter suggested replacing the phrase “development and maintenance” with the word “provision,” as in “the provision of housing that is permanently affordable to low- and moderate-income persons,” thereby aligning the proposed community land trust definition with the HOME definition of a CHDO as “[having] among its purposes, the provision of decent housing.”</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department agrees with the commenter that many community land trusts do not develop or maintain housing. As models vary nationwide, the Department recognizes that the wording of the definition was too narrow to permit community land trusts that acquire and hold existing housing to be considered land trusts. Likewise, the use of the term maintenance was confusing for some community land trusts that do not have the responsibility of maintaining the housing during the term of the ground lease. The Department would note that in order to exercise a right of first refusal, the housing must have been developed by a community land trust using HOME funds.
                        <SU>26</SU>
                        <FTREF/>
                         Therefore, while a community land trust may have, as its purposes, “acquiring” or “holding” land, in order to exercise rights of first refusal, the housing must have been developed by the community land trust.
                    </P>
                    <FTNT>
                        <P>
                            <SU>26</SU>
                             The Consolidated Appropriations Act, 2016 only allows community land trusts to exercises purchase rights for “funds provided in prior and subsequent appropriations acts that were or are used by community land trusts for the development of affordable homeownership housing pursuant to section 215(b) of such Act.” Public Law 114-113, div. L, title II, Dec. 18, 2015, 129 Stat. 2878.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">E. Revise Organizational Requirements of Community Land Trusts To Allow New Smaller Community Land Trusts</HD>
                    <P>One commenter stated that HUD should consider amending the community land trust board requirements to allow flexibility for new community land trusts with small portfolios of homes that do not have sufficient lessees to comply with the requirements.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The definition of community land trusts in § 92.2 does not have strict board requirements other than the community land trust not be sponsored by a for-profit entity. A new organization is a community land trust once it meets all of the requirements of the definition. If a new organization meets the requirements in the definition, even if it was only for a small portfolio, it is a community land trust for the purposes of the HOME program definition. The Department would like to remind the public that to exercise the right of first refusal described in § 92.254, which is what the definition of community land trust is used for, the new community land trust must develop HOME homeownership housing in accordance with the requirements of 24 CFR part 92.
                    </P>
                    <HD SOURCE="HD3">F. Conflicts Between the Definition of Community Land Trust in § 92.2 and § 92.302</HD>
                    <P>One commenter stated there is an internal conflict between the proposed definition of a “community land trust” in § 92.2 and the proposed housing education and organization support language at § 92.302(b)(3)(i). Specifically, the commenter stated there is a conflict between the language of the proposed community land trust definition, which allows a combination of a deed restrictions and a preemptive purchase right at a formula price in lieu of a ground lease, and § 92.302(b)(3)(i), which is limited to community land trusts that retain title and convey it via a “long-term ground lease.” The commenter noted there is no easy solution because allowing non-ground lease approaches may inadvertently expand the definition of a community land trust in a manner HUD may not have anticipated.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department acknowledges that the community land trust requirements established in § 92.203(b)(3)(i) differ from the definition of community land trust proposed by the Department in § 92.2. Under NAHA, to receive housing education and organizational support 
                        <PRTPAGE P="781"/>
                        funds, a community land trust must meet the requirements established in the statute, including but not limited to the requirement that a community land trust acquire parcels of land, held in perpetuity, primarily for conveyance under long-term ground lease. The Department codified these requirements in the regulations at § 92.302(b)(3)(i).
                    </P>
                    <P>The Consolidated Appropriations Act, 2016, which for the first time permitted community land trusts to exercise preemptive purchase rights for HOME-assisted homeownership units, required that HUD establish a revised definition of community land trust for this purpose that did not limit program participation to the narrower definition of community land trusts that solely enforce restrictions through a ground lease, as is required for housing education and organizational support funds under NAHA. The proposed definition of community land trust in § 92.2 is reflective of how community land trusts enforce restrictions nationwide, including in the HOME program. The requirements of homeownership in § 92.2, as revised, still apply, as do the period of affordability requirements in § 92.254. The Department understands that there are different dates and different definitions for related requirements and will provide additional implementation guidance on the definitions of community land trust in § 92.2 and § 92.302, how to meet the requirements for homeownership, and preserving affordability when a community land trust exercises a purchase right.</P>
                    <P>The Department will continue to use the definition of community land trust established in the Act and promulgated at § 92.302(b)(3)(i) should the Department receive funds for housing education and organizational support in the future. The Department is moving forward with the separate regulatory definition of community land trust in § 92.2 for those community land trusts that will be eligible to exercise preemptive purchase rights pursuant to the Consolidated Appropriations Act, 2016, as codified in § 92.254(b)(3).</P>
                    <HD SOURCE="HD3">G. Concern Regarding 30-Year Ground Lease Term and Conflicts Between the Definition of Community Land Trust in § 92.2 and the Definition of Homeownership in § 92.2</HD>
                    <P>Several commenters expressed concern or opposition to the proposed regulatory definition that would, in part, require community land trust housing and related improvements to be affordable for at least 30-years. Two commenters noted that community land trusts typically impose ground leases of 90-plus years and are concerned about the reduced 30-year ground lease included in the community land trust definition. One commenter recommended that HUD increase the ground lease for community land trusts to 90-plus years. The commenter stated that it dilutes the mission of community land trusts to reduce the ground lease to 30 years. The commenter stated that the community land trust movement internationally is focused on permanent-affordability with 98- and 99-year ground leases or land use restrictions. In support of their comments, the commenter included additional information regarding community land trusts, including the: (1) Grounded Solutions Network, 2011 Model Ground Lease &amp; Commentary (2018); (2) National League of Cities, Community Land Trusts: A Guide for Local Governments (2021); and (3) Burlington Associates in Community Development, Frequently Asked Questions about Community Land Trusts (2007). Another commenter stated that community land trust ground leases typically restrict resale of a home to an income eligible buyer at an affordable price for 99 years, and typically require that the buyer enter into a new 99-year ground lease upon purchase. The commenter referred HUD to Grounded Solutions Network Model Declaration of Affordability Covenants and Model Ground Lease (Article 10).</P>
                    <P>One commenter stated that there is an internal conflict within the definitions of a “community land trust” and “homeownership.” The commenter noted that the definition of community land trust includes organizations that provide ground leases of at least 30 years while the definition of homeownership requires that community land trust ground leases be for at least 50 years. The commenter stated that these definitions could allow organizations to qualify as a community land trust by offering ground leases of only 30 years but make said community land trusts ineligible to receive HOME funds unless the HOME-assisted units were accompanied by 50-year ground leases.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The definition of community land trust at § 92.2 establishes the minimum requirements an organization must meet to qualify to hold a preemptive purchase option on a HOME-funded homebuyer unit, including but not limited to the requirement that a community land trust must use a lease, covenant, agreement, or other enforcement mechanism to require housing and related improvements on land held by the community land trust to be affordable to low- and moderate-income persons for 
                        <E T="03">at least</E>
                         30 years. Organizations that meet these minimum requirements may exercise the purchase option, right of first refusal, or other preemptive rights afforded to community land trusts by the Continuing Appropriations Act, 2016 (Pub. L. 114-113) and codified in § 92.254(b)(3). Community land trusts that do not meet this definition are not precluded from receiving HOME funds for projects; however, if they exercise a preemptive purchase right within the period of affordability, then the housing will cease to be considered affordable housing under the Act and the participating jurisdiction will be required to repay the HOME investment associated with that housing unit pursuant to 42 U.S.C. 12745(b)(3)(A) and 42 U.S.C. 12749(b).
                    </P>
                    <P>The Department understands that community land trust models throughout the country often impose a 90 or 99-plus-year ground lease. Because the definition of community land trust at § 92.2 only establishes a minimum ground lease term for the purposes of determining an organization's eligibility to hold or exercise a preemptive purchase right on a HOME-assisted unit without violating the Act and requiring repayment of the HOME investment, community land trusts imposing longer ground lease terms are still permitted.</P>
                    <P>
                        The Department also acknowledges that it is using different minimum terms for ground leases in the definition of community land trust and the definition of homeownership in § 92.2. The definition of homeownership at § 92.2 defines homeownership under a community land trust as fee simple ownership of a dwelling, or equivalent form of ownership approved by HUD, on land with a ground lease that meets one of the requirements in § 92.2. Under this definition, if a ground lease is provided by a community land trust and is not in an insular area, the minimum required ground lease for the unit to be considered a homeownership unit under the HOME program is 50 years. As noted above, the definition of community land trust only requires that an organization impose a minimum 30-year ground lease for the organization to be considered a community land trust for purposes of exercising a right of first refusal to preserve affordability under § 92.254(b). The Department understands that this establishes a higher threshold for the term of a ground lease to be considered homeownership under the HOME program than it does for an organization providing that ground lease to be 
                        <PRTPAGE P="782"/>
                        considered a community land trust, but the Department also wanted to remain consistent with State laws and community land trust models that may require ground leases of fewer years when considering whether an organization meets the definition of community land trust.
                    </P>
                    <HD SOURCE="HD3">H. Opposition to Community Land Trust Model</HD>
                    <P>One commenter opposed the use of governments subsidies for homeownership projects under the community land trusts model. The commenter stated that government subsidies for community land trusts should be reserved for affordable rental housing. The commenter also stated that downpayment assistance is a better method for building financial security and generational wealth through homeownership because community land trusts are closer to rental housing than homeownership. The commenter submitted a study conducted by the National League of Cities comparing the results of community land trust and downpayment assistance models. The commenter supported greater use of the HUD's 203(k) Loan Program to create accessory dwelling units and tax exemptions to encourage homeownership.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for reviewing the proposed rule and notes that by statute, community land trusts may participate in the HOME program and HOME homeownership activities.
                        <SU>27</SU>
                        <FTREF/>
                         Congress explicitly authorized their participation, and the Department must faithfully adopt the language of the Consolidated Appropriations Act, 2016 and the provisions of 42 U.S.C. 12773 of the Act.
                    </P>
                    <FTNT>
                        <P>
                            <SU>27</SU>
                             See 42 U.S.C. 12773(a)(2), expressly permitting housing education and support to community land trusts to assist them in developing HOME community housing development organization projects, and see and Public Law 114-113, div. L, title II, Dec. 18, 2015, 129 Stat. 2878 permitting community land trusts to hold and exercise certain purchase rights without violating the affordability requirements contained in the homeownership provisions of Section 215 of NAHA.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD2">§ 92.2—Homeownership Definition</HD>
                    <HD SOURCE="HD3">A. Require That Long-Term Ground Leases to HOME-Assisted Manufactured Homeowners Are Affordable</HD>
                    <P>One commenter recommended requiring participating jurisdictions to remove barriers to manufactured home homebuyers and homeowners to access HOME programs regardless of the manufactured home being on owned-land, leased-land, Tribal land, or in manufactured home communities. The commenter also specifically urged HUD to ensure that HOME-funded manufactured home communities offer homeowners a standard, long-term lease with predictable rent provisions that support affordable “home-only” financing, notice of sale and opportunity to purchase the community, and require that projects with HOME funding for 30 years or more include shared-equity affordability provisions of resident-owned communities and rent limitations. The commenter urged HUD to issue guidance and education for participating jurisdictions, subrecipients, and developers.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         While the definition of homeownership in § 92.2 requires that manufactured housing ground leases be for at least the period of affordability in § 92.254, the Department has not specified the amount that may be charged under such ground leases. The Department believes that adding such restrictions could have the unintended effect of reducing the amount of manufactured home purchasers that can be assisted with HOME funds and defers to participating jurisdictions in designing their programs. The Department also believes that it provided insufficient information the public to appropriately place the public on notice of any changes to the ground lease requirements for manufactured housing owners and that doing so without additional comment would be unwise.
                    </P>
                    <HD SOURCE="HD3">B. Explicitly Include Cooperative Owners as Owners for Purposes of the Definition of Homeownership in Paragraph (4)</HD>
                    <P>One commenter suggested that to ensure eligibility status for affordable housing cooperatives, HUD should consider revising its definition of homeownership to include housing cooperative members as homeowners directly. The commenter explained that designating co-op member-owners as homeowners will grant additional flexibility to participating jurisdictions, creating another tool to be utilized to create affordable homeownership for low-income households and to reduce persistent wealth inequities.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Unfortunately, HUD cannot always draw bright line rules in this area. Much of what the commenter is requesting depends upon State law and is a fact-sensitive inquiry that must be engaged in by the participating jurisdiction. Paragraph (4) of the definition of Homeownership in § 92.2 states that the “participating jurisdiction must determine whether or not ownership or membership in a cooperative or mutual housing project constitutes homeownership under State law; however, if the cooperative or mutual housing project receives Low-Income Housing Credits (26 U.S.C. 42), the ownership or membership does not constitute homeownership.” The Department believes these are the correct considerations. The Department defers to State law on whether membership within a cooperative or being a shareholder of a cooperative constitutes homeownership. It also defers to the participating jurisdiction to determine whether the cooperative's governing documents provide the necessary rights to the member or shareholder to constitute homeownership. Under many State laws and cooperative governing documents, the commenter may be right that a member or shareholder is an owner. However, this is a fact-sensitive inquiry and HUD is declining to state that as a rule a member or shareholder of a cooperative is an owner of the housing. HUD also continues to maintain that where a cooperative is receiving LIHTC and is within its compliance period, it is not engaging in a homeownership activity.
                    </P>
                    <HD SOURCE="HD2">§ 92.2—Period of Affordability Definition</HD>
                    <P>Commenters supported HUD's proposed definition of “period of affordability.” One commenter noted that distinguishing between the Federal period of affordability and any participating jurisdiction-imposed additional period will be useful and follows a similar model to the LIHTC compliance period. One commenter noted that it was an important clarification that addressed confusion about whether this term applied to time periods beyond 20 years.</P>
                    <P>One commenter stated they supported the proposal because it would clarify that this term is different from an extended period of affordability or an additional compliance period. The commenter explained that this clarification would permit States and localities to continue to prioritize long-term affordability.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters and is moving forward with the revised definition of period of affordability without change.
                    </P>
                    <HD SOURCE="HD2">§ 92.2—Program Income Definition</HD>
                    <P>
                        Commenters stated that they oppose changing the definition of program income to include the phrase “at any time.” The commenters stated that this change would extend the participating jurisdiction's monitoring obligations, potentially in perpetuity, which would strain limited participating jurisdiction resources.
                        <PRTPAGE P="783"/>
                    </P>
                    <P>One commenter opposed HUD's proposal to clarify that program income is gross income received “at any time” by the participating jurisdiction, State recipient, or subrecipient. The commenter stated that defining program income as going beyond the period of affordability or the closeout of the grant puts an administrative burden on participating jurisdictions, subrecipients, and developers. The commenter recommended that HUD limit repayment of program income to either the duration of the period of affordability for housing supported by HOME funds or to the closeout of the grant.</P>
                    <P>Two commenters suggested limiting repayment of program income to the duration of the period of affordability for homes supported by HOME funds or at the close out of the grant in order to ease the administrative burden on participating jurisdictions, subrecipients and developers. One of these commenters asked that HUD provide more clarity to participating jurisdictions and program participants on how any final changes would be operationalized if HUD determines to move forward on this question.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The addition of “at any time” to the definition of program income was a clarification of the existing requirement. The Department is aware that there is an administrative burden associated with tracking and spending program income. However, 10 percent of program income received may be used to administer the HOME program. A participating jurisdiction is also capable of providing Subrecipients and State recipients with the ability to retain program income if it is specified in the written agreement (see § 92.504(c)(1)(iii), § 92.504(c)(2)(ii)). The Department is concerned that limiting the reporting and use of program income to the period of affordability or to the time period before grant closeout will result in participating jurisdictions waiting until the end of those timeframes to require the collection of program income to avoid reporting on the source and avoid the restrictions on the use of program income. This might also result in participating jurisdictions misunderstanding program income requirements and using such funds for purposes not eligible under the Act and regulations in 24 CFR part 92. The Department declines to make a change and is moving forward with the language clarifying existing requirements.
                    </P>
                    <HD SOURCE="HD2">§ 92.2—Reconstruction Definition</HD>
                    <P>One commenter stated that it supports applying new construction standards in § 92.251 to newly constructed units within reconstruction projects. However, the commenter noted that some projects involve reconstruction of some units and rehabilitation of others. The commenter objected to applying new construction standards to these rehabilitated units, noting that it would not be a prudent use of resources. The commenter opposed the revised definition of “reconstruction” but supported applying new construction standards in § 92.251 to newly constructed units within reconstruction projects.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department understands there is confusion over how to apply a participating jurisdiction's property standards when a project consists of a combination of rehabilitation, reconstruction, and new construction. In projects where there is a combination of types of development, units that are rehabilitated but not reconstructed may be inspected to the participating jurisdiction's rehabilitation standards. Units that are newly constructed or reconstructed will be subject to the participating jurisdiction's new construction standards. Accordingly, the Department has revised the regulations at § 92.251(d) to address the commenter's concerns and provide clarity on this issue.
                    </P>
                    <HD SOURCE="HD2">§ 92.2—Single Family Housing Definition</HD>
                    <P>Commenters stated that they support the proposal to amend the definition of “single family housing” to refer to units.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters and is moving forward with the changes to the “single family housing” definition.
                    </P>
                    <HD SOURCE="HD2">§ 92.2—Small-Scale Housing Definition</HD>
                    <HD SOURCE="HD3">A. General Comments on Definition</HD>
                    <P>One commenter supported the proposed new definition of “small-scale housing” because it would reduce administrative burden and would, according to the commenter, benefit areas with little development like small rural towns and Tribal areas because smaller projects that are not 30-50 units cannot attract LIHTC or other program investors and become financially infeasible.</P>
                    <P>One commenter stated their support for the addition of the definition of “small-scale housing” because it could help spur development in rural communities.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing the proposed rule and agree that the reduced ongoing monitoring requirements for small-scale housing projects will make using HOME funds more feasible nationwide. The Department is moving forward with the definition of “small-scale housing” without change.
                    </P>
                    <HD SOURCE="HD3">B. Expanding Definition To Include Projects With More Units or Scattered Site Projects</HD>
                    <P>One commenter suggested that HUD consider expanding the definition of “small-scale housing” to apply to rental projects with up to 10 units (rather than 4) to allow the benefits of HUD's proposed streamlined procedures to apply to projects with up to 10 units, which would be especially helpful in rural areas. One commenter stated that for compliance monitoring, further clarification on the definition of “small-scale housing” and the applicability to both the rental housing projects and homeownership funded projects is requested. That same commenter believed that as written, it is unclear whether scattered-site rental housing projects would be considered small-scale housing or not.</P>
                    <P>One commenter stated that HUD's proposed definition of “small-scale housing” to mean 1-4 units is not in line with the housing industry's use of the term. The commenter recommended that HUD revise the definition of “small-scale housing” to be more consistent with the industry's definition.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The purpose of the small-scale housing definition is primarily to provide relief to participating jurisdictions and small landlords in the management of small or scattered site housing projects. Consequently, the Department has determined that a 1-4-unit project, either managed on the same site or on multiple sites (
                        <E T="03">i.e.,</E>
                         scattered site housing) shall constitute a small-scale housing project. The Department considered larger project sizes, as the commenter requested. However, in HUD's experience, 5-10-unit projects can be more difficult to manage than 1-4-unit projects, especially when they are managed as scattered site projects.
                    </P>
                    <P>
                        The Department did note that there is confusion over whether small-scale projects must all be on contiguous sites or be single family housing. While the Department is not revising the definition of “small-scale housing,” the Department is clarifying in this preamble and will clarify again in guidance that small-scale housing projects can be on either contiguous sites or scattered sites and still constitute small-scale housing projects 
                        <PRTPAGE P="784"/>
                        as long as they meet the definition of “small-scale housing” in § 92.2.
                    </P>
                    <HD SOURCE="HD2">§ 92.2—Subrecipient Definition</HD>
                    <HD SOURCE="HD3">A. Opposition to Change in Definition To Prohibit a Governmental Entity or Nonprofit From Being a Subrecipient if it Uses HOME Funds as a Developer or Owner of a Housing Project</HD>
                    <P>One commenter does not support the removal of a subrecipient's ability to acquire and temporarily own standard housing, as subrecipients are often partners in locating and purchasing housing.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the comment but is declining to make the change. In the HOME program, a subrecipient administers an activity or entire program on behalf of the participating jurisdiction. An organization that partners with other entities to locate and purchase housing is not a subrecipient as an organization cannot oversee an activity in which it also functions as an owner, developer, or sponsor as there is an inherent conflict of interest. HUD believes the approach described by the commenter is ineligible for HOME assistance.
                    </P>
                    <HD SOURCE="HD3">B. Comment in Support of the Revised Definition of Subrecipient Because it Allows Greater Flexibility in Income Determinations</HD>
                    <P>A commenter stated that the proposed update to the definition of “subrecipient” is helpful because this updated definition allows HOME funds to be more readily used with rental housing based on the program's own income determination guidelines for eligibility.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The commenter is incorrect. Income determinations in the HOME program must be made in accordance with § 92.203. The definition of subrecipient does not allow a subrecipient to use a different set of income requirements than the participating jurisdiction uses when determining income under § 92.203.
                    </P>
                    <HD SOURCE="HD2">§ 92.2—Unit of General Local Government Definition</HD>
                    <P>One commenter pointed out that the proposed rule does not address eligibility of Tribes nor adds new mentions of Tribes even though the definition of CHDO in § 92.2 includes Tribes in the definition of “governmental entity” in paragraph (5). The commenter requested that HUD add clarifying language through the proposed regulations to clarify that Tribes are eligible, including Indian Tribes, Indian Housing authorities, and Tribally Designated Housing Entities as defined at 25 U.S.C. 4103(22), and requested that HUD clarify that these entities may be project owners anywhere that the terms are not synonymous with State recipient. The commenter suggested such changes in § 92.2 Definitions, State recipient; § 92.2 Definitions, Subrecipient; §§ 92.220(a)(1)(iii)(A) and 92.220(a)(1)(iii)(B) regarding matching funds provided by an Indian Tribe, Indian Housing Authority, or Tribally Designated Housing Entity.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Each of the definitions of State Recipient and subrecipient uses the term “unit of general local government” and not “governmental entity.” The Department is not changing its interpretation of the term unit of general local government. Indian Tribes, Indian Housing Authorities, and Tribally Designated Housing Entities may participate in the HOME program in a variety of capacities, including as developers, owners, or contractors. Indian Housing Authorities or Tribally Designated Housing Entities, if established as nonprofits, may be eligible to be Subrecipients in HOME as well. HUD will provide additional information on how HOME funds can be used by Indian Tribes, Indian Housing Authorities, and Tribally Designated Housing Entities in future guidance.
                    </P>
                    <P>Below-market interest rate loans originated by Tribally Designated Housing Entities and Indian Tribes that are legally constituted as corporations are already eligible as match under the current regulation. HUD will clarify this in guidance.</P>
                    <HD SOURCE="HD2">§ 92.3—Effective Date and Applicability of This Final Rule</HD>
                    <P>One commenter requested that HUD clarify which provisions are applicable to all HOME-funded developments and which changes are applicable only to properties that received commitments of HOME funds after the effective date of the final rule. Another commenter requested that HUD provide phased implementation and permit permissive compliance for a set period of time before mandating required compliance, to allow participating jurisdictions time to update information systems, inform partners and ensure proper policies and procedures are in place. One commenter said that because the changes in the rule will require a significant effort to educate stakeholders and ensure a smooth transition to the new regulatory framework, HUD should dedicate adequate technical assistance resources to this effort. Another commenter stated that HUD should expand training for participating jurisdictions and HUD field officials on implementation of this rule to ensure uniform application, particularly for homeownership projects, because of uncertainty about interpretation of HOME regulations among participating jurisdictions.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department agrees with the commenters that it will take time for participating jurisdictions to prepare to comply with certain provisions of this final rule. HUD has carefully considered the appropriate timeframes for compliance with each provision and has established effective dates in § 92.3. HUD shall provide participating jurisdictions up to one year to perform income determinations and reexaminations under the final rule's § 92.203. HUD shall also allow participating jurisdictions, subrecipients, state recipients, and owners to comply with the HOME requirements as they existed immediately prior to the effective date of the final rule for HOME commitments made up to one year after the effective date of the final rule.
                    </P>
                    <HD SOURCE="HD2">§ 92.50—Formula Allocation</HD>
                    <P>One commenter suggested that one way to target funding to rural CHDOs would be to increase the awards for State-wide participating jurisdictions via a change to HUD's formula allocation regulations. Instead of measuring the number of families living in poverty, which as an absolute measure disadvantages rural areas, the commenter said the metric could instead measure either the percentage of families living in poverty or the percentage of counties in a State that are designated as Persistent Poverty Counties. The commenter stated that either of these approaches would be consistent with the statute, which directs that the formula reflects “poverty, and the relative fiscal incapacity of the jurisdiction to carry out housing activities eligible under section 12742 of this title without Federal assistance.” Another commenter also noted that the HOME program does not proportionately serve rural areas because the smallest and least-resourced places must compete for the balance of State funds, while larger communities receive guaranteed funding.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the commenters' contributions and notes that changes to the calculation of HOME program formula allocations are outside the scope of this rulemaking. The Department was making minor revisions to clarify that “rental units built before 1950 occupied by poor households” meant “rental units built before 1950 occupied by households below the poverty line” but was otherwise not 
                        <PRTPAGE P="785"/>
                        changing the actual data that is used in the calculation. The Department does not believe it has provided sufficient notice to the public of a possible change in formula elements and declines to change any data elements included in the HOME formula in this rulemaking.
                    </P>
                    <HD SOURCE="HD2">§ 92.203—Income Determinations</HD>
                    <HD SOURCE="HD3">A. General Support</HD>
                    <P>Commenters stated that they support the proposed changes to income determination for HOME because participating jurisdictions can use income determinations made by other Federal agencies.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department agrees with commenters that providing additional flexibilities to comply with income requirements for HOME-assisted rental housing will further reduce the administrative burden on participating jurisdictions, project owners, and on low-income families. Therefore, in this Final Rule, HUD streamlines income procedures, reduces the frequency of income determinations for HOME-assisted small-scale rental projects and for families receiving HOME tenant-based rental assistance, and expands a safe harbor to permit participating jurisdictions to rely upon the income determinations made under the rules of other Federal programs or forms of public assistance for HOME-assisted rental units and for tenant-based rental assistance programs.
                    </P>
                    <HD SOURCE="HD3">B. Reducing the Frequency of Income Determinations</HD>
                    <P>Commenters said they support reducing the frequency of income determinations. One commenter asked for clarification if the proposed change to income recertification from annual to every two years applied to Federally funded projects such as housing developed with LIHTC. Another commenter supported the proposal and encouraged HUD to consider triennial income recertifications for all HOME programs, not just small-scale housing, because it would help families experience the intended benefits of the program, help families build wealth, and not inadvertently punish them for increasing their income.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD reduced the frequency of income determinations for HOME-assisted small-scale rental projects and tenants receiving tenant-based rental assistance. Triennial income examinations do not apply to HOME-assisted rental projects or to tenant-based rental assistance programs.
                    </P>
                    <P>For HOME-assisted rental housing, HUD expanded an income safe harbor which permits a participating jurisdiction to rely upon the income determination conducted under the rules of another form of public assistance for HOME-assisted rental units where Federal funds overlap. This safe harbor significantly reduces instances of when the annual income of a family must be calculated in HOME-assisted units that are also assisted with Federal or State project based rental subsidy programs, developed with LIHTC, or occupied by a family that receives Federal tenant-based rental assistance or another form of public assistance such as SNAP or TANF. This means that if the HOME-assisted unit or a family is applying for or occupying an assisted unit that is covered by any of these safe harbors, then a participating jurisdiction may apply these flexibilities to all income determinations performed, including at initial occupancy and subsequent income determinations during the HOME period of affordability. HUD is also clarifying in § 92.252(g)(3) that an owner is not required to examine source documents under § 92.203(b)(1)(i) if the participating jurisdiction is accepting an annual income determination pursuant to § 92.203(a)(1), § 92.203(a)(2), or § 92.203(a)(3).</P>
                    <P>For HOME tenant-based rental assistance, the income determination is aligned with the term of the rental assistance contract, which can have a term of up to 24 months. HUD declines to apply a triennial income determination to HOME tenant-based rental assistance programs because it could not be implemented given the 24-month statutory limitation on the term of the rental assistance contract. HUD considered many scenarios that would trigger a new income examination and how reliant participating jurisdictions are on calculation of adjusted income in determining the amount of assistance for a tenant receiving tenant-based rental assistance and believes that tying the income examination to the rental assistance contract is the best policy. HUD also believes that reducing the frequency of income determinations in HOME-assisted rental units and aligning income determination to the terms of the tenant-based rental assistance contract will encourage families to increase income without fear of losing their assistance or ability to occupy an assisted unit.</P>
                    <HD SOURCE="HD3">C. Change the Requirement in § 92.203(a)(1) That a Participating Jurisdiction “Must” Accept the Income Determination Made Under a Project-Based Program</HD>
                    <P>One commenter objected to requiring participating jurisdictions to use the income determinations made by owners and program administrators in Federal and State project-based rental assistance programs, including both the Section 8 project-based voucher and project-based rental assistance programs. The commenter believes that requiring the use of the income determinations is too strong of a stance and that HUD should provide participating jurisdictions with discretion to choose whether to accept an income determination made under a Federal or State project-based rental assistance program. In the commenter's experience monitoring personnel, they have determined that program administrators may overlook income sources or fail to properly verify income and assets.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department recognizes the commenters' concerns that HUD created an income safe harbor as a requirement rather than a choice in the HOTMA Final Rule, published in the 
                        <E T="04">Federal Register</E>
                         on February 14, 2023. Under HOTMA, HUD required a participating jurisdiction to accept a public housing agency, owner, or rental subsidy provider's determination of a family's annual and adjusted income for each HOME-assisted unit that is assisted by a Federal or State project-based rental subsidy program. HUD's intent was to create alignment in HUD rental programs and to reduce the administrative burden on participating jurisdictions and owners of having to meet two sets of income requirements for the same unit. HUD agrees with the commenter that participating jurisdictions should be provided the choice, as a matter of program design, of whether to accept an income determination made under a Federal or State project-based rental assistance program. Therefore, HUD is revising the “must” to a “may” in §§ 92.203(a)(1) and 92.203(f)(2) and permitting a participating jurisdiction to decide whether to apply this safe harbor. HUD recommends that when making this decision, a participating jurisdiction undertakes an assessment of staff capacity, size and scope of its HOME-assisted rental portfolio, annual monitoring schedules, and the availability of trained and knowledgeable housing partners. HUD reminds participating jurisdictions that whatever choice they make should be explicitly described in the HOME written agreement with project owners to reduce instances of noncompliance with the HOME program income requirements.
                        <PRTPAGE P="786"/>
                    </P>
                    <HD SOURCE="HD3">D. Opposition to 2-Month Source Documentation Requirements in Paragraph (b) of the Definition</HD>
                    <P>One commenter suggested that HUD remove the 2 month source of income documentation requirement in § 92.203(b)(1)(i) and (b)(2) and instead follow the HUD 4350.3 Chapter 5 requirement for all HOME activities which considers circumstances when 2 months of documentation are not available, allows for third party verification, and would allow participating jurisdictions to establish a uniform income review process across HOME and HTF.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department recognizes the commenters' concerns that HOME's income documentation and verification process is different than the processes in other HUD rental programs, but HUD is not revising § 92.203(b)(1)(ii) to remove the requirement to examine 2 months of source documents when determining annual income. The Department has required source documents since the 1996 HOME regulations 
                        <SU>28</SU>
                        <FTREF/>
                         and believes that examination of source documents provides needed safeguards to ensure that tenants meet the income requirements of the Act. Notwithstanding that fact, the Department has also identified other forms of documentation that may also satisfy the requirements, including documentation required to use the safe harbors in § 92.203(a)(1)-(3).
                    </P>
                    <FTNT>
                        <P>
                            <SU>28</SU>
                             See 61 FR 48769.
                        </P>
                    </FTNT>
                    <P>Moreover, HUD disagrees that adopting the income documentation and verification procedures in Chapter 5 of HUD Handbook 4350.3 would establish a uniform income review process across all HOME and the Housing Trust Fund activities. The requirements explained in Chapter 5 of HUD Handbook 4350.3, including the mandatory use of source documents for a period beyond 2 months and the required use of the Enterprise Income Verification (EIV) System, are more burdensome than HOME's current income requirements. Under the HOTMA regulations in 24 CFR 5.609, annual reexaminations must consider all income made in the previous 12 months (See 24 CFR 5.609(c)). HOME regulations at § 92.203(b)(1)(ii) only require an examination of 2 months of income to project the prevailing rate of income for the upcoming 12 months. This is a less burdensome process than what is required in 24 CFR 5.609. HUD's Technical Guide for Determining Income and Allowances for the HOME program (income guidebook), which will be updated to provide guidance related to this Final Rule, already provides participating jurisdictions with the flexibility to establish their own verification procedures or to implement verification procedures consistent with the Housing Choice Voucher Program.</P>
                    <HD SOURCE="HD3">E. Accepting Determinations by Other Federal Assistance Providers in § 92.203(b)</HD>
                    <P>A commenter stated that the policy should be extremely clear that a certification by another Federal assistance provider is sufficient to document income eligibility and no additional documentation would be needed outside of a certification to the owner or participating jurisdiction.</P>
                    <P>Other commenters stated that HUD should expand HOME reciprocity with other Federal agency programs and harmonize income eligibility standards. The commenters requested that HUD engage in reciprocity with the USDA Rural Home Development 502 Direct Mortgage program in a manner similar to how it honored income eligibility under its Self-Help Opportunity Program (SHOP). Specifically, the commenter urged that HUD adopt the USDA Rural Development 502 Direct mortgage program's “income banding” approach to eligibility that the commenter said has been beneficial in rural areas around the country and was a direct response to the lack of access for broad swaths of persistent poverty areas of the country.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         In the HOTMA Final Rule, HUD aligned the HOME income regulations with those of other Federal or State rental subsidy programs and with those of other Federal tenant-based rental assistance programs that determine income eligibility consistent with the HOME program to facilitate the layering of funds in a HOME-assisted project and to reduce the administrative burden on participating jurisdictions and project owners. While the HOTMA safe harbor expanded the number of rental programs that a participating jurisdiction may accept income determinations from, HUD agrees that it can expand this safe harbor to include additional Federal agency programs and other forms of public assistance that are compatible with the HOME program.
                    </P>
                    <P>To accomplish this, HUD is broadening an existing income safe harbor in § 92.203(b)(1)(iii) which permits a participating jurisdiction to determine the annual income of a family by obtaining a written statement from the administrator of a government program under which the family receives benefits, and which examines each year the annual income of the family. The expansion of this safe harbor includes additional forms of public assistance provided under other Federal agencies such as Supplemental Nutrition Assistance Program (SNAP), Temporary Assistance for Needy Families (TANF), Medicaid, as well as LIHTC income determinations for families living in tax credit units. This means that instead of calculating the annual income of a family, a participating jurisdiction may rely on the annual income determination made by the administrators of those programs or forms of public assistance without having to take additional steps to verify the income calculation or determination.</P>
                    <P>
                        To implement this new safe harbor provision, the participating jurisdiction must obtain a written statement from the administrator of the assistance which contains the amount of annual income and household composition (
                        <E T="03">e.g.,</E>
                         two-person household). A participating jurisdiction can then implement this safe harbor for all rental housing income determinations including but not limited to those performed at initial occupancy and every sixth year of the period of affordability. This relieves the participating jurisdictions of the requirement to calculate the annual income of a family by using 2 months of source documents if the family is receiving one of these forms of public assistance and the participating jurisdiction is able to obtain a statement fulfilling the requirements of the new safe harbor in § 92.203(a)(3).
                    </P>
                    <P>
                        With respect to granting reciprocity with the United States Department of Agriculture's (USDA) “income banding” approach for determining income eligibility for the Rural HOME Development 502 Direct Mortgage program, HUD declines to adopt this approach of determining income eligibility for HOME-assisted homeownership programs. HUD has determined that the USDA's method for defining a low-income family is not compatible with HOME's program definition of a low-income family. Under the HOME program, a low-income family means a family whose annual incomes do not exceed 80 percent of the median income for the area, as determined by HUD, with adjustments for smaller and larger families, except that HUD may establish income ceilings higher or lower than 80 percent of the median for the area on the basis of HUD findings that such variations are necessary because of prevailing levels of construction costs or fair market rents, or unusually high or low family incomes. An individual does 
                        <PRTPAGE P="787"/>
                        not qualify as a low-income family if the individual is a student who is not eligible to receive Section 8 assistance under 24 CFR 5.612. In contrast, the USDA uses two categories of income structure: one category is for one-to-four person households and a second category is for five-to eight-person households. The USDA's two-tier income structure is significantly different than the HOME program's income structure and does not take into account other disqualifying factors under the HOME regulations and statute. Creating a safe harbor for the USDA's two-tier income structure is too significant of a change and is outside the scope of this rulemaking because it involves changing the definition of a low-income family and not just providing an expanded safe harbor to defining an eligible family.
                    </P>
                    <HD SOURCE="HD3">F. Revise § 92.203(e) To Extend the Length of Time That an Income Determination Is Valid in Homeownership Programs</HD>
                    <P>A commenter stated that for owner-occupied rehabilitation and homeownership assistance for new construction, it is unclear if the income certification before loan closing can remain valid for 12 months now or if the rule is still limited to 6 months.</P>
                    <P>Another commenter stated that, for new construction, developers should be able to confirm that buyers are eligible to purchase the unit more than 6 months out because of the potential for construction delays. Two commenters recommended that this rule revise the regulations found at § 92.203(e)(2) to indicate that the participating jurisdiction is not required to re-examine the family's income at the time the HOME assistance is provided unless 24 months has elapsed since the homebuyer was determined to be income-qualified at the start of program participation. These commenters also recommended revising the regulations to state that at re-examination, the participant's income should be considered eligible so long as their income has not grown to the point of exceeding the low-income threshold by more than 10 percent.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department recognizes the commenters' concerns but is not revising § 92.203(e)(2) to allow an income determination to be valid for a period of 12 or 24 months as requested by the commenters. The Act is clear that a family must qualify as a low-income family at the time of the home purchase.
                        <SU>29</SU>
                        <FTREF/>
                         This means that if a family is being assisted to purchase existing housing, they must be a low-income family at the time of transfer of ownership (usually at settlement or closing). If a family is being assisted to purchase existing housing or housing to be constructed under a lease-purchase program, the family must be low-income at the time the lease-purchase agreement is executed pursuant to § 92.504(c)(5). If a family is being assisted to purchase housing to be constructed, the family must be low-income at the time the contract to purchase housing to be constructed is signed in accordance with § 92.254(a)(8). The HOME assistance is provided at execution of the contract to purchase housing to be constructed in accordance with § 92.504(c)(5). HUD wants to clarify that if the family was determined to be income eligible at the time the contract to purchase housing to be constructed was executed, there is no additional requirement to redetermine income if there are delays in construction.
                    </P>
                    <FTNT>
                        <P>
                            <SU>29</SU>
                             See 42 U.S.C. 12745(b)(2)(A)-(C).
                        </P>
                    </FTNT>
                    <P>HUD understands the complexity of homeownership programs and how it can vary by locality. HUD permits an income determination to be valid for six months for homeownership activities to account for this complexity and delays in property settlement. The Department has determined that permitting the income determinations to remain valid for six months is consistent with the Act but that providing a longer time period for homeownership activities creates a more tenuous standard, as prospective homebuyers may already have relatively higher incomes than other low-income participants in the HOME program.</P>
                    <P>The commenter's recommendation that families be considered eligible if their annual income has not exceeded the low-income threshold by more than 10 percent, is not statutorily permissible (see 42 U.S.C. 12744(2)). HUD declines to revise the income regulations to permit families to exceed the HOME income limits and still be considered eligible low-income families.</P>
                    <HD SOURCE="HD3">G. Counting Income From All Family Members in § 92.203(e)</HD>
                    <P>One commenter stated that the HOME method of income determination, which counts the income of all household members with some exclusions, does not account for multi-generational households where some family members do not contribute financially. The commenter explained that this method leads to an inflated household income calculation that does not reflect the financial burdens or capacities of families. The commenter recommended that HUD revise its regulations to allow household members who are not immediate family (which the commenter defined as anyone other than parents, siblings, spouses, and children) to be excluded from the income eligibility calculation.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department recognizes the commenters' concerns, but HUD is not revising § 92.203(e)(1) to remove the requirement to include the income from all persons in the household when calculating the annual income of a family under the HOME program. The HOME statute specifically requires that the low- and very low-income thresholds be determined with respect to smaller and larger families,
                        <SU>30</SU>
                        <FTREF/>
                         and necessarily intends that the income of all members of the household 
                        <SU>31</SU>
                        <FTREF/>
                         be used in determining family income under the HOME program.
                    </P>
                    <FTNT>
                        <P>
                            <SU>30</SU>
                             See 42 U.S.C. 12704(9) and (10).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>31</SU>
                             Please note, 24 CFR 5.609 provides certain income exclusions for live-in aides, foster children, and foster adults.
                        </P>
                    </FTNT>
                    <P>
                        The definition of family 
                        <SU>32</SU>
                        <FTREF/>
                         used in the HOME program covers multi-generational households. This is pursuant to the Act, which requires that the definition of “families” in the HOME program be the same definition of “families” contained in the 1937 Act that is applicable to other HUD programs such as the Housing Choice Voucher Program and the public housing program.
                        <SU>33</SU>
                        <FTREF/>
                         The Department has codified the definition of family found in the 1937 Act in 24 CFR 5.403, and HUD is maintaining a consistent interpretation of the 1937 Act across HUD programs by using the definition of family in 24 CFR 5.403 for the HOME program. Therefore, the Department must decline the commenter's suggestion to narrow the definition of family for purposes of determining income in the HOME program.
                    </P>
                    <FTNT>
                        <P>
                            <SU>32</SU>
                             The HOME program uses the definition of family contained in 24 CFR 5.403, see 24 CFR 92.2 
                            <E T="03">Family.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>33</SU>
                             Section 42 U.S.C. 12704(11) of the Act states that “families” shall have the same meaning as the definition of “families” in 42 U.S.C. 1437a. 42 U.S.C. 1437a(b)(3) provides the definition of persons and families.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">Specific Solicitation of Comment #7</HD>
                    <P>
                        <E T="03">
                            The Department seeks input on whether and how the rule should facilitate the conveyance of a financial benefit to low-income tenants when the project owner makes energy efficiency upgrades such as the installation of small-scale wind or solar facilities in connection with an eligible Federal or State program. HUD has issued guidance that currently describes how certain utility discounts or rebates can be treated under HUD income and utility allowance regulations. HOME is subject to the same income requirements under 24 CFR 5.609 as 
                            <PRTPAGE P="788"/>
                            other program areas issuing guidance on the treatment of these discounts and rebates. The Department therefore also requests comment from the public on whether to go farther than this guidance for HOME projects through this HOME rulemaking. For example, should HUD maintain the same utility allowance for the project following energy efficiency upgrades to allow the tenant to realize the benefit of decreased utility costs? Both the current income regulations at 24 CFR 5.609 and 24 CFR 5.609 as revised in the HOTMA Final Rule exclude lump-sum additions to assets, as well as non-recurring income. However, if a HUD program provided a recurring financial benefit directly to a low-income tenant, should the rule exclude this income from the HOME income determinations?
                        </E>
                    </P>
                    <HD SOURCE="HD3">A. Comments Supporting Conveying a Financial Benefit to Tenants</HD>
                    <P>One commenter supported efforts to ensure that tenants are able to receive the benefits of energy efficiency cost savings but requested that HUD eliminate or streamline any obligations on participating jurisdictions to monitor and ensure compliance with this benefit because monitoring would be difficult at best.</P>
                    <P>One commenter supported conveyance of a financial benefit to tenants through the design of HOME utility allowances which would exclude energy efficient features from the model. The commenter explained that the benefit should go to residents because building owners will receive benefits by virtue of decreased energy costs and use in common areas and building systems.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the commenters' responses to this specific solicitation, but HUD is declining to adopt a policy conveying a financial benefit to tenants in this final rule. It was difficult for the Department to determine how to convey a financial benefit in a way that would be fair, equitable, and permissible under the Act. Unfortunately, commenters also did not provide sufficient information on how the Department could effectively convey all or a portion of the benefits of energy efficiency measures to HOME tenants without disincentivizing owners from paying for energy efficiency upgrades. The Department may revisit this topic in a future rulemaking. The HOME program will follow current HUD guidance that describes how certain utility discounts or rebates can be treated under HUD income and utility allowance regulations.
                        <SU>34</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>34</SU>
                             See 
                            <E T="03">https://www.hud.gov/sites/dfiles/Housing/documents/MF_Memo_Community_Solar_Credits_signed.pdf https://www.hud.gov/sites/dfiles/Housing/documents/MF_Memo_re_Community_Solar_Credits_in_MM_Buildings.pdf</E>
                             and 
                            <E T="03">https://www.hud.gov/sites/dfiles/PIH/documents/Community%20Solar%20Credits%20in%20PIH%20Programs.pdf.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">B. Comments Opposing Conveying a Financial Benefit to Tenants</HD>
                    <P>One commenter opposed HUD attempting to include any benefit produced by the use of energy efficiency upgrades. The commenter pointed out that if energy efficiency upgrades result in returns to the project, financial benefits could flow to the participating jurisdiction if the HOME loan requires “cash flow” payments. The same commenter also stated that it would be better if developers and owners invested in long-term benefits instead of focusing on decreased costs and updating utility allowances for all tenants.</P>
                    <P>A few commenters supported allowing the owner to recalculate the utility allowance based on the energy efficiency upgrades so that the owner can benefit from a lower utility allowance deduction from the HOME rent. One of these commenters cautioned HUD against reducing an owner's incentives for undertaking energy efficiency upgrades. One commenter noted that it will be important to ensure that utility allowances are not prematurely lowered before energy savings are realized, which would cause financial harm to economically vulnerable tenants.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the responses from commenters in opposition to the conveyance of financial benefit to tenants when an owner makes energy efficient upgrades. The Department is not adopting any change in this final rule. However, HUD may further study how a financial benefit could be provided to both low-income tenants of HOME-assisted rental units and project owners to incentivize energy efficiency measures. The HOME program will follow current HUD guidance that describes how certain utility discounts or rebates can be treated under HUD income and utility allowance regulations.
                        <SU>35</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>35</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">C. Comments Stating That Determining How To Convey a Financial Benefit for Tenants Is Difficult</HD>
                    <P>Two commenters stated that the cash benefit or discount to tenants would be difficult for owners to implement. One commenter noted that including revenues generated as a result of enhanced efficiency as income to the tenant would also place an administrative burden on the owner, the tenant, as well as on the monitoring participating jurisdictions for a likely small change per month.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing the proposed rule and agrees that it would be administratively difficult to convey such benefit, particularly because consumption of utilities vary by tenant and by season. HUD will not be adopting measures related to providing a financial benefit directly to low-income tenants at this time. Commenters' insights on the difficulty of such a measure's implementation and the administrative burden will be taken into account if HUD chooses to revisit this question in a future rulemaking.
                    </P>
                    <HD SOURCE="HD3">D. Comments Suggesting Methods To Convey Financial Benefit to Tenants</HD>
                    <P>Many commenters agreed that HUD should permit projects to maintain the same utility allowance following energy efficient upgrades. One commenter stated that this would allow the tenant to realize the benefit of decreased utility costs and allow the owner to benefit by making them eligible to access tax credits when pursuing energy efficiency upgrades. Other commenters indicated that utility allowances often do not reflect actual costs of utilities paid for by tenants because there is significant variation among units that are the same type, therefore, increasing rent based on imprecise estimates of theoretical cost savings would make HOME-assisted housing less affordable for tenants after energy efficiency upgrades are made.</P>
                    <P>One commenter said utility allowances should only be updated if there is a risk that utility costs will rise, say, due to electrification of heating. This commenter also said that owners also need to benefit from green construction in order to incentivize them to do the work, and they need green projects to be financially viable. The commenter suggested that one approach may be to rely on the addition to the project subsidy, along with other tax incentives, and Federal and local funding to incentivize owners toward green construction.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for their suggestions to permit projects to maintain the same utility allowance following energy efficient upgrades, which could decrease utility costs and increase affordability for tenants while providing owners with the opportunity to access relevant tax credits. The 
                        <PRTPAGE P="789"/>
                        Department agrees with the commenter that owners must be able to obtain the benefit of energy efficiency upgrades. As a result, the Department is declining to change the current requirement that utility allowances be redetermined annually.
                        <SU>36</SU>
                        <FTREF/>
                         The Department believes holding utility allowances constant would disincentivize owners from making energy efficiency improvements during the period of affordability, as it would deny the owner the benefit of any energy efficiency improvements for those HOME-assisted units without guaranteeing that the owner obtained the benefit of tax credits or other financial incentives. The Department considered whether to maintain the same utility allowance and convey the financial benefit to the tenant by making such a program optional to the owner or dependent upon the owner's participation in a program that conditioned the tax credit or assistance upon providing a financial benefit to the tenant, but determined that this increased the complexity of the HOME program to align with time-limited Federal and state programs without necessarily providing adequate incentive to owners to participate in such programs. As such, the Department is declining to make the change here.
                    </P>
                    <FTNT>
                        <P>
                            <SU>36</SU>
                             Paragraph 24 CFR 92.252(d)(1) of the HOME rule existing immediately before the effective date of this final HOME rule, requires the utility allowance be determined annually. The Department is redesignating and revising this as a paragraph (b) but is not changing the requirement that the utility allowance be determined annually.
                        </P>
                    </FTNT>
                    <P>The Department is adopting a change that will allow participating jurisdictions to use either the HUD Utility Schedule Model, the utility allowance established by the local public housing authority (PHA), or another method approved by HUD as their maximum monthly allowances in the final rule. The Department believes that this added flexibility will allow participating jurisdictions to select methods that are most appropriate for the project, and which can adequately incentivize owners to perform energy efficiency upgrades on their projects.</P>
                    <HD SOURCE="HD3">D. Owners Should Perform a Rental Assistance Demonstration (RAD) Capital Needs Assessment To Determine and Incentivize Owners To Perform Energy Efficiency Upgrades</HD>
                    <P>One commenter recommended that HUD permit owners pursuing energy-efficiency retrofits or other energy-saving measures to pursue the process outlined for RAD conversions in prior HUD notices since owners are not incentivized to pursue energy efficiency measures that would reduce tenant costs when tenants who pay their own utilities and rent are calculated for a utility allowance. The commenter suggested permitting owners to submit the engineering study contemplated by the RAD guidance, along with a request for rent adjustment so that the utility allowance could be conservatively reset and suggested that HUD should grant waivers to facilitate this approach.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the responses from commenters recommending that HUD permit project owners seeking energy efficiency upgrades to pursue the process outlined for RAD conversions. The Department declines to adopt this suggestion in this final rule because it adds a significant level of complexity to the HOME program without necessarily providing adequate benefits to owners. Requiring a physical conditions assessment delays the work to be performed and requires owners to incur additional costs before engaging in energy efficiency upgrades. Absent project development subsidy, which is only available to new HOME projects or troubled HOME projects that are provided new HOME funds pursuant to § 92.210, the owner would have to pay for these costs themselves. Moreover, the mechanism that the commenter is proposing to use to incentivize owners, increasing rents, cannot be performed under the HOME program because rent limits are statutory.
                        <SU>37</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>37</SU>
                             See 42 U.S.C. 12745.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">E. The HOME Program Should Align With Other Federal Programs in the Treatment of Utility Discounts and Rebates in Determining Income</HD>
                    <P>Two commenters recommended aligning requirements for utility discounts and rebates for HOME assisted projects and income and utility allowance requirements with other Federal programs, to the greatest extent possible. One of these commenters noted that the utility allowance could be difficult to enforce if it becomes mandated and instead recommend that the utility allowance be preserved for to tenants up to the net credit on the allowance. In addition, one commenter also urged HUD to consider July 2022 guidance published by the Office of Multifamily Housing on the treatment of solar credits in utility allowance and annual income calculations to facilitate conveyance of financial benefit to residents and to exclude such benefits from HOME income determinations.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for their responses to this specific solicitation. In revising the Final HOME Rule and soliciting comment on energy efficiency measures, HUD examined other Federal programs' utility allowance and income regulations and requirements at length. The Department believes that there is no single approach or method to align income and utility allowances across other Federal programs. The Department has attempted to expand options for aligning with other programs by allowing participating jurisdictions to select a the applicable local PHA utility allowance in § 92.252(b). However, the Department is declining to make further changes such as providing tenants additional financial benefits or sizing and maintaining an artificially inflated utility allowance up to the net amount of the credit received by the owner. As stated earlier, the HOME program will follow current HUD guidance that describes how certain utility discounts or rebates can be treated under HUD income and utility allowance regulations, including the guidance from Multifamily housing.
                        <SU>38</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>38</SU>
                             See 
                            <E T="03">https://www.hud.gov/sites/dfiles/Housing/documents/MF_Memo_Community_Solar_Credits_signed.pdf https://www.hud.gov/sites/dfiles/Housing/documents/MF_Memo_re_Community_Solar_Credits_in_MM_Buildings.pdf</E>
                             and 
                            <E T="03">https://www.hud.gov/sites/dfiles/PIH/documents/Community%20Solar%20Credits%20in%20PIH%20Programs.pdf.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">F. Exclude From HOME Income Determination Any Recurring Financial Benefit Which Results From Energy Efficiency Upgrades</HD>
                    <P>Commenters stated that HUD should exclude this financial benefit, even when regularly recurring, from HOME income determinations. One commenter expressed concern that including the financial benefits from reduced costs resulting from investment in energy efficiency upgrades as income could cause some tenants to become over-income. The commenter explained that this unforeseen income could result in extended negative impacts on the rents charged and compliance of the HOME-assisted units.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates commenters' recommendations that HUD exclude a recurring direct financial benefit to tenants resulting from energy efficiency upgrades from the HOME program's income determinations. The Department recognizes commenters' concern that the inclusion of such benefits in income determination may result in some low-income tenants being considered over-income, resulting in program noncompliance. HUD will not be adopting measures related to providing a direct financial benefit to tenants in 
                        <PRTPAGE P="790"/>
                        upgraded, energy efficient properties in the final rule.
                    </P>
                    <HD SOURCE="HD3">G. Do Not Exclude From HOME Income Determination Any Recurring Financial Benefit Which Results From Energy Efficiency Upgrades</HD>
                    <P>Two commenters opposed any addition of further income requirements and stated that HOTMA has simplified the income eligibility process, and that any further requirements would prove cumbersome, especially given that so many HOME projects also receive Section 8 assistance.</P>
                    <P>Another commenter opposed the use of discount and rebate allowances for income determinations because saved resources are not typically given back to tenants. The commenter also said that if discounts and rebates were to be treated as recurring income, HUD would need to clarify how this income would be documented and to which tax standard the income would be subject. The commenter was also concerned about HUD issuing a single rebate formula for a nationwide implementation and about the fact that carve outs for HOME rebates is not aligned with other HUD programs.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates commenters' recommendations that HUD does not exclude any recurring financial benefit to tenants from the HOME program's income determinations and acknowledges that were such a measure to be implemented, the income documentation, tax standard, and coordination with other HUD programs would need to be determined. HUD declines to convey a financial benefit to low-income tenants following energy efficiency upgrades and excludes said benefit from HOME income determinations in this rule.
                    </P>
                    <HD SOURCE="HD3">H. Clarify Supply Sources and Energy Efficiency Measures</HD>
                    <P>One commenter recommended that HUD clarify that small-scale wind and solar facilities are supply sources, not energy efficient upgrades, because they do not reduce the energy demands of the building/unit. One commenter stated that it is exploring energy efficiency benchmarking opportunities and would welcome the opportunity to share its findings.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the commenter's request that HUD make a distinction between energy efficient upgrades and supply sources. HUD is not proposing a definition of energy efficiency improvements. The Department understands that creating small-scale wind or adding solar power generation is increasing the supply of power to a project and not decreasing the energy demands of the project. The Department solicited comment on these forms of power supply because they may decrease or eliminate the amount an owner or tenant must pay utility providers for utilities to their project or unit respectively. The Department recognizes that one of the commenters is engaged in energy benchmarking and would be happy to share its findings. The Department is happy to discuss this matter with the participating jurisdiction after publication of this final rule but cannot consider these findings for this rulemaking at this time.
                    </P>
                    <HD SOURCE="HD3">I. Other Comments Received—Affordability of Housing</HD>
                    <P>One commenter believed HUD was requesting comment on whether requiring HOME-assisted units to meet a higher energy efficiency standard will negatively impact the affordability of the housing. This commenter strongly urged HUD to consider a broader definition of “affordability,” which it argues is incomplete in that it has historically been limited to the market-rate price of a home and upfront costs like downpayment requirements. Instead, this commenter said, housing affordability must also include the costs associated with staying in the home long-term, which can include heating and cooling. The commenter argued that energy costs disproportionately impact low-income homes and that costs related to energy-efficiency improvements are often mitigated in the first few years. The commenter ultimately suggested HUD examine a formulaic approach to determining affordability that includes downpayment costs, monthly mortgage payments, and monthly utility expenses and regard with skepticism comments that make hyperbolic claims about price increases caused by energy efficiency, green building, or resilience requirements.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for their insight into potential affordability issues that could arise from imposing energy efficiency requirements and the definition of affordability in the context of energy efficiency improvements. However, the suggestions are beyond the scope of the proposed HOME rule. The Department must use the rent limits and homeownership provisions under the Act when determining and preserving affordability of HOME-assisted housing.
                        <SU>39</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>39</SU>
                             See 42 U.S.C. 12745, which defines the rent limits for HOME-assisted rental housing; maximum home sales price for HOME-assisted homeownership housing; and use of resale or recapture provisions in preserving affordability of HOME-assisted homeownership housing.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD2">§ 92.205—Eligible Activities: General</HD>
                    <HD SOURCE="HD3">A. Comments in Opposition to Limitations on Land Banking</HD>
                    <P>A commenter stated that, in paragraph (a)(2) of § 92.205, the commenter opposes HUD explicitly tying the use of HOME funds for acquisition of vacant land to the definition of “commitment,” specifically as it relates to uses of the program to support land banking. The commenter stated that the use of HOME funds for land banking leads to the creation of affordable housing units and increases affordability but just on a slightly longer timeline than other uses. The commenter noted that in many places there are no other funding sources for land banking and enabling partnerships between units of local governments and nonprofit affordable housing developers to take advantage of opportunities to purchase at lower prices is a flexible, efficient use of very limited funding to ensure not only production pipelines but also affordability.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Land banking is statutorily prohibited under 42 U.S.C. 12742(a)(1):“Funds made available under this part may be used by participating jurisdictions to provide incentives to develop and support affordable rental housing and homeownership affordability through the acquisition, new construction, reconstruction, or moderate or substantial rehabilitation of affordable housing.” The Act further explains that [f]or the purpose of this part, the term “affordable housing” includes permanent housing for disabled homeless persons, transitional housing, and single room occupancy housing. Purchase of property without a defined end-use that results in “permanent housing for disabled homeless persons, transitional housing, and single room occupancy housing” is not a permissible use of HOME funds under statute. HUD permits a participating jurisdiction to provide HOME assistance to an owner if the participating jurisdiction reasonably expects construction to begin within 12 months of the project set-up date in paragraph (2) 
                        <E T="03">Commit to a specific local project</E>
                         of the definition of 
                        <E T="03">Commitment</E>
                         in § 92.2 but cannot permit using HOME funds to acquire and indefinitely hold land until such time as enough funds are available to permit development. The participating jurisdiction must not use HOME funds for acquisition of these types of properties if this is the 
                        <PRTPAGE P="791"/>
                        participating jurisdiction's or owner's intent.
                    </P>
                    <HD SOURCE="HD3">B. Concerns About Clarifications to “Demolition” in § 92.205(a)(2) and One-for-One Replacement Requirements</HD>
                    <P>Commenters expressed concerns that HUD's clarification regarding demolition could lead to overly strict interpretations requiring a one-to- one rebuild following demolition.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         By statute, HOME participating jurisdictions are required to comply with the requirements contained in Section 104(d) of the Housing and Community Development Act (42 U.S.C. 5304(d)) (Section 104(d)) and must certify that they have in effect and follow a residential anti-displacement and relocation assistance plan (RARAP) developed in accordance with Section 104(d) as further provided in 24 CFR part 42.
                        <SU>40</SU>
                        <FTREF/>
                         If a participating jurisdiction provides HOME assistance for a project involving demolition, as in the commenters' example, Section 104(d) requires that all occupied or vacant occupiable lower-income dwelling units that are demolished be replaced with lower-income dwelling units on a one-for-one basis. Please see § 92.353(e) and 24 CFR 42.375, which remain unchanged in this rulemaking.
                    </P>
                    <FTNT>
                        <P>
                            <SU>40</SU>
                             See 42 U.S.C. 12705(b)(16).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">C. Concerns About How Strictly the Requirement That “Demolition” and “Vacant Land” Be Used for Affordable Housing in § 92.205(a)(2) Will Be Applied</HD>
                    <P>Some commenters were also concerned that HUD's clarification regarding acquisition of vacant land could lead to overly strict interpretations that require affordable housing on each acquired and aggregated parcel. These commenters suggested adding language to § 92.205(a)(2) to permit the acquisition of vacant land or demolition of structures on parcels adjoining or contiguous to a project that will provide affordable housing, so long as those activities are in furtherance of strengthening property values and promoting public health and safety of future residents as part of a cohesive affordable housing development plan. Another commenter said that permitting acquisition of vacant land or demolition of structures on adjoining or contiguous parcels will enable more affordable housing. Another commenter noted that so long as these activities will further neighborhood stabilization, the nature of vacancy and demolition continues to align with the purpose of the HOME program.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The revisions to the HOME regulations at § 92.205(a)(2) are not intended to disallow reasonable site assembly or demolition activities that are integral to the development of the affordable housing. The revisions are intended to disallow land banking or demolition activities that are not directly tied to the provision of affordable housing through a “specific local project” as defined in § 92.2. If acquisition of vacant land is integral to assembling a site for a specific local project, then the acquisition of the land is a permissible acquisition cost. Similarly, demolition is a permissible cost under the HOME program when the demolition is integral to the creation of an affordable housing project, such as when the demolition removes a structure that would have prevented the owner from developing the affordable housing project. While the Department was revising its regulations for clarity, these revisions do not represent a change in the statutory or regulatory requirements.
                    </P>
                    <P>The Department also notes that the HOME program is subject to one-for-one replacement requirements. Please see earlier comment responses on the statutory requirement that HOME funds be used to construct affordable housing.</P>
                    <HD SOURCE="HD3">D. Comments About Requirement That “Demolition” and Acquisition of “Vacant Land” Must Be Used for a Specific Local Project Within 12 Months in § 92.205(a)(2) </HD>
                    <P>One commenter stated that common delays caused by issues such as securing financing, public entitlement, site assembly, and other requirements make the proposed rule's commitment deadline of 12 months for the acquisition of vacant land or demolition work unreasonable, especially for nonprofit developers. These challenges led the commenter to recommend that HUD extend the 12-month requirement or establish separate deadlines for vacancy and demolition work.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD understands the commenter's concern but is not revising the 12-month requirement contained in paragraph (i) of the definition of 
                        <E T="03">Commit to a specific local project</E>
                         for the reasons stated in HUD's earlier comment response on this subject. Demolition and acquisition of vacant land are only eligible costs as part of an affordable housing project and are not standalone costs or activities under the Act. Therefore, the Department will not treat these costs different from other costs associated with site assembly, preparation, or development.
                    </P>
                    <HD SOURCE="HD3">E. Rewording of Project Completion Requirements for Homeownership in § 92.205(e)</HD>
                    <P>A commenter stated that they disagree with the proposed change in wording from “[i]f a participating jurisdiction does not complete a project within 4 years of the date of commitment of funds, the project is considered to be terminated . . .” to “[i]f project completion, as defined in § 92.2, does not occur within 4 years of the date of commitment of funds for a specific local project, the project is considered to be terminated . . . .” The commenter explained that a participating jurisdiction should not have to repay HOME funds for multi-address activities where some houses were completed and sold to eligible families since the units that were completed and sold in a timely fashion are HOME-assisted units. The commenter requested HUD provide additional guidance on multi-address activities.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD was clarifying that the phrase “complete a project” in this regulation means “project completion” as defined in § 92.2. This was not a change in existing policy and was a clarification of how HUD interprets existing policy. Regarding project completion for multi-address projects, the commenter is correct that in HUD's IDIS data system, a multi-address development is set up as one activity in IDIS and as such construction must be completed for all addresses before the activity can meet the definition of completed and the period of affordability starts. This system functionality is not new and has been established for the entire history of the HOME Program.
                    </P>
                    <HD SOURCE="HD3">F. Support for the Four-Year Project Completion Deadline in § 92.205(e)</HD>
                    <P>One commenter stated that a four-year deadline to complete the project from the commitment of HUD funds is reasonable.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for reviewing the proposed rule. HUD is not revising the four-year project completion deadline. The current regulation is consistent with the comment.
                    </P>
                    <HD SOURCE="HD2">§ 92.206—Eligible Project Costs</HD>
                    <HD SOURCE="HD3">A. Support for Clarification on Ground Lease Costs</HD>
                    <P>
                        One commenter supported the clarification that acquisition through a ground lease is an eligible HOME cost and sought clarification on whether the costs are limited to those eligible under 2 CFR 200.465.
                        <PRTPAGE P="792"/>
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Acquisition of affordable housing through a ground lease that is at least as long as the time periods stated in paragraph (1) of § 92.2 
                        <E T="03">Homeownership</E>
                         is a permissible acquisition cost under § 92.206. HUD clarified this in the proposed rule by revising § 92.206(c) to explicitly state that “(c) Acquisition costs. Costs of acquiring improved or unimproved real property and costs for a long-term ground lease, including costs of acquisition by homebuyers.” The cost principles contained in 2 CFR part 200, subpart E are all applicable to HOME project costs, including eligible acquisition costs through a ground lease. To the extent that 2 CFR 200.465 applies to the ground lease, the participating jurisdiction must determine that the cost of the ground lease is reasonable, determine if there are less than arms-length transactions, and act accordingly.
                    </P>
                    <HD SOURCE="HD3">B. Support for Revising Soft Costs in § 92.206(d)</HD>
                    <P>Commenters stated that they support the proposal to allow property insurance during project development as an eligible HOME soft cost. Commenters stated that they support the proposal to permit the costs associated with conducting environmental assessments and reviews as costs eligible for reimbursement with HOME funds. One commenter explained that time and costs associated with environmental reviews of sites proposed for development often stall or restrict execution of affordable housing projects, and that HUD's proposal, while not a total solution, would advantage programs, especially those providing downpayment assistance.</P>
                    <P>A commenter suggested that oversight-related fees for environmental assessments should qualify for this reimbursement as well, as they can be substantial and cited one example of $96,000 for a 14-unit project. One commenter stated that they support the clarifications made at § 92.906(d)(1) regarding ensuring that developers can be reimbursed for environmental assessments or reviews on successfully awarded HOME projects.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for reviewing the proposed rule. The Department is accepting the comment regarding oversight fees for environmental reviews and environmental studies and revising the final rule text to include such fees as eligible for reimbursement.
                    </P>
                    <HD SOURCE="HD3">C. Opposition to Requiring the Participating Jurisdiction Explicitly Approve of the Soft Costs in § 92.206(d)(1) in the Written Agreement</HD>
                    <P>A commenter stated that they do not support the proposed requirement that the costs for conducting environmental assessments and reviews are only eligible for reimbursement with HOME funds when expressly permitted in the written agreement. The commenter stated that conducting environmental assessments and reviews are consistent requirements and therefore the reimbursement should be automatically approved.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing and is moving forward with the revisions to § 92.206(d)(1). Under 42 U.S.C. 12756(a) and § 92.504, participating jurisdictions must enter into written agreements that bind the owner to comply with HOME program requirements. A written agreement between a participating jurisdiction and an owner must include a description of the eligible uses of the project funds to comply with the regulation. The Department is declining to treat environmental assessments differently from other reimbursable expenses listed in§ 92.206(d)(1),
                        <SU>41</SU>
                        <FTREF/>
                         all of which must be explicitly mentioned in the written agreement to be eligible for reimbursement.
                    </P>
                    <FTNT>
                        <P>
                            <SU>41</SU>
                             The other reimbursable expenses in 24 CFR 92.206(d) will now include: “Architectural, engineering, or related professional services required to prepare plans, drawings, specifications, work write-ups; for HUD environmental review or other environmental studies, assessments, or fees; and for certain costs to process and settle the financing for a project, such as private lender origination fees, credit reports, fees for title evidence, legal fees, accounting fees, filing fees for zoning or planning review and approval, private appraisal fees, fees for independent cost estimates, and other lender required third-party reporting fees.”
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">D. Clarification of Requirement to State Eligible Soft Costs in § 92.205(d)(1) in the Written Agreement</HD>
                    <P>One commenter stated that participating jurisdictions and other participants do not understand that only the costs expressly listed in § 92.206(d)(1) may be reimbursed with HOME funds notwithstanding that they were incurred up to 24 months prior to the commitment of HOME funds. The commenter recommended that HUD address this issue with additional education or clearer regulatory language.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing and is moving forward with the revisions to § 92.206(d)(1) without change. The Department will consider providing implementation guidance on this regulatory change in the future.
                    </P>
                    <HD SOURCE="HD3">E. Allow Additional Predevelopment or Holding Costs To Be Reimbursed if Specified in the Written Agreement</HD>
                    <P>One commenter stated HUD should consider whether it is appropriate to permit predevelopment costs otherwise allowed under § 92.206(d)(2) to be reimbursed with HOME funds in the same manner as predevelopment costs otherwise allowed under § 92.206(d)(1). The commenter noted that it is common for developers to have incurred various predevelopment legal/accounting costs, filing fees for planning/zoning reviews, appraisals and other lender-required third-party reports, etc. prior to the commitment of HOME funds (and often as a predicate for meeting the conditions for commitment). The commenter believed that most of those costs would be “anchored” in § 92.206(d)(2) and that HUD should consider whether it is appropriate to allow predevelopment costs otherwise allowed by § 92.206(d)(2) to be reimbursed with HOME funds in the same manner as other pre-commitment predevelopment costs identified in § 92.206(d)(1).</P>
                    <P>One commenter requested that HUD delineate other holding and interim costs during development that the other parts of industry regularly characterize as soft costs with specific focus on property assessments and taxes, as well as utilities, groundskeeping, and security costs. The commenter stated that this clarification is necessary because these types of costs are not eligible for coverage once the project is ready for lease-up.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department agrees with the commenters and is expanding the project soft costs that may be incurred prior to a commitment to include costs to process and settle financing for the project, including private lender origination fees, credit reports, fees for title evidence, legal fees, private appraisal fees, and fees for independent cost estimates. These were all contained in paragraph (d)(2) but will now be deleted from paragraph (d)(2) and added to paragraph (d)(1). While the Department is moving these provisions to paragraph (d)(2), the Department determined that several provisions could not be moved because there is no reasonable expectation that they should occur prior to commitment. These provisions include obtaining building permits, which require HUD environmental review; fees for recordation and filing of legal documents, as recorded documents relating to an acquisition, rehabilitation, 
                        <PRTPAGE P="793"/>
                        or new construction project should occur after commitment of HOME funds; and builders or developers fees, as those fees should not be earned and chargeable to the HOME grant for work performed prior to the environmental review and commitment of the HOME funds to the project. HUD declines to make reimbursement of holding costs incurred before the commitment of HOME funds eligible as the Department considers these operating costs not project-related soft cost associated with predevelopment.
                    </P>
                    <HD SOURCE="HD3">F. Revise § 92.206(d)(6) To Allow for Additional Costs To Be Reimbursed</HD>
                    <P>One commenter stated HUD should clarify when participating jurisdiction overhead and staff costs remain eligible for reimbursement even when incurred prior to commitment under § 92.206(d)(6) because the rule does not explicitly identify these as eligible costs.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Staff and overhead cost of the participating jurisdiction are eligible for reimbursement as an administrative and planning cost under § 92.207(b) or as a project-related cost under § 92.206(d)(6). However, participating jurisdiction staff and overhead costs for a project that does not proceed as a HOME-assisted project is only eligible to be reimbursed as an administrative cost under § 92.207(b). A participating jurisdiction may only reimburse itself for project-related soft costs under § 92.206(d)(6) after it enters into a written agreement committing funds to the project and funding the project in IDIS.
                    </P>
                    <HD SOURCE="HD3">G. Revise Eligible Project Costs To Include Additional Costs</HD>
                    <P>One commenter suggested expanding HOME's eligible costs so that developing and rehabilitating garage structures would be an eligible cost for the HOME program. The commenter stated that garages provide secure places to maintain personal property, like vehicles and mowers, and also support higher densities in urban neighborhoods through the creation of Accessory Dwelling Units (ADUs).</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for reviewing the proposed rule. HOME funds can be used for the cost of attached garages, 
                        <E T="03">i.e.,</E>
                         garages that are part of the housing structure receiving HOME funds. Unfortunately, the Act does not authorize the use of the HOME funds for appurtenances. Consequently, costs related to construction of freestanding garages or community buildings are not eligible to be paid with HOME funds.
                    </P>
                    <HD SOURCE="HD2">§ 92.207—Eligible Administrative and Planning Costs</HD>
                    <HD SOURCE="HD3">A. Raise Administrative and Planning Cost Cap</HD>
                    <P>One commenter stated that given the addition of new requirements, including BABA and VAWA, and the reduction in recent years of entitlement funding, the limit on only spending 10 percent on administration and planning costs is not sufficient to meet obligations in running compliant programs.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD understands the commenter's concerns about the potential increased costs of compliance and the limited amount of administrative and planning funds. Unfortunately, the 10 percent cap on each administrative and planning costs for each grant is statutory. 
                        <E T="03">See</E>
                         42 U.S.C. 12742(c).
                    </P>
                    <HD SOURCE="HD3">B. Reimbursement of Program Costs for Projects That Do Not Proceed</HD>
                    <P>One commenter stated that HOME applicants often drop out of the process prior to closing, which means grantees are unable to recover the extensive staff time invested in considering or processing applications. The commenter recommended that HUD allow reimbursement of program costs if the grantee can demonstrate they acted in earnest to achieve the national objective. This could include demonstration of standard program deliverables, including inspection reports, work-write ups, bid packages and construction contract materials.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HOME regulations at § 92.207 currently permit payment of administrative costs, including staff and overhead costs for considering or processing applications, monitoring owners, inspections, and other administrative costs associated with program governance. However, for a cost to be an eligible project cost under § 92.206, it must be for a project that provides affordable housing in accordance with 24 CFR part 92.
                    </P>
                    <HD SOURCE="HD3">C. Inability To Pass Along Costs to Program Beneficiaries Necessitates Additional Administrative Funds</HD>
                    <P>A commenter noted that State participating jurisdictions often develop rules regarding eligible administrative and project costs forcing many small cities and counties to exit the program because costs cannot be reimbursed fully. The commenter believes that not allowing costs for work specifications, needed inspections, and title insurance to be charged to successful HOME beneficiaries unfairly limits compensation for program delivery in homebuyer and home rehabilitation programs.</P>
                    <P>The commenter stated that HUD should increase support for administrative and activity delivery costs because participating jurisdictions, State recipients, or local recipients require grantees to provide additional funding from general funds to cover cost overruns that stem from these categories. The commenter suggested an increase in allowable administrative costs to 12 percent if a State recipient contractor or subrecipient is utilized. The commenter suggested allowing project delivery cost reimbursement housing rehabilitation, homebuyer assistance, and ADU programs.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Program beneficiaries in HOME homeownership programs (
                        <E T="03">i.e.,</E>
                         homebuyers and homeowners) may only pay costs in accordance with §§ 92.254, 92.251, and 92.214. Under § 92.504(a) participating jurisdictions are responsible for managing the day-to-day operations of its HOME program, ensuring that HOME funds are used in accordance with all program requirements and written agreements, and taking appropriate action when performance problems arise. The participating jurisdiction must have and follow written policies, procedures, and systems, including a system for assessing risk of activities and projects and a system for monitoring entities consistent with HOME requirements in 24 CFR part 92, and must take all necessary steps to require compliance with the HOME requirements. The Department is not changing these requirements or removing discretion from participating jurisdictions to determine the terms of the HOME assistance. Many of the costs that the commenter mentioned are within the discretion of the participating jurisdiction to pay if they are included in the written agreement, this includes work-write-ups; environmental reviews, studies, or assessments; and title insurance fees.
                        <SU>42</SU>
                        <FTREF/>
                         The HOME rule at § 92.205(d)(6) requires that these costs only be charged as activity costs if the project is funded, and the individual becomes the owner or tenant of the HOME-assisted project. The Department believes this is a reasonable restriction of the costs because, by statute, project delivery costs may only be paid for completed projects that meet the requirements of 24 CFR part 92.
                        <SU>43</SU>
                        <FTREF/>
                         Finally, the Department understands that the commenter is requesting additional administrative and planning funds. The 10 percent cap on each FY's 
                        <PRTPAGE P="794"/>
                        administrative and planning costs is statutory. 
                        <E T="03">See</E>
                         42 U.S.C. 12742(c). There is no HUD-imposed cap on project delivery cost reimbursement for the costs required in § 92.206(d)(1). Reimbursement of those costs are at the discretion of the participating jurisdiction and must explicitly be included in the written agreement committing the funds to be eligible HOME project costs.
                    </P>
                    <FTNT>
                        <P>
                            <SU>42</SU>
                             See 24 CFR 92.205(d)(1) and (2).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>43</SU>
                             See 42 U.S.C. 12742 and 42 U.S.C. 12749.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD2">§ 92.208—Eligible Community Housing Development Organization (CHDO) Operating Expense and Capacity Building Costs</HD>
                    <HD SOURCE="HD3">A. General Support</HD>
                    <P>Commenters supported the proposed rule revisions to correct a drafting error that created an unintended barrier to using CHDO operating expense and capacity building funding to assist nonprofit organizations seeking CHDO designation to meet the demonstrated capacity requirements.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the reviewers for commenting, agrees with the commenters in support of the change, and is moving forward with the change.
                    </P>
                    <HD SOURCE="HD3">B. Concern About Requirement That Operating Assistance Be Provided to an Organization That the Participating Jurisdiction Expects To Commit Assistance to for a Project Within 24-Months</HD>
                    <P>One commenter recommended adding the requirement described in § 92.300(e) of the existing rule, that a participating jurisdiction may only provide operating expense assistance under § 92.208 to a CHDO if the participating jurisdiction expects to commit CHDO set-aside funds to the CHDO for a project within 24 months, to § 92.208. The commenter believed this to ensured that the limitation is not overlooked. A commenter asked that HUD clarify the consequences of providing operating funds to a CHDO that does not receive CHDO set-aside funding for a project within 24 months and recommended that HUD not require repayment of the operating assistance funds if the CHDO has made good faith efforts to qualify for project funding. Another commenter recommended providing examples of good faith efforts in sub-regulatory guidance and two commenters provided potential examples of good faith efforts.</P>
                    <P>One commenter stated that CHDOs receiving capacity building funds should receive more time because developing affordable housing for low-income persons is complex and difficult. Other commenters recommended extending the time period for organizations receiving operating expense funds to secure project-related set aside funds from 24 months to 36 months. Some commenters noted that a 36-month timeline would align CHDO TA with other Federal programs, such as the CDFI Fund, which requires that organizations receiving TA awards become certified as a CDFI within three years of receiving their TA award. A commenter also suggested that the longer timeframe would align with the needs of low-income communities, recognizing the unique challenges and longer timelines that are often faced in those areas.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Based on the comments received, the Department recognizes that there is some confusion among commenters about the use of operating assistance funding for capacity building activities, and the separate category of capacity building funding for development of CHDOs by new participating jurisdictions during their first 24 months of participation of the HOME program. To eliminate this confusion, HUD is revising the language in the proposed rule's paragraph § 92.208(c) to strike the term “capacity building.”
                    </P>
                    <P>In response to the query about the consequences of a CHDO that received operating assistance not receiving a commitment of project funding, in most cases repayment is not required but the participating jurisdiction must cease providing operating assistance to the organization when it determines that it will not be committing funds to the organization for a HOME project.</P>
                    <HD SOURCE="HD3">C. Expand CHDOs That May Receive Operating Funds Under § 92.208(a)</HD>
                    <P>One commenter stated that CHDOs experiencing employee turnover should have access to CHDO operating funds under § 92.208(a).</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for reviewing the proposed rule and notes that the current regulations and this final rule permit participating jurisdictions to provide CHDO operating assistance funds to CHDOs experiencing employee turnover.
                    </P>
                    <HD SOURCE="HD3">D. Expand Eligibility for Capacity-Building Funds in § 92.208(b)</HD>
                    <P>A commenter supported the proposed changes but urged HUD to remove the language at § 92.300(b) that restricts capacity building funding only to participating jurisdictions within the first 24 months of participation in the HOME program as there are many participating jurisdictions that have not identified a sufficient number of capable CHDOs and struggle to use their CHDO set-aside each year.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The restriction that a participating jurisdiction may only engage in capacity building activities for CHDOs in the first 24 months of a participating jurisdiction's participating in the program is statutory. 42 U.S.C. 12771(a) states in relevant part that “[i]f during the first 24 months of its participation under this subchapter, a participating jurisdiction is unable to identify a sufficient number of capable community housing development organizations, then up to 20 percent of the funds allocated to that jurisdiction under this section, but not to exceed $150,000, may be made available to carry out activities that develop the capacity of community housing development organizations in that jurisdiction . . . .” If a participating jurisdiction has been participating in the HOME program for more than 24 months, it may still provide CHDOs with CHDO operating funds in accordance with § 92.208(a) and (c).
                    </P>
                    <HD SOURCE="HD3">E. General Requests To Enhance CHDO Capacity</HD>
                    <P>Commenters urged HUD to provide technical assistance to help CHDOs build and maintain capacity, particularly in rural areas. A commenter that is an organization that serves persons with disabilities and has previously sought CHDO designation requested that HUD provide technical assistance to existing community-serving organizations that wish to or that are becoming CHDOs. One commenter urged HUD to use capacity building money in non-entitlement communities because it would provide needed funding to nonprofit organizations in those communities to address their affordable housing needs.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD acknowledges the importance of providing technical assistance to rural CHDOs to help them succeed in competitive funding cycles administered by their participating jurisdictions. The Department recognizes that rural CHDOs face unique challenges that can be addressed through targeted support. However, HUD can only provide direct program assistance to entities that receive funds directly from HUD. Partners, subrecipients, or project sponsors that receive HUD funds through a participating jurisdiction must coordinate with the participating jurisdiction to submit a request for in-depth program assistance on their behalf. HUD will continue to develop training and tools aimed at providing broad assistance that is relevant to rural CHDOs.
                        <PRTPAGE P="795"/>
                    </P>
                    <HD SOURCE="HD2">§ 92.209—Tenant-Based Rental Assistance</HD>
                    <HD SOURCE="HD3">A. Request for Clarification on Rental Assistance Contract</HD>
                    <P>One commenter asked HUD to clarify § 92.209 by stating that the rental assistance contract is the one under which HOME funds are committed to the activity, not the agreement between the tenant, landlord, and participating jurisdiction/State recipient.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing the proposed rule. The definition of “Commit to specific local project” in paragraph (2) of the definition of “Commitment” in 24 CFR 92.2 states that the committing document for HOME tenant-based rental assistance is the rental assistance contract. When a participating jurisdiction is administering its own tenant-based rental assistance program, this will be the document committing HOME tenant-based rental assistance. If a participating jurisdiction is using a Subrecipient (or State recipient) to provide tenant-based rental assistance, then there will be at least two commitments, one will be committing funds to administer a tenant-based rental assistance program that is between the participating jurisdiction and its Subrecipient (or State recipient); the other will be committing funds through the rental assistance contract between the Subrecipient (or State recipient) and the tenant and owner receiving the tenant-based rental assistance.
                    </P>
                    <P>If a participating jurisdiction is using a contractor to provide tenant-based rental assistance, then there will also be at least two commitments, one committing the funds to the contractor to administer the participating jurisdiction's tenant-based rental assistance program; and the other being the rental assistance contract between the Contractor (as agent of the participating jurisdiction) and the owner and tenant assisted by the tenant-based rental assistance.</P>
                    <HD SOURCE="HD3">B. Use of Tenant-Based Rental Assistance in Lease Purchases</HD>
                    <P>One commenter expressed support for HUD's outline in the proposed rule of the parameters within which a tenant may become a homeowner through the lease-purchase process and said that easing lease-purchase in the HOME program would provide a much-needed path toward homeownership for low- to moderate-income homebuyers. The commenter reasoned that allowing a homebuyer-tenant to contribute their TBRA toward a down payment will facilitate rent-to-own processes for HOME-assisted households. According to the commenter, if HUD's proposal were finalized, both participating jurisdictions and potential homebuyers could determine that all or some of the tenant's contribution to rent could be set aside for closing costs or a down payment and solidify terms through the lease-purchase agreement.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The commenter supports changes made to the lease-purchase program but requests the ability for TBRA tenants participating in a lease-purchase program to have a portion of their tenant-based rental assistance, and not just the tenant contribution towards rent, be used to accumulate a downpayment for the unit. The current regulation at § 92.209(c)(2)(iv) only allows a portion of the tenant's monthly contribution towards rent to be set aside for this purpose. The Department did not propose a change to this provision and does not believe it can do so because the result would be that the tenant-based rental assistance provided would be used as both tenant-based rental assistance and homeownership assistance. This dual use of HOME funds would violate the provisions of 42 U.S.C. 12742(a)(3) and (b), which do not contemplate using tenant-based rental assistance for such purpose. Instead, the Department only clarified that when all or a portion of the homebuyer-tenant's monthly contribution toward rent is set aside for closing costs or a downpayment, it must be set aside in accordance with the lease-purchase agreement.
                    </P>
                    <HD SOURCE="HD3">C. Income Reexaminations and § 92.209(c)(1)</HD>
                    <P>Several commenters stated that they support reducing the frequency of income determinations by requiring income redetermination only at TBRA contract renewal instead of an annual determination. Commenters stated that reducing the frequency of income determinations was prudent and would lessen the impact on tenants and reduce administrative burden on participating jurisdictions. One commenter noted that longer recertification periods would allow families to build wealth without immediately having to pay higher rent and utility payments. The commenter was grateful HUD was building off its Bridging the Wealth Gap plan but encouraged the Department to implement longer recertification periods such as triennial income recertifications as proposed in the Bridging the Wealth Gap plan.</P>
                    <P>One commenter noted that, as written, the rule may still require income determinations annually because leases expire annually. The commenter suggested clarifying that income reexamination is not required for amendments to the rental assistance contract during the original term of the contract as project costs may change during the term.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing the proposed rule and is moving forward with the proposed change. In response to the commenters, HUD is adding language to § 92.209(e) that clarifies when an income reexamination is required. While the Department is not moving to triennial income reexamination for tenant-based rental assistance, HUD is revising § 92.209(e) to add a new paragraph (3) that defines what events constitute an amendment or renewal of the rental assistance contract. Specifically, a rental assistance contract may only be amended for the following reasons and within its term if all parties consent, for the following reasons: to extend the term of the rental assistance contract up to 24 months from the original date of execution; when a tenant changes units within the same building or development provided the parties to the lease, the family size, and number of bedrooms remain the same; or the lease term or amount charged under the lease has been changed. Subject to the availability of HOME funds, a rental assistance contract may be renewed after the expiration of its initial term.
                    </P>
                    <P>The Department is also adding language in a new paragraph (4) that explains when initial and subsequent income determinations are required. Income determinations will be required before a participating jurisdiction enters into an initial or new rental assistance contract with the family, and at contract renewal. Participating jurisdictions will not be required to reexamine a family's income if the rental assistance contract is amended. The Department believes this will address the commenters' concerns by establishing a clear framework for reducing income reexaminations in tenant-based rental assistance.</P>
                    <HD SOURCE="HD3">D. Increase Alignment With Section 8 on Income Reexaminations</HD>
                    <P>
                        Commenters stated that HOME TBRA should require income eligibility screening only at new admission and not require it afterwards, 
                        <E T="03">i.e.,</E>
                         not during the annual certification process, because Section 8 requires income eligibility screening only upon new admission.
                    </P>
                    <P>
                        Commenters also suggested that HOME TBRA do not have a lease 
                        <PRTPAGE P="796"/>
                        renewal requirement similar to Section 8, where lease renewal is implied.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for reviewing the proposed rule and acknowledges the commenter's recommendation to align income eligibility requirements across the HOME tenant-based rental assistance programs and Section 8 Housing Choice Voucher programs. Due to HOME statutory limitations, HUD declines to adopt this recommendation.
                    </P>
                    <P>
                        The Act requires income targeting for HOME tenant-based rental assistance to be based on income at the time of occupancy or at the time funds are invested, whichever is later.
                        <SU>44</SU>
                        <FTREF/>
                         The Act also limits the term of rental assistance contracts to 24 months.
                        <SU>45</SU>
                        <FTREF/>
                         The combined effect of the two provisions is that the participating jurisdiction must redetermine income each time it invests its funds into a new rental assistance contract to determine that the family meets the income eligibility requirements and to determine that the funds invested in the rental assistance contract still meet the statutory income targeting requirements. Rental assistance contracts may be renewed if a participating jurisdiction has funds available and the family still meets the income requirements after their income is redetermined.
                    </P>
                    <FTNT>
                        <P>
                            <SU>44</SU>
                             42 U.S.C. 12744.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>45</SU>
                             42 U.S.C. 12742(a)(3)(C).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">E. Remove Requirement That a Rental Assistance Contract Begin on the First Day of the Lease</HD>
                    <P>One commenter asked HUD to remove the requirement in § 92.209(e) that the rental assistance contract begin on the first day of the term of the lease because it imposes a hardship on households that receive TBRA in the rental housing they currently occupy, but where they were unassisted at the time of lease execution. The commenter explained that HUD allows for the lease term to expire during the term of assistance, so long as no HOME assistance is provided when an active lease is not in place and that an existing lease may be amended to include the required tenant protections after the lease term begins, so the lease effective date should be immaterial to the HOME assistance start date, so long as all other requirements are achieved.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD agrees with the commenter that requiring the rental assistance contract to begin on the first day of the lease is problematic for families that are already under an existing lease. The Department is revising § 92.209(e) to state that the term of the rental assistance contract must begin on the first day of the term of the lease or the beginning of the first month in which tenant-based rental assistance is provided in accordance with the rental assistance contract. Permitting the rental assistance contract to begin on the first month in which the tenant-based rental assistance is provided will allow participating jurisdictions to assist families already residing in a unit, provided that the lease conforms to the tenant-based rental assistance requirements in § 92.209 and includes the HOME tenant-based rental assistance tenancy addendum required in § 92.253.
                    </P>
                    <HD SOURCE="HD3">F. Support for Tenant Hardship Provisions in § 92.209(h)</HD>
                    <P>Several commenters stated that they support the proposed change to the TBRA requirements to allow participating jurisdictions to establish hardship policies that permit an exception to the minimum rent requirement for families with little or no income.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for their support and is moving forward with these changes.
                    </P>
                    <P>
                        <E T="03">Specific solicitation of comment #9: The Department currently applies only the tenant protections contained in the current § 92.253(a) and (b) to tenants receiving TBRA. The proposed rule would apply proposed paragraphs (a)-(c) and (d)(2) to tenants receiving TBRA, including tenants that only receive HOME security deposit assistance. The Department is seeking public comment on whether the requirements at § 92.253(b) and (d)(2) should be required for tenants that receive TBRA. If not, what tenant protection requirements should apply to tenants that receive TBRA?</E>
                    </P>
                    <HD SOURCE="HD3">A. Comments in Support of a Tenancy Addendum for Tenant-Based Rental Assistance Recipients</HD>
                    <P>Several commenters supported providing a tenancy addendum for recipients of HOME tenant-based rental assistance. One commenter stated the proposed tenant protections are a positive step towards protecting low-income renters in subsidized units and that they hoped to see the protections expanded to other HUD programs. Another commenter supported the expanded tenant protections and stated that many of the protections already exist in State law and local ordinances. Another commenter said that even though the commenter is unaware of any jurisdictions that use HOME funds to provide TBRA, there is no reason why TBRA should operate differently than the Housing Choice Voucher program, which provides tenant protections.</P>
                    <P>One commenter stated that a universal HOME tenancy addendum would ensure compliance with Violence Against Women Act (VAWA) requirements and other Federal tenant rights and reduce the burden on participating jurisdictions to develop their own addenda or review individual leases. The commenter cautioned HUD must ensure that the universal HOME tenancy addendum does not conflict with any lease provisions or addenda required by other Federal programs, and should avoid conflict with applicable State or local laws to the maximum extent possible. One commenter urged HUD to extend the full range of tenant protections to those receiving HOME TBRA and noted its appreciation for extending these protections to persons with disabilities. The commenter appreciated HUD seeking to minimize owner retaliation for reasonable accommodation requests but notes that HUD enforcement of the regulation is required in order to prevent such retaliation.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for their views and agrees that tenancy addenda are an effective and administratively streamlined way to ensure that leases are free from prohibited lease terms and provide tenants with adequate protections and rights. HUD is adopting tenancy addenda for rental housing, tenant-based rental assistance, and families receiving only security deposit assistance. However, in response to public comment, HUD is making significant changes to the addenda requirements in this final rule so that the requirements in the addenda reflect the extent of HOME involvement in the project.
                    </P>
                    <P>Specifically, HUD is making even greater distinctions between the addenda for rental housing in which the owner has accepted HOME funding for the project and tenant-based rental assistance, as well as between ongoing tenant-based rental assistance and only security deposit assistance. This final rule also better aligns HOME tenancy provisions with those applicable to Housing Choice Vouchers and project-based vouchers to maintain consistency across the programs.</P>
                    <P>
                        HUD declines to include VAWA protections applicable to HOME projects in the HOME-specific tenancy addenda established by this rule because the Department is undertaking separate rulemaking to implement the expanded VAWA protections across HUD programs. The HOME-specific protections in these addenda must be 
                        <PRTPAGE P="797"/>
                        adjudicated through State and local judicial processes. Participating jurisdictions are also required to monitor and enforce HOME requirements. HUD, in its HOME program monitoring and oversight role, may identify when a participating jurisdiction is not enforcing the HOME requirements and may require that the participating jurisdiction enforce tenant protections, as necessary. The Department notes that individuals may report housing discrimination to HUD's Office of Fair Housing and Equal Opportunity (FHEO), including complaints involving violations of VAWA, the Fair Housing Act, Section 504 of the Rehabilitation Act, and Title VI of the Civil Rights Act. See 
                        <E T="03">https://www.hud.gov/fairhousing/fileacomplaint.</E>
                         However, the Department is declining to establish grievance procedures on either the Departmental level or for participating jurisdictions. The HOME program is a block grant affordable housing program, and it is the responsibility of each participating jurisdiction to determine the best systems, policies, and procedures for monitoring and enforcing compliance in accordance with §§ 92.253 and 92.504.
                    </P>
                    <HD SOURCE="HD3">B. Cautious Support of a Tenancy Addendum for Tenant-Based Rental Assistance Recipients</HD>
                    <P>One commenter supported HUD's proposal to expand tenant protections for households receiving TBRA assistance in theory but was concerned that doing so may provide a disincentive for owners of rental housing to participate in the program. While the commenter acknowledged the benefits of extending tenant protections, especially in jurisdictions without many protections for tenants, an expansion of requirements would likely deter available units from being accessed. The commenter recommended providing an option for participating jurisdictions to exempt the new requirements for households that receive TBRA security deposit assistance only, as well as an option for participating jurisdictions to exempt 1-4 family and attached rental dwellings if it is a deterrent for owners in their jurisdiction.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD shares the commenter's concern that HOME lease addenda not act as a disincentive to private landlords accepting participants in HOME TBRA programs, including security deposit assistance only programs. HUD believes that establishing different addenda for HOME rental projects, HOME TBRA, and HOME security deposit assistance that provide different levels of tenant protections based on the form of HOME assistance being provided will help address landlord reluctance to accept the tenant protections in the addenda. The Department believes that HOME TBRA recipients should have protections similar to tenants of HOME-assisted rental units. Consequently, the TBRA addendum is substantially similar to the Rental Housing addendum except that it does not include the requirements: (1) that an owner relocate a tenant if a life-threatening deficiency cannot be addressed on the same day it is identified; and (2) that allows tenants to organize, create tenant associations, convene meetings, distribute literature, and post information. Because of the limited nature of security deposit assistance, the new security deposit assistance tenancy addendum includes the prohibited lease terms in the current regulations. The Department chose this set of protections because the vast majority of the protections have been the minimum standard for tenant protections in the HOME program since 1991, when the HOME program's first rule was issued.
                        <SU>46</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>46</SU>
                             See 56 FR 65354.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">C. Opposition to a Tenancy Addendum for Tenant-Based Rental Assistance Recipients</HD>
                    <P>Several commenters stated that requiring a tenancy addendum on TBRA leases would likely limit the housing supply because fewer landlords would accept tenants with HOME TBRA, especially in places where the expanded protections exceed existing law. One of the commenters recommended that HUD specially reach out to all participating jurisdictions to obtain input on the impact of these proposed changes.</P>
                    <P>One commenter stated that the additional requirements limit the units that are available to tenants for landlords that refuse the additional protections as part of the lease. The commenter explained that where demand exceeds supply the additional requirements limit the units available for rent. Additionally, the commenter said that State and local laws already provide tenant protections and the HOME program should not limit tenants' access to existing available units for rent by adding duplicative regulations and requirements. Another commenter also said the proposed changes would risk decreasing program use and create difficulties finding available units. This commenter said LIHTC units have been lost due to qualified contract provisions that have caused a housing shortage for low-income communities.</P>
                    <P>One commenter stated that the proposed tenant protection provisions would undermine the operational and financial well-being of participating rental properties and would interfere with existing State and local tenant protection laws without any evidence supporting the effectiveness of the proposed provisions. Another commenter stated that the proposed tenant protection provisions would make it more difficult for local courts to interpret lease agreements.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the feedback and has carefully considered the commenters' concerns that a TBRA addendum might create a disincentive for private landlords to rent units to HOME TBRA recipients. The Department understands that there may be owners that refuse tenants with HOME tenant-based rental assistance because of the terms of the HOME tenant-based rental assistance tenancy addendum; nonetheless, the Department has experience with applying tenancy addenda in other tenant-based rental assistance programs, most notably the Housing Choice Voucher program, and believes that it must balance the disincentive to some owners with the overall needs of the tenants being assisted with Federal funds. TBRA recipients are entitled to tenant protections and the Department has determined that these tenant protections should be similar to those being provided to tenants of HOME-assisted rental housing units, as described in the preamble to this final rule. The Department provided notice to the public of these protections in the proposed rule and specifically solicited comment on applying the protections to tenant-based rental assistance, just as the commenter is saying that the Department should have done. After examining the comments received, HUD is adopting the requirement for a HOME tenant-based rental assistance tenancy addendum in this final rule.
                    </P>
                    <P>
                        Tenant protections under State laws vary widely and HUD does not agree with commenters that it should defer to individual State laws that may not always provide sufficient tenant protections for families receiving HOME tenant-based rental assistance. Many State laws do not afford the minimum set of tenant protections provided under the current HOME regulations. After careful consideration of the comments received as part of this rulemaking, the Department has determined that it should not rely upon State laws and should promulgate the tenant protections provided in § 92.253(c) as a 
                        <PRTPAGE P="798"/>
                        minimum standard of tenant protections. The Department does not believe that requiring a minimum level of tenant protections will undermine the operational and financial well-being of participating rental properties, as owners are free to assess the risks and choose whether they are comfortable with executing a tenancy addendum that includes the tenant protections in § 92.253(c). The tenancy addendum will not interfere with existing State and local tenant protection laws and tenants may exercise any protections that are more stringent than HUD requirements. The Department also believes that the preamble discussion of both the proposed and this final rule, the plain language of § 92.253(c), and the HOME tenant-based rental assistance tenancy addendum provide ample materials for courts to interpret tenant leases. The Department also notes that many participating jurisdictions already include a tenancy addendum addressing prohibited lease terms contained in the current HOME regulations, and that such practice has made it easier, not harder, for tenants to assert their rights under their lease.
                    </P>
                    <HD SOURCE="HD3">D. Opposition to Tenancy Addendum for Security Deposit Assistance</HD>
                    <P>One commenter stated HUD should not require a tenancy addendum on security deposit-only HOME clients, as this scenario typically includes TBRA or Housing Choice Voucher or VASH vouchers, which already occur and have an entity monitoring the landlord-tenant relationship for compliance.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD agrees with the commenter that it is not appropriate to use the HOME tenant-based rental assistance tenancy addendum for tenants receiving security deposit only assistance. Unlike tenancy in a HOME-assisted rental unit or receipt of HOME TBRA, security deposit only assistance is one-time assistance. This is especially true when it is coupled with another form of assistance such as a Housing Choice Voucher. However, security deposit only assistance is subject to the prohibited lease terms established in the HOME statute and already promulgated in the current regulations. Consequently, HUD is adopting an addendum solely for use in conjunction with security deposit only assistance that contains only those currently prohibited lease terms, as an addendum is an effective mechanism for ensuring compliance.
                    </P>
                    <P>
                        <E T="03">Specific solicitation of comment #10: Currently, a rental assistance contract can be between a participating jurisdiction and either an owner or a tenant. The Department is also aware of many participating jurisdictions that have tri-party rental assistance contracts where the owner, the tenant, and the participating jurisdiction all sign the rental assistance contract. The Department is seeking feedback on whether a rental assistance contract should always be executed by an owner so that the participating jurisdiction can require that the HOME-assisted tenant's lease contain the HOME tenancy addendum, and that the owner follow all applicable TBRA requirements.</E>
                    </P>
                    <P>To promote robust enforcement, a commenter suggested that HUD should consider elaborating on the participating jurisdiction's obligations upon receiving the lease or revision via final rule or accompanying guidance. The commenter explained that tenants would benefit if the participating jurisdiction was obligated to notify them of proposed lease revisions and if tenants had the right to submit comments regarding those revisions. The commenter also suggested that HUD could also play a role in compliance monitoring if HUD performed audits of the leases and revisions that are submitted. The commenter further suggested that HUD should also require that leases disclose any other Federal housing subsidies that are attached to the unit and the property, as well as a statement that if a property or unit has multiple subsidies, the most restrictive tenant protections apply.</P>
                    <P>Several commenters stated that the rental assistance contract should be executed by an owner to ensure that the owner is compliant with all applicable HOME TBRA requirements, particularly given that the regulatory requirements apply to the owner of the project. One commenter noted that agreements with project owners are common practice. Another commenter noted that it already requires the owner to be party to the rental assistance contract and agrees that it is necessary to ensure tenant protections are enforced. Another commenter stated that they have often experienced instances where tenants sign the agreement but as an owner the commenter did not see the agreement until after execution, which doesn't allow the owner to know up front what is expected of them.</P>
                    <P>One commenter stated that a tri-party rental assistance contract ensures that the owner and tenant have a clear understanding of, and agree to, the program requirements, however the commenter noted that a tri-party contract may be a disincentive to small-scale rental owners' participation in the program. Another commenter noted that while it believes the rental assistance contract should be executed by the owner, it does support triparty contracts as an option.</P>
                    <P>Two commenters stated that HUD should permit participating jurisdictions to choose whether owners should be included on the rental assistance contract, as is currently permitted in the regulations, although one commenter noted that requiring owners to be on the contract may result in owners electing not to participate in the program. The commenter also encouraged HUD to survey participating jurisdictions to see how many currently include owners on the contract and whether they support requiring the HOME tenancy addendum.</P>
                    <P>One commenter stated that the tenant protections should be required to be in the tenant's lease in whatever method is appropriate. Another commenter said that even though the commenter is unaware of any jurisdictions that use HOME funds to provide TBRA, there is no reason why TBRA should operate differently than the Housing Choice Voucher program, which requires a tenancy addendum.</P>
                    <P>One commenter stated that the proposed changes would risk adding an unnecessary layer of oversight and would create a link between participating jurisdictions and owners that would risk property damage concerns and tri-party contract disputes. The commenter also said that since States or subrecipients could also have assistance contracts and/or rental assistance contracts used as emergency solutions, having a requirement to issue contracts with owner signatures would add additional administrative burden. The commenter suggested that HUD leave the regulation in its current form.</P>
                    <P>One commenter stated that participating jurisdictions can always require that the HOME-assisted tenant's lease contain the HOME tenancy addendum and that the owner follow all applicable TBRA requirements either by including that requirement in a participating jurisdiction/owner contract or in a tri-party contract. The commenter is not aware of any data indicating the proposed change would benefit residents and may, in fact, deter owners from participating in HOME TBRA programs.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the feedback provided by the commenters and has decided to require the participating jurisdiction to enter a rental assistance contract with the owner and the family. The Department is revising § 92.209(e) to add paragraph (1) to delineate the required parties to a rental assistance contract. This may take the form of one agreement with the owner and a 
                        <PRTPAGE P="799"/>
                        separate agreement with the family, or one single tri-party agreement with the participating jurisdiction, the owner, and the family. The Department disagrees that requiring an owner be a party to the rental assistance contract would create an administrative burden, but instead believes the participating jurisdiction must have a means of enforcing the tenant-based rental assistance requirements in § 92.209 with both the project owner and the assisted family to ensure compliance with all applicable requirements in § 92.209, including but not limited to tenant protections, income determinations, and unit inspections.
                    </P>
                    <P>In contrast to the comment that requiring a rental assistance contract to be executed by the owner will lead to more contractual disputes, the Department believes the final rule provides clearer rights for tenants in contract disputes, especially those related to property damage. By eliminating normal wear and tear as grounds for an adverse action, and by tying charges for property damage to the tenant's intentional or negligent acts, the HOME tenant-based rental assistance tenancy addendum provides significantly greater clarity on permissible charges. The Department agrees with the commenter who stated that the rental assistance contract is the best vehicle that the participating jurisdiction has to enforce the tenant protections contained in the HOME tenant-based rental assistance tenancy addendum and also believes that this will provide greater clarity in the event of contractual disputes.</P>
                    <HD SOURCE="HD2">§ 92.210—Troubled HOME-Assisted Rental Housing Projects</HD>
                    <HD SOURCE="HD3">A. General Support</HD>
                    <P>Some commenters supported the additional flexibility for troubled HOME-assisted rental projects. A commenter stated that they support HUD's efforts to improve the effectiveness, specificity, and clarity of participating jurisdiction's authority to preserve affordable housing prior to foreclosure or similar events. Two commenters supported the changes in § 92.210(a) and (c), including allowing HUD to consider physical condition and financial viability when preserving HOME-assisted units at risk of failure or foreclosure. One commenter stated that this change would be a critical update providing clarity on this issue, as past interpretations have too narrowly focused on the financial viability of the property. Commenters stated that they support the proposed change to allow units to float-up from 50 percent of area median income to 80 percent of area median income if a project lacks sufficient income to cover operating expenses.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the commenter's feedback on these troubled HOME-assisted rental projects provisions and has revised this final rule based on the comments. Specifically, HUD is broadening the grounds on which a project may be considered financially troubled under § 92.210; under § 92.210(a)(1) of this final rule, a project is no longer financially viable if any one of three conditions exist, including if the project's operating costs exceed its operating revenue, considering project reserves; if the owner is unable to pay for necessary capital repair costs or ongoing expenses for the project; or if the project reserves are insufficient to be able to operate the project. The Department believes that broadening these grounds will better capture the type of projects that may be assisted with additional HOME funds. By contrast, the Department is moving forward with its proposed definition of physical viability, redesignated as § 92.210(a)(2), without change.
                    </P>
                    <HD SOURCE="HD3">B. Request for Clarification on “Significant” Financial Issues</HD>
                    <P>Commenters supported the flexibility in assisting troubled HOME-assisted rental housing projects and recommended HUD provide more clarity on what constitutes “significant” where the rule states “a HOME-assisted rental project is no longer financially viable if its operating costs significantly exceed its operating revenue.” A commenter asked HUD to evaluate “a project's current or future ability to maintain affordability” and asked that HUD detail the expected process and timeline when making a request to HUD regarding troubled HOME-assisted rental housing. The commenter also stated that HUD should allow HOME funds to be used to restructure debt for troubled HOME-assisted projects.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD agrees with commenters that the term “significantly” in § 92.210 is vague and undefined. Consequently, in this final rule HUD is deleting the word so that the flexibilities of § 92.210 will be available to projects in which operating costs exceed operating revenue. HUD notes that in addition to the provisions set forth in § 92.210, HUD has the authority to waive certain regulations and requirements under 24 CFR 5.110 if HUD determines that good cause exists. The Department understands that commenters may not know how to begin the process of determining if a project is troubled under § 92.210 or requesting a waiver under 24 CFR 5.110. To begin the process, the participating jurisdiction requests technical assistance from HUD to conduct a financial workout for a troubled project. Then, the participating jurisdiction and Department engages in a comprehensive assessment of the project's physical and financial sustainability, which includes discussions with other funders, if appropriate, and identification of all viable methods for the participating jurisdiction to ensure the project will comply with all applicable regulatory requirements through the period of affordability. The process then culminates in either a memorandum of understanding or a request for a waiver of HOME project requirements. In most instances, both methods will lead to changes in the number or mix of HOME-assisted units, investment of additional HOME funds, refinancing of debt, recapitalization of operating reserves, or rent adjustments.
                    </P>
                    <HD SOURCE="HD3">C. Support for Considering Physical Condition in Troubled HOME Projects</HD>
                    <P>A commenter supported the flexibility to consider financial viability or the physical condition of housing when preserving HOME-assisted units at risk of failure or foreclosure. The commenter noted the importance of recognizing that physical changes can significantly impact a project's preservation, including deferred maintenance due to unanticipated financial limitations or unforeseen capital needs. The commenter stated that this change would improve collaboration between participating jurisdictions and property owners to identify troubled properties and preserve them.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the commenter's support for the flexibility to consider both financial viability and the physical condition of housing when preserving HOME-assisted rental units at risk of failure or foreclosure. HUD agrees that acknowledging the impact of physical changes, often driven by unexpected financial challenges or unforeseen capital needs, is crucial to preserving these projects.
                    </P>
                    <P>
                        HUD agrees that this flexibility will enhance collaboration between participating jurisdictions and property owners, enabling the early identification of troubled properties and improving preservation efforts. HUD thanks the commenters and concurs that strong partnerships with participating jurisdictions are vital in reducing the number of troubled projects in the HOME rental portfolio. While projects do not deteriorate overnight, early identification, thorough analysis, and 
                        <PRTPAGE P="800"/>
                        proactive management are essential for ensuring the long-term sustainability of HOME-assisted rental projects.
                    </P>
                    <HD SOURCE="HD3">D. Participating Jurisdictions Should Preserve as Many Units as Possible</HD>
                    <P>One commenter understood that unforeseen events can affect projects but encouraged HUD to allow participating jurisdictions to request additional HOME funds to preserve as many units as possible or reduce the number of HOME-assisted units to ensure the safety and health of families. The commenter was concerned that “deferred maintenance” or “unforeseen capital needs” can be considered as factors that impact the long-term affordability or physical viability of projects and recommended that in these cases, 92.210(c) not apply and that HUD do as much as it can to preserve the units, including enforcing inspections regularly and providing additional resources to participating jurisdictions.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD agrees that addressing deferred maintenance and unforeseen capital needs is critical to preserving HOME-assisted rental housing for families. However, the regulatory framework, including § 92.210, establishes clear requirements for when and how units may be assisted with additional HOME funds. While HUD strives to preserve as many units as possible, funding constraints limit HUD's ability to provide additional HOME resources for every at-risk project. HUD encourages participating jurisdictions to leverage other Federal, State, and local funding sources alongside HOME to ensure comprehensive preservation strategies.
                    </P>
                    <P>HUD agrees that regular inspections are essential for identifying potential issues early and will continue to emphasize their importance through monitoring and technical assistance to prevent deferred maintenance and protect long-term affordability. HUD remains committed to working with participating jurisdictions and property owners to maintain the viability of HOME-assisted projects while ensuring the safety and health of residents.</P>
                    <HD SOURCE="HD3">E. Streamlining the Troubled Housing Project Process</HD>
                    <P>One commenter supported process streamlining of troubled HOME-assisted rental projects.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the comment, and acknowledges that workouts of troubled projects can be difficult and time-consuming due to the complexity of the issues and the number of stakeholders that may be involved. In addition to the changes made in this final rule to the financial viability provisions, which the Department believes may aid in streamlining the approval process under § 92.210, HUD plans to further outline the process for addressing troubled HOME-assisted rental projects in guidance.
                    </P>
                    <HD SOURCE="HD2">§ 92.212—Pre-Award Costs</HD>
                    <P>Two commenters supported the proposed change authorizing pre-award costs instead of requiring HUD to issue a waiver in each fiscal year in which Congressional appropriations are not timely.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for reviewing and is moving forward with this change.
                    </P>
                    <HD SOURCE="HD2">§ 92.214—Prohibited Activities and Fees</HD>
                    <HD SOURCE="HD3">A. Revise § 92.214(a) To Allow for Faircloth-to-RAD Transactions</HD>
                    <P>A commenter opposed the prohibition against providing HOME funds to support rental units that will receive subsidies through the Faircloth-to-RAD program. The commenter stated that Faircloth-to-RAD units are considered assisted under section 9 of the 1937 Act which, though HOME cannot fund, the ultimate intent for Faircloth-to-RAD units is for such assistance to be provided through section 8 of the 1937 Act, and as HOME-assisted rental units may also be assisted under section 8.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The commenter is correct. Until the public housing units are converted to Section 8 units through the Rental Assistance Demonstration, they are public housing units under the U.S. Housing Act.
                    </P>
                    <P>42 U.S.C. 12745(d)(4) &amp; (5) prohibits HOME funds from being used to provide assistance authorized under section 9 of the U.S. Housing Act (42 U.S.C. 1437g) or to carry out capital and management activities under the Capital Fund. The HOME rule at § 92.213 states that HOME-assisted housing units may not receive Operating Fund or Capital Fund assistance under section 9 of the 1937 Act (42 U.S.C. 1437g) during the HOME period of affordability. Because the public housing units in a Faircloth-to-RAD transaction are being constructed as public housing units under section 9 of the U.S. Housing Act (42 U.S.C. 1437g), and because the units must receive Public Housing Operating and Capital Funds in order to convert the assistance into a Housing Assistance Payments Contract when the units are converted, HOME assistance cannot be provided to develop the units. After conversion to Section 8 project-based rental assistance or project-based vouchers, HOME funds can be used to assist the development if there are any remaining expenses. Pursuant to § 92.213(c), HOME funds can also be used for non-public housing units if any are being constructed on the same site as the Faircloth-to-RAD units.</P>
                    <HD SOURCE="HD3">B. Revise § 92.214(b) To Clarify the Role of Participating Jurisdictions in Approving Fees</HD>
                    <P>One commenter suggested HUD amend § 92.214(b)(4) to state “With the permission of the participating jurisdiction, rental project owners may charge. . .” The commenter stated this language clarifies a participating jurisdiction's responsibilities with respect to permissible fees.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for reviewing. HUD will not be moving forward with this change. The Department did not propose to limit owners from charging reasonable application fees, parking fees (where customary), or fees for services such as transportation (when such services are voluntary and the fees are charged for the service provided) and these are already fees that owners are permitted to charge tenants of HOME projects under the current regulations. The Department also does not see the utility in requiring that participating jurisdictions regulate the permissible fees and is only requiring that participating jurisdictions prohibit the fees and charges listed in § 92.214(b)(3).
                    </P>
                    <HD SOURCE="HD3">C. Revise § 92.214(b) To Permit Late Fees</HD>
                    <P>One commenter stated that HUD should clarify whether owners may charge late fees and insufficient funds fees, which are common in the industry. The commenter noted HUD has informally indicated such fees are not meant to be prohibited under the current language of § 92.214(b)(1).</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The HOME rule at § 92.214(b)(3)(ii) prohibits “[f]ees that are not customarily charged in rental housing (
                        <E T="03">e.g.,</E>
                         laundry room access fees).” Reasonable late fees and returned check fees are customarily charged in rental housing and would not be prohibited by § 92.214(b).
                    </P>
                    <HD SOURCE="HD3">D. Revise § 92.214(b) To Add Additional Prohibited Fees</HD>
                    <P>
                        Another commenter urged HUD to further clarify prohibited activities and fees in § 92.214 including “normal wear and tear.” The commenter also asked HUD to address predatory fees such as a trip fee in conjunction with a lock-out and requested that HUD require owners to have a free rent payment method to address the fees often required when tenants pay online or with a credit card. The commenter stated that any fees which are not optional, such as 
                        <PRTPAGE P="801"/>
                        mandatory renter's insurance, should be required to be included in the gross rent calculation. The commenter also questioned whether bulk cable/phone/internet providers are allowable fees.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for reviewing the proposed rule and agrees with the commenter's recommendation that HUD clarify that charges for the normal wear and tear be prohibited under § 92.214. In this final rule, HUD is adding this prohibition to § 92.214(b)(3). The Department declines to accept the commenter's suggestion to prohibit fees for lock outs since owners may incur costs where a locksmith is required, or duplicate keys must be made. Provided such fees are customary and reasonable, participating jurisdictions may determine that owners of HOME-assisted projects may charge such fees.
                    </P>
                    <P>With respect to the comment that HUD require owners to have a free rent payment method to address the fees often required when tenants pay online or with a credit card, charging fees associated with online payments and using credit cards is a normal and customary business practice in many markets and as such HUD declines to adopt the commenter's suggestion. However, participating jurisdictions should encourage owners to ensure free rent payment methods are available to low-income families and may restrict the types of fees charged for paying rent through the written agreement with the rental housing project owner, as per § 92.504(c)(3)(x).</P>
                    <P>While the Department understands that one commenter believes that any fees that are not optional, such as mandatory renter's insurance, should be required to be included in the gross rent calculation, HUD is declining to adopt the commenter's recommendation. Fees are not utility costs and are not included in the gross rent determination. Mandatory fees may be permissible when commercially reasonable. The Department is not going to create a compliance standard where the owner must reduce the rent charged to a tenant by the monthly cost of mandatory fees. Instead, the Department is providing participating jurisdictions discretion to restrict fees through the written agreement. The Department also notes that mandatory renter's insurance is a commercially reasonable practice in the rental market.</P>
                    <P>Finally, one commenter questioned whether bulk cable/phone/internet providers are allowable fees. When such fees are not customarily charged within the participating jurisdiction's local rental market, such fees must be prohibited.</P>
                    <HD SOURCE="HD3">E. Revise § 92.214(b) To Clarify How To Determine Reasonable Application Fees</HD>
                    <P>One commenter questioned what a reasonable application fee is, what can be used to calculate a reasonable application fee. In terms of reasonable application fees, the commenter provided HUD the example that in their State's LIHTC Program, the owner can only charge the actual costs of processing an application credit/criminal background and cannot inflate application fees.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the commenter's question concerning reasonable application fees. The Department is declining to define the amount of a reasonable application fee, as commercially reasonable application fees may vary based on the project's location, sources of financing, and the type of background examination selected by the owner.
                    </P>
                    <HD SOURCE="HD2">§§ 92.216 and 92.217—Income Targeting in HOME Rental Housing, Tenant-Based Rental Assistance, and Homeownership Programs</HD>
                    <HD SOURCE="HD3">A. Align Income Limits Across HOME and NAHASDA Programs</HD>
                    <P>
                        One commenter requested that HUD align the definition of area median income for the HOME program with the definition contained in the Native American Housing Assistance and Self-Determination Act (NAHASDA) to facilitate leveraging NAHASDA funds with HOME funds and Tribes' use of HOME funds, and to reduce burden caused by two different methodologies for income for projects that utilize both NAHASDA and HOME funds. The commenter stated that HUD's interpretation seems to be that the median income of an Indian Area is the NAHASDA definition, and that this should be implemented for instances where HOME funding is used in an Indian Area. In support, the commenter referenced section 214 of the Cranston-Gonzalez National Affordable Housing Act (NAHA) (42 U.S.C. 12744); statutory language in NAHASDA at 25 U.S.C. 4103(14), and the definition of “median income” in paragraph (15); the definition of “Indian area” in NAHASDA,; the definition of “median income for an Indian area” in HUD's Indian Housing Block Grant (IHBG) regulations that implement NAHASDA; published guidance containing median incomes for Indian Areas; 
                        <SU>47</SU>
                        <FTREF/>
                         published IHBG area income limits; and the U.S. Department of Treasury's definition of area median income for the Emergency Rental Assistance Program.
                        <SU>48</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>47</SU>
                             
                            <E T="03">E.g., https://www.hud.gov/sites/dfiles/PIH/documents/2022-01_Income_Limits.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>48</SU>
                             
                            <E T="03">E.g., https://www.huduser.gov/portal/datasets/il.html#2022.</E>
                        </P>
                    </FTNT>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for their recommendation that HUD align area median income for the HOME program with the NAHASDA. NAHA and NAHASDA define low-income families differently. NAHASDA permits HUD to establish an income floor for low-income families for NAHASDA programs nationwide that is the greater of 80 percent of the median income for the United States or 80 percent of the median income of the Indian area.
                        <SU>49</SU>
                        <FTREF/>
                         In the definition of low-income families, NAHA permits the Secretary to establish income ceilings higher or lower than 80 percent of the median for the area on the basis of the Secretary's finding that such variations are necessary in accordance with 42 U.S.C. 12704(10).
                        <SU>50</SU>
                        <FTREF/>
                         This revision requires that HUD reexamine its methodology for calculating income limits for the HOME program and make findings based on variations relating to the prevailing levels of construction costs, unusually high or low family incomes. The Department would then propose a different methodology and solicit public input. HUD did not propose to change the definition of low-income families or the way that area median income is calculated in the HOME program in the proposed rule. The Department also did not propose to establish a national income floor for HOME program as part of the proposed rule. The Department believes that such significant changes require notice and 
                        <PRTPAGE P="802"/>
                        comment and will not make this change in the final rule.
                    </P>
                    <FTNT>
                        <P>
                            <SU>49</SU>
                             25 U.S.C. 4103(15) states: “MEDIAN INCOME- The term `median income' means, with respect to an area that is an Indian area, the greater of—(A) the median income for the Indian area, which the Secretary shall determine; or (B) the median income for the United States.” 
                        </P>
                        <P>25 U.S.C. 4103(14) defines low-income families as follows: “LOW-INCOME FAMILY—The term 'low-income family' means a family whose income does not exceed 80 percent of the median income for the area, as determined by the Secretary with adjustments for smaller and larger families, except that the Secretary may, for purposes of this paragraph, establish income ceilings higher or lower than 80 percent of the median for the area on the basis of the findings of the Secretary or the agency that such variations are necessary because of prevailing levels of construction costs or unusually high or low family incomes.”</P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>50</SU>
                             42 U.S.C. 12704(10) states that: “The term “low-income families” means families whose incomes do not exceed 80 percent of the median income for the area, as determined by the Secretary with adjustments for smaller and larger families, except that the Secretary may establish income ceilings higher or lower than 80 percent of the median for the area on the basis of the Secretary's findings that such variations are necessary because of prevailing levels of construction costs or fair market rents, or unusually high or low family incomes.”
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">B. Create a National Income Limit Floor</HD>
                    <P>One commenter recommended that HUD address the failures of its income limit calculations in the HOME program and beyond, noting that “state floors” meant to prevent the effects of concentrated poverty do not work in places with severely depressed economies and high levels of poverty. The commenter stated that families in such places are not able to qualify for assistance under HUD programs despite very low incomes with respect to cost of living because the median family income limits in their communities are so low. The commenter said they are pursuing a legislative change to create a “national floor” and that a HUD January 2024 Notice proposing the idea of a “national minimum income limit” shows that HUD could immediately implement changes to address this existing inequality.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for their recommendation to address the effects of HUD's methodology for calculating the income limits used for determining eligibility for HUD programs, and particularly the HOME program, on individuals and families living in places with severely depressed economies and high levels of poverty. The HOME income limits are calculated using the same methodology that HUD uses for calculating the income limits for the Section 8 program, in accordance with section 3(b)(2) of the U.S. Housing Act of 1937, as amended. These limits are based on HUD estimates of median family income, with adjustments based on family size using the American Community Survey (ACS) and other sources. Every year, HUD publishes the annual income limits, which are used primarily to determine the income eligibility of applicants for the HOME program. In addition to being used to determine eligibility for Federal rental housing programs, income limits are also used to determine the maximum rents allowed for HOME projects.
                    </P>
                    <P>
                        HUD acknowledges the commenters' concerns that HUD's methodology for calculating income limits used by the HOME Program should be reexamined. In a January 10, 2024, 
                        <E T="04">Federal Register</E>
                         Notice (see FR-6436-N-01), HUD first announced a change in the methodology for determining the cap on how much income limits can go up in a single year in any individual Fair Market Rent (FMR) area. Since FY2010 HUD has limited all annual income limit decreases to five percent and all annual increases to the greater of five percent or twice the change in the national area median incomes. For FY-2024, HUD added an absolute cap of 10 percent and clarified that the national median family income is the change in uninflated ACS estimates. HUD made this change for three reasons: to protect tenants from facing a large single-year rent increase resulting from higher income limits, to address statistical errors resulting in fair market rent areas that do not have a large sample size, and to create stable and predictable income limits. However, HUD will not revise how the HOME income limits are calculated with this final rule, as the change is too significant to make without HUD first proposing a different methodology and soliciting public input.
                    </P>
                    <HD SOURCE="HD2">§ 92.221—Match Credit</HD>
                    <P>A commenter requested that HUD clarify that the requirements in § 92.221(b) would be applicable only to carryover amounts going forward from the applicable date of the adoption of the rule otherwise participating jurisdictions would have to have records beyond the current recordkeeping period of documentation.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department will prospectively require compliance with the revised requirements in § 92.221(b), which explicitly requires a participating jurisdiction to have documentation supporting the source, eligibility, and value of match contributions that have been carried over from previous years at the time that they apply the contribution toward their match obligation. However, HUD notes that participating jurisdictions are already responsible for complying with the § 92.508(a)(2)(ix), which requires records related to carryover match. HUD is adopting the proposed rule language without change.
                    </P>
                    <HD SOURCE="HD2">§ 92.250—Maximum Per-Unit Subsidy</HD>
                    <HD SOURCE="HD3">A. Support for Increasing HOME Maximum Per Unit Subsidy Limit</HD>
                    <P>Several commenters supported the increase of HOME subsidy limits. Two commenters stated that HOME subsidy limits should be increased because of the increase in the cost of labor and materials.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the commenters' review of the proposed rule and notes that the policy HUD is establishing through a separate 
                        <E T="04">Federal Register</E>
                         publication increases the maximum per unit subsidy limits from the current levels.
                    </P>
                    <HD SOURCE="HD3">B. General Support for Revising § 92.250(a) To Establish HOME Maximum Subsidy Limits in Accordance With Section 212(e) of NAHA</HD>
                    <P>
                        Generally, commenters stated that they support the proposal of establishing the HOME maximum subsidy limits in accordance with section 212(e) of NAHA. Several commenters stated support for HUD's clarification that the statutory limit in Section 212(e) of NAHA is a floor and not a cap of the subsidy amount, and for revising § 92.250 so that the section refers to the statutory requirements in order to avoid the need to waive or change the HOME regulations to align with section 212(e) in the future. Two commenters supported HUD's proposal to publish the methodology for determining the new maximum per-unit subsidy limits through a future notice published in the 
                        <E T="04">Federal Register</E>
                         and on HUD's website, with the opportunity for public comment. Another commenter recommended HUD seek feedback through a notice and comment period before finalizing a new methodology to ensure it meets the diverse needs of stakeholders.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the commenters' feedback and is moving forward with the changes as proposed.
                    </P>
                    <HD SOURCE="HD3">C. Support for Using Section 234 Limits on an Interim Basis</HD>
                    <P>
                        Several commenters supported HUD's proposal to adopt the Section 234 limits and increase the housing cost percentage from 240 percent to 270 percent in the maximum per-unit subsidy methodology. One commenter said this would permit more flexibility for the commenter's members and other stakeholders looking to maximize their usability of HOME funds ahead of HUD's release of the proposed methodology. One commenter said the resulting increase will be essential for communities where land and building costs are exceptionally high, and that the additional financing might also make the creation of smaller-scale properties unable to obtain LIHTC financially feasible. Another commenter stated that until a new methodology is finalized, HUD should establish the maximum per-unit subsidy limit as 270 percent of the section 234 limitations, educate stakeholders, and consider waivers or high-cost percentage exceptions. Another commenter noted its appreciation that HUD increased the Section 234 limitations to 270 percent while it designs new limits as this will allow more flexibility and affordable 
                        <PRTPAGE P="803"/>
                        homeownership stakeholders who seek to maximize their useability of HOME funds ahead of HUD's release of the proposed methodology. Another commenter stated that changes to the per-unit subsidy limits methodology would affect many other aspects of the proposed rule and urged HUD to issue the notice that will revise the methodology as soon as possible and in the interim to use the Section 234 elevator condominium mortgage limits as the base but lift the cap for high-cost areas to 270 percent. One commenter advocated for an increase in the subsidy limit to 300 percent to accommodate land and construction costs.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the commenters' review of the proposed rule and agrees that increasing the maximum per unit subsidy limits to 270 percent of the Section 234 elevator condominium mortgage limits will help communities where land and building costs are exceptionally high and may also make the creation of smaller-scale properties that are unable to obtain LIHTC financially feasible. The Department believes increasing the limits to 300 percent is currently unnecessary because few HOME-assisted units receive HOME subsidies close to the limits. However, HUD notes that this final rule will permit HUD to reconsider the limits based upon changing circumstances.
                    </P>
                    <HD SOURCE="HD3">D. Specific Considerations in Per-Unit Methodology</HD>
                    <P>Several commenters also recommended that in developing its new methodology HUD consider the specific cost implications of rehabilitation, rural communities, single family housing and multifamily properties, fluctuating construction costs, as well as operating costs, property insurance costs, income limits, administrative costs, and impacts to a developer's revenue stream.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the comments and, as allowed by the Act, may consider appropriate variables such as the cost of land and construction, market area, number of bedrooms, eligible activity type (
                        <E T="03">e.g.,</E>
                         homeownership, rental), and work performed (
                        <E T="03">e.g.,</E>
                         rehabilitation, new construction) when developing a future methodology for maximum per unit subsidy limits.
                        <SU>51</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>51</SU>
                             See 42 U.S.C. 12742(e)(1).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">E. Opposition to Using Maximum Per-Unit Subsidy in Effect at Underwriting</HD>
                    <P>One commenter opposed the proposed change that the HOME subsidy limit must be determined at the time of underwriting and recommended that the HOME subsidy limit be determined at the time of project completion. The commenter stated that their recommended approach is appropriate because: (1) the HOME subsidy limits are published once a year, giving the participating jurisdiction plenty of time to adjust subsidy layering, if needed; (2) projects may take more than a year to complete and, with inflation, the HOME subsidy limits can significantly increase, allowing participating jurisdictions more HOME funds to complete the substantial renovations; and (3) while the maximum per-unit HOME subsidy limit is often not reached, it is the times when a particularly substandard home is renovated that more HOME funds being available allows participating jurisdictions to make the necessary substantial repairs.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department did not propose a change with respect to the maximum per-unit subsidy limit applicable to a project. The proposed language is a clarification. Because a HOME participating jurisdiction is required to perform a subsidy layering analysis before committing HOME funds to a project, the maximum per-unit subsidy limit in effect at this time is the appropriate limit to apply to the project. The Department does not agree that the HOME subsidy limit should be determined at the time of project completion and will adopt this language as proposed.
                    </P>
                    <HD SOURCE="HD3">F. Exceeding the Maximum Per-Unit Subsidy To Meet Green Building Standards in § 92.250(c)</HD>
                    <P>Commenters overwhelmingly supported HUD's proposal to permit participating jurisdictions to provide additional subsidy in excess of the maximum per-unit subsidy limits at §  92.250(a) for HOME projects that meet a green building standard. Several commenters indicated that the increased subsidy could help to defer upfront costs and assist with meeting their sustainability and housing goals, and they encouraged HUD to include mitigation and resilience improvements in the permissible standards. However, commenters also reminded HUD to consider that the application of green building standards is different for rehabilitation and new construction projects. One commenter noted that due to project construction timelines, any new green building requirements should be applicable based on date of commitment of HOME funds rather than grant year.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks commenters for their support of HUD's proposal to permit participating jurisdictions to provide additional subsidy in excess of the maximum per-unit subsidy limits at § 92.250(a) to HOME rehabilitation and new construction projects that meet a green building standard. HUD is moving forward the change and in response to comments has increased the amount by which the maximum per-unit subsidy described in § 92.250(a) may be exceeded to ten percent for a project that meets one of the acceptable green building standards enumerated by the Department. HUD agrees with the commenter that stated that the green building requirements are applicable based on the date HOME program funds are committed to a project.
                    </P>
                    <HD SOURCE="HD3">G. Opposition to Mandatory Green Building Requirements</HD>
                    <P>Commenters opposed any mandatory green building requirements as a condition of receiving HOME funds. These commenters stated that green building standards should be voluntary given reductions in HOME appropriations and increased costs of construction over time. One of these commenters also suggested that requiring green building could result in fewer HOME units produced and decreased interest from contractors and developers in participating in the HOME program.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters and clarifies that it did not propose to require green building requirements under § 92.251 property standards requirements but instead is proposing to incentivize building to industry-recognized green building standards through the use of an increased maximum per-unit subsidy.
                    </P>
                    <HD SOURCE="HD3">H. Additional Green Building Incentives and Considerations</HD>
                    <P>
                        Commenters offered additional policy suggestions and shared concerns for HUD's consideration. One commenter recommended that the rule allow participating jurisdictions to exempt the amount of HOME funds spent on green and resilient building measures from the calculation of the total HOME subsidy for the purpose of determining the minimum HOME period of affordability in accordance with §  92.252(e). Two other commenters stated that HUD should consider Build America, Buy America (BABA) requirements in determining any increases in maximum per-unit subsidy related to green building standards because BABA may result in increased costs from sourcing green building materials.
                        <PRTPAGE P="804"/>
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing the proposed rule. As described elsewhere in the preamble, HUD is adjusting the periods of affordability to reflect increased costs over the last three decades and other requirements that may increase compliance costs for owners. For new construction of rental housing, the incremental cost of meeting green building standards will have no effect on the period of affordability, as HUD has retained the 20-year period of affordability. The Department does not have statutory authority to disregard the costs related to green building from the determination of per-unit subsidy and declines to adopt the change.
                    </P>
                    <P>HUD notes that BABA is beyond the scope of this rulemaking. Until additional guidance is provided about how BABA will apply to HOME and other HUD programs, HUD cannot determine the effect of BABA compliance on the green building incentive or overall compliance with the HOME final rule.</P>
                    <P>
                        <E T="03">Specific solicitation of comment #2: The Department specifically requests public comment from participating jurisdictions, developers, and other affected members of the public about the green building standards that the Department should establish in the</E>
                          
                        <E T="7462">Federal Register</E>
                        . 
                        <E T="03">In addition, the Department seeks public comment about stakeholder experiences regarding the percentage increase in the cost of constructing or rehabilitating affordable housing to a green building standard and whether a 5 percent increase in the maximum per unit subsidy limit is sufficient. Finally, the Department requests public comment on whether permitting participating jurisdictions to exceed the maximum per unit subsidy limit by an amount in excess of the additional costs of green building measures (i.e., to provide additional HOME funds to cover a larger portion of other HOME-eligible development costs),would create a sufficient incentive to developers and owners to meet green building standards in projects that would otherwise not be designed to meet those standards.</E>
                    </P>
                    <HD SOURCE="HD3">A. Requiring a Specific List of Qualifying Green Building Standards</HD>
                    <P>Commenters were divided over whether HUD should specify green and resilient building standards and which standards HUD should permit. Several commenters suggested that HUD should allow participating jurisdictions a range of choices by prescribing a wide variety of qualifying standards to account for differences in the availability of resources, costs of certification, and unique State and local needs based on population and geographic location. Alternatively, two commenters recommended against a HUD-prescribed list and instead suggested that HUD establish a broad definition of green and energy efficient measures that would qualify as a green building standard to allow for maximum flexibility. Furthermore, commenters recommended that HUD allow the increased HOME subsidy if the project meets State and local green standards and requirements. One commenter stated that HUD should review best practices that increase the feasibility of the developer to adhere to green standards while bringing down energy costs for the consumer.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks commenters for their views regarding whether HUD should establish a set list of green and resilient building standards to publish in the 
                        <E T="04">Federal Register</E>
                        . HUD has received numerous recommendations of green building certifications, standards, codes, and thresholds that commenters believe HUD should incentivize, each with differing technical components, building requirements, and effectiveness criteria. HUD will evaluate the standards suggested, publish a provisional 
                        <E T="04">Federal Register</E>
                         notice for effect, and solicit additional public comments.
                    </P>
                    <HD SOURCE="HD3">B. Use of Nationally Recognized Certifications To Align With Other Federal Programs</HD>
                    <P>Commenters that support a HUD-prescribed list recommended that HUD establish green and resilient building standards that are consistent with the national certifications required by other Federal or HUD-assisted programs to promote alignment, limit disruption or confusion, and ease administrative burden, given that these standards are well known by many participating jurisdictions and their developers. One commenter noted that these standards are included by States in their qualified allocation plans (QAPs) for low-income housing tax credits. Another commenter suggested that HUD collaborate with other Federal agencies such as the Department of Energy, Department of Health and Human Services, and the Environmental Protection Agency to create such a list or consider allowing the use of other agency's Green Building Standards. The specific Federal programs suggested for alignment by commenters include the following:</P>
                    <P>1. HUD's Green and Resilient Retrofit Program (GRRP), which permits DOE Zero Energy Ready Home; Zero Energy Ready Multifamily; National Green Building Standard—Silver, Gold, or Emerald; LEED V4.1; Enterprise Green Communities Plus, Greenpoint Gold or Platinum; Earthcraft Gold or Platinum; Passive House; International Living Institute; Well Building Standard; RELi; or FORTIFIED Silver or Gold.</P>
                    <P>2. The Environmental Protection Agency's Greenhouse Gas Reduction Fund program.</P>
                    <P>3. The Department of Energy's Section 45L Tax Credits for Zero Energy Ready Homes, which also includes Energy Star requirements.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks commenters for recommending a large number of green and resilient building standards for HUD's consideration. HUD agrees that green standards consistent with national certifications required by other Federal programs have the highest likelihood of reducing confusion and administrative burden. HUD will evaluate the standards suggested, issue a provisional 
                        <E T="04">Federal Register</E>
                         publication for effect, and solicit additional public comments.
                    </P>
                    <HD SOURCE="HD3">C. Green Building Standards Promoted by Commenters</HD>
                    <P>Irrespective of alignment with other HUD or Federal programs, commenters recommended that the following certifications, standards, codes, or thresholds be used to determine compliance for the purposes of increased HOME subsidy:</P>
                    <P>1. CALGreen (California Green Building Standards Code—Part 11, Title 24, California Code of Regulations).</P>
                    <P>2. GreenPoint Rated (GPR) Certified or 75+ points.</P>
                    <P>3. International Green Construction Code (IgCC), which the commenter indicates will allow for coordination with the statutory HOME energy efficiency requirements for new construction projects. A commenter also notes that Appendix M of the 2024 IgCC provides options for residential compliance with the National Green Building Standard (ICC 700) and Appendix K aligns IgCC requirements with core elements of versions 4.0 and 4.1 of the LEED rating system.</P>
                    <P>4. Home Energy Rating System (HERS) Index threshold specifically for homeownership projects, for example requiring a HERS rating of 50 or lower to qualify as meeting the green building standard.</P>
                    <P>5. Earth Advantage.</P>
                    <P>6. Energy Rating Index (ERI) thresholds, for example requiring that homes achieve an ERI of 60 or lower.</P>
                    <P>
                        7. ENERGY STAR, and specifically ENERGY STAR Multifamily New Construction National Program Requirements Version 1.1.
                        <PRTPAGE P="805"/>
                    </P>
                    <P>8. Enterprise Green Communities, and specifically Enterprise Green Communities Plus.</P>
                    <P>9. National Green Building Standard (NGBS Green).</P>
                    <P>10. Passive House.</P>
                    <P>11. US Green Building Council's LEED, and specifically LEED Silver (50+ points) or LEED Net Zero.</P>
                    <P>12. Zero Energy Ready Homes.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks commenters for recommending a large number of green and resilient building standards for HUD's consideration. Just as in the previous responses, HUD will evaluate the standards suggested, issue a provisional publication in the 
                        <E T="04">Federal Register</E>
                         for effect, and solicit additional public comments. The Department understands that the green building standards mentioned by commenters may not be currently required under or incentivized by Federal programs but that they should be considered, and HUD will perform the necessary examination of these standards before it issues its 
                        <E T="04">Federal Register</E>
                         publication.
                    </P>
                    <HD SOURCE="HD3">D. Support for Electrification</HD>
                    <P>Two commenters urged HUD to prioritize electrification as an essential measure for reducing greenhouse gas emissions and improving indoor air quality, and therefore, the health and safety of the occupants. Both commenters suggested that the HOME rule should require that new construction and substantial rehabilitation projects be all electric, and that HUD prevent the use of HOME funds in new fossil fuel connections. However, one commenter suggested that an exception may be necessary in cold weather climates to allow for fossil fuel backup sources.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for their recommendations on improving energy efficiency and resident health outcomes via the prioritization of electrification. However, these recommendations are not within the scope of this rulemaking. The Department will continue to assess ways to further incentivize green building in the HOME program.
                    </P>
                    <HD SOURCE="HD3">E. Five Percent Increase in Maximum Per-Unit Subsidy Is Insufficient</HD>
                    <P>Although several commenters support HUD's proposal to permit an increase in the maximum per unit subsidy by five percent for meeting a green building standard, the majority of commenters indicated that five percent is insufficient to cover the increased costs of constructing or rehabilitating affordable housing to a green standard including the costs associated with obtaining a certification. Two commenters asserted that the proposed five percent increase is insufficient even to cover the increased costs of meeting the HOME statutory energy efficiency requirements as updated by FR-6271-N-03. Meanwhile, other commenters indicated that they could not determine whether a five percent increase would cover increased costs of construction or provide any incentive for green building without knowing which standards would be required to access the benefit. One commenter recommended that HUD request funding to establish a competitive Green Building pilot program in conjunction with the HOME program to gather data on costs associated with various green building standards.</P>
                    <P>Several commenters also expressed concern that the proposed policy to permit an increase of the maximum per-unit subsidy would be ineffective at any level to incentivize green building because participating jurisdictions lack the additional HOME funds needed to provide the benefit. Specifically, commenters noted that HOME projects are often not awarded the full amount of the current maximum per unit subsidy, particularly homeownership projects. In addition, one commenter suggested that providing additional funding to HOME projects would be a more effective means of incentivizing owners to meet green building standards rather than allowing participating jurisdictions to exceed the maximum per-unit subsidy by five percent.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters and agrees that the proposed five percent increase in the maximum per-unit subsidy is insufficient to cover the costs associated with meeting nationally recognized green building standards. Subsequently, the Department is adopting a change in this final rule to increase the percentage in § 92.250(c) to 10 percent. The Department acknowledges that ascertaining whether this 10 percent increase sufficiently covers associated costs is difficult without having confirmed green and resilient building standards. Moving forward, HUD will complete an additional review and include standards in a provisional notice for effect with public comments. The Department will continue to reevaluate both green building standards and other methods of incentivizing green building for the HOME program.
                    </P>
                    <HD SOURCE="HD3">F. Increasing the Maximum Per-Unit Subsidy by 5 Percent Is Not Sufficient To Incentivize Meeting Stronger Green Building Standards</HD>
                    <P>Of the commenters who supported a 5 percent increase, several indicated that 5 percent would only be sufficient to cover the increased costs of meeting certain basic standards. These commenters indicated that 5 percent is not sufficient to cover the higher costs of more rigorous green and resilient building standards and that the 5 percent increase would not incentivize the type of wraparound measures necessary to achieve meaningful energy and cost savings. Commenters who suggested a greater increase in the maximum per unit subsidy limit proposed a wide variety of alternatives. Commenters stated that the appropriate amount would be closer to 10, 15, 20, or even 30 percent of the maximum per unit subsidy given the wide range of costs associated with different green building standards and the varying costs of acquiring certifications based on location. One commenter indicated that all residential buildings in California are required to meet CALGreen, so the additional costs of building to green standards are already reflected in the costs of residential construction in the State. However, this commenter also recommends allowing an increase of 20 percent in the maximum per unit subsidy, which in States like California where green building compliance is required, the additional HOME investment will help to mitigate the current high cost of construction and make assisted projects less reliant on other highly competitive funding sources. In addition, two commenters stated that an increase up to 30 percent would support green building by covering the increased upfront costs of supplies while lowering the rents required to be charged at the project.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing and agrees that the proposed five percent increase in the maximum per-unit subsidy is insufficient to cover the costs associated with meeting green building standards. The Department is adopting a change to increase the percentage in § 92.250(c) to 10 percent. The Department understands that many commenters recommended the maximum per-unit subsidy limits be increased by an even higher percentage. However, the Department must balance the benefits from more sustainable, energy-efficient housing against the potential that fewer units will be created or fewer families will be served. Given the level of annual appropriations that 
                        <PRTPAGE P="806"/>
                        the HOME program receives, the Department believes it can only move to 10 percent at this time but will reevaluate in the future.
                    </P>
                    <HD SOURCE="HD3">G. A Higher Maximum Per-Unit Subsidy Increase for Rehabilitation Projects</HD>
                    <P>One commenter noted that meeting green building standards for new construction is fundamentally different than for rehabilitation projects and the commenter estimated that an increase of 25 percent of subsidy would be required for rehabilitation projects to achieve a green building standard beyond the State energy code. However, the commenter expressed concerns with permitting a significant increase in maximum per unit subsidy due to the impact on production and instead suggested that HUD provide a 10 percent increase for rehabilitation projects in States with ambitious green building standards, as determined by HUD. The commenter stated that this proposal could increase the number of HOME-assisted rehabilitation projects in areas where green building standards are already required.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing and is adopting a change increasing the maximum per-unit subsidy limit percentage to 10 percent in § 92.250(c) for both new construction and rehabilitation projects that meet certain green building and resiliency standards. The Department understands that many commenters had requested increases that were significantly higher, particularly for rehabilitation projects. However, the Department must balance the benefits from more energy-efficient housing against the potential that fewer units will be created or fewer families will be served. Given the level of annual appropriations that the HOME program receives, the Department believes it can only move to 10 percent for both new construction and rehabilitation project at this time but will reevaluate in the future.
                    </P>
                    <HD SOURCE="HD3">H. Use of Actual Construction Costs Instead of Set Percentage Increases in Maximum Per-Unit Subsidy for Green Building</HD>
                    <P>Rather than permitting a specific percentage increase in the maximum per unit subsidy limits, several commenters supported permitting participating jurisdictions to exceed the limits by actual additional construction costs of green building measures for the project. One of these commenters suggested that the rule should permit project owners to apply for the amount above the maximum per unit subsidy needed for a rehabilitation project, and that the participating jurisdictions should provide the largest awards to proposed projects with the highest energy and cost savings potential, therefore prioritizing rehabilitation of the most inefficient housing. Other commenters recommended that the rule permit a participating jurisdiction to determine the percentage increase because needs and costs vary geographically.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for their recommendation that HUD adopt increases in the maximum per-unit subsidy limit based on either documented construction costs or at a participating jurisdiction's discretion, rather than adopting a set percentage increase. The Department declines to adopt these recommendations, as measuring, documenting, and implementing these methods would be unduly burdensome and complex for all parties involved.
                    </P>
                    <HD SOURCE="HD3">I. Using a Tiered Approach to Maximum Per-Unit Subsidy Increases for Different Types of Green Building Standards</HD>
                    <P>Many commenters also suggested that HUD implement a tiered approach to providing an increased HOME subsidy to account for the varying nationally recognized standards, with more aggressive standards equating to larger incentives based on the relative level of value-added above-code efficiency in terms of both energy savings and energy cost savings and resilience in the project. One commenter remarked that increased subsidy levels designed to cover the higher costs of advanced standards would be a sufficient incentive in projects that would not otherwise have been designed to meet green building standards. However, the commenter also noted that there is not always an additional cost to meet green building standards, particularly for standard level green certifications and that the cost differential is likely to diminish over time as developers become more familiar with green building standards, so an increased HOME subsidy will eventually become a true incentive to build greener housing.</P>
                    <P>Two commenters suggested that a tiered approach be tied to Energy Rating Index (ERI) thresholds with the largest subsidy available for net zero design and/or the installation of solar in assisted projects. Other commenters suggested that HUD allow a lower increase, from 2 to 5 percent for base green building certifications such as ENERGY STAR and a 10 percent increase for buildings that achieve higher certifications consistent with the recent National Definition of a Zero Emissions Building, such as Enterprise Green Communities Plus, the forthcoming LEED Zero Carbon, ENERGY STAR NextGen, and/or the Department of Energy's Zero Energy Ready Homes combined with specific required criteria or additional requirements to make them zero emissions. Another commenter suggested that to create an incentive, HUD should implement a range of increased subsidy rather than a set percentage using a formula based on criteria such as disparities between State code and HUD requirements, the extent of green building rating systems and any subsidies offered at the State or local level. The commenter recommended that the further “behind” a State is in adopting the most recent International Energy and Conservation Code (IECC) and American Society of Heating, Refrigerating and Air-Conditioning Engineers (ASHRAE) codes, the higher the base subsidy should be. A different commenter stated that HUD should implement an “up to or higher” standard, which could be provided through a waiver process based on taking into account the type of activity and technology deployed.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for the recommendations. However, HUD believes that establishing a tiered approach or ranges based on the green building standards individual participating jurisdictions use would be extremely complicated and potentially unworkable. HUD is declining to adopt these recommendations at this time but will continue to assess ways to pay for the increased costs of developing affordable housing that meets higher standards for green building, climate resiliency, and a greater level of energy efficiency and may revisit this issue in a future rulemaking.
                    </P>
                    <HD SOURCE="HD3">J. Opposition to Five Percent Increase in Maximum Per Unit Subsidy Because of Uneven Application and Reduction of Overall Units Produced</HD>
                    <P>
                        Commenters anticipated that homeownership projects would be the most affected by cost increases related to energy efficiency requirements and green building standards. Commenters agreed that large multifamily rental development projects are the most likely to benefit from any permitted increase in maximum per unit subsidy. However, a commenter stated that data they analyzed showed that the amount of HOME funds awarded even to rental projects depends largely on the participating jurisdiction's policies rather than on local conditions (
                        <E T="03">e.g.,</E>
                         high cost areas), and therefore it is not 
                        <PRTPAGE P="807"/>
                        clear that participating jurisdictions will provide additional HOME funds based on the increased costs of meeting a green building standard. Consequently, this commenter does not support HUD's proposal because they believe it would have an uneven impact nationally, with most of the country unable to take advantage of the flexibility. In addition, the commenter worried that HUD's proposal will result in a decrease in the number of assisted projects and limit unit production. However, in anticipation of this challenge, two other commenters suggested that HUD provide guidance and tools on how to leverage other funding sources and maximize available HOME funds to allow for more comprehensive energy efficiency projects while maintaining unit production.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the comments. HUD notes that HOME is a block grant program with local choice and flexibility at its core. Consequently, the Department does not believe that because not all participating jurisdictions will exercise this or any other flexibility in the regulations is a sound reason for not offering the flexibility at all. HUD does not expect that all participating jurisdictions will choose or need to take advantage of the increase in the subsidy limit. HUD takes seriously the need to balance the benefits from more resilient and energy-efficient housing with the added costs and marginal reduction in the total number of HOME-assisted unit. Because the regulation does not require the use of green building standard and instead makes it more feasible to pursue this housing that meets the standards, HUD is devolving the choice to State and local government based upon their priorities. The Department is moving forward with the 10 percent increase and will continue to reevaluate green building standards, other methods of incentivizing green building, and the prospect of requested technical assistance once green standards are implemented for the HOME program.
                    </P>
                    <HD SOURCE="HD3">K. Incentivizing Universal Design With Increases in the Maximum Per-Unit Subsidy</HD>
                    <P>One commenter suggested that in addition to increasing Green Building standards, HUD should consider how the HOME program can incentivize or require increased disability-related accessibility standards. For example, the commenter suggested that the HOME program could adopt the Universal Design criteria which is currently in the HUD Section 811 Capital Advance application.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the comment and urges HOME program participants to create projects with Universal Design in units and common areas, enhanced accessibility features, and more than the minimum number of units that meet Federal accessibility requirements for persons with disabilities. However, the commenter's proposal is outside the scope of this regulation as HUD has not solicited public comment on suitable standards for a regulatory provision or the incremental cost of compliance with them. Individual projects that require HOME investment exceeding the maximum per unit subsidy limits due to the cost of incorporating universal design elements may seek case-specific relief from HUD.
                    </P>
                    <HD SOURCE="HD2">§ 92.251—Property Standards and Inspections</HD>
                    <HD SOURCE="HD3">A. General Support for Changes</HD>
                    <P>One commenter provided general support for all the changes to HOME property standards to include energy efficiency, carbon monoxide detectors, incorporate green building standards and include NSPIRE changes.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for reviewing the proposed rule and for their support.
                    </P>
                    <HD SOURCE="HD3">B. Statutory Energy Efficiency Requirements in § 92.251(a)—Support</HD>
                    <P>Commenters supported the proposal to codify the statutory HOME energy efficiency requirements in the HOME regulations. One commenter recommended HUD update the reference from section 109 of NAHA to HUD's recent minimum energy standards determination (FR-6271-N-03) to streamline requirements across programs and minimize confusion about the requirements.</P>
                    <P>A commenter agreed with HUD's proposal that the rule should be clear that the ASHRAE Standard 90.1-2019 (for high-rise multifamily) and the 2021 Energy Conservation Code (for single-family and low-rise multifamily) apply to all new construction under HOME, including alternative compliance pathways such as specified green building certifications and future HUD-developed standards. The commenter recommended that HUD go further and apply the standards to major rehabilitations under HOME, arguing that rehabilitated homes can and should meet the same standards as new construction. Additionally, the commenter said that HUD should consider setting higher minimum standards for HOME new construction and major rehabilitation that require certifications consistent with the Department of Energy's National Definition of a Zero Emissions Building.</P>
                    <P>One commenter noted that low-income households are more likely to experience higher utility costs, and that energy efficiency means residents do not need to choose between paying utilities, rent, or putting food on the table and responds to climate instability. The commenter noted the importance of energy standards being codified in accordance with section 109 of NAHA, including any revisions adopted by HUD and USDA and encouraged the use of HUD funding to implement these requirements.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for their review and is adopting the proposed change codifying the statutory requirement that all HOME-assisted rental and homebuyer new construction projects meet the energy efficiency standards promulgated by HUD in accordance with section 109 of NAHA, including any revisions adopted by HUD and the U.S Department of Agriculture (USDA). To maintain consistency in regulations and energy efficiency requirements as standards are updated over time, the Department declines to update the reference from section 109 of NAHA to the recent minimum energy standards determination (FR-6271-N-03). The Department also declines to apply these standards to rehabilitation projects, or to apply new, higher minimum standards to new construction or rehabilitation projects under the HOME program. The priority of this final rule is to maintain consistency and advance alignment across programs, meaning that the HOME program has the same energy efficiency standards as the rest of the Department. The Department will continue to assess ways to further produce efficient, healthy, and resilient affordable homes, and may revisit this issue in a future rulemaking.
                    </P>
                    <HD SOURCE="HD3">C. HUD Should Engage in Monitoring of Energy Efficiency Requirements in § 92.251(a)</HD>
                    <P>One commenter stated that the energy efficiency standards would require monitoring to ensure that HUD's energy efficiency goals are being met. The commenter stated that HUD could ensure the goals are met by tracking developer use of inspections and assessments. The commenter stated that HUD could require these assessments since the proposed rule allows for reimbursements of environmental assessments.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks commenters for their recommendation that HUD require 
                        <PRTPAGE P="808"/>
                        tracking developer use of inspections and assessments to ensure that energy efficiency goals are being met. Requirements at § 92.504 state that participating jurisdictions must have and follow, among other things, a system for monitoring entities to ensure that HOME program requirements for HOME-assisted units set forth in 24 CFR part 92 are met throughout the specified period of affordability. As the energy efficiency standards under § 92.251 fall under that umbrella and are subject to monitoring, the Department declines to adopt this recommendation that more stringent or developer-specific monitoring requirements be put into effect.
                    </P>
                    <HD SOURCE="HD3">D. HUD's Energy Efficiency Standards Should Prohibit New Fossil Fuel Connections</HD>
                    <P>One commenter stated that HUD's proposal to have projects meet high energy efficiency standards was beneficial but could go further by further eliminating new fossil fuel hookups.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         In a separate rulemaking, HUD has developed energy efficiency standards in order to comply with 42 U.S.C. 12709. Revising those energy efficiency standards to prohibit new fossil fuel connections is beyond the scope of this rulemaking.
                    </P>
                    <HD SOURCE="HD3">E. Allowing the Use of NSPIRE Inspections To Determine Compliance With HOME Property Standards in § 92.251(a), (b), and (f)—Support</HD>
                    <P>Multiple commenters stated that they support the proposed alignment in the HOME program of permitting the use of inspections from other programs or sources.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters. HUD is moving forward with its proposal to accept inspections performed under other HUD programs.
                    </P>
                    <HD SOURCE="HD3">F. Allowing the Use of NSPIRE Inspections To Determine Compliance With HOME Property Standards in § 92.251(a), (b), and (f)—Concern About Current Properties</HD>
                    <P>Commenters stated that HUD should clarify the specifics of the applicability of NSPIRE to various HOME-eligible activities. One of these commenters noted that it is unclear how NSPIRE applies differently among homebuyer activity, homeowner rehabilitation activity, rental new construction activity and rental rehabilitation activity. The commenter requested that the final rule address the as-applied differences between these activities. One commenter cautioned that applying new physical condition standards such as the NSPIRE program to old properties is problematic because they were built under very different code and standard requirements.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD recognizes the commenter's concerns. Under § 92.251(f)(2), if a participating jurisdiction is monitoring a project that received a HOME commitment before January 24, 2015, then the participating jurisdiction is required to monitor that project under the applicable State or local housing quality standards or code requirements, and if there are no such standard or code requirements, the housing must meet the housing quality standards in 24 CFR 982.401. For projects with commitments after January 24, 2015, they must meet all applicable State or local code requirements and ordinances and in the absence of existing applicable State or local code requirements and ordinances, at a minimum, the participating jurisdiction's ongoing property standards must provide that the property does not contain the specific deficiencies established by HUD based on the applicable standards in 24 CFR 5.703 and published in the 
                        <E T="04">Federal Register</E>
                         for HOME rental housing (including manufactured housing) and housing occupied by tenants receiving HOME tenant-based rental assistance (see § 92.251(f)(1)(i)). 
                    </P>
                    <P>
                        Under the Effective Date section of the NSPIRE Final Rule, HUD clarified that “[p]articipants and owners subject to these regulations are subject to the Code of Federal Regulations as it exists on the publication date of this rule and are not subject to the regulatory changes being made by this rule on July 1, 2023, until October 1, 2023.” HUD has since delayed the compliance date for implementing NSPIRE inspection standards and requirements until October 1, 2025,
                        <SU>52</SU>
                        <FTREF/>
                         giving participating jurisdictions more time to update their property standards and owners more time to bring their properties into compliance with the new ongoing property standards. HUD will provide additional guidance and materials aimed at assisting participating jurisdictions and owners in complying with the requirements, including a streamlined list of minimum inspectable items that shall be a subset of the larger set of standards published in the NSPIRE Standards notice at 88 FR 40832.
                    </P>
                    <FTNT>
                        <P>
                            <SU>52</SU>
                             On September 2023, HUD delayed the compliance date for CPD programs (88 FR 63971) and for the HCV and PBV programs (88 FR 66882) until October 1, 2024, to allow PHAs, jurisdictions, participants, recipients, and HUD grantees additional time for implementation. On July 5, 2024, HUD further extended the compliance date for CPD programs and for the HCV and PBV programs until October 1, 2025 (89 FR 55645).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">G. Allowing the Use of NSPIRE Inspections To Determine Compliance With HOME Property Standards in § 92.251(a), (b), and (f)—Compliance Concerns</HD>
                    <P>While one commenter was supportive of the changes made to accept inspections under other HUD programs, they noted that the success of the policy will depend upon effective implementation and coordination among the various entities involved in the project and urged HUD to take steps to ensure that all entities involved are committing to inspection standards that prevent issues in units from going undetected for extended periods. In addition, one commenter requested that HUD clarify whether a participating jurisdiction must be a party to the contract for an inspector conducting the inspection in satisfaction of another funding source's requirements. Another commenter asked which entity is responsible for ensuring that inspections are conducted in compliance with HOME requirements and stated that they wished to avoid conflicts between states and local jurisdictions.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD acknowledges the commenter's concerns and believes that the final rule requirement that a participating jurisdiction perform an onsite inspection within 12 months after project completion coupled with the ongoing inspection requirements at § 92.251(f)(3)(i) address the commenter's concern. The participating jurisdiction will still be required to determine that HOME units meet the property standards at the completion of rehabilitation. Moreover, once every three years, either the participating jurisdiction will perform an onsite inspection of the units to determine if they meet the ongoing property standards (§ 92.251(f)(3)(i)(A)) or it may accept an inspection conducted on the HOME-assisted units within 12 months that met the NSPIRE requirements in 24 CFR part 5, subpart G or an alternative inspection standard, which HUD may establish through 
                        <E T="04">Federal Register</E>
                         publication (§ 92.251(f)(3)(i)(B)). To help ensure that all entities involved are meeting inspection standards, HUD will continue to develop training and tools aimed at ensuring compliance.
                    </P>
                    <P>
                        The participating jurisdiction is not required to be a party to the contract of an inspector that is inspecting on behalf of another program but may enter into contracts with inspectors to perform the on-site inspection of units under the HOME program. The Department is not 
                        <PRTPAGE P="809"/>
                        responsible for monitoring the entity that inspects the units under another funder's program but is simply provided the option of accepting the inspection results if it meets the requirements of the final rule in § 92.251.
                    </P>
                    <HD SOURCE="HD3">H. Allowing the Use of NSPIRE Inspections To Determine Compliance With HOME Property Standards in § 92.251(a), (b), and (f)—Equivalent Standards in Tax Credit Programs</HD>
                    <P>Two commenters stated that the proposal to allow a participating jurisdiction to “[a]ccept a determination made under another HUD program . . .” should be expanded to also include rental inspections made for tax credit programs. One of these commenters stated that tax credit programs, while not HUD programs, are by far the most frequent and prominent other funding source for affordable housing. The commenter requested that HUD revise the proposed language in § 92.251 to allow participating jurisdictions to accept inspections made by any other funding source when the other funding source's inspection requirements equal or exceed HUD's requirements. One commenter noted that the language of the proposed rule states that HUD may accept the determination of “another HUD program,” which could limit HUD's ability to accept the determination of programs outside of HUD that engage in similar determinations. The commenter stated they were especially confused because the informational portion of the comment session made it seem as though HUD “may accept the determination of another funder in accordance with [§ ]92.251 every three years thereafter.”</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks commenters for their recommendation that HUD revise the proposed language in § 92.251 to allow participating jurisdictions to accept inspections made by other funding sources when those other funding sources' requirements equal or exceed HUD's own requirements. This recommendation would allow participating jurisdictions to accept rental inspections for tax credit programs. The Department is moving forward with language allowing for participating jurisdictions to use an inspection performed under the requirements of NSPIRE (24 CFR part 5, subpart G) as evidence of compliance with the HUD housing standards required under § 92.251(b)(1)(viii), and is clarifying that inspections for tax credit programs such as LIHTC are acceptable so long as those inspections meet or exceed the NSPIRE standard in 24 CFR 5.703. The Department acknowledges that the language stating that HUD may accept the determinations made under “another HUD program” may be limiting when it comes to non-HUD programs that make similar determinations.
                    </P>
                    <HD SOURCE="HD3">I. Allowing the Use of NSPIRE Inspections To Determine Compliance With HOME Property Standards in § 92.251(f)—Accepting an Inspection Within 3 Months</HD>
                    <P>One commenter suggested that the flexibility of accepting physical inspections performed by other HUD programs using the Housing Quality Standards and NSPIRE standards for tenant-based rental assistance units should operate in a slightly different manner. The commenter recommended extending the timeframe for when the other inspection has occurred from 3 months to 12 months because requiring duplicative inspections annually can cause unnecessary delays in getting families housed.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department understands the commenter's concern but must balance the potential delay in receiving assistance with the requirement that a tenant receiving tenant-based rental assistance live in a unit that meets all applicable local or State codes and applicable housing quality standards. HUD believes 3 months is a reasonable period of time in which an inspection reflects the state of the property condition. Any inspections before that period may not accurately represent the condition of the property because too much time will have passed in which intervening events may have negatively impacted the property causing new deficiencies that must be corrected before the tenant could occupy the unit. HUD also retained the language in § 92.251(f)(4)(ii) of the proposed rule that stated that “[a] participating jurisdiction may move its inspection cycle to align with an inspection” made under another program. This will better enable the participating jurisdiction to reduce the frequency of inspections during the tenancy.
                    </P>
                    <HD SOURCE="HD3">J. Allowing the Use of NSPIRE Inspections To Determine Compliance With HOME Property Standards in § 92.251(a), (b), and (f)—Use of Housing Quality Standards (HQS) Under § 982.401</HD>
                    <P>One commenter stated that they support HUD's proposal to accept physical inspections performed by other HUD programs that were completed using Housing Quality Standards, or eventually, NSPIRE. Another commenter asked whether inspections conducted under NSPIRE replace inspections conducted under previous standards such as the Uniform Physical Condition Standards (UPCS) or Housing Quality Standards.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD wishes to clarify that it is not allowing the use of Housing Quality Standards inspections performed under 24 CFR 982.401 to be used to determine compliance through either § 92.251(b)(1)(viii)(A) (rehabilitation property standards) or § 92.251(f)(3)(i)(B) (ongoing property standards). HOME property standard regulations allow inspections conducted under 24 CFR part 5, subpart G. This provision does not contain Housing Quality Standards inspection requirements, it contains NSPIRE requirements. The Department did not propose to apply or allow the application of the Housing Quality Standards requirements contained in 24 CFR 982.401 beyond its current application to projects with commitments before 2015. Please see § 92.251(f)(2). The Department has determined that the use of NSPIRE standards will result in better housing quality and long-term viability of HOME-assisted units than Housing Quality Standards. In addition, through the Economic Growth Regulatory Relief and Consumer Protection Act: Implementation of National Standards for the Physical Inspection of Real Estate (NSPIRE) Final Rule published on May 11, 2023 (88 FR 30442), the Department replaced the Uniform Physical Condition Standards previously at 24 CFR 5.703 with NSPIRE. In accordance with the 
                        <E T="04">Federal Register</E>
                         Notice titled Economic Growth Regulatory Relief and Consumer Protection Act: Implementation of National Standards for the Physical Inspection of Real Estate (NSPIRE); Extension of NSPIRE Compliance Date for HCV, PBV and Section 8 Moderate Rehab and CPD Programs published on July 5, 2024 (89 FR 55645), HOME participating jurisdictions are not permitted to use UPCS inspection requirements to determine compliance through either § 92.251(b)(1)(viii)(A) (rehabilitation property standards) or § 92.251(f)(3)(i)(B) (ongoing property standards) for HOME-assisted projects with commitments on or after October 1, 2025. The use of NSPIRE as a unified inspection protocol will facilitate alignment inspections of HOME-assisted units with other housing programs.
                        <PRTPAGE P="810"/>
                    </P>
                    <HD SOURCE="HD3">K. Allowing the Use of NSPIRE Inspections To Determine Compliance With HOME Property Standards in § 92.251(b) and (f)—Use of NSPIRE Results During Rehabilitation and Ongoing Inspections</HD>
                    <P>One commenter supported HUD's proposal to provide administrative relief by better aligning HOME inspection standards with the standards of other funding sources. The commenter supported allowing participating jurisdictions to accept NSPIRE inspections conducted under another funding source, in lieu of the final completion inspections for rehabilitation projects as well as ongoing inspections of rental projects and housing occupied by tenant-based rental assistance tenants because it would reduce participating jurisdictions' administrative burden and reduce the impact on owners and tenants of having multiple project inspections due to layered Federal funding.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the commenter's review and is moving forward with language allowing for participating jurisdictions to use an inspection performed under the requirements of NSPIRE (24 CFR part 5, subpart G) as evidence of compliance with the HUD housing standards required under § 92.251(b)(1)(viii).
                    </P>
                    <HD SOURCE="HD3">L. Elimination of Initial, Progress, and Final Inspections in § 92.251(b)</HD>
                    <P>One commenter believed HUD's proposal allowed participating jurisdictions to accept NSPIRE inspections of rehabilitation projects performed for other funding sources instead of final and ongoing periodic inspections. The commenter also believed that this allowed the use of LIHTC inspections. The commenter stated that it recommends that HUD still provide participating jurisdictions the option of performing final and ongoing inspections to prevent delays in inspection.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for reviewing the proposed rule. However, the commenter misunderstands the inspection provision in the proposed rule. HUD did not propose to eliminate initial, progress and final inspections under § 92.251(b)(3). HUD proposed to allow the use of another HUD inspection conducted under 24 CFR part 5, subpart G to be evidence that the property met the requirements under § 92.251(b)(1)(viii) once construction was completed. The participating jurisdiction must still conduct initial and ongoing progress inspections, as HUD explained in the preamble to the proposed rule. 
                        <E T="03">See</E>
                         89 FR 46630.
                    </P>
                    <HD SOURCE="HD3">M. Inspection to Applicable Housing Codes in § 92.251(a), (b), and (f)</HD>
                    <P>One commenter stated that HUD should allow State participating jurisdictions to inspect all their HOME properties in accordance with either local codes or a national standard as determined by HUD and that if a State participating jurisdiction chooses to use the national uniform standard, participating jurisdictions should still require owners to certify that they meet local codes but should not be required to inspect the property in accordance with the local code.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Participating jurisdictions are required, by statute, to provide on-site inspections to determine compliance with housing codes and other applicable regulations. 
                        <E T="03">See</E>
                         42 U.S.C. 12756(b). HUD does not believe that is has the flexibility to require a national uniform property standard instead of applicable local and State housing codes because the requirement to perform on-site property inspections to those codes is statutory.
                    </P>
                    <HD SOURCE="HD3">N. Support for Adding Carbon Monoxide Detection Requirements to § 92.251(a), (b) and (f)—General Support</HD>
                    <P>Many commenters expressed general support for requiring the installation of carbon monoxide detectors in HOME projects. One commenter went further, stating that carbon monoxide alarms should also be accessible for people with hearing loss.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates commenters' support of the provisions. HUD will describe standards for carbon monoxide detection through a 
                        <E T="04">Federal Register</E>
                         publication, as described in § 92.251(a)(3)(vi)(A), (b)(1)(xi)(A), and (f)(1)(iv)(A).
                    </P>
                    <HD SOURCE="HD3">O. Adding Carbon Monoxide Detection Requirements to Paragraphs (a), (b), and (f)—Concerns</HD>
                    <P>Many commenters also conveyed concerns about imposing strict requirements for the installation of hard-wired carbon monoxide detectors. One commenter requested that the rule provide an exception be made for those housing units where a gas line or similar hazard is not present. Another commenter only supports requiring hard-wired alarms in HOME-funded new construction. One commenter supports a requirement for a 10-year battery-powered carbon monoxide detector in rehabilitation and homebuyer acquisition projects and in units occupied by tenants receiving HOME tenant based rental assistance. However, for homebuyer acquisition and tenant-based rental assistance projects, the commenter requested that the installation of a carbon monoxide detector be permitted as an eligible HOME cost. This commenter expressed concern that requiring a seller or landlord to pay for the cost of installation of carbon monoxide detectors may reduce the available housing stock for these types of activities. Furthermore, this commenter and another were not in favor of requiring a HOME-assisted homebuyer to pay these costs. Other commenters also requested that HUD make additional HOME funding available for the costs of installing carbon monoxide detectors.</P>
                    <P>Another commenter stated that they do not support the proposal because carbon monoxide detectors are already required by the International Housing Code, and they view any additional HOME requirements for carbon monoxide detectors as overreach.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD recognizes commenters' concerns regarding the installation costs of carbon monoxide alarms. Through final rule, HUD will be establishing carbon monoxide alarm requirements through a 
                        <E T="04">Federal Register</E>
                         publication. HUD believes installing carbon monoxide alarms is a reasonable cost for homeowners and owners of rehabilitated rental units. Finally, HUD is unable to make additional funds specifically available for the costs of installing carbon monoxide detectors but notes that installation of carbon monoxide alarms is an eligible use of HOME funds for new construction and rehabilitation projects.
                    </P>
                    <HD SOURCE="HD3">P. Carbon Monoxide Requirements in § 92.251(a), (b), and (f) Should Align With Other HUD Programs</HD>
                    <P>One commenter emphasized that any HOME requirements for carbon monoxide detectors should align with other HUD programs.</P>
                    <P>A different commenter noted that some State regulations require a smoke alarm in every unit room that also contain carbon monoxide detection. Consequently, the commenter suggests that the rule defer to applicable State and local laws for carbon monoxide detection standards.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         This final rule seeks to align HOME carbon monoxide requirements with those of the NSPIRE Final Rule and those contained in the U.S. Housing Act of 1937 (42 U.S.C. 1437), thereby promoting consistency with other HUD programs. HUD declines to defer to State and local codes due to the safety benefits of these carbon monoxide alarm requirements to 
                        <PRTPAGE P="811"/>
                        occupants of HOME-assisted housing and in the interest of aligning HOME requirements with other HUD programs.
                    </P>
                    <HD SOURCE="HD3">Q. Permitting Property Standards Compliance Six Months After Title Transfer in Homeownership Programs Under § 92.251(c)—Support</HD>
                    <P>Most commenters support the proposal to allow homebuyer acquisition projects to meet HOME property standards within six months after the assisted homebuyer purchases the unit because such a change would expand homebuyers' purchasing options and simplify the pre-purchase period. One commenter reasoned that this change would provide more choices for homebuyers and provide access to bank foreclosures, and that this change would prove advantageous for buyers because of risks for buyers to cover out-of-pocket repairs before closing. Furthermore, commenters noted that sellers would often not consider offers that included contingencies regarding property standards, which made HOME-assisted homebuyers less competitive in the private market. In addition, one commenter indicated that the proposal would align HOME with other funding sources before closing. Furthermore, commenters noted that sellers would often not consider offers that included contingencies regarding property standards, which made HOME-assisted homebuyers less competitive in the private market. In addition, one commenter indicated that the proposal would align HOME with other funding sources.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for their support. HUD is adopting the six-month deadline for a homebuyer to make necessary repairs so that their unit meets applicable property standards. However, HUD has also adopted language in the final rule permitting participating jurisdictions to provide the homebuyer a written extension of up to an additional six months to meet property standards. Participating jurisdictions that wish to exercise the authority to provide extensions, when necessary, must establish policies and procedures for reviewing and approving a homebuyer's request for an extension of the deadline.
                    </P>
                    <HD SOURCE="HD3">R. Permitting Property Standards Compliance Six Months After Title Transfer in Homeownership Programs Under § 92.251(c)—Need for Additional Time</HD>
                    <P>Several commenters suggested that the proposed six-month timeframe would be insufficient time for many homebuyers to complete the necessary rehabilitation. As reasons for this statement, one commenter cited supply chain issues, Build America, Buy America requirements, contractor availability, and green certifications requirements. Commenters proposed allowing longer periods, such as 9, 12, or 18 months after acquisition, to bring a property to standard. Allowing for reasonable extensions or phased rehabilitation plans based on property conditions and local market dynamics could alleviate some of the pressure on participating jurisdictions while maintaining housing quality standards.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD agrees with commenters' concerns about potential obstacles to homebuyers meeting the proposed six-month deadline and is revising the proposed language to allow participating jurisdictions when necessary to provide up to an additional six months for homebuyers to meet property standards. This revision allows participating jurisdictions to exercise their judgment regarding a homebuyer project's unique circumstances and local market conditions.
                    </P>
                    <HD SOURCE="HD3">S. Permitting Property Standards Compliance Six Months After Title Transfer in Homeownership Programs Under § 92.251(c)—Opposition</HD>
                    <P>One commenter stated that they do not support the proposed revision due to concerns around enforcement and the possibility that the participating jurisdiction may be required to foreclose on the property or allow the homeowner to live in substandard conditions. Another commenter supportive of the proposal expressed similar concerns about the difficulty of monitoring the six-month deadline to rehabilitate housing and meet homebuyer acquisition property standards. One commenter opposed the proposal, recommending instead that the requirement should align with a local jurisdiction's certificate of occupancy requirements. This commenter agreed with the previous commenter that it may not be practicable for a participating jurisdiction to enforce property inspection requirements on a homeowner after title transfer.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for reviewing the proposed rule. However, HUD believes that there are adequate safeguards in place to prevent homebuyers from occupying substandard properties. Participating jurisdictions are required to conduct inspections to ensure that homes purchased with HOME assistance comply with HOME property standards, in accordance with § 92.251(c)(3). In the case of projects under this delayed compliance date, the participating jurisdiction must confirm through onsite physical inspection that all required work has been completed to meet property standards. Regarding the concern related to inspecting units after title transfer, participating jurisdictions will be required to make such inspections a condition of the receipt of funds in the homebuyer written agreement. HUD recognizes that permitting homebuyers six months to meet property standards will require participating jurisdictions to adjust their policies and procedures but views this as a worthwhile change to expand the supply of homes that homebuyers may purchase with HOME funds. Regarding the risk that a homebuyer may be unable to afford the rehabilitation necessary to meet property standards, HUD emphasizes that participating jurisdictions must establish and use homebuyer underwriting standards and ensure that HOME funds are supporting sustainable homeownership opportunities, in accordance with § 92.254(f). If a homebuyer is unable to fund necessary repairs, the participating jurisdiction must either provide HOME or other funding for rehabilitation or decline to provide HOME funds to the homebuyer for the purchase.
                    </P>
                    <HD SOURCE="HD3">T. Permitting Property Standards Compliance Six Months After Title Transfer in Homeownership Programs Under § 92.251(c)—Defining How “Funds are Secured for Rehabilitation”</HD>
                    <P>Several commenters requested clarification of the proposed policy. Specifically, two commenters requested that HUD clarify what evidence a homebuyer must provide to demonstrate that “funds are secured for rehabilitation.” One of these commenters suggested that HUD consider a letter provided by a mortgage lender or a bank statement as evidence of sufficient funds.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         In accordance with § 92.254(f), participating jurisdictions must establish and use homebuyer underwriting guidelines that ensure homebuyers will have sufficient savings post-purchase or secured financing to complete rehabilitation necessary to meet HOME property standards. This final rule does not prescribe specific documentation that a homebuyer must provide to the participating jurisdiction, as this is for the participating jurisdiction to define in its policies and procedures. It is in the interest of participating jurisdictions to ensure that rehabilitation can and will be completed because the project will otherwise be determined to be ineligible for HOME funding.
                        <PRTPAGE P="812"/>
                    </P>
                    <HD SOURCE="HD3">U. Permitting Property Standards Compliance Six Months After Title Transfer in Homeownership Programs Under § 92.251(c)—Clarifying Consequences of Non-Compliance</HD>
                    <P>One commenter requested that the Department clarify in the regulation at § 92.251(c) the consequences of failure to meet the property standards requirements within six months after title transfer in a homeownership program.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         If the homeownership unit does not meet property standards within six months, the participating jurisdiction may extend the time period in which the property must meet the participating jurisdiction's property standards to 12 months (see § 92.251(c)(3)(ii)(D)). If the property still does not meet the participating jurisdiction's property standards after six months (if no extension is given) or 12 months (if an extension is given), then the housing does not meet the requirements of 24 CFR part 92 and the participating jurisdiction must repay the HOME investment. The corrective and remedial actions for failure to comply with HOME program requirements are outlined at § 92.551. HUD declines to make the suggested change to further clarify the consequences of failing to meet the property conditions because it is unnecessary.
                    </P>
                    <HD SOURCE="HD3">V. Permitting Property Standards Compliance Six Months After Title Transfer in Homeownership Programs Under § 92.251(c)—Guidance</HD>
                    <P>Two commenters requested HUD provide guidance on the inspections required to ensure that the housing met property standards after a HOME-assisted homebuyer purchases the unit and completes the required rehabilitation. One of these commenters requested that HUD provide a sample template inspection form for jurisdictions that operate downpayment assistance programs to standardize practices.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD is unable to provide a sample inspection form as part of this final rule. HUD encourages the commenter to review the provisions of this final rule and HOME program resources on the HUD Exchange. As part of the implementation of the NSPIRE Final Rule, HUD will provide additional guidance and materials aimed at assisting participating jurisdictions and owners to comply with the requirements, including a streamlined list of minimum inspectable items that shall be a subset of the larger set of standards published in the NSPIRE Standards notice at 88 FR 40832.
                    </P>
                    <HD SOURCE="HD3">W. Exempt Manufactured Homes From Construction and Safety Standards if They Meet HUD National Construction and Safety Standards for Manufactured Housing</HD>
                    <P>One commenter requested HUD provide for an exemption for HUD Code manufactured housing from all proposed requirements that deal with construction and safety standards. The commenter is concerned that HUD's proposal would impose new construction requirements on all housing structures utilized under the HOME program. For manufactured homes, the commenter believed this would result in conflicts with the Manufactured Home Construction and Safety Standards (the HUD Code) resulting in the inability to utilize manufactured housing for projects funded by the program. The goals of the new construction requirements may make sense for other forms of housing that are not subject to national construction standards administered by HUD. However, the commenter believed they are not necessary for manufactured homes, which as noted, already are subject to such standards.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department agrees with the commenter that construction of manufactured housing should meet the requirements contained in the HUD manufactured housing regulations. Under § 92.251(e), “Construction of all manufactured housing including manufactured housing that replaces an existing substandard unit under the definition of “reconstruction” must meet the Manufactured Home Construction and Safety Standards codified at 24 CFR part 3280 . . . .”
                    </P>
                    <HD SOURCE="HD3">X. Use the International Code Council/Modular Building Institute Standards for Off-Site Construction</HD>
                    <P>One commenter encouraged HUD to recognize the International Code Council/Modular Building Institute standards for off-site construction in order to facilitate their expanded use and encourage efficient design and construction that addresses housing affordability and availability, sustainability, workforce availability, and supply chain disruptions.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The HOME rule at § 92.251(e) requires that construction of all manufactured homes meet the Manufactured Home Construction and Safety Standards codified at 24 CFR part 3280 and additional requirements. Section 92.251(e) also requires that in HOME-funded rehabilitation of existing manufactured housing the foundation and anchoring must meet all applicable State and local codes, ordinances, and requirements or in the absence of local or State codes, the Model Manufactured Home Installation Standards at 24 CFR part 3285. Manufactured housing that is rehabilitated using HOME funds must meet the participating jurisdiction's rehabilitation standards requirements, as required in § 92.251(b). When building components are built off-site and then installed on the HOME project site as a form of new construction or reconstruction but not as a form of manufactured housing under the Manufactured Home Construction and Safety Standards, the new construction must meet the requirements in § 92.251(a).
                    </P>
                    <HD SOURCE="HD3">Y. Revise Financial Oversight Requirements in § 92.251(f)</HD>
                    <P>One commenter is not supportive of the financial oversight requirements applying to rental projects with 10 or more HOME-assisted units. While the commenter understands that it can always adopt more restrictive requirements, the reality is that financial oversight is an invaluable tool in understanding how properties are performing, as well as early indications of financial distress and/or properties having surplus beyond what was originally underwritten. The commenter uses financial oversight during annual rent increase requests to verify it is reasonable for HOME-funded projects which more than likely have a blend of LIHTC, HOME, Housing Trust Fund (HTF), and/or local resources.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD is noting that it has not changed the financial oversight provisions in § 92.504(d)(2). In the proposed rule, HUD reorganized the HOME regulations and moved those requirements to § 92.251(f). HUD understands that many participating jurisdictions may wish to exert greater financial oversight on HOME-assisted projects in their portfolio and encourages participating jurisdictions to determine and implement the best approach for their jurisdictions. At this time, the Department is not reducing the 10-unit threshold for when a participating jurisdiction is required to conduct financial oversight under § 92.251(f). HUD believes this is inconsistent with its efforts to provide monitoring flexibilities to small-scale housing projects and that it is best left to the participating jurisdiction to determine how to monitor projects with fewer than 10 units.
                        <PRTPAGE P="813"/>
                    </P>
                    <HD SOURCE="HD3">Z. Energy Efficiency Considerations for Manufactured Homes and Off-Site Construction</HD>
                    <P>One commenter also suggested that HUD should ensure that energy efficiency considerations are addressed for off-site built housing like manufactured homes. The commenter noted that HUD should consider the Environmental Protection Agency's EnergyStar v.3 standard or the Department of Energy's Zero Energy Ready standard for manufactured homes as a minimum for any activities related to the purchase of new manufactured housing with HOME funds.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the comment. However, the Department was not proposing to change the minimum property standards for manufactured housing, which are covered by § 92.251(e). Paragraph § 92.251(e) continues to require that manufactured housing be constructed in accordance with the Manufactured Home Construction and Safety Standards found at 24 CFR part 3280. The Department just recently revised its Manufactured Home Construction and Safety Standards as part of another rulemaking and the Department is declining to make further revisions to those rules or to the HOME rules in response to this comment.
                        <SU>53</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>53</SU>
                             See 89 FR 75704.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">AA. Use of Inspection Performed by Third Parties</HD>
                    <P>Another commenter recommended allowing States to accept ongoing inspection reports from local government inspections that review compliance with local codes during construction of a HOME-assisted project. The commenter believed that HUD should only require the final inspection be conducted by the State participating jurisdiction before completing the project in the IDIS, instead of requiring frequent State participating jurisdiction inspections during construction. The commenter explained that this would avoid unnecessary burden, especially for larger States where it can take several hours to commute to a project's location.</P>
                    <P>Another commenter stated that HUD should create a process to accept either State or local rental inspections in lieu of HUD required inspections.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD declines to revise the requirement that participating jurisdictions conduct progress inspections and notes that HOME regulations do not require participating jurisdiction staff to conduct the inspections. Participating jurisdictions may contract with qualified third-party inspectors, including contractors for other funders or units of government, to conduct HOME inspections in accordance with the participation jurisdiction's policies and procedures.
                    </P>
                    <HD SOURCE="HD3">BB. Provide Small-Scale Rental Housing Inspection Requirements to All Owners</HD>
                    <P>One commenter said that the changes being proposed to the small-scale development compliance requirements, such as requiring inspections every three years, should be extended to larger-scale developments as well.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD declines to extend the revisions to compliance requirements for small-scale rental housing to all rental projects. These revised requirements are based on the unique considerations of small-scale housing and would result in insufficient monitoring if applied to larger rental projects. HUD also notes that current HOME regulations at § 92.504(d)(1)(ii)(A) require inspections every three years following the inspection within 12 months of project completion.
                    </P>
                    <HD SOURCE="HD3">CC. Reduce Property Standards Requirements for Homeowner Rehabilitation</HD>
                    <P>One commenter stated that HOME's Housing Quality Standards, especially the requirement to address all health and safety hazards, impose significant challenges on low-income homeowners who cannot afford critical repairs due to limited equity or reluctance to encumber properties. The commenter stated that these issues cause HOME applicants to drop out of the process, which often means that grantees cannot recover the extensive staff time invested in considering or processing applications. The commenter recommended that HUD remove the Housing Quality Standards (HQS) requirements for single-family rehabilitation projects. One commenter stated HUD should expand grant funding available to cover critical repairs, such as roofs, plumbing, and electrical systems, which are often unaddressed due to limited equity, hesitation of homeowners to participate in the program, and concerns about encumbering their property with debt vs income. The commenter noted that HUD could expand the range of available grants to mirror CDBG programs.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HOME is an affordable housing program with the statutory purpose of bringing rental and homeownership housing up to standard physical condition and imposing periods of affordability on the housing.
                        <SU>54</SU>
                        <FTREF/>
                         CDBG is a community development program that can fund single purpose or emergency rehabilitation that does not address all deficiencies in a property or impose long-term affordability restrictions. Unlike the CDBG program, the HOME regulations require that the rehabilitation meets the participating jurisdiction's rehabilitation standards, which are more stringent standards that require that the entire housing structure is code compliant and meets the HUD housing standards contained in 24 CFR 5.703, as provided for in § 92.251(b). HQS do not apply to HOME-assisted homeowner rehabilitation projects. For HOME-assisted homeowner rehabilitation, participating jurisdictions must determine the scope of repairs needed to bring the homeowner's property up to code as well as the form of assistance to homeowners, including any loan terms. The critical repairs noted by the commenter are eligible costs if such repairs are necessary to meet participating jurisdiction's rehabilitation standards. Salaries, wages, and related costs of program administration are also eligible costs under the HOME program (§ 92.206(d)(6)). The Department declines to reduce the property standards requirements for homeowner rehabilitation projects and acknowledges that other programs may be better suited for more limited-scope homeowner rehabilitation projects than the HOME program.
                    </P>
                    <FTNT>
                        <P>
                            <SU>54</SU>
                             See 42 U.S.C. 12721, 42 U.S.C. 12722, and 42 U.S.C. 12741.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">DD. Reduce Property Standards Requirements for Homebuyer Acquisition</HD>
                    <P>One commenter requested that HUD only require participating jurisdictions to ensure that homebuyer housing is free of immediate life and safety issues rather than imposing extensive property standards. The commenter stated that this may create a more reasonable option for income eligible buyers and private sellers instead of financing additional rehabilitation costs, which may put debt-to-income ratios too high.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department declines to reduce the property standards requirements for homebuyer acquisition projects. The purpose of the HOME program is to bring housing into compliance with property standards and ensure the housing remains affordable over time.
                        <SU>55</SU>
                        <FTREF/>
                         For homeownership, adequate property condition is key to 
                        <PRTPAGE P="814"/>
                        the sustainability of a household's homeownership over the period of affordability. When a participating jurisdiction uses HOME funds for downpayment assistance or other homebuyer assistance programs, the participating jurisdiction is required to determine that the housing being acquired meets property standards at purchase or to ensure that necessary rehabilitation is performed soon after purchase. HUD encourages participating jurisdictions to use HOME funds to complete necessary repairs to units being acquired by homebuyers with HOME funds. However, this final rule also reduces a key barrier for private sellers by providing the HOME-assisted homebuyer 6 months to meet property standards. When permitted by a participating jurisdiction, this time period may be extended to 12 months. This should be rare. Meeting property standards may require additional investment by the participating jurisdiction or the homebuyer. The participating jurisdiction must work with the homebuyer and determine the correct amount of homeownership assistance based not only on the cost of acquisition but also any necessary rehabilitation to bring the property into compliance with the participating jurisdiction's property standards.
                    </P>
                    <FTNT>
                        <P>
                            <SU>55</SU>
                             See 42 U.S.C. 12721, 42 U.S.C. 12722, and 42 U.S.C. 12741.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">EE. Align Rehabilitation Standards With the Community Development Block Grant (CDBG) Program</HD>
                    <P>One commenter suggested that the Department align HOME rehabilitation requirements with the rehabilitation requirements under the CDBG program.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department declines to align HOME rehabilitation requirements with CDBG. The CDBG program does not require that all rehabilitated residential properties meet the national Standards for the Condition of HUD housing contained in § 5.703. The Department chose to align with programs that are subject to the standards contained in § 5.703 because those programs, which include but are not limited to the Section 8 project-based rental assistance and Housing Choice Voucher program, are the forms of assistance most likely to be combined with HOME assistance. The CDBG program does not require rehabilitation projects to meet these property standards or inspection requirements, and therefore, the CDBG program does not align with other HUD programs under NSPIRE inspection protocols. Adopting the CDBG rehabilitation requirements for HOME-assisted rehabilitation would mean the removal of property standard and inspection requirements from the existing regulation. 42 U.S.C. 12722 states that one of the purposes of the HOME program is “to expand the supply of decent, safe, sanitary, and affordable housing, with primary attention to rental housing, for very low-income and low-income Americans.” HUD does not believe that is has the flexibility to remove rehabilitation property standards and inspection requirements because the requirement that all HOME-assisted projects be decent, safe, and sanitary is statutory.
                    </P>
                    <P>
                        <E T="03">Specific solicitation of comment #3: The Department specifically seeks public comment on the proposal to require HOME-assisted units comply with NFPA 72, or any successor standard, to use hardwired smoke alarms or sealed or tamper resistant smoke alarms with ten-year non rechargeable, nonreplaceable batteries, that provide notification for persons with hearing loss. The Department is particularly interested in public comment on the feasibility of these requirements in HOME-funded homeownership programs that do not include rehabilitation or construction of housing (e.g., downpayment assistance programs).</E>
                    </P>
                    <HD SOURCE="HD3">A. Support for Smoke Alarms in HOME Projects</HD>
                    <P>
                        Commenters generally expressed support for requiring the installation of smoke alarms in the interest of promoting safety. In addition, only a few commenters stated their support for the specific proposal to require NFPA 72 smoke alarms in HOME-assisted projects. Of those commenters, one indicated support of the proposal for all types of HOME-assisted projects (
                        <E T="03">i.e.,</E>
                         new construction, rehabilitation, homeowner or rental acquisition and TBRA) and indicated that the minimal additional cost is worth the potential lifesaving impact. One other commenter indicated support for compliance with NFPA 72 specifically in homebuyer acquisition (
                        <E T="03">i.e.,</E>
                         downpayment assistance) programs. The third commenter reasoned that hard-wire smoke detectors would reduce both the removal of batteries and the frustration of tenants responsible for replacing batteries but could not comment on the impact of the policy on homebuyer acquisition projects because the participating jurisdiction does not use funds for that purpose.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for sharing their views. HUD is revising the proposed language in order to achieve an approach that improves safety while addressing feasibility concerns that commenters raised. This final rule requires that HOME-assisted new construction projects use hardwired smoke alarms. For rehabilitation projects, if the use of hardwired smoke alarms places an undue financial burden on the owner or is infeasible, a participating jurisdiction may provide a written exception to an owner to allow the owner to install a sealed and tamper resistant smoke alarm that uses 10-year non-rechargeable, non-replaceable primary batteries. Participating jurisdictions may also provide exceptions for projects including the acquisition of standard housing for homeownership, such as downpayment and closing cost assistance programs. Finally, a participating jurisdiction's standards must require that existing rental housing and housing occupied by tenants receiving tenant-based rental assistance contain smoke alarms in accordance with the requirements contained in 24 CFR 5.703(b) and (d). These standards do not require NFPA 72 compliance but do require that units occupied by a hearing-impaired person contain smoke alarms designed for hearing-impaired persons.
                    </P>
                    <HD SOURCE="HD3">B. Concerns Over Requiring Installation of NFPA 72 Compliant Smoke Alarms</HD>
                    <P>Most commenters expressed concerns about the specific proposal to require the installation of NFPA 72-compliant smoke alarms. Their primary concerns are costs, availability of such smoke alarms, and feasibility in projects that do not involve new construction or rehabilitation. Specifically, commenters were unclear how compliant smoke alarms would be paid for in homebuyer programs and speculated the proposal could increase administrative burden and cost in many jurisdictions where homeownership assistance programs are often oversubscribed and financially stretched. Many commenters were also concerned that installation would be challenging and cost-prohibitive in the rehabilitation of older housing. One of these commenters stated that adoption of the NFPA 72 standard would cause their participating jurisdiction to discontinue use of HOME funds for rehabilitation projects.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD acknowledges commenters' concerns and has revised the proposed language to provide flexibility for participating jurisdictions. For new construction projects and many rehabilitation projects, installing hardwired smoke alarms is feasible and promotes safety and user-friendliness. However, installing hardwired alarms may be challenging for certain rehabilitation projects. This final rule allows participating jurisdictions to provide written exceptions to allow the 
                        <PRTPAGE P="815"/>
                        owner to install a sealed and tamper resistant smoke alarm that uses 10-year non-rechargeable, non-replaceable primary batteries. Likewise, the participating jurisdiction may provide an exception for homebuyers participating in homeownership assistance programs. HUD believes installing battery-powered smoke alarms is a reasonable cost for homeowners and owners of rehabilitated rental units. Finally, HUD notes that smoke alarms are widely available and that their installation is an eligible use of HOME funds for new construction and rehabilitation projects.
                    </P>
                    <HD SOURCE="HD3">C. Smoke Alarm Requirements Should Be Optional</HD>
                    <P>To address concerns about costs, one commenter proposed that smoke alarm requirements should be encouraged but not required. Other commenters suggested that the rule not require smoke alarms to be hard-wired. One commenter, however, supported hard-wired smoke alarms only in HOME-funded new construction projects. Two other commenters agreed that HUD should differentiate requirements for new construction and rehabilitation projects. The first commenter suggested that the rule require 10-year battery-powered smoke alarms in rehabilitation, homebuyer acquisition, and HOME tenant based rental assistance projects. However, this commenter's recommendation for homebuyer and TBRA projects was contingent on the HOME rule allowing the installation of alarms as an eligible HOME cost.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the commenters' recommendations. This final rule requires all HOME-assisted units to contain smoke alarms while differentiating requirements by project type. Hardwired smoke alarms are required in new construction projects, while participating jurisdictions may provide exceptions for rehabilitation and homebuyer projects. The installation of smoke alarms is not an eligible HOME cost for homebuyer and tenant-based rental assistance activities. As with other property standards requirements, homebuyers and owners of tenant-based rental assistance units must ensure compliance with smoke alarm requirements. This final rule revises § 92.251(c)(3) to allow a homebuyer to bring a home up to the participating jurisdiction's property standards within 6 months after acquisition, rather than requiring the home to meet all property standards at the time of purchase. The final rule also allows for the participating jurisdiction to extend that time up to 12 months through an amendment to its written agreement with the homebuyer.
                        <SU>56</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>56</SU>
                             See 24 CFR 92.251(c)(3).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">D. Cost Concerns Are Not Eliminated by Eliminating Hardwired Smoke Alarms</HD>
                    <P>Other commenters disagreed that eliminating the requirement for hard-wired smoke alarms would address cost concerns. They stated that compliant battery-operated smoke alarms can also be significantly more expensive and harder to find than more widely available models. One commenter suggested that 10-year non-rechargeable, non-replaceable batteries pose the risk of increased replacement costs due to uncertainty about future safety codes after initial battery life has expired. In addition, one commenter indicated that these smoke alarms may require training for the tenant or homeowner to use this system and creates additional expense for homeowners and rental housing owners to replace and maintain.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD recognizes that the smoke alarms required by this rule may be more expensive than other smoke alarms in some cases and that battery-powered alarms will involve future replacement costs. However, the marginal cost of these smoke alarms is not significant in the context of rehabilitation or new construction and smoke alarms required by this rule are widely available in stores and online. HUD believes potential additional costs are reasonable in order to promote the safety of tenants and homeowners. Additionally, training for tenants and homeowners on using battery-powered smoke alarms, if required, may already be available online from manufacturers and should be minimal in any case.
                    </P>
                    <HD SOURCE="HD3">E. Consider Availability and Cost of NFPA 72 Smoke Alarms</HD>
                    <P>One commenter urged HUD to assess the availability and cost of NFPA 72 smoke alarms before imposing such a requirement on HOME projects.</P>
                    <P>Several commenters requested that HUD make additional funds available to cover the costs of meeting any new smoke detector requirements. One commenter stated that national standards must not disadvantage rural places or low-income people, so Federal funds should be provided to cover the cost of any new Federal standards.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         This final rule allows participating jurisdictions to make exceptions for rehabilitation and homebuyer projects where installing hardwired alarms would be infeasible or prohibitively costly. HUD notes that installation of the smoke alarms required by this rule is an eligible HOME cost for rehabilitation and new construction costs. Very few projects receive HOME subsidies at or near the maximum per-unit subsidy limit and this rule increases those limits. HUD does not believe that installation of these smoke alarms will be cost prohibitive.
                    </P>
                    <HD SOURCE="HD3">F. Requiring NFPA 72 Smoke Alarms Reduces Ability To Use HOME for Homeownership Opportunities</HD>
                    <P>Commenters who expressed concern about imposing NFPA 72 requirements on homebuyer acquisition projects stated that the proposal would reduce single family homeownership opportunities because it would be difficult for HOME-assisted homebuyers to negotiate specialized smoke detector requests during the purchase and sales of existing units on the market with private owners. For this reason, one commenter noted that such a policy would reinforce its decision to decline to offer homebuyer assistance independently of HOME-assisted new construction or rehabilitation projects. Another commenter suggested that even if the cost of smoke detector installation was permitted as an eligible HOME cost, low-income homebuyers cannot afford to use their downpayment assistance for this purpose due to the high cost of housing. A third commenter suggested that if a household requires a specialized smoke detector, it should either be requested at the time of construction as a reasonable accommodation or should be installed by the homeowner after purchase. However, commenters also expressed concerns about requiring the assisted family to pay for upgrades after purchase, the ability of participating jurisdictions to enforce smoke alarm requirements after closing, and the additional program costs of additional post-closing inspections.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD recognizes that HOME property standards can sometimes make it challenging for HOME-assisted homebuyers to find a compliant home to purchase. In this final rule, HUD has revised the requirements at § 92.251(c)(3) in order to provide HOME-assisted homebuyers 6 months to make improvements necessary to meet HOME property standards, with the ability for participating jurisdictions to extend that period for up to 12 months from purchase. Therefore, homeowners selling to HOME-assisted buyers will not need to install the smoke alarms required by this rule prior to closing. In cases where acquired homes do not have smoke alarms meeting the requirements of this rule, HUD believes 
                        <PRTPAGE P="816"/>
                        it is a reasonable cost for homebuyers to install a hardwired alarm or, with written exception from the participating jurisdiction, a 10-year battery-powered smoke alarm. Participating jurisdictions will monitor smoke alarm requirements as part of its final inspection for overall property standard compliance. HUD notes that the smoke alarms required by this rule present safety benefits for all tenants and homeowners, not only for persons experiencing hearing loss.
                    </P>
                    <HD SOURCE="HD3">G. Property Standards Requirements Should Only Require That Housing Meet State and Local Smoke Alarm Requirements</HD>
                    <P>Several commenters noted that current building codes in some States and local jurisdictions already require compliance with NFPA 72 smoke alarm standards for single and multifamily buildings. Consequently, a number of commenters urged HUD to defer to State and local code requirements for smoke alarms. Commenters explained that State building codes facilitate choice and therefore flexibility based on the conditions of the project.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Due to the safety benefits of the smoke alarms required by this rule, HUD declines to defer to State and local codes. This final rule provides participating jurisdictions flexibility in rehabilitation and homebuyer projects and does not require NFPA 72 smoke alarms for existing rental and TBRA units.
                    </P>
                    <HD SOURCE="HD3">H. Don't Use Only the NFPA 72 Standard</HD>
                    <P>One commenter advised against solely applying NFPA 72 because these requirements do not align with the Consolidated Appropriations Acts of 2021 and 2023 which require all public housing to meet or exceed the requirements of Chapters 9 and 11 of the 2018 International Fire Code and that smoke alarms are installed in Federally assisted housing in accordance with the International Code Council or NFPA and NFPA 72. The commenter urged HUD to reference the smoke alarms requirements outlined in the International Building Code, International Residential Code, and International Fire Code which the commenter stated are industry-leading national voluntary consensus standards, are widely used by government agencies across the nation, and trigger NFPA 72 smoke alarm installation requirements. The commenter stated that implementation of the hearing impairment requirements will be difficult because they are not referenced in the international codes and the technology is limited in availability. The commenter noted that the international codes require smoke alarms be hardwired with battery backup unless it is a first-time install and that the allowance to install seal tamper resistant non-replaceable 10-year battery operated alarms are intended to be limited to existing buildings that do not currently contain hardwired alarms and that it is unclear whether these alarms would comply with NFPA 72 for hearing impairment.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for their suggestion. This final rule requires that, for new construction, rehabilitation, and homebuyer projects, smoke alarms be installed in accordance with certain specific requirements of HUD. In addition, meeting the applicable codes and standards published by the International Code Council or the National Fire Protection Association ensures compliance § 92.251(a)(3)(vi)(B). Ongoing property standards require that a participating jurisdiction's standards require housing contain smoke alarms in accordance with the requirements contained in 24 CFR 5.703(b) and (d). All carbon monoxide detectors in HOME-assisted units must be installed in a manner that meets or exceeds the standards that HUD will further describe in a forthcoming 
                        <E T="04">Federal Register</E>
                         publication.
                    </P>
                    <HD SOURCE="HD3">I. Clarification on Smoke Alarms in Projects With Floating Units</HD>
                    <P>Several commenters asked for clarification of the proposed policy. One commenter asked how the proposal would apply (f) in HOME-assisted properties with floating HOME units. Other commenters asked HUD to clarify monitoring and compliance requirements, especially after resale for homebuyer activities.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         For rental projects with floating units, in accordance with § 92.252(j), project owners must ensure that units are comparable in terms of their features, which includes ensuring that units have compliant smoke alarms. For homebuyer projects, participating jurisdictions will monitor compliance with smoke alarm requirements as part of final inspections for overall property standard compliance. This final rule revises § 92.251(c)(3) to allow a homebuyer to bring a home to property standards within 6 months after closing and provides participating jurisdictions the ability to extend that to 12 months, if necessary. Whether at initial sale or resale, the participating jurisdiction would therefore inspect the unit once the homebuyer has completed necessary improvements.
                    </P>
                    <P>Specific solicitation of comment #4: The Department specifically seeks public comment on the proposal to require that a participating jurisdiction inspect at least 20 percent of the HOME assisted units during its ongoing on-site inspections of rental housing.</P>
                    <HD SOURCE="HD3">A. General Support for 20 Percent Sample Size</HD>
                    <P>Many commenters supported the proposal to require participating jurisdictions to inspect at least 20 percent of the HOME-assisted units. One commenter agreed that the current HOME rule requirement that participating jurisdictions inspect a “statistically valid” sample of units is challenging for participating jurisdictions that lack software capabilities to develop such a sample. In addition, one commenter in support of the proposal also recommended that HUD require that each inspection include accessible units and evaluate the accessibility of common areas.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for their support. HUD notes that accessible units in a project are not always HOME units and their designation can change during the period of affordability. Further, requiring each inspection to include accessible units may lead to the same, limited number of accessible units being inspected repeatedly. HUD believes this would be burdensome for the tenants of accessible HOME units. HUD agrees that it is important that common areas remain accessible to persons with disabilities. While the NSPIRE inspection protocol does not specifically include an accessibility section, it requires inspection of common areas for inspection of walkways, ingress and egress, and railings.
                    </P>
                    <HD SOURCE="HD3">B. General Opposition to 20 Percent Sample Size</HD>
                    <P>Many commenters also opposed the proposal, their primary concern being that an inspection of 20 percent of the HOME-assisted units will result in a large sample size, particularly in large projects, and will place an undue burden on residents, project owners, property managers, and participating jurisdictions. In response, several commenters requested that HUD provide additional administrative funds because the proposal would require additional staff time and costs.</P>
                    <P>
                        One commenter noted that, for properties with a limited number of HOME units, it will be difficult to avoid inspecting the same units each year. Another commenter maintained that current requirements are sufficient for 
                        <PRTPAGE P="817"/>
                        ensuring properties' compliance with property standards.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the comments and shares commenters' concerns about burden. HUD is providing burden relief in this final rule by reducing the minimum required sample size to less than 20 percent for projects with 136 or more HOME-assisted units. Beginning with properties that include between 167 and 214 HOME-assisted units, the minimum inspection sample size table in this final rule aligns with the inspection size table included in the NSPIRE Final Rule.
                        <SU>57</SU>
                        <FTREF/>
                         HUD also considered aligning with the LIHTC sample size chart but felt it was more appropriate to align HOME with other HUD programs subject to NSPIRE.
                    </P>
                    <FTNT>
                        <P>
                            <SU>57</SU>
                             See “Table 9—Number of Units Sampled Under NSPIRE Scoring and Sampling Methodology Based on Property Size.” 
                            <E T="03">https://www.govinfo.gov/content/pkg/FR-2023-07-07/pdf/2023-14362.pdf.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">C. Impose a Lower Percentage of Units for Larger Projects and Align With LIHTC</HD>
                    <P>Several commenters proposed reducing the sample size for larger projects. Two commenters stated that the proposed sampling method differs from the requirements of other funding sources, including LIHTC, and recommended that HUD instead align the HOME and LIHTC program requirements. One of these commenters suggested using the LIHTC standard of the lesser of 20 percent or an amount on a chart included in the LIHTC regulation 1.42-5 for larger projects to lessen the burden for participating jurisdictions.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for their suggestions. HUD agrees that the 20 percent sample size in the proposed rule is too large for very large projects and is adopting the NSPIRE sample size chart for larger projects to align with other HUD programs.
                    </P>
                    <HD SOURCE="HD3">D. Require a Bifurcated Sampling Standard for Large and Small Projects</HD>
                    <P>One commenter proposed 20 percent of units in projects with 5-50 units and 10 percent in projects with 50 or more units. Similarly, a different commenter recommended 15 percent of HOME-assisted units in projects with 20-30 units, and 10 percent for projects with more than 30 HOME assisted units.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for their suggestions and agrees that it should have different sample sizes based on whether the project has a smaller or larger number of units. Although HUD did not adopt the commenter's precise suggestions, this final rule does reduce the minimum required sample size for larger projects as suggested by the commenters.
                    </P>
                    <HD SOURCE="HD3">E. Reduce Sample Size to 10 Percent</HD>
                    <P>One commenter suggested that 10 percent of HOME-assisted units be inspected in all HOME projects, regardless of the total number of units in the project with a minimum of one unit per building.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for the suggestions. HUD declines to adopt this approach uniformly within the rule because, in most cases, a sample size of 10 percent of HOME-assisted units would be insufficient to ensure the project's compliance with HOME property standards. In larger projects, the Department has determined that it may be appropriate to reduce the percentage to 10% or less, and for projects with greater than 300 HOME units, the sample size is 10% or less.
                    </P>
                    <HD SOURCE="HD3">F. Reduce Sample Size for Small-Scale Rental Housing Projects</HD>
                    <P>One commenter proposed that developers with multiple properties containing between one and four HOME units should be required to inspect 20 percent of the HOME-assisted units across their portfolio every three years.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the commenter's suggestion but declines to adopt this change. The HOME statute and regulations apply HOME requirements individually to each HOME-assisted project. While a single ownership entity may have multiple HOME-assisted projects in its portfolio, the physical characteristics, management, and occupancy of those project may vary significantly. Physical deficiencies or a lack of deficiencies in one project do not necessarily reflect the condition of other properties in the portfolio. Therefore, the Department believes that each project should be on its own on-site inspection cycle and that the participating jurisdiction cannot sample units across the owner's portfolio to satisfy the individual project inspection requirements for that owner.
                    </P>
                    <HD SOURCE="HD3">G. Confusion Over Sampling Units for Unit Inspections in HOME</HD>
                    <P>Several commenters expressed confusion or requested clarification about the proposed requirements. One commenter stated that the proposed rule is unclear about how the sample size requirement relates to the requirements for timing of HOME onsite inspections. The commenter asked whether annual inspections that, in sum, surpass 20 percent of HOME-assisted units over three years, but do not in a single year, would satisfy the proposed requirement. Another commenter stated that they thought the 20 percent inspection sample size was the existing requirement. And a commenter also stated that no additional inspections should be added to the regulations at all because they are administratively burdensome.</P>
                    <P>A different commenter requested that HUD clarify whether both HOME and non-HOME units would be required to be included in the inspection sample. The commenter suggests that inspection requirements apply only to HOME-assisted units and that HUD should allow inspection of voucher units without affordability agreements to qualify as inspection and monitoring for HOME. In its final rule, we ask HUD to mandate agreement disbursement for documentation of HOME properties.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         This final rule does not change the number or timing of required inspections. Participating jurisdictions must conduct on-site inspections within 12 months after project completion and at least once every 3 years thereafter during the period of affordability. A participating jurisdiction may choose to conduct ongoing inspections more frequently, but each inspection must meet the appropriate minimum inspection sample size defined in this final rule. The inspection must only include HOME-assisted units, and HUD is unable to allow voucher units that are not HOME-assisted to be included in the inspection sample, as these units are not subject to HOME requirements.
                    </P>
                    <HD SOURCE="HD3">H. Other Comments Received on the Solicitation—Adopting Different Property Standards</HD>
                    <P>One commenter urged HUD to adopt the most recent International Property Maintenance Code as the basis for on-site inspections of rental homes to promote standardization of requirements.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for this suggestion but declines to adopt this change. The Department has engaged in extensive rulemaking on the required standards for on-site inspections and is not going to substantially change those standards at this time.
                    </P>
                    <HD SOURCE="HD3">I. Other Comments Received on the Solicitation—Publish Inspection Components</HD>
                    <P>One commenter asked HUD to publish the components that will be included in a required inspection.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD encourages the commenter to review the provisions of this final rule and HOME program resources on 
                        <E T="03">HUD.gov</E>
                        . As part of the 
                        <PRTPAGE P="818"/>
                        implementation of the NSPIRE Final Rule, HUD will provide additional guidance and materials aimed at assisting participating jurisdictions and owners in complying with the requirements, including a streamlined list of minimum inspectable items that shall be a subset of the larger set of standards published in the NSPIRE Standards notice at 88 FR 40832.
                    </P>
                    <HD SOURCE="HD3">J. Other Comments Received on the Solicitation—Source Documentation in Income Determinations During the Sixth Year of Affordability</HD>
                    <P>One commenter also asked whether the sixth year of affordability is measured by the individual tenant's occupancy date or the date of the project completion date and how the six-year period of affordability will be affected if ownership changes during that period. The commenter expressed confusion between the current six-year period of affordability and the period of affordability outlined in HOTMA, so they asked HUD to provide occupant variance probabilities and to incorporate said variances into the final rule. The commenter also supported participating jurisdictions making the final determination of period of affordability based on variance probability guidance from HUD in the final rule.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The period of affordability in a HOME-assisted rental project starts when the project meets the definition of project completion (see § 92.2 definitions), and the project is placed into service. During the period of affordability, the HOME-assisted units must be occupied by income eligible families and comply with applicable rent requirements. To ensure the HOME-assisted units qualify as affordable housing, the project owner must determine the annual income of the family using a variety of methods permitted under HOME and selected by the participating jurisdiction. HUD's rule is that unless a person is qualifying under § 92.203(a)(1), (a)(2), or (a)(3), the owner must calculate the person's annual income using source documentation prior to initial occupancy, and then once every six years during the period of affordability (
                        <E T="03">e.g.,</E>
                         the six-year schedule of examination for a project with a 20-year period of affordability would be to perform an income examination with source documents in years 1, 6, 12, and 18). The six-year schedule applies to the period of affordability and not to a tenant's occupancy. The requirement to redetermine income eligibility using source documents every sixth year applies only in units where a participating jurisdiction permits the use of self-certification in accordance with § 92.203(b)(1)(ii). The six-year schedule and method of determining income eligibility under this schedule does not change if there is a change in ownership; it is based on when the project was completed and placed into service. When there is a change in ownership during the period of affordability, the HOME requirements continue to apply to the project and the income examination cycle remains the same. This is the methodology that HUD uses to ensure the HOME-assisted units remain affordable during the period of affordability as established in the table in § 92.252(d).
                    </P>
                    <P>The Department is also clarifying that the six-year schedule in this Final Rule is the same as the six-year schedule in the HOTMA Final Rule, and that the requirements are consistent with one another. HUD does not believe it necessary to calculate occupant variance probabilities (within the six-year period of period of affordability) as requested by a commenter or to reexamine HUD's methodology for verifying units remain affordable and occupied by low-income families during the period of affordability.</P>
                    <P>
                        <E T="03">Specific solicitation of comment #8: The Department specifically requests public comment from participating jurisdictions, developers, and other affected members of the public about the appropriateness of the length of the HUD-required periods of affordability for HOME-assisted rental housing. The current regulation at 24 CFR 92.252(e) establishes periods of 5 years for a per-unit HOME investment of under $15,000, 10 years for a per-unit investment between $15,000 and $40,000, and 15 years for a per-unit investment of more than $40,000, 15 years for any unit involving refinancing of existing debt, and 20 years for any unit involving new construction. Section 215(a)(1)(E) of NAHA (42 U.S.C. 12745(a)(1)(E)) requires that the period of affordability be for the remaining useful life of the HOME-assisted property, as determined by HUD, without regard to the term of the mortgage or to transfer of ownership, or for such other period that HUD determines is the longest feasible period of time consistent with sound economics and the purposes of NAHA. Since the Department established these periods of affordability in 1991, costs have increased significantly, LIHTCs have become the primary funding mechanism for rental housing, and the housing affordability crisis in the country has worsened significantly. The Department seeks input about whether the length of the periods of affordability and the dollar thresholds and activity thresholds that are the basis of the current periods of affordability remain appropriate. In addition, the Department seeks input about any project feasibility challenges of the current HOME periods of affordability and factors that the HUD should consider in contemplating changes to the current periods of affordability.</E>
                    </P>
                    <HD SOURCE="HD3">A. General Comments</HD>
                    <P>HUD received a broad range of responses to this solicitation on the appropriate periods of affordability to impose on HOME-assisted projects. Commenters recommended that HUD leave the existing regulations intact, increase the dollar thresholds for existing periods of affordability, eliminate the longer period of affordability for new construction of rental housing, align HOME requirements with other housing program requirements, establish longer periods of affordability, establish different periods for homeownership activities, or allow participating jurisdictions to determine their own periods of affordability.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the many thoughtful comments submitted by commenters. HUD is guided by the Act, which states that HOME-assisted housing must “remain affordable for the remaining useful life of the property, as determined by the Secretary, without regard to the term of the mortgage or to transfer of ownership, or for such other period that the Secretary determines is the longest feasible period of time consistent with sound economics and the purposes of this Act,” Therefore, HUD carefully balanced commenters legitimate concerns about increases in land and construction costs in the past 30 years with the degree to which the nation's affordability crisis has deepened and spread during that period. HUD also notes that the most recent HOME appropriation of $1.25 billion is less than the $1.5 billion appropriated for HOME in Fiscal Year 1992. Had the HOME appropriation kept pace with the rate of general inflation, the current appropriation would be nearly $3.9 billion. In this final rule, HUD has retained the periods of affordability of 5, 10, and 15 years based on per-unit investment and 20 years for new construction of rental housing but partially adjusted the thresholds for the per-unit investment-based periods to reflect cost increases over the past three decades. However, these limits are not fully adjusted for inflation due to the need to address the significantly worsened affordability crisis with an 
                        <PRTPAGE P="819"/>
                        appropriation that in real dollar terms is less than half what it was in Fiscal Year 1992. The rule imposes the following periods of affordability: (1) 5 years when per-unit HOME investment is less than $25,000; (2) 10 years when the per-unit HOME investment is between $25,000 and $50,000; (3) 15 years when the per-unit HOME investment is more than $50,000; and (4) 20 years for all projects involving new construction of rental housing.
                    </P>
                    <HD SOURCE="HD3">B. Make No Changes to Period of Affordability</HD>
                    <P>Some commenters stated that the current length and amount criteria for period of affordability is appropriate and can remain as currently written.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the comments. However, the Department believes that it is appropriate to partially adjust the dollar ranges for the period of affordability to reflect the 226 percent increase in the Consumer Price Index between 1992 and 2024, the increase in compliance costs, and the current cost of labor and materials.
                    </P>
                    <HD SOURCE="HD3">C. Adjust Dollar Thresholds To Reflect Cost Increases</HD>
                    <P>Numerous commenters stated that the length of the current periods of affordability are appropriate but recommended that HUD adjust the dollar thresholds to reflect the significant increase in the cost of land and construction since the current thresholds were established in December 1991. Two commenters who supported the length of current periods of affordability recommended that HUD adjust the existing dollar thresholds to reflect the cumulative change in the Consumer Price Index (CPI) since that time. One of these commenters noted that the existing $15,000 threshold between the 5-year and 10-year periods would be nearly $35,000 if adjusted by the CPI.</P>
                    <P>Several commenters cited increased costs of rehabilitation since 1991 and stated that HUD should adopt alternative dollar thresholds. Commenters recommended thresholds of between $20,000, and $125,000 for a 5-year period of affordability and between $50,000 and $250,000 for the 15-year period of affordability. One commenter who supported higher dollar thresholds also recommended that HUD adopt a 25-year period of affordability for new construction. One commenter suggested a period of affordability of 20 years for a HOME investment of less than $1,000,000 and 50 years for a HOME investment of more than $1,000,000.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department agrees with commenters that the HOME periods of affordability should be adjusted to reflect cost increases over time and appreciates the various suggestions. HUD also declines to adopt suggestions that would increase the thresholds far beyond the 226 percent increase in the Consumer Price Index as such increases would reduce the affordability achieved through HOME subsidies below what was required at the inception of the HOME program. HUD also notes that some of the suggested amounts far exceed the maximum HOME subsidy that may be provided to a unit. The thresholds established in this rule constitute a 66 percent increase in the five-year period of affordability threshold, and a 25 percent increase in the threshold separating the 10-year period of affordability and the 15-year period of affordability, which HUD believes balances the competing needs for modernized thresholds and the severity of the current shortage of affordable housing. HUD also declines to extend the period of affordability for new construction of rental units to 25 years because even newly constructed units will require rehabilitation and recapitalization before the expiration of that period. Extending this period would complicate efforts to recapitalize housing projects, including efforts to further extend periods of affordability through additional HOME funds or other funding sources.
                    </P>
                    <HD SOURCE="HD3">D. Eliminate the Longer Period of Affordability for New Construction of Rental Housing</HD>
                    <P>A commenter recommended eliminating the 20-year requirement for new construction projects and applying the per-unit subsidy-based periods of 5-, 10-, or 15-year to all units irrespective of the activity undertaken. The commenter stated that a gut rehabilitation project has a 15-year period of affordability and new construction has a 20-year period of affordability, although there is essentially no difference in housing quality of these two project types. Another commenter advocated eliminating the 20-years period of affordability for new construction to allow for the reinvestment of HOME funds after 15 years.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the comments but declines to make this change. HUD believes that the longer period of affordability for newly constructed rental housing faithfully implements the statutory requirement that HOME periods of affordability reflect the useful life of the property or such other period that the Secretary determines is the longest feasible period of time consistent with sound economics and the purposes of this Act. The fact that some substantial rehabilitation or reconstruction projects may be similar in construction and useful lifespan to new construction is not an adequate justification to reduce the period of affordability for HOME-funded new construction projects.
                    </P>
                    <HD SOURCE="HD3">E. Align Period of Affordability Requirements With Other Programs</HD>
                    <P>One commenter stated that periods of affordability are critical to ensuring that the investment of Federal funds has an impact on housing availability and affordability over time, but also make project underwriting at the time of funding and ongoing maintenance of the financial and physical health of the property more challenging. The commenter stated that the affordability restrictions in HOME are a barrier to HOME-assisted rental housing development in high-cost areas, given the need to layer financing from multiple sources. The commenter suggested aligning HOME periods of affordability with the 15-year credit compliance period of the Low-Income Housing Tax Credit (LIHTC) to enable preservation of existing affordable housing through recapitalization. Another commenter recommended that HUD align the HOME period of affordability 30-year LIHTC extended use period to allow cities to track period of affordability more easily among various affordable housing project types. One commenter stated HUD should align its periods of affordability with the minimum 55-year period frequently used in affordable housing programs in California.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the comments and recognizes that most HOME projects also include one or more other Federal, State, local, or private funding sources, which means that there are multiple restricted use periods imposed by other affordable housing funding sources to which HOME could possibly align. The Department believes that the multiplicity of possible options is a compelling reason not to align with a single other funding source and maintain the current periods, which are well-understood among affordable housing developers. HUD also reads the Act to require it to affirmatively establish periods of affordability that apply to HOME-assisted units rather than deferring to one or more other funding sources.
                        <PRTPAGE P="820"/>
                    </P>
                    <HD SOURCE="HD3">F. Change Lengths of Periods of Affordability</HD>
                    <P>Several commenters stated that HUD should impose longer periods of affordability. One commenter supported a period of affordability up to 40 years and encouraged HUD to consider mandatory periods coterminous with the compliance requirements of the superior funding source as long as they exceed 30 years.</P>
                    <P>One commenter requested that HUD require HOME periods of affordability to be the greater of (1) the longest period of affordability of any other public assistance program supporting the assisted housing or (2) 10 years for a per-unit HOME investment of under $15,000, 15 years for a per-unit investment between $15,000 and $40,000, 20 years for a per-unit investment of more than $40,000 or any unit involving refinancing of existing debt, and 30 years for any unit involving new construction. The commenter also recommended that HUD consider incentivizing permanent or 99-year periods of affordability by increasing the maximum per-unit HOME subsidy limit in exchange for a commitment to permanent affordability. Another commenter supported lengthening the HOME periods of affordability but urged HUD to reduce long-term compliance requirements to ease administrative burden.</P>
                    <P>Other commenters opposed longer periods of affordability. One commenter said that cash flow challenges are already an obstacle to rental housing development in rural areas, and extending periods of affordability would increase the difficulty of cash-flowing potential projects in those areas further limiting already constrained new unit production. The commenter emphasized that impact on project viability in rural areas should be a prime factor when HUD contemplates changes, including changes to the periods of affordability. Another commenter said that although it requires a 30-year or 40-year affordability terms on multifamily development projects, it does not recommend extending the HOME periods due to the prohibition on investing additional HOME funds in a project during the period of affordability. The commenter opposed extending HOME periods of affordability beyond the life of the HOME-funded improvements. A commenter opposed any extensions to the periods, and especially the 15-year period applicable when HOME funds are used to refinance existing debt, due to increased liability and decreased flexibility and recommended that the period begin when a building is put into service not when it is entered into IDIS.</P>
                    <P>One commenter stated that the period of affordability is too long based on the funding provided and recommended that HOME allow participating jurisdictions to set the period of affordability. The commenter noted that this change would provide flexibility in various housing markets, where needs can vary significantly.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for reviewing the proposed rule and making suggestions. However, for reasons explained above, HUD is declining to lengthen, to align to other programs, or to devolve decision-making on HOME periods of affordability. As required by the Act, HUD has considered both what is the longest period of affordability consistent with sound economics and the purposes for which the HOME program was established in making the determinations reflected in this rule. HUD believes that a participating jurisdiction's use of HOME funds to refinance an owner's existing debt as part of a HOME transaction should be entered into only after careful consideration and a finding that it is an absolute necessity to enable a project to proceed. The period of affordability selected by HUD ensures that the investment of taxpayer funds to pay off an owner's existing debt results in a tangible benefit.
                    </P>
                    <HD SOURCE="HD3">G. Require Different Periods of Affordability Based on Different Considerations</HD>
                    <P>One commenter recommended different periods of affordability for rental and homeowner activities. The commenter stated that a longer period of affordability is a deterrent for single family homeowner programs. The commenter also urged HUD to investigate ways to update the periods of affordability to take into account scenario planning for varying annual appropriations, how long tenants stay in a HOME unit, and the average cost of repairs and how long repairs last.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for reviewing the proposed rule. HUD declines to establish different periods of affordability for homebuyer and rental housing. The longest period of affordability applicable to homebuyer housing is 15 years for a total investment of more than $50,000 in a homebuyer development project or direct subsidy to a homebuyer of $50,000 to facilitate the purchase of a property. The Department does not believe that these periods are unreasonable given the public subsidy being provided. HUD has taken the size of recent HOME appropriations, the useful life of construction or rehabilitation, and the costs of these activities into account in finalizing this rule.
                    </P>
                    <HD SOURCE="HD2">§ 92.252—Qualification as Affordable Housing: Rental Housing</HD>
                    <HD SOURCE="HD3">A. Support for Changes to Rent and Utility Allowances</HD>
                    <P>Commenters supported proposed changes that resulted in more flexible policies with respect to rent and utility allowances. Other commenters worded their support differently and stated that they supported the proposed alignment of the HOME program with the rent limits from other programs involved in a project.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing the proposed rule and providing comments on the proposals related to HOME rental housing. The Department is moving forward with changes to the rent and utility allowance requirements, as described in this preamble.
                    </P>
                    <HD SOURCE="HD3">B. Changes to Marketing Provisions in Introductory Provision</HD>
                    <P>One commenter supported the elimination of the requirement for participating jurisdictions to submit marketing plans to HUD for HOME-assisted units not being leased up within 6 months of project completion. The commenter explained that it, as a participating jurisdiction, works with owners and managers to ensure lease up is timely but would not be the best equipped party to create a marketing plan.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for their support. HUD is moving forward with the proposed change.
                    </P>
                    <HD SOURCE="HD3">C. Support for Not Applying Rent Limits to Payments Under Federal or State Rental Assistance or Subsidy Programs in § 92.252(a)</HD>
                    <P>Commenters stated that they supported the proposal to permit housing developers to allow an owner of a HOME-assisted unit to charge the permissible Housing Choice Voucher (HCV), project-based voucher, or project-based rental assistance rent instead of the maximum HOME rent because it would increase the financial viability of developments.</P>
                    <P>
                        One commenter stated that housing developed for persons at or below 30 percent area median income often includes eight or more government funding sources, each with separate inspection and reporting requirements. 
                        <PRTPAGE P="821"/>
                        The commenter stated that the proposed HOME program alignment will reduce redundancy and increase efficiency. Commenters stated that they support allowing the public housing authority (PHA) rent reasonableness study to serve as the upper limit for rents in a property when an outside subsidy such as Section 8 is used. Another commenter expressed support for aligning § 92.252(a) requirements with HERA rules, and LIHTC rules allowing the owner to receive the rent determined by a PHA in accordance with proposed § 982.507(c)(3) or another Federal or State rental assistance or subsidy program. A commenter noted that the change would align with what has been allowed in LIHTC properties for decades and improve cash flow at properties that have had limited options previously, but that it would be important to ensure adequate funding was provided. Another commenter explained this would ease administrative burden and reduce confusion related to overlapping requirements.
                    </P>
                    <P>Several commenters supported only applying the rent limits to the amounts paid by the tenants in HOME projects. One commenter also supported the removal of rent subsidy from the rent calculation.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing and is moving forward with the proposed language. In addition, in response to the commenters, the Department also considered further streamlining of the rent limit provisions. The Department has determined that it is permissible to revise the High HOME rent limits to exclude the tenant payment when a tenant is participating in a program where the tenant pays no more than 30 percent of their monthly adjusted income or 10 percent of their monthly income towards rent.
                        <SU>58</SU>
                        <FTREF/>
                         This allows Section 8 voucher holders to pay the total tenant payment in accordance with Section 8 requirements and permits the HOME rental housing project owner the ability to accept the rent from both the rental assistance provider and the tenant without limitation. This provision will also increase alignment when combining multiple sources of funding.
                    </P>
                    <FTNT>
                        <P>
                            <SU>58</SU>
                             See 24 CFR 92.252(a)(1)(A).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">D. Opposition to Changes in Rent Limits</HD>
                    <P>One commenter sought clarification on the HOME rent limits and stated that it would not support rent limits being only applied to the tenant portion of rent. The commenter wished for the rent limits to apply to the overall amount received by the owner.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department declines to make the changes recommended by the commenter. HERA is statutory and it is the Department's legal interpretation that the rent limits under the Act do not apply to either the tenant contribution or the rental assistance or subsidy provided to a person or unit under the Section 8 rental assistance programs. The Department lacks discretion to apply the rent limits to the overall amount received by the owner, as this is contrary to law and the intent of Congress.
                    </P>
                    <HD SOURCE="HD3">E. Request To Further Revise HOME Rent Requirements in § 92.252(a)</HD>
                    <P>Another commenter supported the proposed change as it considerably simplifies compliance for voucher holders. The commenter recommended that the changes should remove the “project-based” language and the requirement that the “very low-income family pays as a contribution toward rent not more than 30 percent of the family's adjusted income” from § 92.252(b)(2)(ii) because the PHA or subsidy provider should be determining what the household must contribute to rent under their program.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department is revising the language of § 92.252(a) in response to public comments. The Department has expanded the provision to state 30 percent of the family's monthly adjusted income or 10 percent of the family's monthly income, to align with the Section 8 regulations on total tenant payment. The Department has added this language to both the High and Low HOME rent provisions and will allow tenants to pay the amount determined under the Section 8 program when a voucher holder is also living in a HOME-assisted unit.
                    </P>
                    <HD SOURCE="HD3">F. Permit an Owner To Receive Rent Determined by a Local Government Rental Assistance or Subsidy Program in § 92.252(a)</HD>
                    <P>Commenters stated that HUD should permit an owner to receive rent determined by a local government rental assistance or subsidy program in addition to the allowance of receipt of rent determined by a PHA or another Federal or State rental assistance or subsidy program. The commenter recommended HUD amend the proposed language in § 92.252(a) from “rent limits do not apply to any payment provided under a Federal or State rental assistance or subsidy program . . .” to “rent limits do not apply to any payment provided under a Federal, State, or local government rental assistance or subsidy program.”</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department considered the commenter's request, examined the Act in light of the passage of HERA, and has determined that Congress did not intend to apply the rent limits to families that were paying, as a contribution towards rent, no more than 30 percent of their monthly adjusted income or 10 percent of their monthly income in another program. The Department has revised § 92.252(a) accordingly. The Department also expanded the language in § 92.252(a) to cover local rental assistance programs, as requested by the commenter. This fully addresses the commenter's concerns and allows owners to accept the rent contribution of a family under Section 8 and similar rental assistance programs.
                    </P>
                    <HD SOURCE="HD3">G. Change Low HOME Rent Requirements in § 92.252(a) To Be Based on Gross Income</HD>
                    <P>Commenters also proposed amending the language of § 92.252(a)(2)(ii) to say, “[T]he rent contribution of the family is not more than 30 percent of the family's gross income,” similar to recent HOTMA changes implemented for rental assistance programs, in order to align more closely with the intent to streamline housing programs and assistance.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for reviewing the proposed rule. 42 U.S.C. 12745(a)(1)(B) requires that “not less than 20 percent of the units (i) occupied by very low-income families who pay as a contribution toward rent (excluding any Federal or State rental subsidy provided on behalf of the family) not more than 30 percent of the family's monthly adjusted income as determined by the Secretary . . .” HUD lacks the discretion to change the requirement from the statutory 30 percent of “monthly adjusted income” to 30 percent of “gross income” that the commenter has recommended.
                    </P>
                    <HD SOURCE="HD3">H. Allow Owners To Collect Full Contract Rent When the Tenant Rental Contribution of a Family That Received Section 8 Rental Assistance in a HOME Unit Earns More Than 65 Percent of Area Median Income in § 92.252(a)</HD>
                    <P>
                        A commenter supported the alignment of project- and tenant-based subsidized rents and Low and High HOME units in § 92.252 but stated that High HOME rent units still face an issue when tenants paying their share of the rent under the subsidy program have a tenant rent that exceeds the otherwise applicable HOME limit. The commenter urged HUD to allow the collection of the 
                        <PRTPAGE P="822"/>
                        full subsidy for all HOME units that are currently allowed for Low HOME rent units where families are paying 30 percent of adjusted income as required by a rental assistance program. The commenter suggested addressing this issue by adding the same clause to the definition of High HOME rent limits as exists for Low HOME by adding a new § 92.252 (b)(1)(iii) which would say “[t]he rent contribution of the family is not more than 30 percent of the family's adjusted income.” The commenter stated that PBRA policy allows families to decide if they want to keep the security of their subsidy or let it go in favor of lower rents applicable to another program and stated that this could also apply to HOME.
                    </P>
                    <P>One commenter expressed support for the change to allow owners to charge rents that exceed the HOME rent limits for units occupied by tenants with tenant-based vouchers (in alignment with changes made to the Section 8 programs and HERA), but was concerned about how this will impact underwriting financial feasibility at the time of application and possible unintended consequences.</P>
                    <P>Another commenter stated that HUD should align HOME rent limits with the Section 8 programs for PBVs. The commenter stated that they support this approach because, from an underwriting perspective, it is important to not over-subsidize units, and it is easier to underwrite higher rents when they are guaranteed PBVs.</P>
                    <P>A commenter stated that, as long as the unit is receiving at least one dollar in subsidy, the HOME program should not impose any restrictions on gross rent or the tenant portion of rent for households receiving PBVs, housing choice vouchers (HCV), or Veterans Affairs Supporting Housing (VASH) vouchers. The commenter stated that this approach aligns with the LIHTC program requirements.</P>
                    <P>A commenter stated that for projects that have both PBVs and HOME funds, it will be more difficult for PJs to regulate the HOME rent limit being applied to the tenant portion of the rent.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department considered the commenter's request, examined the Act and HERA, and has determined that Congress did not intend to apply the HOME rent limits to families that were paying, as a contribution towards rent, no more than 30 percent of their monthly adjusted income or 10 percent of their monthly income. The Department has revised § 92.252(a) accordingly. This fully addresses the comment and allows for owners to accept the rent contribution of a family under Section 8, including HUD VASH and similar rental assistance programs.
                    </P>
                    <HD SOURCE="HD3">I. Underwrite to HOME Rent Limits in § 92.252(a) for Units Without Project-Based Rental Assistance</HD>
                    <P>
                        One commenter recommended that HUD specifically state in the final rule that the HOME rent limits 
                        <E T="03">must</E>
                         be used for units 
                        <E T="03">without</E>
                         project-based rental assistance (
                        <E T="03">i.e.,</E>
                         units that 
                        <E T="03">may</E>
                         have tenants with vouchers, but it is not certain at the time of underwriting). If higher rents are assumed for those units, rental income may be artificially inflated; however, after initial occupancy, the commenter believes it would be appropriate to allow owners to charge the allowable rents under the tenant based rental assistance program to generate additional income and help ensure the project is sustainable for the long term.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for the feedback and agrees with the commenter that unless a project has been awarded a HAP contract and is assured continued provision of project-based rental assistance or project-based vouchers, HOME units should be underwritten using the High and Low HOME Rents. It would not be consistent with the regulation at § 92.250(b) to assume that HOME units will be occupied by people who have Housing Choice Vouchers because there would be no basis for the assumptions around the operating income for the project. However, the Department declines to codify this requirement, as each project is different and there are a variety of other funding sources that may be layered together in a HOME project, some with their own rents that must be factored into underwriting.
                    </P>
                    <HD SOURCE="HD3">J. Allowing Owners To Accept the Full Section 8 Contract Rent in § 92.252(a) May Change Owner Behavior</HD>
                    <P>
                        One commenter expressed concern that allowing owners to charge rents that exceed the HOME rents for units occupied by tenants with vouchers might inadvertently incentivize owners to rent 
                        <E T="03">only</E>
                         to tenants 
                        <E T="03">with</E>
                         vouchers. The commenter notes that many more households need rental assistance than receive the assistance; however, HOME units are more affordable than market rate housing, and eligible tenants should be able to access the units without barriers. The commenter expressed concern that the unintended incentive for owners to rent only to tenants with vouchers could have fair housing implications.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the commenters concern but would like to note that the Act expressly permits project owners to accept tenants with Section 8 vouchers. Specifically, section 12745(a)(1)(D) of the Act states that “Housing that is for rental shall qualify as affordable housing under this subchapter only if the housing . . . (D) is not refused for leasing to a holder of a voucher or certificate of eligibility under section 1437f of this title because of the status of the prospective tenant as a holder of such voucher or certificate of eligibility . . .” This statutory requirement is reflected in § 92.253 which also requires project owners to have and follow written tenant selection policies and procedures and provide for the selection of tenants from a written waiting list in the chronological order of their application, insofar as is practicable. Given the statutory and regulatory requirements for tenant selection, the Department believes it is Congress's intent to incentivize owners in the HOME program to include tenants with Section 8 vouchers or rental assistance in their projects and to allow the owners to accept the total tenant payment and the contract rent for the family's unit. To that end, the Department has expanded the prohibition against source of income discrimination to also include State and local rental assistance programs, as the Department believes it is consistent with the purposes of the Act to allow holders of such forms of assistance the ability to use their assistance to live in HOME units.
                    </P>
                    <HD SOURCE="HD3">K. Support for Utility Allowance Changes to § 92.252(b)</HD>
                    <P>
                        One commenter expressed support for the proposed language in § 92.252(b) that would allow use of the HUD Utility Schedule Model (HUSM), public housing authority utility allowance, or other method approved by HUD, reasoning that HUD should allow more options because: there are difficulties in getting detailed utility data in rural areas; more options would be consistent with other HUD program requirements; and, if options remain limited, Indian Tribes and Indian Housing Authorities may operate rental assistance programs with their own conflicting rules. The commenter explained that the public housing authority utility allowance would be easier to administer for less-experienced project owners with small projects and portfolios. The commenter also encouraged HUD to allow HUSM as an option for all HOME-assisted rental units rather than just units with specified rental assistance programs. Furthermore, the commenter requested that both telephone 
                        <E T="03">and</E>
                         internet be 
                        <PRTPAGE P="823"/>
                        listed as exclusions from utilities and services in § 92.252(b).
                    </P>
                    <P>Another commenter supported the proposed exceptions for HOME projects with Section 8 Project Based Voucher (PBV) and HUD-VASH but noted that utility allowances determined by local public housing authorities are almost always either significantly higher or lower than other models, which ends up being inequitable for tenants or unfair for owners.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing and is moving forward with the proposed language in § 92.252(b) allowing participating jurisdictions to use the HUD Utility Schedule Model, the utility allowance established by the applicable local PHA, or other method approved by HUD for its maximum monthly utility allowances. This change will make all three options available for all HOME-assisted rental units. The Department is listing broadband as an exclusion from utilities and services in § 92.252(b) to help clarify utilities covered by the utility allowance.
                    </P>
                    <P>The Department has noted the commenter's concern about inequities in utility allowances determined by public housing authorities but has seen no data demonstrating that price differences as drastic or prevalent as described exist. Furthermore, if a participating jurisdiction finds the utility allowance determined by its local PHA unsuitable, it is now able to choose a more suitable model (the HUD Utility Schedule Model or another method approved by HUD) for its project.</P>
                    <HD SOURCE="HD3">L. Support for Utility Allowance Changes in § 92.252(b)—Alignment With PHA Utility Schedule</HD>
                    <P>One commenter supported the use of the PHA utility allowance in all HOME-assisted rental projects because a standardized utility allowance allows for better compliance monitoring. In addition, the commenter stated that, to make compliance significantly easier, a participating jurisdiction should still be able to establish the effective date of the utility allowance to align with revisions to the HOME rents.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for their review and notes that the final rule does not prescribe a timeline for annual updates to rents and utility allowances.
                    </P>
                    <HD SOURCE="HD3">M. Confusion Over Utility Allowances in § 92.252(b)</HD>
                    <P>One commenter recommended that HUD create a pathway for compliance for rental subsidy programs that include the household's contribution to utilities as part of their rental contribution and that HUD move the language at § 92.252(b)(2)(ii) out of paragraph (b) so that rent can go up to the maximum allowed under the Federal or State rental subsidy.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         In the rental subsidy programs that the commenter describes, the subsidy provider pays the owner directly on behalf of the renting household or tenant. Under the HOME regulations § 92.252, utility allowances are provided for tenant-paid utilities in HOME-assisted rental units. The Department declines to change the existing language, as the situation outlined by the commenter does not apply to HOME.
                    </P>
                    <HD SOURCE="HD3">N. Support for 60-Day Notice Requirement Before Imposing Rent Increases in § 92.252(e)</HD>
                    <P>One commenter supported the increase in the minimum number of days required from 30 to 60 for a rent increase.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for their support of the proposed period for rent increases. HUD is adopting propose rule language to ensure that tenants of HOME-assisted rental units have adequate notice of rent increases proposed by the owner and approved the participating jurisdiction.
                    </P>
                    <HD SOURCE="HD3">O. Revise § 92.252(g)(2) To Use Different Terminology</HD>
                    <P>One commenter suggested that the proposed regulatory text at § 92.252(g)(2) be revised to list “rental” rather than “multifamily”.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD agrees with the commenter and is making the change.
                    </P>
                    <HD SOURCE="HD3">P. Rent Restrictions in § 92.252(h)</HD>
                    <P>One commenter stated that the proposed §  92.252(h)(2)(i) should allow tenants of HOME-assisted projects with multiple sources of funding to pay the rent amount required under any of the programs' requirements, not just LIHTC.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department agrees with the commenter and has expanded the owner's ability to accept the rent and total tenant payment for other programs that are often combined with HOME assistance in HOME rental housing projects, including programs that require tenants to pay no more than 30 percent of their monthly adjusted income or 10 percent of their monthly income. The Department also codified provisions on LIHTC rents that are contained in 42 U.S.C. 12745(a)(1)(B) of the Act. The Department also expanded the amount of rent that an owner may receive for over-income tenants by also allowing the owner to accept the subsidy provided under a program that provides Federal, State, or local rental assistance or subsidy (see § 92.252(h)(iii)). This should adequately address the commenter's concerns.
                    </P>
                    <P>
                        <E T="03">Specific solicitation of comment #6: Rather than permitting all HOME-assisted projects to use the local PHA's utility allowance, should HUD limit the use of the PHA utility allowance to only HOME-assisted projects which also receive PBV or HUD-VASH PBV assistance?</E>
                    </P>
                    <HD SOURCE="HD3">A. Comments in Support of Allowing a Participating Jurisdiction To Use a Local PHA Utility Allowance</HD>
                    <P>Commenters predominantly supported permitting all HOME-assisted projects to use the local public housing authority's utility allowance, noting that the change would make the process simpler, more effective, provide greater flexibility to participating jurisdictions and developers, and align HUD's process and operations with programs like HTF and LIHTC.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks commenters for reviewing and is adopting language permitting participating jurisdictions to use the HUD Utility Schedule Model, the utility allowance established by a local PHA, or other methods approved by HUD for their maximum monthly allowances.
                    </P>
                    <HD SOURCE="HD3">B. Comments in Support of Allowing a Participating Jurisdiction To Use a Local PHA Utility Allowance With Changes</HD>
                    <P>In expressing their support, many commenters included addendums or clarifications they suggested be made to this proposed policy. One commenter advised HUD to clarify that using the housing authority-established utility allowance is not a requirement for all units, and that a participating jurisdiction may work with the property owner to determine whether the public housing authority or a property-specific utility allowance is more appropriate. This commenter, as well as another otherwise-supportive commenter, advocated for the use of alternative energy models to provide flexibility for projects with different energy use profiles, with the public housing authority's utility allowance serving as the baseline option to reduce soft costs and provide clear alignment with other funding programs.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing and is moving forward with the proposed language in § 92.252(b) allowing participating jurisdictions to use the HUD Utility Schedule Model, the utility allowance established by the local PHA, or other method approved by HUD for their maximum monthly utility allowances. Which of the three methods 
                        <PRTPAGE P="824"/>
                        is selected is at the participating jurisdictions' discretion. Participating jurisdictions that wish to utilize alternative energy models (or any other utility allowance method that is not the HUD Utility Schedule Model or the utility allowance established by a local PHA) may submit a request to HUD for review.
                    </P>
                    <HD SOURCE="HD3">C. Requests for Clarification of Utility Allowance Requirements</HD>
                    <P>One commenter recommended that HUD clarify the utility rates for communities not served by a local public housing authority. Commenters noted that grantees are confused when State agencies require different utility allowances than local participating jurisdictions and recommended that HUD allow participating jurisdictions to coordinate program funding.</P>
                    <P>Another commenter recommended HUD clarify which utility allowance should be used where more than one housing authority has PBVs in a development layered with HOME units. In the absence of PBVs, the commenter stated that the participating jurisdiction needs to have authority to determine the most applicable housing authority utility allowance. If HUD does not leave this decision to participating jurisdictions, the commenter suggested that HUD adopt a rule stating that the applicable public housing authority utility allowance is the smallest unit of government. The commenter also recommended that HUD allow participating jurisdictions to establish rules in areas without applicable housing authorities preventing developments from using a housing authority's utility allowance.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks commenters for their review and is adopting the proposed language in § 92.252(b) allowing participating jurisdictions to use the HUD Utility Schedule Model, the utility allowance established by the applicable local PHA, or other method approved by HUD for their maximum monthly utility allowances. HUD does not recommend or require any one of the three available options over any other—this is left up to the participating jurisdictions' discretion. If a utility model from a statewide entity that is funding a project is available, the participating jurisdiction may submit a request to HUD for use of that model in its project. Usually, there is at least one public housing authority serving a specific jurisdiction, whether it be a state, regional, county, or city public housing authority. The Department believes that the applicable local public housing authority will typically be the one that administers the project-based voucher assistance to the property, if the project contains project-based voucher units, or the public housing authority that the participating jurisdiction determines is most representative of the community where the project is located.
                    </P>
                    <HD SOURCE="HD3">D. Request for Technical Assistance on Utility Allowance Requirements</HD>
                    <P>One commenter supported the inclusion of public housing authority utility allowance but stated that HUD should provide technical assistance to ensure allowances are updated in a timely manner.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department provides technical assistance to public housing authorities and participating jurisdictions in a variety of areas, including utility allowances. The Department will examine further ways to ensure that utility allowances are updated in accordance with the applicable program regulations, including through additional guidance and engagement with participating jurisdictions and public housing authorities.
                    </P>
                    <HD SOURCE="HD3">E. Align Utility Allowances With State LIHTC Requirements</HD>
                    <P>One commenter supported mirroring State agency requirements for utility allowance use on LIHTC properties.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department is adopting the proposed language in § 92.252(b) allowing participating jurisdictions to use the HUD Utility Schedule Model, the utility allowance established by the local PHA, or other method approved by HUD for their maximum monthly utility allowances. Which of the three methods the participating jurisdiction uses is up to the participating jurisdictions' discretion. State LIHTC requirements do not fall under HUD's purview. If a participating jurisdiction wishes to use a utility model from a statewide entity for its HOME project, the participating jurisdiction may submit a request to HUD for use of that model.
                    </P>
                    <HD SOURCE="HD3">F. Opposition or Conflicted Beliefs on Applying PHA Utility Allowance</HD>
                    <P>Two commenters did not support permitting all HOME-assisted projects to use the local housing authority's utility allowance. The first commenter stated that using utility information specific to a property is in the best interests of all parties and suggested that HUD use gathered data to ensure that tenants will not be harmed with higher rents caused by less accurate utility allowances (in the case that the local housing authority's utility allowance be permitted for all HOME-assisted projects). The second commenter supported no change to the current method, as HUD has generally expressed flexibility on the rule in the past, which the commenter found helpful when other funding sources have different utility allowances.</P>
                    <P>One commenter was conflicted about whether aligning HOME-assisted units with PBVs and/or HUD-VASH Vouchers should apply universally to all HOME-assisted units, explaining that while public housing authority rates could be more cost- and time-effective for nonprofits, they are often higher than those found with individual analysis by a developer using the HUSM at the time of application.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the recommendations made by the commenters but believes that allowing participating jurisdictions to use the HUSM, the utility allowance established by the local PHA, or other method approved by HUD for their maximum monthly utility allowances provides participating jurisdictions with far more flexibility than was permitted prior to this change. With the ability to choose one of the three options presented, participating jurisdictions will be able to select a method that they have determined to be in the best interests of all parties, whether that is in regard to accuracy, time-, or cost-effectiveness. If the Department does not include the local public housing authority's utility allowance as one of the options, then each time that HOME assistance is combined with project-based vouchers or project-based VASH units, the Department will have to waive the utility allowance regulations in § 92.252. This misalignment between HUD programs delays the provision of HOME assistance and projects, requires the Department to waive the regulation, and causes some owners and developers not to combine the two forms of assistance in the same project.
                    </P>
                    <P>
                        <E T="03">Specific solicitation of comment #5:</E>
                         The Department specifically requests public comment from participating jurisdictions and program participants regarding the challenges they have encountered in using HOME funds to assist small-scale housing, as defined in this proposed rule. The Department also requests public comment regarding the costs and benefits of the changes that HUD is proposing for small-scale housing in requirements for the frequency of income determinations and inspections and the use of alternative waiting lists.
                    </P>
                    <HD SOURCE="HD3">A. Support for Small-Scale Changes</HD>
                    <P>
                        Several commenters supported the changes to monitoring compliance in 
                        <PRTPAGE P="825"/>
                        small-scale housing projects. One commenter supported the lowering of barriers for small-scale rental properties through the proposed changes to §§ 92.2, 92.251, 92.252, and 92.253. The commenter emphasized their belief that rural areas, as well as areas with limited buildable land, would greatly benefit from the same lowering of barriers, due to a dearth of CRA-driven investment, and economic challenges to new rental unit development in these communities. One commenter believed that small-scale housing provides a tremendous investment opportunity for production and preservation of affordable housing.
                    </P>
                    <P>Another commenter supported HUD's proposed changes and believes the benefits of reducing the burden for owners of small-scale housing outweigh the possible public benefit loss of reduced compliance requirements.</P>
                    <HD SOURCE="HD3">
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for their review of the HOME rule. HUD is moving forward with the small-scale flexibilities it proposed.
                    </HD>
                    <HD SOURCE="HD3">B. Support for Small-Scale Housing Inspection Requirements</HD>
                    <P>Several commenters supported a three-year property inspection for small-scale HOME-assisted projects. One commenter supported inspecting small-scale housing every three years instead of using a risk-based schedule for small-scale housing inspections. One commenter supported the proposal to allow participating jurisdictions to adopt customized inspection schedule for small-scale housing where health and safety deficiencies have been identified and corrected.</P>
                    <P>One commenter stated that the streamlined inspection procedures for small-scale rental projects would not likely assist emerging developers, but would assist existing affordable housing developers acquire, rehabilitate, or build new small-scale units.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the commenter's review of the proposed rule. HUD is adopting the proposed rule language related to the frequency of physical inspections. HUD believes the flexibilities provided to small-scale housing owners will help all owners of small-scale housing projects, whether they be emerging developers, homebuyers that purchase multi-unit structures and rent them as HOME rental housing units, or developers that have significant experience in the program already.
                    </P>
                    <HD SOURCE="HD3">C. Objections to Small-Scale Housing Inspection Requirements</HD>
                    <P>One commenter objected to HUD's changes to property inspection requirements for small-scale rental housing. The commenter explained that small-scale projects already struggled to maintain compliance with physical condition requirements, that this was exacerbated by the pandemic and the shortage of qualified property managers in their State. The commenter believed that reducing the frequency of inspections will lead to the rapid deterioration of units and to ongoing compliance challenges.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the commenter's concern about inspections of physical condition for small-scale rental projects. The HOME program is a block grant program that permits participating jurisdictions to determine how best to design and administer their affordable housing programs, as long as they comply with the minimum requirements established in the HOME regulations. As a participating jurisdiction, the commenter has the flexibility to adopt inspections procedures for small-scale rental projects and other rental projects that are more frequent than required in the regulations. HUD is adopting the alternative inspection protocol for small-scale projects to help facilitate the use of HOME for small-scale rental housing. As a reminder, participating jurisdictions must also comply with all applicable Federal fair housing and civil rights requirements in the administration of their affordable housing programs in addition to the HOME regulations.
                    </P>
                    <HD SOURCE="HD3">D. Support for Small-Scale Rental Housing Waiting List Requirements</HD>
                    <P>Several commenters supported the proposed changes to tenant selection procedures in small-scale rental housing. Commenters specifically supported permitting participating jurisdictions to establish policies to identify tenants when vacancies occur in small-scale housing. One commenter believed that HUD's proposed update allowing participating jurisdictions to create alternative waiting list procedures would empower participating jurisdictions to create and enact policies aligned with their respective programs and more responsive to owner and tenant needs. One commenter stated that they support HUD's proposed changes to the alternative waiting list requirements because they would reduce the length of turnover of units from one renter to the next.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for reviewing the rule and is adopting the alternative waiting list provision with a revision described below.
                    </P>
                    <HD SOURCE="HD3">E. HUD Approval of Waiting List Requirements</HD>
                    <P>One commenter stated the requirement to get pre-written HUD approval of alternative procedures for a written waiting list for small-scale housing would hamper small-scale housing. The commenter recommended that HUD publish in a manner viewable by all participating jurisdictions and a list of previously approved alternative tenant selection procedures, as well as grant participating jurisdictions presumptive approval if they implement one of the previously approved methods for small-scale housing. Another commenter similarly requested clarification or examples of acceptable alternatives to written tenant waitlists.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for reviewing the proposed rule. To reduce burden, the Department is removing the requirement that it approve a participating jurisdiction's alternative written waiting list and will provide further guidance on required and recommended elements of such plans. Such plans, among other obligations, must be nondiscriminatory and all tenant selection plans and waiting list procedures must comply with Federal fair housing and civil rights requirements. Participating jurisdictions' alternative waiting lists will be subject to compliance monitoring rather than prior approval.
                    </P>
                    <HD SOURCE="HD3">F. Support for Reducing Income Examination Requirements</HD>
                    <P>Several commenters supported permitting streamlined or less frequent procedures for small-scale rental housing projects (one to four total units) for reexamination of annual income. One commenter supported the changes HUD made to reduce the burden but believed that HUD should make income recertifications more flexible.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD believes that it is being as flexible as it can be with income recertifications. By moving to a triennial income recertification process for small-scale rental housing, the Department is balancing the need to examine income for families whose rents are income-dependent with the need to provide administrative relief to participating jurisdictions administering small-scale projects across their jurisdictions. HUD has provided additional flexibilities to expand safe harbors in income examinations and believes that the combination of these flexibilities is sufficient to address the commenters concerns. HUD will continue to review income examination policies in the future as the Department seeks to balance the need for accurate 
                        <PRTPAGE P="826"/>
                        family income data with the burden of income reexamination placed on tenants, owners, and participating jurisdictions.
                    </P>
                    <HD SOURCE="HD3">G. Eliminate Income Reexaminations in Small-Scale Rental Housing Projects</HD>
                    <P>One commenter suggested conducting income determinations only upon unit turnover to reduce administrative burden and impact on tenants. The commenter also suggested requiring that 100 percent of beneficiary households have incomes at or below 60 percent of area median income at initial lease up, which is what the City of Madison and State of Wisconsin require, to address concerns regarding benefitting households over 80 percent of area median income.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The HOME statute at 42 U.S.C. 12756(b) and 42 U.S.C. 12745(a) require that participating jurisdictions monitor owners for compliance with HOME requirements, including income examination requirements, and that rents be determined based upon income examinations. The commenter is proposing that tenants never be reexamined for income, similar to HOME's homeownership activities. This is not consistent with the HOME statute. 42 U.S.C. 12756(c) permits the Secretary to “provide for such streamlined procedures for achieving the purposes of this section” for small-scale or scattered site projects. The Department has determined that eliminating income reexamination requirements for tenants in small-scale rental housing is inconsistent with the HOME statute, which requires income reexaminations for all tenants in rental housing. Rents for over-income tenants have an income-based component and to ignore those requirements completely would not be achieving the purposes of the monitoring provisions of the Act.
                    </P>
                    <HD SOURCE="HD3">H. Small-Scale Housing Projects Present Monitoring and Oversight Challenges</HD>
                    <P>One commenter was critical of the small-scale and scattered site housing models. The commenter said that the new rules would make it challenging to produce small-scale and scattered site housing. The commenter believed that enforcing the period of affordability and monitoring requirements on these owners causes additional administrative burden to participating jurisdictions. The commenter also thought that this was encouraging an inefficient use of scare program resources. The commenter encouraged HUD to review financial and commercial viability of the scattered site approach for housing fulfillment, given these concerns.</P>
                    <P>Two commenters stated they were concerned about the small-scale housing inspections and monitoring because small-scale housing providers often have less oversight experience or ability. One of these commenters stated that this lack of experience may unintentionally decrease the frequency and quality of inspections.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for reviewing the proposed rule. One commenter mistakenly believes that the small-scale housing requirements are new requirements imposed on participating jurisdictions. This is incorrect. The commenter also states that enforcing the period of affordability and monitoring small-scale projects are too burdensome for participating jurisdictions. Small-scale housing has heretofore been subject to all HOME rental housing requirements; this final rule reduces this burden to make it easier to use HOME for these projects. The Department is adding these monitoring flexibilities for small-scale housing projects to better implement the Act, which authorized the Department to provide streamlined procedures for achieving the purposes of the Act as the Secretary determines to be appropriate.
                        <SU>59</SU>
                        <FTREF/>
                         The Department believes that the drafters of the Act intended for small-scale housing projects, including scattered site projects, to be funded under HOME, and that it is best left to participating jurisdictions on whether to fund these types of projects.
                    </P>
                    <FTNT>
                        <P>
                            <SU>59</SU>
                             See 42 U.S.C. 12756(c).
                        </P>
                    </FTNT>
                    <P>Other commenters who expressed concerns about the adequacy of monitoring and inspections under this proposal mistakenly assume that owners, not participating jurisdictions conduct physical inspections and monitoring. HUD is not changing the requirement that the participating jurisdiction engage in onsite monitoring and review of small-scale projects, it is just changing how this monitoring is performed to reduce the burden on participating jurisdictions and owners. HUD believes that this final rule appropriately balances burden reduction and compliance for small-scale housing projects.</P>
                    <HD SOURCE="HD3">I. Opposition to Changes to Small-Scale Housing</HD>
                    <P>One commenter believed that the small-scale changes were not helpful. The commenter was not supportive of using HOME funds for small-scale rental housing projects, believed that CDBG funding was more attractive because it entailed fewer requirements, and believed that owners of small-scale rental housing had no interest in complying with HOME requirements. In the commenter's experience, when the commenter did provide CDBG funds to owners of small-scale housing projects, it was difficult to obtain required documentation, including tenant rents, ethnicity, and income. The commenter also believed that the small-scale housing project requirements did not streamline requirements for the development small-scale housing but only improved how the ongoing requirements are monitored.</P>
                    <P>Another commenter expressed concerns about enabling increased owner-occupied HOME-assisted rental unit creation, as the commenter's experience is that low-income homebuyers who are immediately made the owners of HOME-assisted rental units have a very high failure rate when it comes to compliance with HUD regulations. The commenter said that the administrative burden on such homeowners would still be too high even despite the lowering of barriers in this proposed rule and the commenter does not support a system that sets its neighbors up to fail. Further, the commenter said that a newly rehabilitated or constructed duplex or triplex would better serve their communities as either individual homeownership units or as properly administered affordable rental units.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for reviewing the proposed rule. The Department understands that developing and managing small-scale housing can be challenging. Despite these challenges, such housing can play an important role in meeting a community's affordable housing needs. HUD notes that NAHA provides it with authority to establish streamlined requirements with ongoing oversight and compliance of small-scale and scattered site projects, not with respect to the development of that housing. HUD recognizes that not all communities will decide to pursue small-scale housing due to the challenges and priorities cited by the commenters. However, the Department believes that burden relief is beneficial to participating jurisdictions that wish to pursue that strategy and that such revisions are in furtherance of the Act.
                    </P>
                    <HD SOURCE="HD3">J. Small-Scale Housing Project Flexibilities Are Insufficient or Not Helpful</HD>
                    <P>
                        One commenter supported HUD's changes but noted that leading challenges of applying HOME towards small-scale housing include high costs in providing gap financing in rural areas and a lack of training. The commenter 
                        <PRTPAGE P="827"/>
                        encouraged HUD to create policies that are responsive to State and local conditions and empower participating jurisdictions to use HOME funds for targeted developments accordingly. The commenter noted that the use of property management firms may assist in managing small-scale rental housing.
                    </P>
                    <P>Another commenter said that the reduction or streamlining of regulatory requirements such as inspections and wait lists would make it more attractive to use HOME funding, but compliance would still remain more onerous than the commenter's city-funded program. The commenter explained that their city offers a rental rehabilitation loan program for properties with seven or fewer units where landlords are required only to preserve 50 percent of units for occupants earning at or less than 60 percent of area median income through a 10-year loan term; but that HOME's compliance requirements make it undesirable to utilize HOME for such programs.</P>
                    <P>Another commenter urged HUD to consider how private market financing conflicts with HOME requirements, especially for condominium development which have early pre-sale requirements from Fannie Mae and Freddie Mac that conflict with HOME's requirement to recheck income after six months.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for reviewing the proposed rule. As stated above, the Department understands that developing and managing small-scale housing can be challenging, as can oversight by participating jurisdictions and other funders. HUD did not propose these streamlining measures for small-scale rental housing because it believed that every jurisdiction would or should adopt this activity with its HOME funds. Rather, HUD's intent is to make small-scale housing easier to manage and oversee for owners and participating jurisdictions that choose to undertake it with HOME funds. With respect to the comments regarding conflicts between HOME requirements and Fannie Mae and Freddie Mac pre-sale programs, HUD notes that while a small-scale housing project can have a homeownership unit, the rest of the units in the project must be for rental. Therefore, the condominium purchase rules being described are likely not applicable. In any event, the Department has given exhaustive explanation earlier in this preamble about why it is declining to extend the amount of time that an income determination is valid when purchasing housing with HOME homeownership assistance.
                    </P>
                    <HD SOURCE="HD3">K. Accessibility Requirements Are a Barrier to Small-Scale Housing Projects</HD>
                    <P>One commenter stated that the Uniform Federal Accessibility Standards (UFAS) requirements for small-scale housing have made it virtually impossible to fund small rehabilitation developments. The commenter supported more waivers or modified requirements for small rehabilitation developments.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for reviewing the proposed rule. Section 504 of the Rehabilitation Act of 1973 (Section 504), and HUD's implementing Section 504 regulation at 24 CFR part 8 prohibit recipients from discriminating on the basis of disability. By definition, small-scale housing projects are single family housing consisting of no more than four units or scattered-site projects consisting of no more than four units. These projects do not meet the definition of multifamily housing subject to the requirements that a percentage of newly constructed or rehabilitated units be accessible to individuals with mobility impairments and an additional percentage of units be accessible to individuals with vision and hearing impairments in compliance with HUD's accessibility standards, (
                        <E T="03">i.e.,</E>
                         UFAS or HUD's Deeming Notice).
                    </P>
                    <P>A recipient must provide for reasonable accommodations that may be necessary for individuals with disabilities. A recipient's obligations under Section 504 cannot be waived. Such requirements ensure that individuals with disabilities are able to participate in, and are not denied the benefits of, such programs or activities. As a reminder, recipients may also be subject to additional accessibility requirements under the Fair Housing Act, and title II of the Americans with Disabilities Act (ADA).</P>
                    <HD SOURCE="HD3">L. Request To Reduce Environmental Review Requirements for Small-Scale Housing Projects—HUD Should Change Environmental Review Requirements for Small-Scale Projects</HD>
                    <P>One commenter suggested that, to lower the cost of the production of affordable housing and encourage more supply while still protecting the environment, HUD should change its regulations governing the three project/activity types in this paragraph. They are currently governed under 24 CFR 58.35(a) but should be governed under 24 CFR 58.35(b). The commenter stated that this change would still ensure that reasonable impacts were examined before project commencement, while lowering the burdens and costs to re-entering dilapidated housing stock back onto the market. The commenter also supported retaining limited historic preservation protections, explaining that such limited protections would reduce the delays incumbent in current historic preservation compliance, while retaining State Historic Preservation Officer notification. The commenter suggested that flexibility for waiting periods to run concurrently with participating jurisdictions and HUD review should be explored.</P>
                    <P>The commenter stated that to lower the cost of the production of affordable housing and encourage more supply while still protecting the environment, HUD should expand the scale of projects that can qualify as categorically excluded. The commenter reasoned that increasing the current categorical exclusion to individual actions on between 5 and 15 scattered site dwelling units or housing units will lower costs, burdens, and speed the delivery of units, while still examining all environmental impacts.</P>
                    <P>Lastly, the commenter recommended that HUD should use this existing authority to include HOME funds deployed for small (one-four unit) residential projects via nonprofit affordable housing developers as an exception criterion35. The commenter explained that this would allow the nonprofits to work with their local governments, who act as the responsible entity, for speedier resolutions of all existing environmental review processes.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the commenter's suggestions related to streamlining the environmental review procedures at 24 CFR part 58. However, the authority granted to HUD at 42 U.S.C. § 12756 to establish streamlined procedures for small-scale and scattered site housing extends only to monitoring of such housing after project completion. The commenter's suggestions relate to project development rather than ongoing compliance and thus are outside the scope of this rulemaking. Moreover, the Department did not propose making any revisions to environmental review requirements for HOME projects in the proposed rule and believes that such changes are also beyond the scope of this rulemaking.
                    </P>
                    <HD SOURCE="HD3">M. Other Comments in Solicitation—Create New Eligible Activity for Inspections</HD>
                    <P>
                        One commenter stated that participating jurisdictions stated that the need to regularly inspect all units in small-scale housing every three years is a major expense. The commenter 
                        <PRTPAGE P="828"/>
                        recommended that HUD allow participating jurisdictions to create an IDIS activity called “HOME Inspections” that would enable inspection costs to be charged to that activity and not count the on-site inspection expenses as a part of HOME administration. The commenter recommended that the planning and preparation for the HOME inspections be counted as an administrative cost while the actual site inspection costs would be counted as activity delivery expenses.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the comment. However, the HOME statute The Act does not permit HUD to establish new activities in IDIS for the types of ongoing administrative costs described by the commenter. 
                        <E T="03">See</E>
                         42 U.S.C. 12742. During the HOME period of affordability, the participating jurisdiction may charge the cost of periodic inspections to HOME administration in accordance with § 92.207, or the participating jurisdiction may charge a reasonable monitoring fee to the project owner in accordance with § 92.214(b)(1)(i).
                    </P>
                    <HD SOURCE="HD3">N. Other Comments in Solicitation—Opposition to Financial Oversight Requirements</HD>
                    <P>One commenter believed that the current financial oversight requirements are inadequate and that not performing financial oversight on small-scale rental housing ignores an invaluable tool in understanding how properties are performing. The commenter believed that such oversight detects signs of financial distress or over subsidization and assists in the rent setting process and other processes involved in LIHTC, HOME, HTF, and local resources.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Though it does apply to small-scale housing, the 10-unit threshold for performing financial oversight that the commenter is objecting to is not a small-scale housing flexibility. This is a provision within § 92.504(d)(2) that is being moved to § 92.251(f). Please see HUD's response above on financial oversight for the HOME program for why HUD is declining to reduce the 10-unit threshold.
                    </P>
                    <HD SOURCE="HD2">§ 92.253—Tenant Protections and Selection</HD>
                    <HD SOURCE="HD3">A. General Comments on Requiring a Tenancy Addendum in § 92.253(a)</HD>
                    <P>Commenters supported the tenant addendum changes. One commenter stated that outlining the required elements of the HOME lease addendum in the affirmative is much more effective and provides clarity for all parties. Some commenters expressed broad support for the proposed expansion of tenant rights and protections provisions. Another commenter supported HUD's proposed changes to § 92.253(a)-(b) and the proposed addition of paragraph (c), which the commenter stated would simplify TBRA and improve TBRA for tenants, landlords, and participating jurisdictions.</P>
                    <P>Another commenter strongly supported the proposed requirement of a HOME lease addendum. The commenter suggested that HUD should consider providing additional means of enforcement. For example, the commenter suggested that tenants should have the right to access a grievance procedure, which would permit tenants to request an information conference with the owner when their rights are violated. The commenter further suggested that tenants should be able to appeal the owner's decision to the participating jurisdiction, and they should also have an explicit avenue to bring a complaint to HUD.</P>
                    <P>One commenter requested that HUD develop a HOME addendum template that contains all of the HOME program requirements in a single addendum. Another commenter supported the tenancy addendum requirement but stated that it should not be a requirement until there is a HUD HOME tenancy addendum that can be used on all rental housing projects.</P>
                    <P>One commenter generally opposed the proposed tenant protections to the HOME program. The commenter explained that apartment owners and managers already are subject to a myriad of tenant protection and fair housing statutes, regulations, administrative policies, and case law from all levels of government. The commenter further explained that this existing framework provides balanced protections for both tenants and landlords. Specifically, the commenter points out that the proposed mandatory HOME lease addendum would impose a set of one-size-fits-all tenant protections for HOME-assisted rental housing and HOME tenant-based rental assistance (TBRA) recipients.</P>
                    <P>One commenter preferred that lease addendum and protections be left to State landlord-tenant law but did not strongly oppose the use of a Federal addendum for purposes of consistency and reducing participating jurisdiction burden. Another commenter stated that HUD should not engage in tenant protection rulemaking because State and local regulations are sufficient.</P>
                    <P>One commenter stated that tenant protections will increase a tenant's ability to locate and sustain units that are affordable and that tenant protections should be included in a tenant's lease agreement. However, that commenter was also concerned that since the HOME funds they used made up a small percentage of the total cost of the project and resulted in a limited number of HOME-assisted units (usually 5-10), a HOME-specific lease addendum would be impractical to implement.</P>
                    <P>One commenter supported the proposal (under § 92.253(a)) to require owners to attach VAWA and HOME addenda to the lease, as this would help ensure that owners, tenants, and eviction court judges clearly understand tenant rights and owner obligations. However, this commenter suggested simplifying the addendum by drafting an addendum that cites to HOME regulations for additional detail.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the comments and is moving forward with requiring a HOME tenancy addendum for rental housing, tenant-based rental assistance, and security deposit assistance only. The Act states that the lease between a tenant and owner of HOME-assisted rental housing and HOME tenant-based rental assistance “shall contain such terms and conditions as the Secretary shall determine to be appropriate.” (42 U.S.C. 12755(a)). HUD has determined that Congress intended that HUD use the terms and conditions of the lease to provide tenant protections in the HOME program. Instead of requiring a standard form lease or prohibiting terms contained in an owner's lease, HUD believes that creating HOME tenancy addenda for rental housing, tenant-based rental assistance, and security deposit assistance is the best way to enforce reasonable tenant protections in a consistent manner while reducing participating jurisdiction burden.
                    </P>
                    <P>HUD's HOME tenancy addenda will include the tenant protections listed in the HOME regulations. HUD maintains that the tenant protections it is including in the HOME tenancy addenda represent a minimum standard that is based in a thorough analysis of Federal, State, and local laws. Before proposing these protections, HUD examined State and local landlord-tenant laws and protections and the requirements of other Federal programs that serve the same tenants and are frequently combined with the HOME program (such as the Section 8 programs). Through this analysis and comment from the public, HUD is confident that the inclusion of the tenant protections contained in the HOME tenancy addenda are consistent with the intent of the drafters of the Act.</P>
                    <P>
                        The Department understands some commenters' desire to formalize a 
                        <PRTPAGE P="829"/>
                        grievance process and an appeal right to HUD. However, the Act does not require participating jurisdictions to establish a grievance process or for HUD to establish a right to appeal to the Department. Participating jurisdictions must determine their own systems for assessing risk and methods for enforcing compliance with the requirements of 24 CFR part 92.
                    </P>
                    <P>
                        The Department also recognizes that some commenters have significant concerns about the one-size-fits-all nature of tenancy addenda and the potential for adding new HOME tenant protections to other Federal, State, and local requirements. The Department did its best to address the commenters' concerns by aligning certain tenant protection provisions with other Federal programs (most notably the Section 8 programs) and tailoring each tenancy addendum to the type of HOME program (
                        <E T="03">i.e.,</E>
                         rental housing, tenant-based rental assistance, security deposit assistance only).
                    </P>
                    <P>In response to commenters that stated that the Department should not require tenant protections for HOME because the HOME funding may only be a small portion of the overall financing or fund only a few housing units, the Department understands the concerns, but this does not diminish the need to guarantee tenants of HOME rental housing projects a baseline level of tenant protections, as intended under the Act. Some participating jurisdictions provide HOME funds to projects that require only a small amount of funding to move forward. Others provide much more significant amount of funding and fund much larger HOME projects. Tenants should receive the same protections regardless of the decisions made by the participating jurisdiction on how much funding to provide to a particular rental housing project. The Act did not specify that tenant protections were to be based upon the level of HOME funds and the Department is declining to draw such distinctions or only require a reduced set of protections for HOME simply because some participating jurisdictions may use HOME funds to fund fewer units in larger rental projects.</P>
                    <P>The Department considered one commenter's request that the HOME tenancy addenda should cite to the appropriate regulations and be as simple as possible. However, the Department intends to create tenancy addenda that do not require a tenant or owner to look up HUD regulations in order to know what they are agreeing to and shall provide a standalone tenancy addendum for HOME rental housing, tenant-based rental assistance, and security deposit assistance only.</P>
                    <HD SOURCE="HD3">B. Requiring a Tenancy Addendum Under § 92.253(a) Violates the Rights of Housing Project Owners</HD>
                    <P>Commenters said that the rule infringes on property rights by circumventing the established legal process for eviction, denying housing providers due process rights, and creating an imbalance in tenant-landlord relations by making nonpayment of rent a protected class. Commenters also called on HUD to be fair and not overreach.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Act states that the lease between a tenant and owner of HOME-assisted rental housing and HOME tenant-based rental assistance “shall contain such terms and conditions as the Secretary shall determine to be appropriate.” (42 U.S.C. 12755(a)). HUD has determined that this is a Congressional delegation of authority to the Secretary and provides the Secretary with the discretion to determine the appropriate lease terms for tenants living in HOME-assisted rental units. Owners accept HOME assistance in the development of their rental housing projects with the knowledge that they do so subject to Federal laws and regulations. This includes the prohibited lease terms and the current termination of tenancy and refusal to renew provisions that are currently listed in § 92.253. HUD is updating these protections but will not, and does not have legal authority to, circumvent State or local eviction processes, alter any due process rights of owners under State or local law, or define any new protected classes.
                    </P>
                    <P>In recognition of the concerns that the commenter raises, the Department is requiring that the new and revised tenant protections only apply prospectively (See § 92.3). This will allow owners of HOME rental housing to knowingly agree to the new tenant protections before accepting the HOME funds for a project. This will allow the same for owners entering into a rental assistance contract with participating jurisdictions. The Department believes that this meaningfully addresses any legal concerns that the commenter had, even though the Department disagrees with the assertion that imposing such protections upon existing owners would violate their rights.</P>
                    <HD SOURCE="HD3">C. Requirement To Provide the Participating Jurisdiction With a Copy of the Lease in § 92.253(a)</HD>
                    <P>One commenter stated that the components in the rule related to lease contents are generally reasonable, but that the requirement that the owner provide the participating jurisdiction with a copy of the written lease before it is executed and once revised is unclear and potentially troublesome. The commenter recommended that HUD reconsider this requirement because it could be burdensome and lack an understandable review process. The commenter noted that if HUD proceeded with the requirements, to avoid significant confusion and delays, HUD should clarify that a participating jurisdiction would not be required to review or approve individual leases and that a model lease would be sufficient.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD is adding the requirement to § 92.253(a) that owners must provide the participating jurisdiction with a copy of the written lease to allow the participating jurisdiction to verify that the lease complies with the requirements in § 92.253, including that it includes the applicable HOME tenancy addendum. This should not be disruptive for participating jurisdictions or owners. HUD is not changing its requirement that 
                        <E T="03">each lease</E>
                         comply with the requirements in § 92.253 (See § 92.252 (rental housing) and § 92.209 (TBRA)). Section 92.504(a) already requires participating jurisdictions to have and follow written policies, procedures, and systems, including a system for assessing risk of activities and projects and a system for monitoring entities consistent with 24 CFR part 92 to ensure that the HOME requirements are met, including lease requirements. Also unchanged, § 92.508(a)(3)(ix) requires the participating jurisdiction to maintain records demonstrating that each lease complies with HUD requirements. A participating jurisdiction is therefore already required to determine that each lease complies with HOME requirements and maintain project records proving that the leases are compliant. HUD is adding the requirement that the owner provide the participating jurisdiction with the lease in advance to allow a participating jurisdiction to review under their procedures before any potential noncompliant leases are executed.
                    </P>
                    <HD SOURCE="HD3">D. Methods of Communication in § 92.253(a)</HD>
                    <P>
                        Commenters expressed strong support for the requirements to provide essential information to tenants, including those in proposed § 92.253(a) regarding (1) accessible means to contact owners, managers, and participating jurisdictions; (2) accessible notice specifying the grounds for any adverse action; and (3) that owners provide 30 days advance notice of an impending 
                        <PRTPAGE P="830"/>
                        sale or foreclosure of the property. A commenter explained that these are important for maintaining decent, safe, and sanitary conditions in assisted housing; allowing tenants to clear misunderstandings and giving them information needed to challenge adverse actions and avoid unjust outcomes; and allowing tenants to prepare for possible disruptions. However, the commenter stated that without an enforcement mechanism, the requirements will be meaningless and the burden for enforcement will fall on individual tenants. The commenter suggested that for (1) and (2), HUD should require participating jurisdictions to develop and publish an enforcement mechanism. For (3), the commenter suggested that HUD's rulemaking should specify that no adverse action shall become effective unless such notice has been provided. Another commenter supported the HOME lease addendum but suggested that HUD simplify the addendum to make it more user friendly.
                    </P>
                    <P>One commenter recommended deleting the requirement in § 92.253(a)(2) that leases include the participating jurisdiction's contact information to avoid tenants calling participating jurisdictions. If HUD keeps the requirement the commenter recommended moving it to a new § 92.253(b)(8) so that contact information would be included in the HOME tenancy addendum. Another commenter supported the requirement for tenant leases to contain more than one method to communicate directly with the owner or property manager but stated that as a participating jurisdiction, it does not feel that review prior to lease execution or revision is necessary. Additionally, owners must ensure effective communication with persons with disabilities, including, for example those with hearing, visual, speech, or disabilities consistent with Section 504 and the ADA, as applicable.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department is moving forward with the changes and will require that contact information be provided in the lease. The Department is not embedding this requirement in the tenancy addenda regulations in § 92.253(b)-(d) but will include an area in the HOME rental housing tenancy addendum and the HOME tenant-based rental assistance tenancy addendum for this information to be added. By building this information into the addendum, it should reduce the need to create an enforcement mechanism. However, there are other enforcement mechanisms in § 92.504. The Department is committed to ensuring that the tenancy addenda are user-friendly. The Department also recognizes the commenter's concern that no adverse action should occur for a tenant until the notice in the proposed rule's paragraph (a)(3) had been provided. The Department would like to clarify that the proposed rule paragraph (a)(3) was the requirement that a VAWA addendum be added and not the requirement that notice be provided of VAWA protections. The notice the commenter is describing is required under § 92.359(c) and is unchanged by this rulemaking.
                    </P>
                    <P>The Department has noted the concerns of participating jurisdictions and owners who do not believe that it is appropriate to provide contact information but strongly disagrees. When tenants have clear ways to communicate with the participating jurisdiction that is monitoring the HOME rental housing owner or that is assisting them with tenant-based rental assistance, it empowers them to be able to assert their rights or protections, and better enables participating jurisdictions to learn about potential compliance problems.</P>
                    <HD SOURCE="HD3">E. General Support for Changes to HOME Tenancy Addendum Physical Condition Requirements in § 92.253(b) Description of Tenancy Addendum Contents</HD>
                    <P>One commenter supported HUD's proposed changes requiring owners to provide tenants with the expected timeframe for maintenance and/or repair work, prohibiting owners from charging tenants for normal wear and tear, and requiring owners to prompt relocate tenants to decent, safe, and sanitary housing, or to suitable lodging when there is a life-threatening deficiency that can't be repaired the same day—at no cost to the tenant.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for their support of the proposed changes. The Department agrees and believes that these changes will promote a better, safer environment for tenants and will enable them to live in units that meet property standards. Tenants must not be exposed to life-threatening deficiencies. Where such deficiencies are present, they should be corrected by owners expeditiously and with as few disruptions to the family as possible. Requiring owners to provide alternative suitable units until such repairs are made is a strong incentive to repair life-threatening deficiencies quickly and comprehensively to avoid future disruption and expense. Notwithstanding the foregoing, the Department believes this requirement is only acceptable where the participating jurisdiction has provided the owner with HOME assistance in the acquisition or development of the project and therefore is not applying the requirement to owners whose units are occupied by tenants with tenant-based rental assistance. This is because the requirement could have the potential to chill participation from private landlords whose only assistance is the rental assistance received from the participating jurisdiction on behalf of the tenant.
                    </P>
                    <HD SOURCE="HD3">F. Unit Maintenance and Repair in § 92.253(b) Description of Tenancy Addendum Contents</HD>
                    <P>One commenter suggested that HUD should require that the owner “provide expected time frames for maintaining or repairing units” in writing in § 92.253(b)(1)(ii)(A). The commenter explained that this encourages transparency between the owner and tenant and provides the tenant with the information needed to hold owners accountable in case of delayed maintenance.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for reviewing the proposed rule. HUD agrees with the commenter that the owner must provide written notice to a tenant of the expected timeframes for maintaining or repairing a HOME-assisted unit. HUD is revising § 92.253(b)(1)(A) to incorporate this change. HUD is also adding similar language to the HOME tenant-based rental assistance tenancy addendum in § 92.253(c)(1)(A).
                    </P>
                    <HD SOURCE="HD3">G. Unit Damage and Charges in § 92.253(b) Description of Tenancy Addendum Contents</HD>
                    <P>One commenter recommended, for HUD's proposed regulatory text in § 92.253(b)(1)(ii)(C), that HUD provide text enabling a tenant to bring a challenge to the participating jurisdiction regarding any charges the tenant believes are unwarranted and requested sub-regulatory guidance regarding such proceedings.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the comment but is moving forward without the commenter's proposed change. A participating jurisdiction is not responsible for litigating disputes between tenants and owners for charges a tenant may feel are unwarranted. However, the participating jurisdiction is required to monitor and enforce the requirements of 24 CFR part 92, including the tenant protections requirements. The Department defers to participating jurisdictions in determining the best method for enforcing the tenant protections requirements. While some 
                        <PRTPAGE P="831"/>
                        participating jurisdictions may establish or use existing grievance procedures, there may be others that take a more targeted or risk-based monitoring and enforcement approach.
                    </P>
                    <HD SOURCE="HD3">H. Temporarily Moving Tenants Due to Emergencies on the Property in § 92.253(b) Description of Tenancy Addendum Contents</HD>
                    <P>One commenter supported HUD's proposal in § 92.253(b)(1)(iii) to require owners to temporarily relocate tenants, at the owner's expense, in the situations involving a life-threatening emergency because this clarifies owners' existing duty to provide decent, safe, and sanitary housing for tenants. The commenter expressed concern that “life” was too high a bar to achieve HUD's purpose for the change stated in the preamble of the proposed rule, “to prevent HOME tenants from remaining in housing that poses a threat to their physical safety and from being subjected to additional costs as a result of physical housing conditions outside their control.” The commenter explained that many housing conditions pose serious but not life-threatening threats to occupants' physical safety, including mold, infestation, and lead-based paint. The commenter also noted that occupants remaining in the home during remediation of emergencies or adverse conditions may not be safe. The commenter suggested extending the relocation requirement to cover all conditions and repair activities that “pose a threat to the health and safety of the tenant household.” Another commenter stated that the requirement that owners temporarily relocate tenants at the owner's expense should apply to all conditions that pose an immediate threat to the health and safety of the tenant household.</P>
                    <P>One commenter recommended that HUD should modify the standard at which an owner must relocate a tenant in § 92.253(b)(1)(iii) to reflect more commonly used standards. Specifically, HUD should require that an owner relocate the tenant when “maintenance or repairs are necessary to ensure the habitability of the housing unit”—rather than when the unit's physical condition creates “a life-threatening deficiency.”</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for reviewing the proposed rule but disagrees that HUD should adopt a different standard for relocating tenants in the case of physical deficiencies in the unit. The proposed language in § 92.253(b)(1)(iii) seeks to prevent HOME tenants from remaining in units that pose a threat to their physical safety if a life-threatening deficiency cannot be corrected on the day the deficiency is identified. This provides a strong incentive to fix immediate, life-threatening problems with the unit. Requiring project owners to relocate tenants for health and safety deficiencies that are severe but not life-threatening, especially when those deficiencies could be corrected in a reasonable time frame without posing a life-threatening risk to the tenant, may impose too significant of a financial burden on project owners or deter participation in the HOME program. HUD is moving forward with its proposed change. Participating jurisdictions are always capable of requiring more stringent requirements through their written agreements, but the Department believes that the minimum requirement must prevent families from living in units with life-threatening deficiencies.
                    </P>
                    <HD SOURCE="HD3">I. Owner Requests for Access to Unit Under § 92.253(b) Description of Tenancy Addendum Contents</HD>
                    <P>One commenter supported the new tenant protections except for the notice to enter requirement which it believed should be 24 hours, not 2 days. The commenter stated that 2 days' notice to enter is longer than what many States and HUD programs require and that it may be too long in non-emergency situations where time is still of the essence. One commenter suggested that HUD should strengthen the written statement requirement in § 92.253(b)(2)(iii)(A) by requiring the written statement to include the date and time, as well as the purpose of the owner's entry. The commenter further suggested that HUD should require that the owner deliver the written statement to the tenant, not simply the “dwelling unit,” to ensure that the tenant actually received the statement. The commenter stated that it would also encourage accountability and transparency on the owner's behalf.</P>
                    <P>One commenter supported HUD's proposed changes requiring at least two days' notice before entering a tenant's unit for normal business, but anytime without advanced notice if there is a reasonable belief that there is an emergency.</P>
                    <P>One commenter suggested that for emergency entries in § 92.253(b)(2)(iii)(B), HUD should require that the owner provide the tenant with a notice similar to the notice required in § 92.253(b)(2)(iii)(C).</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing the proposed rule. HUD disagrees with commenters that feel that providing the owner providing the tenant with 2 days' notice prior to entry is too long. This is a commercially reasonable time period in much of the country and a best practice in many jurisdictions already. The Department also believes that 2 days' notice provides tenants with ample time to arrange to be present for the repairs and make other arrangements, such as childcare. In non-emergency situations, owners should be able to appropriately plan to notify a tenant 48 hours before repairs or maintenance.
                    </P>
                    <P>HUD is requiring owners to provide the tenant a written statement specifying the date, time, and purpose of entry when the tenant is not present in the unit but declines to require this notice under all circumstances. This notice is not always necessary, especially if the original notice was already delivered and the tenant is present in the unit when the owner or their agent enters the unit to perform the repairs. The Department does agree that a project owner that enters a unit in the case of emergency should provide the tenant with a written notice of entry upon entering the unit. HUD is revising § 92.253(b)(2)(iii)(C) to require an owner to provide the tenant a written statement specifying the date, time, and purpose of entry after entering the unit in the case of emergency. HUD is also adding similar language to the HOME tenant-based rental assistance tenancy addendum in § 92.253(c)(2)(iii)(2).</P>
                    <P>HUD disagrees that an owner should be required to serve notice directly to the tenant instead of to the unit. Requiring an owner to locate a tenant to serve notice of entry to the unit is not customary and could cause undue delays to project owners attempting to perform emergency repairs.</P>
                    <HD SOURCE="HD3">J. Reasonable Use of Common Areas in § 92.253(b) Description of Tenancy Addendum Contents</HD>
                    <P>One commenter supported HUD's proposal to require HOME-assisted tenants to have reasonable access to, and use of, common areas and to prohibit having separate elevators or amenities that are only available to non-assisted tenants, which furthers HUD's commitment to fair housing and equity.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for reviewing the proposed rule and is moving forward with the proposed change.
                    </P>
                    <HD SOURCE="HD3">K. Right To Organize in § 92.253(b) Description of Tenancy Addendum Contents</HD>
                    <P>
                        Commenters supported HUD's proposal in § 92.253(b)(2)(v) to explicitly state that tenants have the right to organize, create tenant associations, convene meetings, and 
                        <PRTPAGE P="832"/>
                        conduct other similar actions. Two commenters suggested HUD issue guidance mirroring the details of 24 CFR part 245 for clarity and consistency. One of those commenters urged HUD to explicitly state that the rights are further elaborated in sub-regulatory guidance. One commenter recommended elaborating on the tenant's protected organizing activities in § 92.253(b)(2)(v). In addition to the rights under the proposed rule, the commenter suggested that tenants should have the right to provide building access to outside tenant organizers, conduct door-to-door surveys of tenants' interest in establishing a tenant organization and/or offer information about tenant organizations, and distribute leaflets in lobby areas, other common areas, or under tenants' doors.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department believes that the final rule's right to organize language sufficiently protects tenants and declines to implement 24 CFR part 245 for HOME tenants. The 24 CFR part 245 protections apply to only a few programs and were not part of HUD's proposed rule. The Department does not believe it is appropriate to add these requirements and the level of detail in 24 CFR part 245 into the tenancy addenda for either HOME rental housing or tenant-based rental assistance. The Department will consider providing additional guidance and best practices based on the lessons learned from implementing 24 CFR part 245 requirements in the future but will not revise the regulation to refer to outside guidance.
                    </P>
                    <HD SOURCE="HD3">L. Notice of Adverse Action in § 92.253(b) Description of Tenancy Addendum Contents</HD>
                    <P>One commenter supported the proposed requirement for owners to provide written notice to tenants for any adverse actions. Another commenter recommended that the notice required prior to an owner carrying out an adverse action in § 92.253(b)(3)(i) specify that the notice be two-weeks advanced notice. The commenter also recommended that the final rule provide for a tenant's ability to bring to the participating jurisdiction a challenge of any adverse action the tenant believes is unwarranted and requested sub-regulatory guidance for such proceedings.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the comments. HUD agrees that a tenant should be notified in writing of an adverse action prior to the adverse action taking effect. Consequently, HUD is revising § 92.253(b)(3)(i) to state that before an owner may take an adverse action against a tenant, the tenant must be notified in writing. HUD is also adding similar language to the HOME tenant-based rental assistance tenancy addendum in § 92.253(c)(3)(i).
                    </P>
                    <P>The Department disagrees with the commenter that two weeks' notice should be required prior to any adverse action. This time period is too long, especially when the adverse action is one that may require more immediate correction. HUD also disagrees that the participating jurisdiction must have a formal process for adjudicating any tenant challenges to an owner's adverse action. NAHA does not require a grievance progress for participating jurisdictions to settle disputes between tenants and owners. Participating jurisdictions must determine what is best for monitoring and enforcing compliance with the new tenant protections requirements. Some may wish to establish grievance procedures, while others may choose to perform risk-based monitoring or take other preventative measures to address landlord-tenant disputes in their HOME programs.</P>
                    <HD SOURCE="HD3">M. Take Into Account Income and Medical Expenses Before Imposing Adverse Actions in Paragraph Description of Tenancy Addendum Contents</HD>
                    <P>A commenter suggested that for tenants whose income and medical expenses were high, the expenses (including rent, fines, or damage) should be prorated based on benefit income, taking into account medical spend downs. The commenter believed that this would reduce the number of people that would have to choose between paying housing expenses or paying healthcare expenses.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for reviewing the proposed rule. Requiring project owners to request and review a tenant's medical expenses to determine a prorated fine or other damage prior to taking an adverse action would be unduly burdensome for project owners and may conflict with other statutes such as the Health Insurance Portability and Accountability Act (Pub. L. 104-191). The Act also does not permit HUD to impose this type of requirement, as it was never contemplated. For families receiving tenant-based rental assistance, families living in Low HOME rent units where their rental payment is based upon 30 percent of their adjusted income, or families receiving rental assistance or living in a subsidized rental unit under another program that calculates adjusted income, the adjusted income calculation will consider health and medical expenses as a deduction from annual income (see 24 CFR 92.203(f)). Moreover, participating jurisdictions that administer a tenant-based rental assistance program may also wish to establish hardship policies as now permitted in § 92.209(h)(2). A TBRA family receiving a hardship would be provided an exception to the requirement that the family contribute a minimum amount of rent which would alleviate some of the financial burden on the family. As a reminder, participating jurisdictions must also provide reasonable accommodations that may be necessary for individuals with disabilities in accordance with Section 504, the Fair Housing Act, and the ADA, as applicable.
                    </P>
                    <HD SOURCE="HD3">N. Notice of Intent To Sell Property or Foreclosure of Property in Description of Tenancy Addendum Contents</HD>
                    <P>One commenter supported the proposed requirement for owners to provide written notice to tenants within 5 business days of any change in ownership (including foreclosure) and at least 30 days' notice before a sale or foreclosure. One commenter also supported the delivery of a 5-day notice for ownership or management company change.</P>
                    <P>Commenters asked HUD to amend § 92.253(b)(3)(ii) to require an owner to provide a 60-day notice of intent to sell property or foreclosure of property. The commenters stated that 60 days' notice was appropriate given the burdens of finding new housing and moving.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing the proposed rule. HUD agrees with the commenter that tenants should be notified of a change in the property management company and is revising § 92.253(b)(3)(ii) and § 92.253(c)(3)(ii) to require the property owner to notify tenants within 5 days of any change to the property management company managing the property. Property management staff are often the face of the owner and have the most communication with tenants. Adding a requirement that tenants be notified if the management company changes is prudent to prevent disruption to families and ensures clear lines of communication between tenants and an owner's representatives at all times. HUD is moving forward with the proposed change to require 30 days' notice prior to an impending sale or foreclosure of the property.
                    </P>
                    <P>
                        The Department believes that 60 days' notice may be too long and may not always be reasonable or possible. The Department would note that when there is a change in ownership in HOME 
                        <PRTPAGE P="833"/>
                        rental housing during the period of affordability that is not due to foreclosure, the owner takes the property subject to all the requirements of 24 CFR part 92. Therefore, the change in ownership may not always result in an immediate move from the property or disruption to tenants. The Department understands the concern may be greater for tenant-based rental assistance and is noting that HUD's requirement is a minimum standard, and participating jurisdictions can always require more advance notice of a potential sale or foreclosure in rental assistance contracts or written agreements with owners of rental housing projects, especially if those participating jurisdictions wish to exercise any rights to preserve the affordability of the rental housing project.
                    </P>
                    <HD SOURCE="HD3">O. Act or Failure To Act in Description of Tenancy Addendum Contents</HD>
                    <P>A commenter suggested that HUD add clarifying language to § 92.253(b)(4)(iii) specifying that the liability for action or failure to act is only in connection with the lease. The commenter suggested revisions to HUD's proposed language, “(iii) The tenant may hold the owner or the owner's agents legally responsible for any action or failure to act in connection with the lease, whether intentional or negligent.”</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department considered the commenter's recommendation but disagrees with the commenter. The prohibited lease term upon which this is based was one that prohibited excusing an owner from responsibility and was written to apply to owners broadly. It prohibited the tenant from agreeing not to hold owners responsible for any action or failure to act. The Department understands that not every adverse action that an owner can take against a tenant or household relates to the lease. For instance, retaliatory acts may not be acts that are entirely born from or related to the lease; they may be personal in nature. Narrowing potential liability to only matters pertaining to the lease could create a gap in protections that could be exploited by unscrupulous owners who could claim that the negative actions were related to personal matters and not the lease.
                    </P>
                    <HD SOURCE="HD3">P. Retaliation and Unreasonable Interference With the Tenant's Comfort, Safety, or Enjoyment of the Tenant's Housing Unit in § 92.253(b) Description of Tenancy Addendum Contents</HD>
                    <P>One commenter supported the addition of anti-retaliation provisions in § 92.253. Another commenter supported the addition of specific language to the regulations prohibiting owners from retaliating against tenants who exercise their rights, by decreasing services, interfering with a tenant's right to privacy, and/or harassing households or their guests.</P>
                    <P>One commenter supported the non-exhaustive list of tenants' rights protected by a right against retaliation in § 92.253(b)(5). However, the commenter stated that, as currently written, the prohibition against retaliation provision is ineffective. The commenter said that the actions described in the prohibition against retaliation are independently prohibited as unjust interference, regardless of retaliatory motive. The commenter also stated that the rule fails to specify consequences for retaliation. The commenter suggested that HUD adopt a mechanism similar to that used by States and municipalities to discourage retaliation, and state in regulation that (1) no termination or non-renewal of a lease or alteration of a term or condition of the lease is valid if taken in retaliation for the exercise of a legal right by the tenant or member of the tenant's household, and (2) any such adverse action taken within a specified period of time (the commenter suggested 12 months) of the exercise of a legal right will be presumed to have been taken in retaliation unless the owner proves that the action was taken solely for a non-retaliatory purpose. Another commenter expressed a similar objection to the protection against retaliation in § 92.253(b)(5), stating that it is ineffective as currently written and should specify consequences for violations.</P>
                    <P>One commenter suggested that HUD should revise § 92.253(b)(5) to more clearly convey that subsection (i) includes examples of owner interference or retaliation and that subsection (ii) includes examples of tenant rights. To better reflect commonly used terms, the commenter recommended that HUD should replace “comfort, safety, or enjoyment” with “right to peaceful enjoyment.”</P>
                    <P>One commenter recommended adding “refusal to renew a tenant lease agreement” and “increase rental amount in renewal or otherwise initiate a termination of tenancy” as protections against retaliation in 92.253(b)(5)(i), either by addition or explicit reference to 92.253(d)(1)(i)-(v).</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing the proposed rule and is making several revisions to the HOME rental housing tenancy addendum retaliation and unreasonable interference regulations in § 92.253(b)(5), and similar provisions in the tenant-based rental assistance tenancy addendum provisions in § 92.253(c)(5). The Department agrees with the commenter that § 92.243(b)(5) and § 92.253(c)(5) should differentiate between unreasonable interference and retaliation by the owner. Consequently, HUD is revising the section headings to include unreasonable interference as its own standalone prohibition and reorganizing the sections to clarify that the consequences for retaliation are that the owner is in breach of the tenant lease, is violating the requirements in 24 CFR part 92, and is in violation of the written agreement with the participating jurisdiction (in the case of rental housing) or the rental assistance contract (in the case of tenant-based rental assistance).
                    </P>
                    <P>The Department considered changes to shift burden or create presumptions that certain actions were interference or retaliation based upon the time in which they occurred in relation to the protected acts that the Department had initially linked to the retaliation provisions. The Department also considered stating that refusal to renew or termination of tenancy would not be effective if it was to retaliate or interfere with a tenant. However, after the Department specified consequences relating to the written agreement, and made examples of rights that a tenant could take free from retaliation or interference into explicit rights in the tenancy addendum, the Department believed these further revisions would be unnecessary and add undue complexity to the regulation. The Department will consider guidance on how to determine that an action is retaliation in response to a protected act by a tenant or household member in the future.</P>
                    <P>
                        The Department also agrees with the commenter that recommended that both “refusal to renew a tenant lease agreement” and “increase rental amount in renewal or otherwise initiate a termination of tenancy” should be examples of retaliation or unreasonable interference. Section 92.253(b)(5)(iii)(A) states that “[r]ecovery of, or attempt to recover, possession of the housing unit in a manner that is not in accordance with paragraph (b)(10) of this section” is an action evidencing retaliation or unreasonable interference. HUD is also adding similar language to the HOME tenant-based rental assistance tenancy addendum in § 92.253(c)(5)(iii)(A). Paragraphs § 92.253(b)(10) and § 92.253(c)(10) provide both the termination of tenancy and refusal to renew lease provisions. The Department has also revised § 92.253(b)(5)(iii)(B) and § 92.253(c)(5)(iii)(B) to state that “[d]ecreasing services to the housing 
                        <PRTPAGE P="834"/>
                        unit (
                        <E T="03">e.g.,</E>
                         trash removal, maintenance) or increasing the obligations of a tenant (
                        <E T="03">e.g.,</E>
                         new or increased monetary obligations, etc.) in a manner that is not in accordance with the requirements of this part” is an example of retaliation or unreasonable interference. Increasing monetary obligations in retaliation or in an attempt to unreasonably interfere with a tenant is now explicitly prohibited by the tenant protections in § 92.253(b)(5)(iii)(B) and § 92.253(c)(5)(iii)(B) in addition to the rent setting provisions in § 92.252.
                    </P>
                    <HD SOURCE="HD3">Q. Other Recommend Provisions in § 92.253(b) Description of Tenancy Addendum Contents</HD>
                    <P>One commenter stated that the HOME tenancy addendum should provide notice to the tenant that there are income restrictions for occupancy and the tenant is required to re-certify and document changes in their household income. The commenter stated that the regulations allow a lease to state that the rent may change if the household income exceeds the income limit at the time of re-certification.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department understands the desire to enforce income requirements as part of the tenant lease. This is inappropriate as a required term of the lease addendum. It is up to the participating jurisdiction to determine how best to obtain the necessary income information to determine income for HOME rental housing projects and tenants with tenant-based rental assistance. The Department provides participating jurisdictions with a variety of options for calculating income, including the use of safe harbors, and gives participating jurisdictions the discretion to allow owners to accept self-certification of tenant income in years 2-5, 7-11, and 13-17 of a rental housing project's period of affordability. As such, the Department is declining to add these terms as an explicit part of the lease.
                    </P>
                    <HD SOURCE="HD3">R. Security Deposit Requirements Should Be in the Tenancy Addendum</HD>
                    <P>One commenter suggested that HUD should include the security deposit protections in the HOME tenancy addendum.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD agrees with the commenter that security deposit provisions are a material term of the lease, as described earlier in Section III of this preamble, and agrees that these provisions are best contained and enforced through the lease. The Department is revising § 92.253(b) and (c) to add security deposit provisions as part of the terms of the HOME rental housing tenancy addendum and the HOME tenant-based rental assistance tenancy addendum.
                    </P>
                    <HD SOURCE="HD3">S. Security Deposit Limit—Two Month's Rent</HD>
                    <P>One commenter supported the proposed changes to the HOME rule requiring security deposits to be no greater than two months' rent and refundable. One commenter supported imposing a maximum on security deposits but stated that two months of rent is an insurmountable barrier to tenancy and suggested HUD limit security deposits to no more than 1 month's rent. The commenter stated that if HUD does not change the limit, it should require the option of paying any amount over one month's rent monthly installments. Another commenter also recommended that HUD should limit security deposits to the equivalent of one-month's rent, not two months' rent. This commenter asserted that of the States that have enacted limits on security deposit amounts, the majority have opted for a one-month limit over a two-month limit. The commenter provided citations for 14 States that had enacted one-month security deposit limits and three States that had enacted one and one half-month security deposit limits.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD understands the commenter's concern that paying a security deposit of two months' rent is not always affordable for HOME tenants, even when that rent is set at the Low HOME Rent Limits. However, HUD also recognizes that a two-month security deposit is a commercially reasonable request that is consistent with most State laws. The Department also understands that there are different ways to reduce that type of barrier, such as by allowing the security deposit to be paid in installments. HOME is a block grant program. Participating jurisdictions and owners must underwrite and determine the level of risk they wish to expose themselves to when determining the amount they wish to charge for a security deposit. Moreover, participating jurisdictions and owners also must determine what is commercially reasonable for affordable housing in their markets. In many of those markets, this necessitates charging a security deposit equal to two months' rent or requiring the security deposit to be paid all at once.
                    </P>
                    <P>HUD also recognizes that a number of States have different, more stringent security deposit requirements that require that the security deposit be less than the maximum security proposed in § 92.253(c). A lease for a HOME tenant must comply with State and local landlord-tenant law, and where State landlord-tenant laws are more restrictive than HUD requirements, then the owner must follow the more restrictive requirements. Therefore, in those States or localities where landlord-tenant law requires the security deposit be less than two month's rent, the owner may only charge the maximum amount allowable under the applicable law.</P>
                    <HD SOURCE="HD3">T. Use of Surety Bonds and Security Deposit Insurance</HD>
                    <P>Many commenters supported HUD's proposal to prohibit the use of surety bonds and security deposit insurance. The commenters supported HUD's reasoning that these tools disadvantage tenants without any material benefit for landlords. One commenter noted that surety bonds can be costly to both tenants and housing providers. Another commenter believed the use of surety bonds or security deposit insurance in lieu of security deposits don't meet the intent of the National Affordable Housing Act (NAHA) and aren't treated as security deposits under-State statutes.</P>
                    <P>Other commenters opposed the proposed rule's prohibition of surety bonds or security deposit insurance in lieu of a security deposit. One commenter believed it would be cost-prohibitive for potential renters of HOME-assisted rental housing. The commenter explained that the use of a surety bond or security deposit insurance can be a more affordable option for low-income renters who may not be able to pay up to the allowable two-months' rent in advance as security deposit.</P>
                    <P>Another commenter asked HUD to remove the prohibition in § 92.209(j)(6) on surety bonds or security deposit insurance and similar instruments in lieu of or in addition to a security deposit because it may deter landlords from renting to TBRA tenants. The commenter also pointed to the possibility that a TBRA tenant could receive assistance in a unit they already occupy and for which a security bond was already purchased. The commenter recommended that HUD only prohibit the use of HOME funds for surety bonds or security deposit insurance as an ineligible fee as proposed in § 92.214(a)(10). Another commenter also stated that a property owner should not be allowed to require a tenant to pay for security deposit insurance but that the regulations should not prohibit property owners from informing the tenant about the availability of third-party insurance coverage.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         As HUD explained in the preamble to the proposed rule, HUD 
                        <PRTPAGE P="835"/>
                        determined as a matter of law that surety bonds and security deposit insurance are not security deposits within the meaning of NAHA nor are they treated as security deposits under State statutes.” 
                        <SU>60</SU>
                        <FTREF/>
                         The drafters of NAHA contemplated that renters would pay security deposits and authorized security deposit assistance as part of the tenant-based rental assistance program.
                        <SU>61</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>60</SU>
                             89 FR 46266.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>61</SU>
                             42 U.S.C. 12742(a)(3)(E).
                        </P>
                    </FTNT>
                    <P>The Department recognizes that commenters are requesting flexibility to accept these instruments, which are generally insurance instruments, in lieu of security deposits and not just as a substitute form of security deposit. To that end, some commenters described allowing the owner to waive the security deposit requirement entirely in exchange for a surety bond or security deposit insurance. Beyond the legal barriers the Department identified, the Department also believes that at each phase of the process, surety bonds and security deposit insurance can pose a risk to both tenants and owners. Tenants must pay a nonrefundable fee or premium and are still liable under State landlord-tenant law and the lease contract for damages that are not covered by the issuer. The owner must submit a claim through a claims process and there is a risk of nonpayment or delayed payment that is significantly higher than if the owner itself held the security deposit in a bank account. Finally, the payment by the issuer of the surety bond or security deposit insurance is reliant upon the sufficiency of the overall fund itself. If the fund's underwriting standards or fund management are insufficient to enable the issuer to pay claims on the instruments it issued, then the owner will still be required to press their claim against the tenant.</P>
                    <P>While the Department strenuously objects to the use of these instruments in the HOME program, it also recognizes the commenter's concern that there may be some tenants that are already in a lease and are seeking to obtain tenant-based rental assistance. The Department believes that these instances will be rare but has added language to the HOME tenant-based rental assistance tenancy addendum provisions to hold landlords and tenants harmless if the tenant is already leasing the unit from the owner at the time that the HOME tenant-based rental assistance is provided. The Department is doing this because it does not wish to create unnecessary barriers to obtaining tenant-based rental assistance, especially when a tenant has already fulfilled whatever security deposit requirements the owner had set forth under the lease, before the participating jurisdiction provided the tenant-based rental assistance.</P>
                    <P>As a result of the above, the Department will be moving forward with language barring the use of surety bonds and security deposit insurance in § 92.253(b)(9) and (c)(9). The Department considered tenants that would be receiving tenant-based rental assistance after the beginning of their lease and has revised § 92.253(c)(9) to address the commenter's concerns.</P>
                    <HD SOURCE="HD3">U. Charges Against Security Deposit</HD>
                    <P>One commenter supported the proposed changes to the HOME rule requiring that if charges are made against the tenant's security deposit, owners must list all items charged and their cost, and promptly refund the security deposit to the tenant at move-out, less any documented charges made.</P>
                    <P>Another commenter recommended that HUD's final rule should enable a tenant to bring to a participating jurisdiction a challenge to any damage claims made by an owner and/or amounts charged against a tenant's security deposit refund. The commenter suggested that a tenant could use this challenge process if an owner does not refund all or a portion of a security deposit within two weeks. The commenter noted that sub-regulatory guidance regarding any such proceedings would be helpful.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department is maintaining its proposed language on charges against the security deposit and embedding the language in both the HOME rental housing tenancy addendum (§ 92.253(b)(9)) and HOME tenant-based rental assistance tenancy addendum (§ 92.253(c)(9)). The Department believes that requiring owners to list all items charged against the security deposit and the amount of each item is a minimum standard that should be required of all owners assisted by HOME or whose units are occupied by tenants with HOME assistance.
                    </P>
                    <P>The Department understands the desire to require participating jurisdictions to decide disputes between owners and tenants, especially when the participating jurisdiction has an agreement with the owner. However, it is up to the participating jurisdiction to determine how best to enforce compliance with the tenant protections provisions and the provisions of the lease addenda. While many participating jurisdictions may wish to inject themselves in disputes such as those over property damage and returning security deposits, there will be many other participating jurisdictions that only respond when the tenant alleges a violation of the HOME requirements and will leave more commonplace landlord-tenant disputes to the courts. The Department defers to participating jurisdictions to choose what is best for their jurisdictions but reminds them that they must demonstrate that they monitored and enforced the tenant protection requirements.</P>
                    <HD SOURCE="HD3">V. Direct Threats to Health and Safety Should Constitute Good Cause Regardless of Whether a Criminal Violation Has Occurred</HD>
                    <P>One commenter emphasized that the proposed changes do not address situations where eviction is necessary due to violence or other lease violations that may endanger other residents or the integrity of the property—situations that the commenter stated the housing provider should have the ability to take appropriate legal action against.</P>
                    <P>
                        <E T="03">HUD Respons</E>
                        e: The Department agrees with the commenter that there are explicit grounds for termination of tenancy or refusal to renew under the Act when a tenant poses a direct threat to the safety of the tenants or employees of the housing, or an imminent and serious threat to the property. The Department is adding these grounds to the termination of tenancy provisions at § 92.253(b)(10)(i)(B)(1) and § 92.253(c)(10)(i)(B)(1) in this final rule.
                    </P>
                    <HD SOURCE="HD3">W. Nonpayment of Rent as Grounds for Termination or Refusal To Renew</HD>
                    <P>One commenter questioned whether nonpayment of rent qualified as a “serious violation of the lease.” The commenter believed that because the Department further specified the grounds for termination of tenancy or refusal to renew, the omission of nonpayment of rent as a ground for eviction could be interpreted as HUD stating that it is not grounds to take those actions. The commenter was certain it was not HUD's intention to exclude nonpayment of rent as grounds for termination or refusal to renew but believed that one could interpret the new regulations to exclude this as grounds due to its omission.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department is not changing its position that nonpayment of rent is a violation of the lease and that violation of this term of the lease is grounds to terminate a tenancy or refusal to renew. The Department disagrees with the commenter that any silence or omissions in the regulation would allow a determination that nonpayment of rent 
                        <PRTPAGE P="836"/>
                        is not grounds for termination or refusal to renew under the HOME regulations. The Department declines to further explain each type of lease violation that could be considered by an owner. If HUD were exhaustive in its explanation of each type of lease violation that an owner could consider, HUD may inadvertently omit grounds for termination and make the very mistake that the commenter is describing in their comment.
                    </P>
                    <HD SOURCE="HD3">X. Increase in Income or Assets Is Not “Other Good Cause”</HD>
                    <P>One commenter supported HUD's proposed changes that clarify “other good cause” may not include a tenant's assets or the type of income or assets.</P>
                    <P>One commenter objected to the proposed change. The commenter stated that this was an example of a conflict with the Section 8 program. The commenter noted that if a PHA terminates the Housing Assistance Payment for a tenant who becomes over-income, in accordance with existing HUD regulations, “the lease automatically terminates”. However, neither being over-income nor the termination of a rental assistance contract are allowable reasons for the termination of a tenancy under the proposed regulations for a HOME-assisted unit. The commenter questioned whether HUD defines “governmental entity” as including PHAs, and whether a PHA termination represents “an order from a governmental entity.” The commenter requested clarity on how to apply the requirements where a PHA terminates assistance because the tenant is over-income or over the asset limitation in 24 CFR 5.618.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for reviewing the proposed rule and supporting the proposed change. Continuing to live in a HOME rental housing unit when there has been an increase in income is statutorily protected for tenants of HOME rental housing (see 42 U.S.C. 12745(a)(3)). The Act does not permit an increase in assets or assets of a certain type or amount to be considered good cause, even though this is good cause in other programs, most notably certain programs under the U.S. Housing Act of 1937 (42 U.S.C. 1437 
                        <E T="03">et seq.</E>
                        ) such as the Housing Choice Voucher program. The Department does not have discretion to permit termination or refusals to renew for these reasons and is clarifying this so that owners continue to comply with HOME requirements when assistance is combined with programs that do consider an increase in income or assets to be good cause for termination or refusal to renew. To that end, the Department is clarifying for the commenters that termination of tenancy due to the amount, form, or type of income or assets is a violation of the Act and current HOME regulations. The Department clarified this for the amount and type of assets in the preamble to the HOTMA final rule and is now further clarifying for over income tenants as well.
                        <SU>62</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>62</SU>
                             See 88 FR 9625, which states: 
                        </P>
                        <P>
                            There is no HOME statutory requirement to limit a family's assets or to remove a family from the HOME program if the family's net family assets exceed a threshold. HUD solicited public comment on whether HUD should impose asset limitations in the proposed rule to align with other programs. However, after due consideration and examination of the Cranston-Gonzalez National Affordable Housing Act (42 U.S.C. 12701 
                            <E T="03">et seq.</E>
                            ), HUD has determined that it will not impose asset limitations through this rulemaking. Section 225(b) of the Cranston-Gonzalez National Affordable Housing Act (42 U.S.C. 12755(b)), which provides tenant protections in the HOME program, states in relevant part that “[a]n owner shall not terminate the tenancy or refuse to renew the lease of a tenant of rental housing assisted under this subchapter except for serious or repeated violation of the terms and conditions of the lease, for violation of applicable Federal, State, or local law, or for other good cause.” HUD has never interpreted holding a certain level or type of assets as sufficient good cause for an owner to terminate a tenancy under the HOME statute and declines to do so in this rulemaking.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">Y. Other Good Cause Should Include Unreasonably Denying Access to the Owner To Make Repairs</HD>
                    <P>One commenter supported HUD's proposed changes that clarify “other good cause” may include when a tenant unreasonably refuses to provide the owner access to the unit for repairs.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for reviewing the proposed rule and supporting the proposed change. Owners must be able to reasonably access and repair units. All HOME-assisted rental housing units and units occupied by tenants with tenant-based rental assistance must meet applicable property standards. Requiring tenants to allow owners reasonable access to properly maintain the units in accordance with applicable property standards is prudent and protects tenants and owners alike.
                    </P>
                    <HD SOURCE="HD3">Z. Other Good Cause Requirements—Material Lease Violations, Nuisance, and Nondiscrimination Requirements</HD>
                    <P>One commenter suggested that in § 92.253(d)(1)(i) HUD should amend the rule by adding “material” to clarify that good cause exists for serious or repeated violations of the material terms of the lease.</P>
                    <P>Alternatively, the commenter suggested HUD put landlords on notice that nuisance ordinances may violate Federal civil rights law and recommended the following potential language: Other good cause may include when a tenant creates a documented nuisance under applicable State or local law or when a tenant unreasonably refuses to provide the owner access to the unit to allow the owner to repair the unit, but only when termination or refusal to renew a tenancy would be consistent with Federal civil rights law, such as the Fair Housing Act.</P>
                    <P>One commenter supported HUD's proposed changes that clarify “other good cause” may include a tenant creating a documented nuisance under applicable State or local law. Some commenters expressed concern with the language at § 92.253(d)(1)(i)(B) and asked HUD to remove it as a basis for good cause, stating that it is their experience that alleged nuisances are often disability related.</P>
                    <P>Commenters recommended that HUD not use the term “nuisance” in § 92.253(d)(1)(i)(B) and (C) because States and local governments have laws that target residents responsible for alleged nuisance activity, including calls to emergency services or noise disturbances related to domestic violence, with penalties such as fines and evictions. One commenter stated that these policies stand in opposition to HUD's efforts to protect tenants against unjustified evictions, and that HUD should instead establish a “good cause” for eviction that requires an actual, substantial, and imminent threat to the health and safety of, and right to peaceful enjoyment of the premises by, others.</P>
                    <P>
                        <E T="03">HUD Respons</E>
                        e: The Department agrees with the comment regarding addition of “material” and is adding “material” in § 92.253(b)(10) and § 92.253(c)(10) of this final rule to characterize the types of lease violations that constitute good cause to terminate a tenancy or refuse to renew a tenancy of a tenant in HOME rental housing or assisted with HOME tenant-based rental assistance. Inconsequential or minor lease violations that are easily curable or whose conditions no longer exist should not be the basis for a termination or refusal to renew.
                    </P>
                    <P>
                        The Department has removed from this final rule the use of nuisance as grounds for termination of tenancy or refusal to renew. The Department agrees that this ground has been the subject of significant fair housing and civil rights abuses and has led to the denial of necessary housing for survivors of domestic violence, dating violence, sexual assault, or stalking. The Department does not wish to perpetuate this cycle of discrimination through the 
                        <PRTPAGE P="837"/>
                        use of this terminology as an explicit ground for termination or refusal to renew.
                    </P>
                    <P>The Department already required that all terminations or refusals to renew are in accordance with all applicable Federal, State, and local laws and believes its revisions have addressed the commenter's concerns.</P>
                    <HD SOURCE="HD3">AA. Good Cause in Lease-Purchase Projects</HD>
                    <P>One commenter expressed concerns about the “good cause” definition, at proposed § 92.253(d)(1)(i)(A), stating that the language provides no provision for when a homebuyer fails to purchase a housing unit in a lease-purchase project. The commenter stated that this creates a loophole where after the failure of a lease-purchase agreement, a developer of property specifically for homeownership becomes locked into the long-term ownership and management of a HOME-assisted rental unit because the Department is not allowing this failure to be good cause to terminate the tenancy. The commenter recommended that a “business or economic reason” clause be added to the proposed “good cause” definition.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department agrees with the commenter and is adding to this final rule a provision in § 92.253(b)(10)(i)(A) and § 92.253(c)(10)(i)(A) allowing for termination of a tenancy for a family that is occupying a unit under a lease-purchase program when that family does not acquire the housing unit in accordance with a lease-purchase agreement. The Department recognizes that owners of homeownership development projects should have the ability to terminate the tenancy of a tenant that fails to purchase the housing so that the owner may sell the homeownership unit to another eligible low-income homebuyer before the housing is converted to rental housing (see § 92.254(a)(7) for more information).
                    </P>
                    <P>The Department is declining to consider a business or economic reason as adequate grounds for termination of tenancy for the HOME rental housing tenancy addendum. In the proposed rule, HUD proposed that it would be good cause to terminate a tenancy when an owner intends to withdraw the unit from the rental market to occupy the unit; allow an owner's family member to occupy the unit; or demolish or substantially rehabilitate the unit. This language is being maintained in this final rule and will allow owners to terminate for certain specific business or economic reasons. However, the Department was concerned that providing the more general grounds that the commenter requested would be too broad and could have unintended consequences.</P>
                    <HD SOURCE="HD3">BB. Use of Previous Convictions To Terminate Tenancy or Refuse To Renew a Tenancy</HD>
                    <P>Commenters stated that the preamble for § 92.253(d)(1)(i)(D) discusses how the crime for which there has been a conviction is a crime “during the tenancy period” and that good cause cannot be based on a violation “that occurred prior to tenancy.” However, the commenter pointed out that these are not explicit in the regulatory text and urged HUD to explicitly state in the final rule that the record of conviction be of a crime that took place during a person's tenancy and not prior to tenancy. The commenter also urged HUD to specify in the final rule that for “good cause” the conviction must have a direct bearing on the tenant's continued occupancy and pose an actual, substantial, and imminent threat to the health and safety of, and peaceful enjoyment of the premises by, others. The commenter repeated these suggestions as applied to the proposed TBRA provisions in § 92.253(d)(2)(i)(B).</P>
                    <P>One commenter added that HUD should consider limiting this provision to convictions by a tenant, household member, current guest, or other person under the tenant's control. The commenter further suggested that HUD should consider adding a definition of “crime that bears directly on the tenant's continued tenancy” or, alternatively, provide examples in sub-regulatory guidance accompanying the final rule. The commenter stated that the standard in the proposed rule is vague and could result in owners evicting for pretextual reasons and for criminal activity that does not pose a real threat to the health and safety of others.</P>
                    <P>One commenter noted that the preamble states there must be a record of conviction for a crime “during the tenancy period” to justify termination of tenancy or refusal to renew a lease, but the text of the rule is not as explicit, and the commenter recommended HUD make the final rule text as clear as the preamble discussion.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department agrees with the commenter that stated that the Department should define or provide examples of a “crime that bears directly on the tenant's continued tenancy.” After much consideration, the Department is revising the language in the new paragraphs § 92.253(b)(10)(i)(C) and § 92.253(c)(10)(i)(B)(3) to state that an owner may establish good cause for a violation of an applicable Federal, State, or local law through a record of conviction of a crime that threatens the health, safety, or right to peaceful enjoyment of the premises by other tenants in the project. This standard is a sufficient threshold and is directly related to the statutory good cause conditions found in 42 U.S.C. 12755.
                    </P>
                    <P>The Department is declining to specify the time period of the conviction of the crime in the regulation itself. There may be times, such as when a person moves into a unit during a family's ongoing tenancy, where tying the conviction to the family's initial occupancy may be inappropriate. However, the Department maintains, as it stated in the proposed rule, that for tenants that have already been screened by the owner—</P>
                    <P>
                        “good cause based on a violation of applicable Federal, State, or local law cannot be based on a violation that occurred prior to tenancy, a violation that does not have a direct bearing on a tenant's continued tenancy, or a basis other than a record of conviction. An owner may consider any mitigating circumstances relevant to whether the tenant will commit further violations of the lease or applicable Federal, State, or local law.” 
                        <SU>63</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>63</SU>
                             89 FR 46639.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">CC. Good Cause for Violation of Law Evidenced by Arrest for a Crime</HD>
                    <P>One commenter supported HUD's proposal that an owner shall not use a record or arrest, parole or probation, or current indictment to establish a violation of law.</P>
                    <P>Some commenters expressed opposition to the proposed language in § 92.253(d)(1)(i)(D) that would require that establishment of good cause for violation of law to be predicated on the conviction of a crime. One commenter explained that this lease renewal requirement is an excessively high standard because a criminal conviction requires a “beyond a reasonable doubt” evidentiary standard. The commenter suggested that the rule should require a more reasonable “preponderance of the evidence” standard. Additionally, the commenter suggested that the proposed rule specify the types of criminal activity that would qualify as affecting the safety of persons or property, as it does not consider the potential risks to tenant and staff safety in cases where an arrest or current indictment is due to violent actions of the tenant.</P>
                    <P>
                        The commenter also noted that the proposed rule requires “that an owner shall not use a record of arrest, parole or probation, or current indictment to 
                        <PRTPAGE P="838"/>
                        establish a violation of applicable Federal, State, or local law.” The commenter expressed concerned that this language only gives power to owners in cases where a tenant has a record of conviction. The commenter suggested that the rule should allow for other evidence to be used besides just a conviction in cases where the owner believes the tenant or prospective tenant is a threat to the safety of residents, staff, or property.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department understands the concerns of the commenters. The Department believes that direct threats to the safety of the tenants or employees of the housing, or imminent and serious threats to the property should constitute separate grounds for terminating a tenancy or refusing to renew a lease and is adding § 92.253(b)(i)(B)(
                        <E T="03">1</E>
                        ) and § 92.253(c)(i)(B)(
                        <E T="03">1</E>
                        ). The Department does not believe that such threats require a record of conviction so long as the threat to safety or property is evidenced by credible acts or threats that the harm will occur. As described in Section III of this preamble, this is not a low standard, but it is also not the legal standard of “beyond a reasonable doubt” evidenced by a conviction. The Department believes that with this change, and the change to allow termination in accordance with certain rules of other programs when tenants are assisted by each (see the next comment response), it has addressed the commenters' concerns.
                    </P>
                    <HD SOURCE="HD3">DD. Conviction of a Crime and Section 8 Housing Choice Voucher Regulations</HD>
                    <P>One commenter opposed the proposed changes to § 92.253(c) and (d), citing that many of the changes would create conflicts with existing HUD regulations because they go beyond what other HUD programs require and create conflict with the Housing Choice Voucher program.</P>
                    <P>One commenter stated that the proposed changes to the current termination of tenancy regulations should match more closely the Housing Choice Voucher program's termination of tenancy regulations to avoid conflicting interpretations. The commenter cites to examples where language mirrors section 8 regulations but is silent as to definitions of key terms. The commenter also stated that the requirement that “good cause” be established by conviction of a crime at the proposed § 92.253(d)(1)(i)(D) conflicts with treatment of criminal convictions under section 8 regulations, which allow for termination of tenancy for criminal activity regardless of conviction. The commenter also wanted clarification about whether signs of repeated drug activity on the premises through objectively verifiable contacts by emergency services were sufficient to constitute good cause to evict or if such activity must be coupled with a conviction because it constituted criminal activity in the jurisdiction.</P>
                    <P>The commenter also explains that where a household member is engaged in criminal activity in the Section 8 program, the requirements of 24 CFR 982.310(h)(2) permit an owner to require a tenant to exclude a household member in order to continue to reside in the assisted unit, where that household member has participated in or been culpable for action or failure to act that warrants termination. The commenter believes that the HOME rule conflicts with the Section 8 rule because it requires that a civil court proceeding is instituted against the household member to remove them from the unit.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department has revised the regulation at § 92.253(b)(10)(i) to address the commenter's concerns. If the tenant is participating in a program that is subject to 24 CFR part 5, subpart I; 24 CFR 882.511; or 24 CFR 982.310, then the owner is permitted to terminate the tenancy of any tenant or household member or refuse to renew the lease of a tenant of rental housing assisted with HOME funds pursuant to those provisions. This new provision will allow these regulations that govern other programs to form the basis of a termination or refusal to renew and constitute good cause under the HOME program even though these would not necessarily be grounds for HOME tenants that are not assisted through programs subject to those regulations. This improves alignment and addresses the commenter's concerns.
                    </P>
                    <HD SOURCE="HD3">EE. 60-Day Notice Before Termination of Tenancy or Refusal To Renew</HD>
                    <P>Some commenters supported the proposed change in § 92.253(d)(1)(ii) that would require owners to provide 60 days notice to tenants before termination of tenancy or refusal to renew instead of 30 days notice before termination of tenancy or refusal to renew. One commenter stated that HUD should amend 92.253(d)(1)(ii) and 92.253(d)(2)(ii) to require a 60-day notice of intent to terminate tenancy and/or not renew (both rental housing and TBRA should get 60-day notice). Another commenter suggested extending the 30-day eviction notice period for TBRA to 60 days to allow time for finding a suitable housing alternative.</P>
                    <P>One commenter explained that this would help tenants avoid eviction by providing sufficient time to dispute or cure lease violations and, where tenants are unable to do so, 60 days notice would provide better opportunity for those tenants to find new affordable housing and avoid being rendered homeless. One commenter suggested that HUD should clarify that the tenant has the right to cure a lease violation during the notice period in 92.253(d)(1)(ii). The commenter explained that allowing tenants to cure evictions in that time period promotes clarity in the law, and also prevents needless evictions.</P>
                    <P>One commenter noted that while a 60-day notice could provide better tenant protections, a concern would be if an industry norm of reciprocated notice periods pushed landlords to extend these expanded 60-day timeline for tenants to notify landlords beyond HOME supported units.</P>
                    <P>Some commenters opposed the provisions in the proposed rule that would extend the current requirement of a 30-day notice before a termination of tenancy to 60 days. Commenters expressed concern that the extension of the 30-day notice to a 60-day notice would conflict with local or State laws that vary widely on timing and requirements for eviction. A commenter stated that when a State has a 30-day notice in place for non-HOME tenants, administering and determining evictions in mixed-income communities will become difficult and may unintentionally cause confusion and inequity. The commenter recommended that HUD not institute a 60-day notice requirement and maintain the current 30-day notice requirement.</P>
                    <P>
                        Other commenters also expressed concern with the extension of the notice period, contending that many housing providers cannot sustain the financial burden of nonpayment for an extended period of time and that the 30-day timeframe already leads to loss of income, increased operational costs, unsustainable balances for tenants, and disruptive delays. One commenter stated that the proposed 60-day notice of lease termination provision is particularly onerous and does not provide financially distressed tenants with the financial support that they need. Another commenter noted that owners should have access to timely recourse in the event of continued and ongoing lease violations and there are risks to housing providers, property operations, and maintenance when landlords are unable to collect rent revenue for extended periods and that HUD should not further extend the 
                        <PRTPAGE P="839"/>
                        HOME notice to quit period without additional resources for owners to weather the resulting “economic vacancies” or the resources for residents to find alternate housing.
                    </P>
                    <P>Commenters opposed increasing the notice of termination of tenancy to 60 days for nonpayment of rent because it adds challenges to owners and current and prospective tenants. The commenters explained that increasing the timeline for nonpayment of rent to 60 days increases the financial burden on owners who need rent to sustain property operations. The commenter further explained that enforcement of a longer notice period may incentivize owners to file for evictions sooner due to the slow pace of the court process and the costs it will incur.</P>
                    <P>One commenter emphasized that its members are affordable housing providers; they are not in the “eviction business” as they are sometimes “branded,” and a 60-day notice period would lead to a significant departure of some great housing providers from participation in the HOME program. This commenter further stated that its member housing providers often face noncommunication from tenants who are unable to pay their rent and argued that HUD needed to be fair and require tenants to communicate with landlords when they can't pay their rent and make their best efforts to make timely partial payments as possible. The commenter also stated that housing providers are facing 60-120 days of nonpayment and uncollected rent in the millions, which leads to decreased operating budgets and fewer households assisted. Additionally, the commenter said that eviction cases can last several months.</P>
                    <P>Another commenter objected to the eviction period extension from 30 days to 60 days, stating that it finds that statistically the longer someone is permitted to stay in a unit without paying rent, the longer they will stay without paying rent. The commenter said that it is more likely that the month's rent will be just another month's rent that goes unpaid to the landlord and decreases the cash available for that landlord to pay its bills or maintain the property. The commenter also stated that anything longer than a 30-day eviction notice would not benefit tenants because it could increase exposure to harmful conditions and increase owners' scrutiny of tenants' background records relative to past-owed amounts to landlords, bad landlord references, and credit issues.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing the proposed rule. HUD agrees with commenters that the 60-day eviction notice for tenants in HOME-assisted rental units may conflict with State and local laws as well as the eviction requirements for tenants in units with project-based vouchers. HUD agrees that requiring owners to provide 60 days' notice may be a financial burden to owners, particularly when the good cause for eviction is the tenant's failure to pay rent. This burden may negatively impact the overall financial stability of the rental housing project, given local court processes and other delays once a termination action has been filed. The Department also understands that extending the notice period from 30 days to 60 days reduces alignment with other HUD programs that require only 30 days' notice and could have a chilling effect on new and existing landlords. For these reasons, HUD is maintaining the existing regulatory requirement that a project owner provide a written notice to vacate at least 30 days before the termination of tenancy or refusal to renew in this final rule.
                    </P>
                    <HD SOURCE="HD3">FF. Providing Notice To Vacate to Participating Jurisdictions</HD>
                    <P>One commenter requested HUD explain what a participating jurisdiction is required to do once they receive an owner's notice to vacate in accordance with the proposed § 92.253(d). For example, the commenter suggested that the final rule could clarify that, once collected, the participating jurisdiction should make the information available to HUD for compliance review.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The participating jurisdiction already must maintain the documentation for its files and provide it to HUD upon request. So, the commenter's recommendation is already covered by the recordkeeping requirements in § 92.508. The Department defers to participating jurisdictions on how best to use the notice to vacate. Some participating jurisdictions may wish to monitor the owners of projects that issue notices to vacate, especially if such notices are frequent. In other instances, participating jurisdictions may wish to intercede to attempt to stabilize the landlord-tenant relationship, if it is possible and practicable. These decisions are best left to participating jurisdictions and the owners they assist. The Department is simply attempting to empower participating jurisdictions by making sure they have current information on lease terminations in their HOME rental housing and tenant-based rental assistance portfolios.
                    </P>
                    <HD SOURCE="HD3">GG. Difference Between HOME Requirements and State Law Requirements on Notice of Termination of Tenancy or Refusal To Renew</HD>
                    <P>A commenter stated that many States have a rule of a 7-day “pay or quit” for an eviction based on non-payment of rent. The commenter asked for additional clarity on how to manage the 7-day notice requirement in States with the proposed requirement of providing an accessible notice to vacate at least 30 days prior to termination.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Regardless of other State laws that may be more permissive, the HOME statutory minimum notice period prior to termination of tenancy or refusal to renew is 30 days (see 42 U.S.C. 12755(b)). The only exception to the 30-day notice period is when the person poses a direct threat to the safety of the tenants or employees of the housing or an imminent and serious threat to the property and the termination or refusal to renew is in accordance with the requirements of State or local law.
                    </P>
                    <P>
                        If an owner is in a State where the notice requirements are less stringent (
                        <E T="03">i.e.,</E>
                         States that require shorter notice periods) than the HOME statutory notice requirements, then the owner must still comply with the HOME tenant protections and adhere to the HOME requirements. The owner is making the decision to adhere to these stricter notice requirements when the owner and participating jurisdiction enter into a HOME agreement where the owner agrees to comply with the tenant protection requirements (see 24 CFR 92.504(c)). This treatment and the statutory requirements are not being changed as part of this rulemaking.
                    </P>
                    <HD SOURCE="HD3">HH. Termination of Tenancy for Refusal To Provide Income Documentation</HD>
                    <P>One commenter suggested that the provision should also clearly state that the landlord may terminate their tenancy or not renew their lease for failure to provide satisfactory documentation.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department declines to make failure to provide sufficient documentation an explicit form of good cause to terminate tenancy or refusal to renew in this final rule. The participating jurisdiction and owner must work with HOME-assisted tenants to obtain the appropriate documentation to determine the applicable income and HOME rents for HOME-assisted rental housing tenants. Failure to provide documentation may be for legitimate reasons. Further, the Department is attempting to reduce the burden of providing source documents during 
                        <PRTPAGE P="840"/>
                        income determinations by providing an additional safe harbor that can be used at initial and annual income examinations in the new § 92.203(a)(3).
                    </P>
                    <HD SOURCE="HD3">II. Right To Renew Clause</HD>
                    <P>One commenter stated that HUD should have a right to renew clause for all tenants unless the tenants have violated the terms of their agreement. The commenter stated that HUD should require a landlord to provide 180 days advanced notice of their decision not to renew and said notice must offer a written explanation of the good cause for non-renewal. The commenter recommended that good cause be defined as follows: (1) the tenant has not accepted the renewal offer in writing within the time allowed; (2) the tenants who accepted the renewal offer, along with any replacement tenants acceptable to the landlord, have not returned a signed lease to the landlord within 10 days of receipt; (3) the landlord can demonstrate a lease violation; (4) the owner or a member of the owner's immediate family is going to occupy the unit for a succeeding term; or (5) the landlord will no longer be renting the property out.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department declines to create the right to renew clause described by the commenter in this final rule. The Department is also not going to impose through this final rule a requirement that an owner provide a family with 180 days' notice before refusing to renew a lease. The Department believes 180 days is an unreasonably long amount of time and has reverted its notice requirements to 30 days' notice in response to public comment (see earlier preamble responses).
                    </P>
                    <P>
                        The good cause requirements in the HOME program are statutory. In HOME, the tenant has the right to renew unless the owner has good cause to refuse to renew or terminate the tenancy.
                        <SU>64</SU>
                        <FTREF/>
                         The Department is providing different forms of good cause that may allow an owner to terminate the tenancy but many of the grounds provided by the commenter provide insufficient protections to families or are inherent in the way that HOME projects and private market properties are managed.
                    </P>
                    <FTNT>
                        <P>
                            <SU>64</SU>
                             See 42 U.S.C. 12755(b).
                        </P>
                    </FTNT>
                    <P>
                        The Department is declining to describe in this final rule whether a tenant's failure to accept a lease renewal offer or failing to execute a lease would constitute good cause to refuse to renew the tenants lease because in each case, the tenant has not renewed the lease. The Act requires that only serious or repeated lease violations be good cause. The Department is further defining the types of lease violations that should constitute good cause as “material” as the Department does not believe that frivolous or inconsequential lease violations should constitute good cause. As such, the Department believes the commenter's language that “the landlord can demonstrate a lease violation” is not legally acceptable under the Act and is declining to adopt it. The Department does allow for owners of units occupied by tenants receiving tenant-based rental assistance to terminate a tenancy or refuse to renew if the owner wishes to occupy the unit, allow family to occupy the unit, or take the property off the market. The Department had proposed those as appropriate grounds for termination of tenancy or refusal to renew the lease in the proposed rule in § 92.253(d) and is maintaining those grounds in the redesignated § 92.253(c)(10)(i)(B)(
                        <E T="03">5</E>
                        ). As these grounds apply only to units on the private market and not to HOME rental housing, which must be owned and operated in accordance with the requirements of 24 CFR part 92 for the minimum period of affordability, the Department declines to include in this final rule these grounds for HOME rental housing terminations of tenancy or refusals to renew.
                    </P>
                    <HD SOURCE="HD3">JJ. Termination of Tenancy in Tenant-Based Rental Assistance</HD>
                    <P>One commenter recommended that any deviations between the two sets of protections be clearly stated. One commenter opposed the addition of § 92.253(d)(2) because, according to the commenter, these standards should already apply more broadly and not just for TBRA clients. Additionally, the commenter stated that the word “reasonable” would be too subjective and not allow for standardization of tenant selection across the program.</P>
                    <P>This commenter also asserted that TBRA contracts should continue to be executed by the owner and support tri-party rental assistance contracts where the owner, tenant, and participating jurisdiction all sign, as an option. This method would ensure the lease contains the HOME tenancy addendum and that the owner follows applicable TBRA requirements.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department has reorganized the tenant protections in § 92.253 and the tenant-based rental assistance contract provisions in § 92.209(e) in this final rule in a way that addresses some of the commenters' concerns. The Department is now placing the termination provisions directly in the HOME rental housing tenancy addendum and the HOME tenant-based rental assistance tenancy addendum. The Department is also requiring in § 92.209(e)(1) that owners and tenants each enter into a rental assistance contract with the participating jurisdiction when tenant-based rental assistance is provided. This may take the form of a tri-party contract or individual agreements between the participating jurisdiction and the owner and the participating jurisdiction and the tenant.
                    </P>
                    <P>
                        The Department is declining in this final rule to define reasonable or to remove its usage in HUD regulations. Reasonable is a commonly used and understood term and is not too subjective. There is a body of caselaw and jurisprudence surrounding what is and is not reasonable under certain circumstances and HUD declines to further specify what reasonableness is in tenant selection. The Department also declines in this final rule to apply the termination of tenancy provisions applicable to tenant-based rental assistance to HOME rental housing tenants. The termination provisions for tenant-based rental assistance contain certain provisions that only apply to owners of private rental housing and not HOME rental housing projects, such as termination of tenancy so that the owner may move into their unit (See § 92.253(c)(10)(i)(B)(
                        <E T="03">5</E>
                        )).
                    </P>
                    <P>The Department agrees with the commenter on the benefits of tri-party rental assistance contracts but is providing participating jurisdictions with the option of entering into tri-party rental assistance contracts or into separate agreements with the owner and the tenant. This is because HOME is a block grant program, and participating jurisdictions should have discretion in how they bind owners and tenants to the requirements of their tenant-based rental assistance program.</P>
                    <HD SOURCE="HD3">KK. Prohibiting Constructive Evictions</HD>
                    <P>One commenter supported HUD's proposal to prohibit owners from performing “constructive evictions” (aka “self-help” evictions”), such as locking a tenant out of their unit or stopping service on their utilities. One commenter supported requiring owners to provide tenants with uninterrupted utility service to “counteract a disturbing trend of so-called ‘self-help’ evictions”, whereby owners use their control of utilities to force tenants to end their tenancy.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters and is including these provisions in this final rule. Due to reorganization of the tenancy addenda provisions, these provisions are now contained in § 92.253(b)(10)(v) 
                        <PRTPAGE P="841"/>
                        and § 92.253(c)(10)(iv) and shall apply to both tenants in rental housing and tenants receiving tenant-based rental assistance.
                    </P>
                    <HD SOURCE="HD3">LL. Termination of Tenancy Because of Termination of Rental Assistance Contract</HD>
                    <P>One commenter opposed the revisions to § 92.253(d)(2)(i)(E) because the commenter believes tenants should have the ability to request termination if the rental assistance contract ends, but the landlord should not have the discretion to do so. The commenter also suggested adding tenant liens as a prohibited action in § 92.253(d)(1)(v). The commenter urged HUD to further indicate how confidential tenant information is handled.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department agrees with the commenter and is removing from this final rule the termination of the rental assistance contract as specific grounds for termination of tenancy or refusal to renew. Instead, the Department is revising § 92.253 of this final rule to state that the HOME tenant-based rental assistance tenancy addendum shall terminate upon the termination of the rental assistance contract.
                    </P>
                    <P>
                        The Department is declining to enumerate in this final rule specific measures projects owners must take to ensure tenant information is handled confidentially. Participating jurisdictions and owners should take reasonable measures to prevent unauthorized access to confidential information by persons without a need to know, (
                        <E T="03">e.g.,</E>
                         password protected systems, locking file cabinets and desk drawers that contain personal identifying information, etc.).
                    </P>
                    <HD SOURCE="HD3">MM. Tenant Selection Procedures Should Require That Owners Do Not Evaluate Previous Bankruptcies</HD>
                    <P>A commenter stated that a previous bankruptcy should not be treated as equivalent to a previous eviction when a person is applying for low-income housing. The commenter also recommended that, prior to charging an application processing fee, properties must inform persons applying for housing that a previous bankruptcy disqualifies them from housing at the property, if applicable.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HOME is a block grant program, and neither the statute nor the regulations address whether or how previous bankruptcies are treated in the tenant screening process. The Act provides owners with discretion in tenant selection. As long as tenant selection is performed in accordance with the Act, all applicable Federal, State, and local laws (including but not limited to nondiscrimination and VAWA requirements), the owner has discretion to consider the effect of prior bankruptcies or past financial problems. The Department encourages tenant selection policies that do not unfairly penalize families for factors that no longer negatively impact their ability to pay or to live in HOME-assisted rental housing but recognizes that these determinations are fact-sensitive. The Department therefore declines to further impose requirements in this area at this time, including requiring notice prior to submission of application. HUD notes that the comment appears to address all low-income housing, not only housing funded through the HOME program. To the extent that this comment also describes programs that are not part of this rulemaking, that portion of the comment is outside the scope of this rulemaking.
                    </P>
                    <HD SOURCE="HD3">NN. Tenant Selection Procedures Should Incorporate Fair Chance Housing Practices</HD>
                    <P>One commenter suggested that HUD prohibit the use of explicit credit score and criminal history requirements, as well as limit the “look-back” period for eviction records to one year from the date of application.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the commenter's feedback, but HOME is a block grant program, and participating jurisdictions and project owners are permitted to establish tenant screening and selection criteria. Similar to the previous response, the Department encourages tenant selection policies that do not unfairly penalize families for factors that no longer negatively impact their ability to pay or to live in HOME-assisted rental housing. The Department also reminds owners and participating jurisdictions that all tenant selection is subject to Federal, State and local requirements, including nondiscrimination and VAWA protections. However, as these determinations are fact-sensitive and the Act provided owners with discretion in tenant selection,
                        <SU>65</SU>
                        <FTREF/>
                         the Department declines to further impose requirements in this area at this time.
                    </P>
                    <FTNT>
                        <P>
                            <SU>65</SU>
                             See 42 U.S.C. 12755(d).
                        </P>
                    </FTNT>
                    <P>
                        Owners should be aware that screening based on credit score and criminal history can have a disparate impact against protected classes in violation of the Fair Housing Act 
                        <SU>66</SU>
                        <FTREF/>
                         and should ensure that their screening procedures do not run afoul of these laws.
                    </P>
                    <FTNT>
                        <P>
                            <SU>66</SU>
                             See 
                            <E T="03">Guidance on the Application of the Fair Housing Act to the Screening of Applicants for Housing” https://www.hud.gov/sites/dfiles/FHEO/documents/FHEO_Guidance_on_Screening_of_Applicants_for_Rental_Housing.pdf,</E>
                             mentioned by a commenter, and 
                            <E T="03">“Tenant Background Checks and Your Rights”, https://www.hud.gov/sites/dfiles/FHEO/documents/HUD_Tenant_Background_Checks_and_Your_Rights.pdf,</E>
                             which is joint guidance developed by HUD, the Federal Trade Commission, the Department of Justice, and the Consumer Financial Protection Bureau.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">OO. Notification of Grounds of Disapproval Under § 92.253(e) Tenant Selection Procedures</HD>
                    <P>With regard to § 92.253(e)(6), one commenter suggested that HUD should require that the written notification to reject applicants describe the grounds for rejection with sufficient specificity that a person can prepare an appeal of the housing provider's decision. The commenter stated that any supporting materials, such as a consumer report, must be provided to the tenant. The commenter further stated that these additional requirements align with HUD's recent fair housing guidance on tenant screening.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         42 U.S.C. 12755(d)(4)(B) only requires “the prompt notification in writing of any rejected applicant of the grounds for any rejection” and does not provide any additional recourse. If an applicant believes that the grounds for disapproval violate Federal, State, or local law, they may make a complaint with the relevant legal authorities in accordance with the applicable process (
                        <E T="03">e.g.,</E>
                         contact HUD's Office of Fair Housing and Equal Opportunity if an applicant has reason to believe that the grounds for rejection are due to discrimination). The Department has issued guidance on tenant screening and the Fair Housing Act, and such guidance applies to all HOME rental housing units and HOME tenant-based rental assistance.
                        <SU>67</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>67</SU>
                             See the Fair Housing Act guidance for tenant screening in rental housing here: 
                            <E T="03">https://www.hud.gov/sites/dfiles/FHEO/documents/FHEO_Guidance_on_Screening_of_Applicants_for_Rental_Housing.pdf.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">PP. Environmental, Health, and Safety Hazards</HD>
                    <P>One commenter supported the change to add language requiring a participating jurisdiction to notify owners and tenants of any environmental, health, or safety hazards affecting the project, a unit, or tenants, and provide them with a summary of the nature, date, and scope of the hazard.</P>
                    <P>
                        One commenter urged HUD to include in the final rule, in § 92.253(f), a requirement that where an owner has actual knowledge of an environmental, health or safety hazard, the owner must inform tenants (in addition to the 
                        <PRTPAGE P="842"/>
                        participating jurisdiction), and provide them with a summary of the nature, date, and scope of the hazard as well as actions the owner will take, if able, to address the hazard. Furthermore, one commenter suggested that HUD should require that the summary be in writing and that the owner should provide notice of the hazard to tenants, in addition to the participating jurisdiction.
                    </P>
                    <P>One commenter expressed concern regarding the proposed language at § 92.253(f) requiring both a participating jurisdiction and an owner to notify the other party if one party has “actual knowledge of an environmental, health, or safety hazard affecting a project, unit, or HOME tenants.” The commenter noted that it is unclear what HUD intends “environmental, health, or safety hazards” to mean and expressed concern about the lack of any defining language to guide participating jurisdictions' and owners' actions to comply. The commenter stated that without definitions, several interpretations are possible. The commenter also noted concerns about the burden of paperwork and compliance monitoring on participating jurisdictions, their partners, and their staff.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department has taken the comments into consideration and revised the language of § 92.253(f) to specify that a summary of the nature, date, and scope of such hazards be provided in writing. The Department also revised paragraph (f) to state that an owner must provide notice of the environmental, health, or safety hazard affecting their project, units within their project, or tenants residing within their projects to tenants in addition to the participating jurisdiction. The Department believes both commenters making recommendations are right. The Department is not further defining the language in regulation and has provided examples of the types of hazards in the proposed rule. The Department will provide additional implementation guidance on this provision and other tenant protections after publication of the final rule. The Department is also declining to require owners to further specify how they will address the damage. While the commenter's intent is noble, most environmental, health, or safety hazards are not caused by owners of rental housing projects but by other intervening outside events. It is inappropriate to require owners to specify how they will address hazards they did not cause and are not responsible for resolving.
                    </P>
                    <HD SOURCE="HD3">QQ. Increasing Tenant Protections Could Increase Litigation or Other Costs</HD>
                    <P>One commenter expressed concerns about the potential for litigation and increased costs for nonprofit affordable housing developers and operators. The commenter expressed concerns about the provision of the proposed rule requiring “secure and confidential” storage of the personal records of applicants and residents and how HUD will monitor and enforce this requirement. The commenter stated that the costs for information technology staff or software packages would be burdensome, particularly for smaller organizations or organizations in rural areas that do not already have that capacity. The commenter also questioned whether HUD intended to require a certain information security standard, and, if so, at what cost. The commenter also stated that the vague nature of proposed language in the lease addendum section could expose owners to frivolous lawsuits and be difficult to comply with. The commenter recommended further clarification and definitions regarding words like “unreasonably” or “reasonable” to avoid compliance issues, unnecessary litigation, or uneven application across participating jurisdictions.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department disputes the commenter's assertion that litigation costs are likely to increase through the provision of a baseline level of tenant protections. In response to the commenter's concerns about how an owner can maintain confidential records, the Department notes that an owner can maintain confidentiality and securely store records through storing files in locked drawers, password protecting their computers, and using basic encryption if transmitting personally identifying information through email. This standard is not as burdensome as what the commenter describes and represents standard industry practices. Commonly used terms such as “reasonable” and “unreasonably” have a body of jurisprudence and common law precedent that should provide greater predictability not less. The “frivolous” or “unnecessary” litigation that the commenter is describing would be litigation if an owner were to disclose or otherwise not protect confidential information of a tenant or household member participating in a Federal program. The Department does not believe that this is an accurate characterization and that violations of confidentiality are serious matters that may have major negative ramifications on people's lives. As such, the Department is not removing the confidentiality requirements in the final rule.
                    </P>
                    <HD SOURCE="HD3">RR. Tenant Protections in the Rule May Conflict With Other Laws and Programs That Have Different Standards</HD>
                    <P>One commenter stated that the proposed language does not account for possible conflicts between local, State and other regulatory schemes and the protections in the proposed rule. Commenters recommended that HUD add language clarifying that the protections in the rule are not exhaustive and that they do not preempt participating jurisdictions, States or local governments from requiring other tenant protections.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department revised the tenant protections to make the protections more consistent with Federal laws and HUD programs. The Department has revised § 92.253(b)(10) to enable owners to terminate tenancy in accordance with the requirements in 24 CFR part 5, subpart I; 24 CFR 882.511; or 24 CFR 982.310. This will apply to tenants living in units or receiving assistance that are covered by one of these regulations and allows owners to maintain a consistent approach to termination of tenancy when overlapping HUD program requirements apply. Similarly, the Department withdrew the proposal to extend the notice period for termination of tenancy or refusal to renew tenancy in rental housing to also maintain alignment with other Departmental rulemaking efforts.
                    </P>
                    <P>The Department agrees with the commenter that these requirements do not preempt a participating jurisdiction, State, or local government from providing additional protections. The Department has revised § 92.253(b)(6) and § 92.253(c)(6) to explicitly state that tenants may assert any protection under their lease and any applicable Federal, State, or local tenant protections. Where State or local landlord-tenant laws are more restrictive than HUD requirements, then the owner must follow the more restrictive requirements.</P>
                    <HD SOURCE="HD2">§ 92.254—Qualification as Affordable Housing: Homeownership</HD>
                    <HD SOURCE="HD3">A. Downpayment Assistance Programs Help Low-Income Households</HD>
                    <P>One commenter stated that downpayment assistance programs are vital for low-income households to be able to purchase homes.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD agrees with the commenter.
                        <PRTPAGE P="843"/>
                    </P>
                    <HD SOURCE="HD3">B. Homeownership Value Limits in § 92.254(a)</HD>
                    <P>HUD received several comments on the HOME homeownership value limits, with many commentors stating that the limits are too low and that the data and process for calculating them should be updated to reduce burden on participating jurisdictions and increase options for homebuyers. One commenter noted that by limiting the value to 95 percent of area median home prices, families at or below 80 percent of area median income struggle to access homeownership in the community of their choosing.</P>
                    <P>Some commentors pointed out that the value limits disproportionally impact rural communities or concentrate opportunities in minority communities while limiting opportunities in predominately white neighborhoods. One commenter stated the 95 percent HOME price limit hinders developers and homebuyers from accessing high opportunity neighborhoods. Another commenter agreed that the limitation creates a barrier for both developers looking to meet housing demand and homebuyers wanting to live in communities of their choice. The commenter said that the home price limit has long been an impediment to fair housing but given unprecedented home prices it is now an insurmountable obstacle.</P>
                    <P>Several commentors suggested that HUD revert to using the FHA 203(b) Single Family Mortgage Market data. Commenters suggested the data from FHA 203(b) better supports rural communities as it is more dynamic than the current numbers and offers a higher national floor. Additionally, the commenters noted that there is precedent for this practice as HUD used 203(b) data as the basis for the 95 percent of median home price calculation ahead of its 2013 rulemaking.</P>
                    <P>One commentor stated that the homeownership value limit has been a problem for years, particularly in rural areas, because it is too low to enable the construction of new units or the acquisition-rehab of homeownership units for affordable sale. The commenter noted that HUD cited statutory restrictions against changing the limit but argued that there is significant room for HUD to make regulatory changes. For example, the commenter said that the statute is silent on how HUD should determine the median purchase price for an area, and, in fact, in 2013 HUD changed the source of the median home purchase price data from the FHA Single Family Mortgage Limits (203(b) limits) to the current source.</P>
                    <P>One commentor stated that the limits are too low to cover repairs to older homes or meet the needs of larger families due to a lack of flexibility in rural areas to account for high costs from limited local contractor availability and infrastructure.</P>
                    <P>A commentor stated that giving local participating jurisdictions a chance to calculate their own price limits is well-intentioned but of limited use. Another commenter stated that participating jurisdictions struggle with cost and capacity issues while attempting to establish their own limits. Commenters recommended that HUD build out its regulations to further limit the effect of the HOME homeownership value limits as much as possible.</P>
                    <P>Another commentor argued that homeownership value limits were not needed as other quantitative controls exist in the form of income limits and affordability limits but acknowledged that HUD is still statutorily required to provide them.</P>
                    <P>One commentor suggested that HUD use an alternative maximum sales price allowed to align with certain State programs that use 90 percent of the IRS annually published Average Area and Nationwide Area Average Purchase Prices.</P>
                    <P>Commentors acknowledged congressional action, or new legislation would be needed to eliminate the 95 percent limit, with one commentator suggesting that it be replaced with a 110 percent limit or a percentage established by the Secretary.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD acknowledges the numerous challenges communities face implementing homebuyer and homeowner rehabilitation programs. Section 215(b) of NAHA requires that the initial purchase price or after-rehabilitation value of homeownership units assisted with HOME funds not exceed 95 percent of the area median purchase price for single family housing, as determined by HUD. Historically, HUD used the FHA Single Family Mortgage Limit (known as the 203(b) limits) as a surrogate for 95 percent of area median purchase price. However, statutory changes require the 203(b) limits to be set at 125 percent of area median purchase price. Consequently, in its July 2013 final rule, HUD eliminated the 203(b) limit as the sales price or after rehabilitation value limit for HOME-assisted homeownership housing. The 2013 Final Rule established that HUD would begin to provide limits for affordable newly constructed housing based on 95 percent of the median purchase price of newly constructed housing in the area using data from the Federal Housing Administration (FHA) and other appropriate data sources, with a minimum limit based on 95 percent of the U.S. median purchase price for new construction for nonmetropolitan areas. For existing single family housing units being acquired or rehabilitated with HOME funds, HUD would begin to provide limits for affordable existing housing based on 95 percent of the median purchase price of existing housing in the area using data from the FHA and other appropriate data sources on sale prices of existing homes in standard condition, with a minimum limit based on 95 percent of the State-wide nonmetropolitan area median purchase price using this data.
                    </P>
                    <P>The Department understands the unique challenges rural communities face using the HUD published homeownership value limits and has begun taking steps to assist those communities. In 2024, HUD made a major revision to the homeownership value limit methodology outlined in section 92.254(a)(2)(iii) of the July 2013 Final Rule. For existing housing, HUD is now using the greater (rather than the lesser) of the State non-metropolitan and U.S. non-metropolitan media sales values as the minimum value in which the limit is calculated. This change will substitute more local, State-level data for national-level data.</P>
                    <HD SOURCE="HD3">C. Beginning the Period of Affordability at Project Completion</HD>
                    <P>One commenter stated that the period of affordability for homebuyer projects should be measured by the assisted-homebuyer's acquisition of the unit, not the project completion date. This is because the current rule is administratively burdensome, leads to unintentional noncompliance by participating jurisdictions, and confuses assisted buyers. The commenter noted that parties never know when the period of affordability ends because none of the parties knows for certain when the project is marked complete in the Integrated Disbursement and Information System (IDIS), which leaves participating jurisdictions confused. The commenter noted there is often unintentional compliance because participating jurisdictions need some time, if even only a few days, to review and compile final financial information needed to complete a project in IDIS, which means that project completion cannot be achieved on the same day an assisted buyer purchases the unit.</P>
                    <P>
                        One commenter noted that the period of affordability is a problem in multi-address homeownership projects 
                        <PRTPAGE P="844"/>
                        because the buyer of the first HOME-assisted unit in a multi-address project may have taken possession and lived in their unit for months while other units were still under construction. The commenter stated that the project would not be considered complete under the definition until all assisted units have been transferred to eligible buyers, so no buyer's POA has started to run until the last assisted unit is sold. The commenter recommended that HUD could encourage this information to be disclosed to buyers.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department agrees with the commenter and is revising § 92.254(a)(4) to begin the period of affordability after execution of the instrument that requires the recapture of the HOME investment or recordation of the resale restrictions for sale to the next homebuyer. The Department is further requiring that execution of the instrument that requires the recapture of the HOME investment or recordation of the resale restrictions for sale to the next homebuyer only occur after the housing meets the participating jurisdiction's property standards in accordance with § 92.251(c)(3) and the property title is transferred to the homebuyer. This will provide the same necessary protections for homebuyers (
                        <E T="03">i.e.,</E>
                         that the property meets property standards, that title has transferred, and that the resale or recapture provisions have been applied to the property) without conditioning the period of affordability on the participating jurisdiction's completion of the information in the disbursement and information system.
                    </P>
                    <HD SOURCE="HD3">D. Data Sources and Methodology Recommendations</HD>
                    <P>Commenters suggested that HUD change the data that it uses to calculate the homeownership limit to make the data more accurate or timely, with one commentor even suggesting that HUD remove the value limits if more accurate data couldn't be used. One commentor recommended HUD incorporate an adjustment factor or inflation factor to make limits more current. Another commentor suggested using data that excludes investor-purchased homes and only includes owner-occupied sales, as investor purchases can skew data thereby undermining affordability goals. The commenter also suggested replacing the limit with a HOME Subsidy Limit focused on the “appropriateness of the amount of assistance” by participating jurisdictions to address concerns around the prudent use of funds without restricting homebuyers' choices in neighborhood or home.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         While the Department is somewhat limited by NAHA, HUD will continue to look for ways to ensure the data used to calculate area median purchase price is as accurate as possible to support the use of HOME funds for homeownership assistance. Unfortunately, for the reasons stated earlier in this preamble, the Department cannot change the 95% limit itself.
                    </P>
                    <HD SOURCE="HD3">E. Support for Resale Formula Revisions in § 92.254(a)(5)(i)</HD>
                    <P>Several commentors expressed support and appreciation for providing resale formulas. Commenters stated that the formulas would improve consistency and fairness to homebuyers while resolving the frustrations felt by participating jurisdictions as they develop provisions or rely on inconsistent guidance. Commenters also expressed appreciation for retaining the ability to submit their own resale formulas for HUD approval, with one commentor asking HUD to provide more detail on the HUD approval process for submitting their own formulas. A commenter encouraged HUD to work with Congress to amend the relevant statutory language to better facilitate the homebuyer resale provision process.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Through this rule making, HUD has worked within the statutory requirements of the Act to amend and clarify the homebuyer requirements at § 92.254 to assist participating jurisdictions that undertake homebuyer activities. HUD thanks the commenters for reviewing the proposed rule and is moving forward with the resale models without change.
                    </P>
                    <HD SOURCE="HD3">F. Undefined Terms in Resale § 92.254(a)(5)(i)</HD>
                    <P>One commenter stated that a “reasonable range of low-income buyers”, “capital improvement”, and how to value a capital improvement are not explained and are open to interpretation. A commenter suggested that HUD provide a definition of “fair return on investment” in precise percentage terms and recommended that HUD, or the participating jurisdiction, be responsible for providing down payment assistance to ensure the sale price provides an ROI that meets the definition.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         As a Federal block grant program, HOME provides flexibility to State and local governments to determine how best to address community needs. By giving participating jurisdictions the ability to define what constitutes a fair return on investment, and a reasonable range of low-income buyers, HUD is permitting participating jurisdictions to design resale provisions to address community goals and adapt to local market conditions. The Department also believes that “capital improvement” is a known term in real estate and that a participating jurisdiction should not have difficulty determining whether a capital improvement has been made to the property. Capital improvements can be valued based on appraisals, the cost-to-build, or other commercially reasonable methods. The Department is providing four models that can be used to determine resale, some of which involve the selection of a fixed percentage or use of an index that can assist the participating jurisdiction in determining the fair return on investment in accordance with the HOME regulations and statute. The Department refuses, however, to provide a fixed percentage or range, as the commenter suggests. To assist participating jurisdictions in defining these terms, HUD has published guidance in CPD Notices and technical assistance products. For the reasons listed above, HUD has declined to further define these terms in regulation.
                    </P>
                    <HD SOURCE="HD3">G. Use of HUD-Provided Formulas in § 92.254(a)(5)(i) Will Not Provide Significant Return to Homebuyer</HD>
                    <P>One commenter, that does not use the resale option in its program, stated that a HOME-assisted buyer who sells their home wouldn't receive much of a return using HUD's four proposed formulas. The commenter noted that the benefit of homeownership is wealth building through the appreciation of home value and equity.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD does not agree with this comment. HOME is a block grant program. Participating jurisdictions have the flexibility to establish fair return standards that are more or less generous depending on their markets and their policy objectives. Moreover, if an assisted homebuyer owns the housing as their principal residence through the period of affordability, then the resale provisions terminate, and they will be able to realize the full benefits of wealth accumulation that come with homeownership.
                    </P>
                    <HD SOURCE="HD3">H. Support for Recapture of Investment Revisions in § 92.254(a)(5)(ii)</HD>
                    <P>
                        A commenter stated that they support the proposed changes to the HOME recapture language clarifying that the recapture amount is the direct assistance to the homebuyer that enabled the homebuyer to purchase the unit.
                        <PRTPAGE P="845"/>
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for reviewing and is moving forward with this clarification.
                    </P>
                    <HD SOURCE="HD3">I. Adding Rent Restrictions to Accessory Dwelling Units in § 92.254(a)(6)</HD>
                    <P>A commenter stated that the HOME program should set a rent cap on ADUs where a homebuyer is purchasing a multi-unit property with HOME assistance. The commenter stated that this would prevent the misuse of HOME funds. The commenter also stated that real estate tax exemptions should be provided to homebuyers who are operating within an ADU rent cap limit. The commenter stated that these suggestions would help increase community support for ADU projects and benefit the wider community while offering a modest boost to homeowners.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Whether a unit is subject to the HOME rental housing period of affordability requirements in § 92.252 depends upon whether HOME funds were used to assist in the acquisition of the unit, as described more fully in § 92.254(a)(6), which was only revised for minor technical corrections. The Department believes that through its revisions to small-scale housing provisions in §§ 92.2, 92.251, 92.252, and 92.253, it has enabled purchasers of single family housing, including housing with ADUs, to more effectively manage these units as HOME rental housing units when those requirements apply. State and local property tax exemptions are outside the scope of this rule.
                    </P>
                    <HD SOURCE="HD3">J. Preserving Affordability in § 92.254(b)—Clarify the Parties That Have Rights of First Refusal</HD>
                    <P>One commenter expressed concerns that neither participating jurisdictions nor program participants fully understand that rights of first refusal and other preemptive rights are not acceptable beyond those permitted to a participating jurisdiction and a community land trust. The commenter noted that some developers seek to retain rights of first refusal, particularly in the case of homeownership units under recapture provisions, and the repurchase price prevents buyers from realizing any appreciation otherwise attributable to the owner. The commenter noted that HUD should make clear that only participating jurisdictions and community land trusts are permitted by statute to exercise rights of first refusal.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the commenter's concern that program participants often fail to understand when preemptive rights are granted and to whom. The Continuing Appropriations Act, 2016 (Pub. L. 114-113) extended a participating jurisdiction's right to exercise purchase options, rights of first refusal or other preemptive rights provided in 42 U.S.C. 12742 of the Act to Community Land Trusts that developed the homeownership units. Neither the Act nor the Continuing Appropriations Act, 2016 (Pub. L. 114-113) provide any other entity the right to exercise purchase options, rights of first refusal or other preemptive rights to acquire housing when there is a termination event threatening the affordability restrictions (
                        <E T="03">e.g.,</E>
                         foreclosure, transfer in lieu of foreclosure or assignment of an FHA-insured mortgage to HUD). If a developer of HOME-assisted homebuyer housing attempts to exercise a right of first refusal during the HOME period of affordability, the unit will no longer be in compliance with HOME period of affordability requirements. Section 12744(b) of the Act requires owners of HOME-assisted homebuyer units under a resale provision to sell only to another low-income homebuyer, while units under a recapture provision must be sold on the open market and the participating jurisdiction must use the recaptured funds for other eligible activities in accordance with HOME requirements. Thus, if another entity other than the participating jurisdiction or community land trust that developed the project attempts to exercise a right of first refusal, it could lead to repayment of the HOME investment because the unit will cease to be affordable housing under the Act.
                    </P>
                    <HD SOURCE="HD3">K. Concerns With § 92.254(b) Requirement That the Home Be Resold Within 6 Months to an Eligible Homebuyer</HD>
                    <P>Two commenters expressed concerns regarding the proposed requirement in § 92.254(b)(1)(i) that would require a participating jurisdiction to resell a home acquired by the participating jurisdiction through preemptive rights to an eligible low-income homebuyer within 6 months. Both commenters recommended that HUD extend the deadline for the participating jurisdiction to resell a home acquired through preemptive rights to 12 months instead of 6 months. Several commenters expressed concern that the proposed § 92.254(b)(3)(i) would require community land trusts that acquire HOME-assisted housing through preemptive rights to resell the housing to an eligible homebuyer within 6 months. These commenters stated that HUD should raise the 6-month resale requirement to 9 or 12 months, which several commenters noted would align with the current regulation or proposed revisions in § 92.254(a)(3). One commenter noted that HUD may want to measure compliance with any established resale date against the date of a ratified sales contract. The commenter also suggested that HUD could establish provisions that would extend the period of affordability by the period the community land trust is in possession of the property prior to transferring it to another buyer. Another commenter stated that establishing a minimum deadline of no less than 12 months for both community land trusts and participating jurisdictions to complete the sale of a property would allow community land trusts, which often have limited resources a reasonable amount of time to bring the housing to an appropriate standard and identify an appropriate buyer.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD agrees that extending the timeframe from 6 to 12 months to resell a homebuyer unit acquired through purchase options, rights of first refusal, or other preemptive rights will provide both participating jurisdictions and community land trusts additional time to rehabilitate a unit, identify a qualified buyer, and permit the buyer to obtain the financing necessary to acquire the unit. Extending the timeframe from 6 to 12 months will also align with the 12-month homebuyer sales deadline in § 92.254(a)(3).
                    </P>
                    <HD SOURCE="HD3">L. Confusion Over Preserving Affordability in § 92.254(b)</HD>
                    <P>One commenter found the language on preserving affordability of housing assisted with HOME funds in § 92.254(b) confusing and suggested reversing sections (1) and (2) such that the proposed language would begin by stating how the participating jurisdiction may acquire the housing by using additional HOME funds, followed by the requirements for selling the housing.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for the suggested reorganization but is maintaining the order of sections (1) and (2) in § 92.254(b), as section (b)(1) defines the specific actions a participating jurisdiction may take to preserve affordability of homebuyer housing when there is a termination event, and section (b)(2) defines the eligible use of additional HOME funds should the participating jurisdictions choose to preserve the affordability of the housing.
                        <PRTPAGE P="846"/>
                    </P>
                    <HD SOURCE="HD3">M. Community Land Trusts Exercising Preemptive Purchase Rights Under § 92.254(b)</HD>
                    <P>One commenter supported the inclusion of community land trusts' right to exercise preemptive purchase rights while several commenters expressed concern or opposition to HUD's proposed language codifying the amendments to NAHA in the Consolidated Appropriations Act, 2016 (Pub. L. 114-113) that community land trusts may hold and exercise purchase options, rights of first refusal, or other preemptive rights to purchase housing to preserve affordability, including but not limited to the right to purchase the housing in lieu of foreclosure.</P>
                    <P>One commenter expressed broad concerns about the proposed language in § 92.254(b)(3) stating that it was unclear what would happen should a community land trust be unable to purchase a home prior to foreclosure, find an eligible household within 6 months, and the participating jurisdiction cannot provide additional HOME funds to assist the unit. The commenter noted that proposed language would create barriers for the community land trust, the participating jurisdiction because the unit would likely be sold on the private market, and the participating jurisdiction may be required to repay the HOME funds. The commenter stated it would welcome additional guidance from HUD.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the comments. HUD understands that a community land trust may need additional funds to exercise a preemptive purchase right on a HOME-assisted homebuyer unit to preserve affordability. Because it cannot use additional HOME funds for this purpose, community land trusts interested in exercising the preemptive rights pursuant to the Continuing Appropriations Act, 2016 (Pub. L. 114-113) and the requirements promulgated in § 92.254(b)(3) must either use other non-HOME funds to acquire the unit and preserve affordability, or may request the participating jurisdiction to preserve affordability of the unit through the preemptive rights provided to the participating jurisdiction under § 92.254(b)(1) and (2).
                    </P>
                    <P>Further, even if a community land trust may not assist the next homebuyer using HOME funds, the participating jurisdiction is permitted to provide additional HOME assistance directly to the next homebuyer should a community land trust exercise its preemptive purchase rights to preserve the affordability of the unit. HUD thanks the commenter that believed that a participating jurisdiction is prohibited from directly assisting the next homebuyer. This was not HUD's intent, and to address any confusion, HUD is adding clarifying language to § 92.254(b)(3)(iv) to state that a participating jurisdiction may provide direct assistance to the next homebuyer of a unit preserved by a community land trust through preemptive purchase rights.</P>
                    <HD SOURCE="HD3">N. Other Organizations Should Be Able To Use Preemptive Purchase Rights Under § 92.254(b)</HD>
                    <P>Two commenters encouraged HUD to evaluate whether preemptive purchase rights could be made available to a wider range of organizations or affordable housing models. One commenter stated that they believed Congress meant to apply preemptive rights broadly to non-profit organizations whose purpose and goal is to preserve affordable homeownership opportunities, including shared equity/long-term affordability homeownership programs and not just to community land trusts. The commenter noted that many participating jurisdictions do not have the capacity or desire to expend time and resources to repurchase properties and should be permitted to allow nonprofit developers to use a preemptive purchase option or to assign the participating jurisdiction's preemptive purchase options to nonprofit developers to ensure long-term affordability. The commenter also states that limiting preemptive rights to participating jurisdictions and community land trusts only in the case of foreclosure is too limiting, particularly if HUD and Congress' goal is for HOME-assisted housing to fulfill the required period of affordability. The commenter states that the homeowner is unnecessarily burdened by these restrictions because they are responsible for finding and qualifying a subsequent, eligible homebuyer. The commenter suggests that eligibility for using preemptive purchase options should be determined based on the intent of the nonprofit developer to exercise the right for the purpose of preserving affordability and reselling to another eligible homebuyer, not whether the nonprofit formerly owned the land after the initial sale or acquired both land and improvements through exercise of the preemptive purchase right.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Continuing Appropriation Act, 2016 (Pub. L. 114-113) provided preemptive purchase rights only to community land trusts and only with respect to properties these community land trusts properties developed with HOME funds. Congress did not intend broader applicability of these preemptive purchase right than HUD is promulgating in this final rule.
                    </P>
                    <P>The Department disagrees with the commenter's statement that participating jurisdictions do not have the capacity or resources to exercise preemptive rights. HUD clarified in § 92.254 (b)(2) that participating jurisdictions may use additional HOME funds for certain eligible costs. Specifically, a participating jurisdiction may use additional HOME funds in accordance with § 92.254(b)(2) to obtain ownership of the housing, undertake any necessary rehabilitation, hold the housing pending sale to another homebuyer, and assist an eligible homebuyer in purchasing the unit. Consequently, a participating jurisdiction that chooses to exercise preemptive rights should have the resources necessary to preserve affordable housing.</P>
                    <P>Further, a participating jurisdiction is not permitted to assign its preemptive rights to a developer to exercise in response to a termination event, or in the case of a right of first refusal should a developer wish to acquire a HOME-assisted unit at resale. The commenter incorrectly states that homeowners' seeking to sell the HOME-assisted unit during the period of affordability are responsible for identifying and qualifying another eligible low-income homebuyer. While a homebuyer unit under a resale provision must be sold to another low-income buyer at a price that provides the seller with a fair return on investment, the homeowner is not responsible for identifying the next buyer or determining whether the buyer is income eligible. The participating jurisdiction is responsible for overseeing the subsequent sale of a homebuyer unit under resale and ensuring that all HOME requirements are met. Homebuyer units under a recapture provision must be sold on the open market with any recaptured funds returned to the participating jurisdiction to use for other eligible activities in accordance with HOME requirements.</P>
                    <HD SOURCE="HD3">O. Recalculating the Period of Affordability When a Participating Jurisdiction or Community Land Trust Exercises a Preemptive Purchase Right Under § 92.254(b)</HD>
                    <P>
                        One commenter stated that the proposed requirement at § 92.254(b)(3)(iii) that the period of affordability for the eligible buyer must be equal to the remaining period of affordability of the former homeowner will inadvertently bar a community land trust from requiring a new 99-year affordability restrictions upon resale of 
                        <PRTPAGE P="847"/>
                        a previously assisted home. The commenter stated that rather than requiring a fixed period of period of affordability upon resale as a condition to a community land trust's preemptive acquisition and resale of a HOME-assisted property in order to preserve its affordability, HUD should encourage long-term affordability by stating that the new period of affordability must be “at least equal to” or “equal to or greater than” the remaining period of affordability of the former homeowner.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the commenter's feedback but believes the commenter is confusing the community land trust long-term ground lease with the HOME period of affordability required in § 92.254(a)(4). The HOME period of affordability and associated affordability restrictions are separate from the long-term ground lease the homeowner executes with the community land trust. Nothing in the HOME regulations would prohibit a community land trust from continuing to enforce a 99-year ground lease on a new homebuyer following the community land trust executing its preemptive rights under § 92.254(b)(3). Should a community land trust choose to exercise its preemptive rights during the period of affordability in accordance with § 92.254(b)(3), the new HOME-assisted homebuyer would be required to meet the HOME affordability restrictions (
                        <E T="03">i.e.,</E>
                         principal residency and resale requirements) for the remaining period of affordability on land held by the community land trust under a ground lease for a term established by the community land trust. Participating jurisdictions are permitted to impose longer periods of affordability, perhaps even aligning with the term of the ground lease but would be required to monitor the HOME affordability restrictions for the longer period.
                    </P>
                    <HD SOURCE="HD3">P. Providing Additional HOME Assistance to Property Purchased Through Preemptive Purchase Rights Under § 92.254(b)</HD>
                    <P>Several commenters expressed concern or opposition to the proposed language at § 92.254(b)(3)(iv) that states that a participating jurisdiction may not provide additional HOME funds to a community land trust to obtain ownership, rehabilitate the housing, own/hold the housing pending sale to the next homebuyer, or provide down payment assistance to the next eligible homebuyer.</P>
                    <P>A commenter questioned why HUD would prohibit community land trusts from providing additional HOME funds to rehabilitate units acquired through their right of first refusal or from assisting buyers of such units because a property may need renovations or upgrades to comply with codes between owners. Several commenters expressed concern or opposition to the proposed language at § 92.254(b)(3)(iv) that states that a participating jurisdiction may not provide additional HOME funds to a community land trust to obtain ownership, rehabilitate the housing, own/hold the housing pending sale to the next homebuyer, or provide down payment assistance to the next eligible homebuyer. A commenter questioned why HUD would prohibit community land trusts from providing additional HOME funds to rehabilitate units acquired through the next eligible homebuyer.</P>
                    <P>
                        Two commenters questioned why participating jurisdictions may use additional HOME funds to obtain ownership, rehabilitate, hold the housing pending resale, or provide downpayment assistance, yet a community land trust is not. Both commenters questioned the policy rationale behind this distinction, and one commenter stated that this prohibition runs counter to the regulatory definition's purpose of enshrining the preemptive right to purchase,
                        <SU>68</SU>
                        <FTREF/>
                         and urged HUD to provide community land trusts with a more complete array of tools to preserve the structure and affordability of their housing units.
                    </P>
                    <FTNT>
                        <P>
                            <SU>68</SU>
                             See the proposed definition of 
                            <E T="03">community land trust</E>
                             in § 92.2, paragraph (4), in the proposed rule. 89 FR 46657.
                        </P>
                    </FTNT>
                    <P>One commenter expressed concern regarding the proposed restrictions on community land trusts that would prevent community land trusts from obtaining ownership through a preemptive purchase option. The commenter argued that disallowing the use of HOME funds undercuts the benefit to a community land trust of having a preemptive purchase option at all, and as a result of this restriction participating jurisdictions would not support community land trusts' purchase option since exercising their own would allow them to apply additional funding to the HOME-assisted project, and that the restriction places the burden of rehabilitation and management on a community land trust without providing additional resources to do so responsibly. The commenter said that it is essential that a community land trust exercising the preemptive purchase option be able to access HOME funds to rehab a home in preparation for a new homebuyer and recommended that community land trusts be able to use HOME funds for the same purposes as participating jurisdictions.</P>
                    <P>One commenter stated that the proposed language creates ambiguity regarding assistance to subsequent homebuyers purchasing property in a community land trust. The commenter stated that the language is unclear on whether the term “to the Community Land Trust” modifies each of the following listed elements in § 92.254(b)(3)(iv) or only applies to the “to obtain ownership” element. The commenter stated that the lack of clarity led to confusion on whether it could provide homeownership assistance directly to a subsequent buyer of a home in a community land trust where it had provided assistance to a previous buyer and the prior period of affordability was still applicable. The commenter suggested that HUD could address the issue by updating the proposed definition to the following: “The participating jurisdiction may not provide additional HOME funds to the Community Land Trust to obtain ownership, to rehabilitate the housing, to own/hold the housing pending resale to the next homebuyer, or to provide homeownership assistance to the next eligible homebuyer.” One commenter asked for clarification on the preemption of providing HOME funds to community land trusts for ownership, rehab, holds pending resale, or downpayment under proposed § 92.254(b)(3)(iv). The commenter also sought clarification on the misalignment with § 92.254(a)(9)(ii) that permits additional HOME funds if it meets the maximum-per-unit subsidy cap. One commenter explained that community land trusts require an enforcement mechanism due to their structure and purpose to provide permanent affordability, requiring financially sound operators to adhere to covenant enforcement and to retain sufficient resources to execute the right of first refusal. The commenter further explained that because of these additional measures, HUD should consider if participating jurisdictions should perform underwriting similar to that of a robust organization to cover these mechanisms, perhaps using the multifamily requirements as a template. The commenter stated that this could better ensure a sound operational foundation for the organization during the duration of the period of affordability.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for their feedback. However, HUD is moving forward with the provisions in § 92.254(b)(3), which do not permit a participating jurisdiction from 
                        <PRTPAGE P="848"/>
                        providing additional HOME funds to a community land trust that has exercised preemptive rights to preserve affordability of HOME-assisted homebuyer housing. The Continuing Appropriations Act, 2016 (Pub. L. 114-113) did not authorize HUD to permit a community land trust, during the HOME period of affordability, to request additional HOME funds from a participating jurisdiction. Instead, the Continuing Appropriations Act, 2016 (Pub. L. 114-113) only allowed a community land trust to take possession of the property and resell to an eligible low-income homebuyer, thereby preventing the participating jurisdiction from having to repay the HOME investment because the property failed to meet the HOME requirements for the full period of affordability.
                    </P>
                    <P>
                        While the Continuing Appropriations Act, 2016 (Pub. L. 114-113) permitted community land trusts to exercise preemptive rights to preserve the affordability of housing, a community land trust is not required to exercise such options and may instead notify the participating jurisdiction that action is required to preserve the HOME-assisted unit. The participating jurisdiction may invest additional HOME funds in accordance with § 92.254(b)(1) and (2) to acquire, rehabilitate, hold the housing pending sale, and assist an eligible homebuyer to purchase the unit. The total amount of HOME funds invested, (
                        <E T="03">i.e.,</E>
                         the original investment plus additional investment) cannot exceed the maximum per-unit subsidy in effect at the time of the additional investment, subject to HUD approval.
                    </P>
                    <P>A community land trust that chooses to exercise its preemptive rights under § 92.254(b)(3) may use existing organizational resources or other funding sources to acquire, rehabilitate, hold the unit pending sale to another eligible homebuyer, and assist the next eligible homebuyer. The Department is adding clarifying language to § 92.254(b)(3)(iv) that a participating jurisdiction may provide direct assistance to an eligible homebuyer of a unit preserved by a community land trust through preemptive rights. The Department agrees with the commenter that the original proposed language in § 92.254(b)(3)(iv) was not clear about whether a participating jurisdiction could directly assist the subsequent buyer should a community land trust take action to preserve the affordability of the unit. The Department is also clarifying the period of affordability applicable to any homeownership assistance provided by the participating jurisdiction to the next eligible homebuyer.</P>
                    <P>While the Department agrees with the commenter that community land trusts that exercise preemptive rights under § 92.254(b)(3) should have sufficient resources to execute these rights and resell the unit to an eligible homebuyer, the Department is not requiring a participating jurisdiction to underwrite the community land trust. The participating jurisdiction may choose to exercise its own preemptive rights in lieu of the community land trust should the community land trust not have the financial resources needed.</P>
                    <HD SOURCE="HD3">Q. Revise the Lease-Purchase Requirements in § 92.254(e)(7)</HD>
                    <P>One commenter recommended HUD extend the lease purchase completion deadline from 36 months to 5 years because they believe local experience suggests that the model is more effective when a client has more time from the date of offer and is offered homebuyer education. One commenter requested that the proposed § 92.254(a)(7) enable a second chance at a successful lease-purchase agreement if an initial lease-purchase on the property fails. One commenter stated that if a lease-purchase fails, the developer is locked into a lengthy cycle of rental administration, closing off much-needed affordable inventory for homeownership.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the comments on the proposed lease-purchase changes and agrees that providing additional time to identify an eligible homebuyer is beneficial. However, if the first homebuyer is unable to acquire the housing within 36 months, the Department does not agree that entering into a subsequent lease-purchase agreement with a new homebuyer is prudent as an indefinite period cannot be permitted to pass before the homeownership unit meets the HOME homeownership requirements. Instead, HUD is revising § 92.254(a)(7) to provide the owner with an additional 12 months to sell the housing to another eligible low-income homebuyer. While the owner would be prohibited from selling the unit through another lease-purchase agreement, the participating jurisdiction could provide homeownership assistance to the next eligible homebuyer. If the owner is unable to sell the unit to an eligible homebuyer within 48 months of the execution of the original lease-purchase agreement, the unit must convert to rental housing in accordance with § 92.252.
                    </P>
                    <HD SOURCE="HD3">R. Support for Nonprofit Lender Revisions to § 92.254(f)</HD>
                    <P>One commenter expressed support for HUD's clarification that participating jurisdictions may provide HOME funds to nonprofit lending institutions as a contractor or subrecipient. The commenter stated this would allow nonprofit lenders to provide HOME homeownership assistance alongside first mortgage financing and thereby strengthen the nonprofit delivery system's ability to meet affordable homeownership needs.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for reviewing and is moving forward with revisions to specify that nonprofit lenders can be either contractors or subrecipients.
                    </P>
                    <HD SOURCE="HD3">S. Changes to Homebuyer Underwriting in § 92.254(g)</HD>
                    <P>Several commenters voiced support for the changes to § 92.254(g)(1) that revise the homebuyer underwriting standards. Some commenters praised the simplified focus on evaluating the projected overall after-purchase debt of a family, while others were concerned that families could be subjected to foreclosure if monthly expenses are not properly evaluated. Other commenters suggested HUD instead follow the standards provided by Qualified Mortgages or Community Development Financial Institutions while a few commentors disagreed with HUD's clarification on providing a single amount of assistance to all homebuyers.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the comments and is moving forward with the proposed change.
                    </P>
                    <HD SOURCE="HD3">T. Standardize or Align Third-Party Underwriting Standards in § 92.254(g)</HD>
                    <P>Some commenters noted that the existing structure in which each participating jurisdiction develops their own underwriting standards can create confusion and inconsistencies and suggested that HUD standardize and align with existing mortgage products to help address the issue. These commenters suggested HUD consider establishing a safe harbor if the underwriting of the first mortgage meets the standards of a Qualified Mortgage as defined by the Consumer Financial Protection Bureau (CFPB). Two commentors suggested HUD defer to the underwriting standards of a certified Community Development Financial Institution (CDFI) as CDFIs have experience underwriting loans to low- and moderate-income borrowers.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department disagrees with the commenters that HUD should align homebuyer 
                        <PRTPAGE P="849"/>
                        underwriting requirements with standard mortgage requirements such as the Qualified Mortgage standards established by the CFPB. HOME participating jurisdictions must have separate underwriting standards for HOME-assisted homebuyers because the first mortgage underwriting is not a valid proxy for underwriting a second HOME-mortgage where the participating jurisdiction must consider the homebuyer's overall debt, including the first mortgage debt. Further, Qualified Mortgages, as defined by the CFPB, are not focused on evaluating the low-income populations participating jurisdictions are required to serve. While the CFPB requirements are a good starting point for assessing the appropriateness of private first mortgages, a participating jurisdiction's underwriting policy must consider additional factors because HOME-assisted homebuyers are low-income. Participating jurisdictions must continue to establish and use their own homebuyer underwriting standards in accordance with § 92.254(g) to adequately protect the low-income homebuyers from risky and unsustainable mortgages. The Department is moving forward with the proposed change.
                    </P>
                    <HD SOURCE="HD3">U. Changes to Evaluation of Family Debt in Underwriting in § 92.254(g)</HD>
                    <P>Two commenters noted that HUD correctly identified that the current regulation excludes households that have overall debt and monthly expenses that exceed a participating jurisdiction's underwriting standards but demonstrate an ability to sustain a mortgage through other indicators and argued that rigid ratios for housing expense and total debt is reflective of an outdated practice. The commenters stated that the current requirements can prevent a buyer from buying their preferred home in their location of choice because they favor borrowers with strong credit ratings, high down payments and cash reserves, and other factors. The commenters supported HUD's proposal to eliminate the requirement that a participating jurisdiction evaluate monthly expenses, to establish a standard to determine the maximum amount of direct HOME assistance, and to prohibit participating jurisdictions from providing a single, fixed amount of assistance to every homebuyer receiving assistance but asked HUD to provide additional guidance to participating jurisdictions as it finalizes this rulemaking and implements the requirements. One commenter agreed with some changes that would eliminate the need to evaluate both the housing debt and overall debt of the family in favor of evaluating overall debt of the family projected after purchase, but this commenter expressed concerns with the proposed rule's elimination of the requirement that participating jurisdictions evaluate the monthly expenses of the family. The commenter stated that the lender cannot see if a family can afford a loan if they are not doing their due diligence. The commenter recommended that HUD interpret the rule's language that “the standards must evaluate the... financial resources to sustain housing” as requiring robust evaluations to ensure that the overall financial health of the family is still assured prior to home purchase.</P>
                    <P>Two commenters stated that they do not support HUD's proposal to eliminate the requirement that participating jurisdictions evaluate a family's debt during underwriting. One commenter explained that debt evaluation prevents a family from purchasing a home that is over their income capacity and from putting the family at risk of foreclosure. Another commenter stated that this proposed change is counterintuitive to protecting families from financial distress, jeopardizing the investment of HOME funds due to foreclosure, short sale, or other issues.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD is removing the requirement that the overall debt of the family be reviewed as part of the HUD-required underwriting analysis performed by the participating jurisdiction but is retaining the requirement in § 92.254(g)(1) that “[t]hese standards must evaluate the projected overall debt of the family after the purchase of the housing.” HUD believes that the evaluation of the overall debt of the family after the purchase of the housing is the correct measure for determining whether the housing would be at risk of foreclosure and whether the family would be in financial distress. HUD does not believe that separately accounting for the current overall debt of the family adds to this analysis. HUD notes that restructuring of debt can occur throughout the closing process, and so overall debt of the family pre-closing is not as informative as overall debt of the family after closing and any necessary repair or rehabilitation work that may be needed on the property.
                    </P>
                    <HD SOURCE="HD3">V. Prohibition of Providing a Single Amount of Assistance in § 92.254(g)</HD>
                    <P>Several commenters stated they do not support the proposed change to § 92.254(g)(1) of explicitly stating that a participating jurisdiction may not provide a single, fixed amount of assistance to every homebuyer receiving assistance in the participating jurisdiction's homebuyer program. Two commenters expressed concerns that tailoring the amount of assistance to each homebuyer is difficult and could be seen as arbitrary. Other commenters stated that tailoring assistance may result in a higher subsidy amount to a higher income buyers or buyers purchasing more expensive homes.</P>
                    <P>One commenter stated that HUD should base appropriateness of assistance on the local housing market through methods such as percent of median home value. Another commenter supported HUD's attempt to add clarity by stating that a participating jurisdiction establishes a standard to determine the maximum amount of assistance per family by market area but believes that by establishing a cap, a participating jurisdiction should be considered compliant. The commenter also recommended basing the appropriateness of the assistance on the local housing market and using a percentage of the median home value.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         While the Department appreciates the comments, the prohibition against providing a single amount of homebuyer assistance is not a proposed change. The 2013 HOME Final Rule required participating jurisdiction to establish homebuyer program policies and procedures, including but not limited to homebuyer underwriting guidelines. In accordance with § 92.254(g), a participating jurisdiction must utilize underwriting standards to determine the amount of HOME assistance each applicant needs to sustain homeownership. HUD is declining to make a change that would permit participating jurisdictions to establish programs that provide the same amount of HOME assistance to every homebuyer irrespective of need. The Department is also not providing a safe harbor where the participating jurisdiction establishes a maximum cap. A participating jurisdiction can always establish a maximum cap for assistance, but if that cap is too low, and every homebuyer is provided the same amount, then the participating jurisdiction is not evidencing that it is appropriately sizing the assistance to meet the requirements of § 92.254.
                    </P>
                    <P>
                        The Department also disagrees with establishing the appropriateness of assistance based on a set percentage of median home value or the local housing market. Participating jurisdictions must perform the necessary underwriting to determine whether it is possible to assist the family, and how much assistance the family requires in order to be able to maintain sustainable 
                        <PRTPAGE P="850"/>
                        homeownership. Establishing set percentages or basing assistance on factors that do not involve an evaluation of the family's finances and do not ensure that the homeownership is sustainable. Impact of other resale restrictions on the property.
                    </P>
                    <HD SOURCE="HD3">X. Resale Restrictions</HD>
                    <P>One commenter stated that HUD should clarify whether it is appropriate to allow non-HOME resale restrictions to be imposed by non-participating jurisdiction State or local government programs that are funded by HOME. The commenter noted this clarification is needed because participating jurisdictions have declined to provide homebuyer assistance to low-income buyers from local density bonus programs because the housing was deed restricted in a resale-like manner by non-HOME State or local programs.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The only resale or recapture restrictions that may be placed on a HOME homeownership property are those that are consistent with the restrictions provided in the participating jurisdiction's consolidated plan in accordance with 24 CFR 91.220(l)(2)(iii) or 24 CFR 91.320(k)(2)(ii), as applicable, and included in the participating jurisdictions written agreement in accordance with § 92.504.
                    </P>
                    <HD SOURCE="HD3">Y. Manufactured Housing in HOME Homeownership Programs</HD>
                    <P>One commenter stated that it is important that when States and localities use funds for down payment assistance for affordable first-time home purchase, that these programs do not inadvertently exclude manufactured homes. The commenter noted that personal property manufactured home loans have distinctive attributes that can sometimes result in down payment assistance programs not reaching these homebuyers. The commenter referenced 2003 guidance and requested that HUD updated the program to consider any changes to the regulations would negatively impact manufactured housing homeownership opportunities. The commenter also stated that since manufactured home purchases and financing can be sold differently than site-built home purchases, it is important that States and localities conduct appropriate outreach to these channels, to ensure manufactured homebuyers have the same access to these down payment programs.</P>
                    <P>One commenter stated that while the purchase, rehabilitation, and development of manufactured homes and manufactured home communities are statutorily eligible uses of HOME funds, HOME is not being used to preserve and improve manufactured home communities as affordable housing and homebuyers and homeowners are routinely denied access to HOME-funded programs, even though they are some of the lowest-income homeowners in America and play a crucial role in the inventory of affordable housing. One commenter stated HUD should engage in outreach to States and localities to ensure that their HOME-funded downpayment assistance programs do not exclude manufactured homes. The commenter stated that this unintentional exclusion has persisted for some time often because manufactured homes are ordered in a different manner, and it is imperative to address the issue.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD agrees that the acquisition, rehabilitation, and installation of manufactured homes and manufactured home communities are all eligible HOME projects if they meet the requirements in the HOME regulations. HUD also agrees that manufactured housing is an important source of affordable housing, and that participating jurisdictions and other program partners may not fully understand the ways in which HOME funds can be used for manufactured homes and manufactured home communities, including homeownership assistance and rehabilitation. Because manufactured homes may be personal property in some states and real property in others, there is variation in how HOME funds can be used to assist the acquisition of these units. HOME funds can be used to acquire both the unit and the lot, or to lease the lot for the period of affordability and purchase the housing unit. HOME funds can also be used to rehabilitate manufactured housing as homeowner rehabilitation projects, so long as the units meet the property standards in § 92.251 upon completion. The Department will consider further ways in which to address any misunderstandings about the allowable use of HOME funds in supporting manufactured home homeownership through guidance or technical assistance products.
                    </P>
                    <HD SOURCE="HD3">Z. Barriers to Using HOME To Purchase Manufactured Home Communities</HD>
                    <P>The commenter pointed to regulatory barriers that prevent HOME funds from being used for resident acquisition of manufactured home communities and stated that HOME funds for acquisition need to be implemented through an entity that can meet strict timeframes and work with manufactured home communities owners, that HOME funds should be used to reduce the cost of debt for acquisition, and that HOME funds should be used by participating jurisdictions to make equity grants in CDFIs to specifically finance resident purchases of manufactured home communities.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for reviewing the rule and notes that some of the suggestions fall outside the scope of this rulemaking. However, HUD agrees that, while an eligible use of funds, it can be challenging to use HOME funds to acquire and rehabilitate manufactured home communities. A primary reason for this is that not all residents of a manufactured home community qualify as low-income, and ownership can vary from resident to resident. A more viable model might be to use another financing source such as CDBG to acquire the manufactured housing community and reserve HOME funds to acquire or rehabilitate manufactured housing units for income eligible residents. HUD can provide technical assistance to participating jurisdictions in structuring HOME projects involving manufactured home communities.
                    </P>
                    <HD SOURCE="HD3">AA. Encourage Homeownership Activities </HD>
                    <P>One commenter also suggested that HUD take further steps to encourage participating jurisdictions to make HOME funding available in their communities for affordable homeownership construction, rehabilitation, and repair by promoting guidance for best practices by participating jurisdictions.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Supporting State and local efforts to expand homeownership is a key goal of the HOME program. HUD appreciates the comment and will continue to provide technical assistance and guidance to participating jurisdictions interested in using HOME funds for homeownership. In recent years, HUD has developed and administered several webinars, and in-person trainings focused on providing in-depth guidance and sharing best practices to participating jurisdictions looking to create or expand their homebuyer programs. HUD will continue to offer trainings and look for new ways to ensure participating jurisdictions have the resources and capacity to expand affordable homeownership.
                    </P>
                    <P>
                        <E T="03">
                            Specific solicitation of comment #11: The Department requests public comment on whether the existing 9-month deadline for the sale of homebuyer units acquired, rehabilitated, or constructed with HOME funds is reasonable and whether 
                            <PRTPAGE P="851"/>
                            extending the deadline to 12 months would increase the use of HOME funds for homeownership programs.
                        </E>
                    </P>
                    <HD SOURCE="HD3">A. Comments in Support of a 12-Month Deadline for Purchase by an Eligible Homebuyer </HD>
                    <P>Several commenters supported the extension to 12 months. Commenters stated that they support the proposed extension for the sale of a homebuyer unit acquired, rehabilitated, or constructed with HOME funds to 12 months because 9 months is an insufficient amount of time. One commenter stated that less than 12 months is an unreasonable time period due to market volatility and because small cities do not have the capacity to become landlords or to repay HUD for HOME funds when a property does not sell or convert to a rental unit. In addition, the commenter recommended that HUD remove the requirement for renting all together so that participating jurisdictions have time to sell the home. Another commenter stated that the three additional months would give potential homeowners more time to comply with requirements such as homebuyer counseling and income qualifications. One commenter explained that they support the change because, currently, it takes longer to find income eligible buyers given higher sales prices and interest rates. Some commenters said the extension would add flexibility to the program and one commenter stated it would make it more attractive to use HOME in such projects. One commenter stated that the added time may incentivize some participating jurisdictions to add or expand homeownership programs using HOME funds.</P>
                    <P>One commenter, in expressing support for the extension to a 12-month deadline, stated that this change would especially benefit new construction and enable the local governments who encounter hurdles or delays to close the deal by providing an additional 3 months.</P>
                    <P>One commenter supported extending the deadline from 9 to 12 months but warned that developers and non-profits building owner-occupied housing lack rental property management experience and warned of the risks and deterrent effects of this misalignment. The commenter suggested requiring homebuyer projects to convert to a lease-to-purchase model instead of rental.</P>
                    <P>One commenter noted that having an additional three months to sell HOME-assisted homeownership units may increase the use of HOME funds for homeownership programs for some participating jurisdictions, but high interest rates likely have more of an impact on the success of the program in most markets.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters and agrees that adding an additional three months to the homebuyer deadline will benefit local communities by alleviating potential noncompliance. The Department is moving forward with the proposed change by extending the homebuyer sales deadline from 9 to 12 months.
                    </P>
                    <HD SOURCE="HD3">B. Comments in Support of a Sales Deadline of More Than 12 Months</HD>
                    <P>One commenter stated that because of the current economy the time to sell a home should be extended to 15 to 20 months.</P>
                    <P>One commenter stated the requirement should be at least 12 months because of volatility in the housing market. The commenter suggested that a participating jurisdiction and owner can provide a mutually agreeable plan to obtain occupancy no later than an additional 6 months (total of 18 months) from the completion of construction if there is no sale at 12 months.</P>
                    <P>One commenter stated they support increasing the number of months before converting a homeowner unit that hasn't sold to rental housing from 9 months to 12 months but would prefer that HUD eliminate the provision altogether.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD acknowledges the volatility of the housing market but has determined that 12 months is an appropriate homebuyer sales deadline. A deadline of 15 months or greater is too long for HOME homeownership housing to remain on the housing market. If an owner is not able to sell the unit to an eligible homebuyer within 12 months, then the unit must be converted into rental housing and run in accordance with § 92.252, or the participating jurisdiction must repay the investment.
                    </P>
                    <HD SOURCE="HD3">C. Current Requirement of Nine Months Is Not Hard To Meet </HD>
                    <P>One commenter said that they do not have challenges closing on homebuyer units within the existing timeline but understand that other markets may not be similarly situated and that the shrinking pool of available Federal funding utilized as mortgages is leading to extremely long waiting periods for homebuyers. The commenter doubted whether extending the deadline would meaningfully impact the proportion of HOME funding used to support homeownership programs because the sales deadline is only one very small part of the barriers in the HOME regulations and laws. Rather, the commenter cites the primary reason for the decline in uses of HOME for homeownership is decision-making at the participating jurisdiction level that prioritizes rental uses for HOME funds over homeownership uses as well as shrinking appropriations and a national proportion of HOME set aside for CHDOs that has not exceeded 20 percent since 2015. The commenter recommended that HUD use its authority to ease barriers in HUD regulations, such as raising the Homeownership Value Limits and to work with homeownership advocates to identify ways to incentivize the use of the HOME program for homeownership activities.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for their response and acknowledges that multiple factors impact the proportion of HOME funds that are used for homebuyer housing. In 2024, HUD made changes to the methodology used to calculate the homeownership value limits and will continue to explore how it can address other barriers facing HOME funded homeownership.
                    </P>
                    <HD SOURCE="HD3">D. Clarify Rule on When Housing Is Not Sold by the Deadline</HD>
                    <P>One commenter stated that the extension of the proposed sales deadline to 12 months is appreciated, but the requirements for homeownership housing using HOME funds do not specify how a home that has been leased under the provision can subsequently be sold to an eligible homebuyer. The commenter stated that this has led to participating jurisdictions concluding that selling the home as originally intended is not allowed or that it can only be sold via the lease-purchase provisions of the regulations. The commenter recommended that HUD clarify how a home leased under § 92.254(a)(3) can be sold to an eligible buyer within 12 months of a tenant voluntarily moving out of the rented home or after being legally evicted for cause. The commenter also recommended that HUD issue clear guidance on this matter for participating jurisdictions.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD would like to clarify that a HOME-assisted homebuyer unit that fails to sell to an eligible homebuyer by the 12-month deadline, must be converted to a rental project in accordance with § 92.252. Once the unit is designated as a rental unit in accordance with § 92.252, a participating jurisdiction cannot execute a lease purchase agreement with a potential homebuyer because the unit has become a rental unit and lease 
                        <PRTPAGE P="852"/>
                        purchase is only permitted under § 92.254(a)(7). In accordance with § 92.255, a participating jurisdiction may permit the owner of a HOME-assisted rental unit to convert the unit to homeownership unit if the 
                        <E T="03">existing</E>
                         tenant is willing and eligible to buy the unit. The conversion of a HOME-assisted homebuyer unit into a rental unit after a 12-month vacancy is not intended to serve as a temporary solution for periods of weak market demand. Participating jurisdictions that are unable to sell a homebuyer unit after a 12-month period should consider evaluating local market demand for low-income homebuyer projects. If the owner refuses to convert the unit into a rental housing unit under these provisions, then the participating jurisdiction must repay the investment of HOME funds for the development of that housing unit, as it failed to meet the requirements of § 92.254 and § 92.252.
                    </P>
                    <HD SOURCE="HD3">E. Other Comments Received in the Solicitation</HD>
                    <P>One commenter said that HOME funds are currently unable to assist in areas of homeownership opportunities because of increasing home prices and recommended HUD allow higher per-unit subsidies and after rehabilitation values and sales prices to increase such opportunities. The commenter also supported a rehabilitation per unit subsidy limit that incorporates new construction and requested HUD provide an example of a proposed resale formula in its final rule.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD acknowledges that increasing home prices pose a significant challenge to homebuyer programs. The final rule is proposing to make several revisions to the HOME program's maximum per-unit subsidy limits at § 92.250 and a revised methodology that allows HUD an improved ability to review ongoing construction cost changes will be published in a future 
                        <E T="04">Federal Register</E>
                         publication. HUD has also taken recent steps to update the methodology used to calculate the HOME homeownership value limits and will continue to evaluate how those numbers are calculated.
                    </P>
                    <P>HUD has published examples of each of the four resales models on HUD.gov, and will provide training, technical assistance, and publish updated guidance to support the implementation of the new resale models.</P>
                    <HD SOURCE="HD2">§ 92.255—Purchase of HOME Units By In-Place Tenants</HD>
                    <P>Commenters stated that HUD should make an exception to the current requirement that a tenant must qualify as low-income at the time of purchase of a HOME unit. One commenter encouraged HUD to consider regulatory changes that would provide more flexibility in income determination in the event of a purchase by an in-place tenants. Other commenters stated that if HOME units were originally developed using LIHTCs, then in-place LIHTC tenants that originally income qualified for both HOME and LIHTC should be able to purchase the units as in-place tenants without need for income recertification. In many cases, the commenters specifically cited to lease-purchase programs but the lease-purchase arrangements they were describing were not lease-purchases as defined under the HOME program but actually purchase of rental housing units by in-place tenants.</P>
                    <P>Another commenter stated that homeownership is inadvertently disincentivized due to these existing regulations, and urged HUD to consider regulatory changes that would provide more flexibility in income determination in the event of a lease purchase agreement. The commenter noted that in § 92.254(a)(7), current regulations state that “HOME funds may be used to assist homebuyers through lease-purchase programs for existing housing and for housing to be constructed.” The commenter explained that during the rental period, the HOME rules defer to the LIHTC qualification standards for whether a renter is eligible to rent a HOME-assisted unit. The commenter further explained that LIHTC qualification standards require an initial qualification of the tenant at the time of lease, but if the tenant household income increases over the LIHTC and/or HOME maximum, the tenant is still qualified to live in the unit and is not displaced. However, the commenter pointed out that since HUD's adoption of the 2013 HOME final rule, many participating jurisdictions are requiring a tenant to re-qualify under the homeownership rules at the time of the sales transaction once they are eligible to purchase their single family home at the end of the LIHTC compliance period. The commenter stated that if the tenant exceeds 80 percent of area median income at the time of requalifying, they are disqualified from purchasing the HOME-assisted unit.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department considered its flexibility under 42 U.S.C. 12745(a)(1)(E) to reduce or eliminate the remaining period of affordability on the rental unit to allow the in-place over-income tenant to purchase the property and determined that this was within the Secretary's discretion as it is consistent with the purposes of the Act, which emphasized moving families from poverty to stable homeownership. The Department has added language to §§ 92.254(a)(3), 92.255(b), and 92.255(c) to enable the purchase of units by in-place over-income HOME tenants. As a condition of allowing the in-place over-income tenant to purchase the property, the tenant must agree to the participating jurisdiction's resale restrictions for the remaining period of affordability, similar to other income eligible in-place tenants that purchase their units (see § 92.255(b)). Since an over-income tenant purchasing their HOME unit is no longer income eligible, the tenant may not receive additional HOME funds to assist them in the purchase of their unit.
                    </P>
                    <P>
                        The Department understands that there is a lot of confusion about what rules control when HOME units are designated in a LIHTC project. The Department is correcting the commenter because HOME rules do not “defer” to the LIHTC qualification standards. HOME tenants must be income eligible under the HOME program at initial occupancy. The commenter is correct that an owner may not refuse to renew a tenant's lease because the tenant has become over-income, as this is not good cause under the Act.
                        <SU>69</SU>
                        <FTREF/>
                         However, the commenter is also incorrect that the 2013 HOME Rule revised the regulations to prohibit in-place over-income tenants from purchasing their HOME rental housing units. Until this final rule, this has never been permitted in the HOME program.
                    </P>
                    <FTNT>
                        <P>
                            <SU>69</SU>
                             See 42 U.S.C. 12755 for good cause and 42 U.S.C. 12745(a)(3), which contemplates over-income tenants and explains what rent they must be charged.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD2">§ 92.300—Set-Aside for Community Housing Development Organizations (CHDOs)</HD>
                    <HD SOURCE="HD3">A. Applicability of Proposed Changes</HD>
                    <P>A commenter requested additional clarity as to whether the proposals relating to CHDOs only applied to CHDOs in rural areas or if they are applicable to all CHDOs.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department proposed several changes to the definition of community housing development organization at § 92.2 and the CHDO set-aside requirements at § 92.300, many with the intent of improving CHDO availability and capacity in rural areas. However, the changes made are not specifically applicable to CHDOs in rural areas but any organization receiving CHDO set-aside funds through the HOME program.
                        <PRTPAGE P="853"/>
                    </P>
                    <HD SOURCE="HD3">B. Changes to Role of CHDO in § 92.300(a)—Support</HD>
                    <P>Commenters supported these changes. One commenter stated that the proposed revisions to the required role of the CHDO as owner, developer, or sponsor of housing at § 92.300, when combined with the proposed changes to the CHDO definition at § 92.2, would enable more community-based housing organizations to qualify as CHDOs and access the CHDO set-side.</P>
                    <P>A commenter stated that they support the proposed change that allows CHDOs serving as rental housing sponsors to convey a project to a non-profit organization at a predetermined time after completion of the project.</P>
                    <P>Several commenters supported the proposed change to sponsorship in § 92.300(a)(4) that would allow a CHDO (or its subsidiary) sponsoring a project to be the “managing general partner” rather than the “sole general partner,” or the “managing member” rather than the “sole managing member” of a limited partnership.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenters for their support. However, HUD notes that the provision at § 92.300(a)(5) that permits CHDOs serving as rental housing sponsors to convey a project to a non-profit organization at a predetermined time after project completion is not new and is not being substantively changed by this rulemaking.
                    </P>
                    <HD SOURCE="HD3">C. Changes to Role of CHDO in § 92.300(a)—Opposition</HD>
                    <P>One commenter opposed the proposed changes regarding all three CHDO roles and stated they will have the unintended consequence of reducing CHDO requirements and allowing non-CHDOs to fully benefit from a CHDO designation while not being held accountable to CHDO standards. The commenter stated that for the CHDO owner, developer, and sponsor projects, many non-CHDO for-profit and non-profit developers document their relationships with CHDOs in a way that gives them an appearance of decision-making authority they do not actually have. For sponsorship projects, the commenter recommended that the regulations permit two CHDOs with service areas covering the same geography be permitted to be owners of the general partner entity.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD shares the commenter's concern about entities other than the CHDO controlling the development process in contravention of the regulations and the statutory intent of the CHDO set-aside requirement, which is the reason why it strengthened and clarified the CHDO regulations in the 2013 final rule. However, the Department believes that the possibility that a non-CHDO entity will attempt to use this flexibility to access CHDO set-aside funds for a project it controls, is not a sufficient justification to deny many neighborhood-based nonprofit organizations the opportunity to participate in the CHDO set-aside. This is particularly significant because participating jurisdictions have the ability through recent appropriation provisions to use uncommitted CHDO set-aside funds for other HOME activities after two years. Participating jurisdictions and CHDOs must themselves be alert to efforts to evade the regulatory requirements applicable to CHDO set-aside funds.
                    </P>
                    <P>HUD also notes that under the sponsorship provisions of the current HOME regulations, two CHDOs that work in the same area are permitted to be the partners of the ownership entity, as long as one of the CHDOs is in charge of the project.</P>
                    <HD SOURCE="HD3">D. Request for Greater Flexibility Under § 92.300(a) To Allow for Grant-to-Loan or Other Pass-Through Lending Structures To Facilitate Tax Credit Transactions</HD>
                    <P>Commenters asked HUD to consider permitting alternative funding structures with HOME funds for LIHTC projects, for example, allowing the participating jurisdiction to lend or grant the HOME funds to a CHDO which in turn would have an agreement to loan or contribute the HOME funds to the project.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         A participating jurisdiction may not grant or provide HOME funds to an entity that then lends the HOME funds to the owner of an affordable rental project because HOME statutory and regulatory requirements require the participating jurisdiction to ensure compliance with HOME requirements through binding contractual agreements with the project owner. A participating jurisdiction may only provide HOME funds to an entity to lend to the owner of an affordable rental project if the entity is a subrecipient to the participating jurisdiction. See HOMEfires, Vol. 16 No. 1, September 2021, (HUD discusses the statutory and regulatory provisions governing how HOME project owners are assisted).
                    </P>
                    <HD SOURCE="HD3">E. Ownership by a CHDO Throughout the Period of Affordability and Transfers of Ownership in § 92.300(a)</HD>
                    <P>Commenters stated that they support the proposed change to eliminate the requirement that HOME-assisted rental projects must be owned by the CHDO during the period of affordability. Commenters stated that allowing conveyance of the CHDO-developed or -sponsored project to eligible private nonprofits would create an additional opportunity for long-term preservation and ongoing operation of existing properties. Some commenters stated that permitting a transfer of ownership to a non-CHDO when necessary to maintain compliance with HOME program requirements will help preserve HOME-assisted stock of affordable housing and preserve HOME affordability requirements.</P>
                    <P>Commenters questioned why the same ability was not extended to projects under the CHDO ownership role and advocated that HUD make that change in the final rule. One commenter said that the same difficulties HUD cites with respect to housing that is “developed” and “sponsored” by CHDOs, also applies to housing owned by CHDOs and urged HUD to consider eliminating the requirement that the project be owned by a CHDO throughout the period of affordability at § 92.300(a)(2) in addition to paragraphs (a)(3) and (a)(4).</P>
                    <P>Commenters stated that they support the proposal to eliminate the requirement that HOME-assisted rental projects must be owned by the CHDO during the period of affordability. Several commenters requested that HUD issue sub-regulatory guidance on how to affect such a transfer. Another commenter recommended that the final rule explicitly state that ownership transfers are permitted when necessary to sustain a CHDO project and maintain compliance with HOME affordability requirements and requested HUD issue sub-regulatory guidance to facilitate such transfers.</P>
                    <P>One commenter stated that when such transfers occur, the regulation should permit the participating jurisdiction to impose alternative affordability restrictions at the time of transfer, if the transfer is for the purpose of refinancing the property under the LIHTC program.</P>
                    <P>
                        Two commenters opposed the proposed changes that would permit transfer of CHDO set-aside projects to entities that are not CHDOs. One commenter recommended that HUD grant hardship exceptions rather than changing the regulations, stating that the change would allow for a CHDO-
                        <PRTPAGE P="854"/>
                        developed project to be transferred to a for-profit organization that has no connection to the community to benefit from the asset in the long-term. Another commenter stated that they prefer that CHDOs maintain ownership and asked for additional clarity on how the HOME Program proposed rule incentivizes CHDOs to maintain ownership rather than sell ownership.
                    </P>
                    <P>A commenter requested additional clarity on whether CHDOs are required to maintain ownership of rental housing for the full term of affordability.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the comments. In response to commenters recommending that HUD extend the flexibility provided to projects developed by a CHDO under paragraph (a)(3) and sponsored by a CHDO under (a)(4) to projects owned by the CHDO under § 92.300(a)(2), HUD believes that projects that were funded under the CHDO ownership model should continue to be owned by a CHDO throughout the period of affordability. HUD appreciates the suggestion that it provide hardship exceptions rather than revising the rule. However, HUD has been involved in situations in which a transfer had to occur on a timeframe inconsistent with a case-by-case waiver or exception process. HUD agrees with the commenter that recommended that the final rule explicitly state that ownership transfers are permitted when necessary to sustain a CHDO project and maintain compliance with HOME affordability requirements. As described in the preamble to the proposed rule, HUD intended to apply this flexibility to instances involving a CHDO's bankruptcy, decrease in capacity, or other business necessity that requires sale or other transfer of the housing to preserve the viability or affordability of the project. However, the proposed rule language was more permissive than intended. Consequently, while HUD is adopting the flexibility, it also is revising the final rule to make clear that a participating jurisdiction may permit a CHDO to sell or otherwise convey housing to a nonprofit organization that is not a CHDO only if determines and documents that the CHDO no longer has the capacity to own and manage the housing for the full period of affordability and there are no CHDOs with capacity to own and manage the project for the full period of affordability. This provision would prohibit transfer of a CHDO project to an entity that does not qualify for a CHDO for routine reasons such as refinancing of a project at the end of a LIHTC period.
                    </P>
                    <HD SOURCE="HD3">F. Clarify CHDO Ownership Role</HD>
                    <P>A commenter asked for additional clarity regarding whether a CHDO is always required to be the sole owner or if it is permitted for CHDOs to have partners that are co-owners.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for reviewing the proposed rule. A CHDO is not always required to be the sole owner of a rental housing project. Specifically, rental project partnerships are permitted under the CHDO “sponsor” definition if the CHDO, or its wholly owned subsidiary, is the managing general partner of a limited partnership or the managing member of a limited liability company.
                    </P>
                    <HD SOURCE="HD3">G. Clarify How a CHDO May Share Responsibilities as a Developer Under § 92.300(a)</HD>
                    <P>Commenters supported HUD's proposed changes to §  92.300(a)(3) to permit the CHDO to share responsibilities in the development process, provided that the CHDO remains in charge of these responsibilities. Several commenters recommended that HUD better describe the sharing of responsibilities when the CHDO acts as developers in § 92.300(a)(2), by stating that it means “partnering, contracting, or procuring services from other entities.” These commenters requested that HUD include “project management” in the list of responsibilities that may be shared or contracted.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks commenters for their support of this provision. HUD declines to add project management to the list of responsibilities that may be shared as the term is vague and open to interpretation, whereas the list of responsibilities included in the proposed rule are discrete and easily understood. HUD is adopting the proposed rule language and, in response to comments, is adding language describing the mechanisms through which responsibilities can be shared and decision-making retained.
                    </P>
                    <HD SOURCE="HD3">H. Removal of CHDO in Sponsored Limited Partnerships “for cause” in § 92.300(a)</HD>
                    <P>A commenter supported the proposed change to sponsorship of rental housing in § 92.300(a)(4)(i) that would allow a sponsored CHDO's limited partnership or limited liability company to be removed “for cause” as the managing general partner or managing member, provided that the CHDO must be replaced by another CHDO. The commenter recommended HUD issue sub-regulatory guidance to facilitate transfers necessary to sustain CHDO projects.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter and notes that this is not a change from the existing rule.
                    </P>
                    <HD SOURCE="HD3">I. Opposition to the 10 Percent Limitation on Homeownership Assistance to Homebuyer in CHDO Homeownership Projects in § 92.300(a)</HD>
                    <P>One commenter noted that only 10 percent of the funds awarded to a CHDO for development of housing may be used for downpayment assistance, which is in high demand. The commenter urged HUD to increase the 10 percent threshold and coordinate with Congressional partners, where appropriate, to allow greater flexibility in the 10 percent ceiling.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD is declining to make a change at this time. The downpayment assistance provided as part of a HOME homeownership project developed by a CHDO is only intended to be a small part of the overall homeownership program. HUD had proposed 10 percent as part of a previous rulemaking and this provision was not being revised as part of this rulemaking (see 78 FR 44628 for the final rule, 76 FR 78344 at 78359 for proposed rule).
                    </P>
                    <HD SOURCE="HD3">J. Encourage Participating Jurisdictions To Allow CHDOs To Retain Project Proceeds</HD>
                    <P>One commenter recommended that HUD encourage participating jurisdictions to allow CHDOs to retain proceeds from the sale of housing developed, owned, or sponsored by the CHDO, as permitted under § 92.300(a)(6)(ii).</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Because HOME is a block grant program, each participating jurisdiction has the discretion to determine whether to allow an organization to retain proceeds from the sale of housing in accordance with § 92.300(a)(6)(ii). This determination can be fact-sensitive and organization- or deal-specific. It is best made by the participating jurisdiction in consideration of local housing needs.
                    </P>
                    <HD SOURCE="HD3">K. Provide Easier Format for Designating a CHDO</HD>
                    <P>
                        One commenter urged HUD to issue clarification on the registration requirements for CHDOs in a format that can be shared with organizations because many nonprofits struggle to understand and meet the requirements. The commenter pointed to the CHDO toolkit checklist as an example of clear guidance and urged HUD to align HUD guidance with the checklist.
                        <PRTPAGE P="855"/>
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         There is no set format or “registration requirements” for an organization to be determined to be a CHDO under the regulations. In accordance with § 92.300(a), “[t]he participating jurisdiction must certify the organization as meeting the definition of “community housing development organization” and must document that the organization has capacity to own, develop, or sponsor housing each time it commits funds to the organization.” The definition of CHDO is found in § 92.2. The Department intends on providing further implementation guidance on qualifying an organization as a “community housing development organization” under the revised definition in § 92.2. The Department will ensure that its guidance is aligned with the requirements and will consider other guidance materials that are currently available.
                    </P>
                    <HD SOURCE="HD3">L. Frequency of CHDO Designation in § 92.300(a)</HD>
                    <P>Commenters stated that HUD should remove the current requirement that ties CHDO certification to a HOME-funded project and make certification independent of project-based funding as well as allow certification to be valid for three years. The commenters stated that participating jurisdictions could certify a CHDO for three years and then use a simpler “desktop certification” process to confirm the organization is still eligible whenever funding is requested. A commenter expressed disappointment that the proposed rule does not address the administrative burden of CHDO certification and stated that CHDOs should be certified periodically instead of on a project-by-project basis.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department is declining to change the frequency with which a participating jurisdiction must certify that a CHDO meets the definition in § 92.2 and demonstrates capacity to develop a HOME project. Tying this requirement to the date of commitment is the most consistent approach to implementing the set-aside provisions contained in 42 U.S.C. 12771, which does not contemplate an extended qualification process or a continuous designation for CHDOs. Further, the Consolidated Appropriations Act of 2012 (P. Law 112-55) and Consolidated Appropriations Act of 2013 (P. Law 113-6) stated that a participating jurisdiction may not reserve funds to a CHDO unless it has determined that the CHDO has paid staff with demonstrated development experience, thereby further reinforcing that Congress intended for the CHDO certification process to be a determination made each time a new CHDO project is assisted with set-aside funds.
                    </P>
                    <P>The requirement that qualification as a CHDO be examined each time a CHDO is funded was included in the Consolidated Appropriation Acts and the 2013 HOME final rule to address the prevalence of participating jurisdictions providing CHDO set-aside funds to organizations that lacked adequate development capacity to successfully complete projects. This lack of due diligence by participating jurisdictions resulted in significant numbers of incomplete and failed projects, which took several years to resolve through repayments by participating jurisdictions to their HOME accounts. In addition to questions of capacity, examining a CHDO's qualifications before committing CHDO set-aside funds ensures that a CHDO meets requirements related to the governing board and other provisions, which will also prevent noncompliance. HUD is unable to make this change based on the provisions of the Act but also believes that the regulation is critical to ensuring HOME compliance and successful completion of projects.</P>
                    <HD SOURCE="HD3">M. HUD Should Allow Wholly Owned For-Profit Subsidiaries in § 92.300(a)(4)</HD>
                    <P>One commenter believed that HUD should not revise paragraph (a)(4) to require that wholly owned subsidiaries of CHDOs be nonprofit organizations.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for reviewing the proposed rule. HUD agrees that a subsidiary of a CHDO may be either a for profit or non-profit entity and is making the change.
                    </P>
                    <HD SOURCE="HD3">N. HUD Should Add Additional Oversight Requirements to § 92.300(a)</HD>
                    <P>One commenter recommended that HUD add a subparagraph (a)(8) to implement explicit oversight requirements allowing participating jurisdictions to evaluate the CHDO's ongoing participation in the project as required under (2)-(6).</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenter for reviewing the proposed rule. This is already a requirement for participating jurisdictions, which under § 92.504(a) includes “ensuring that HOME funds are used in accordance with all program requirements and written agreements, and taking appropriate action when performance problems arise.” Additionally, § 92.504(a) also requires that the “participating jurisdiction must have and follow written policies, procedures, and systems, including a system for assessing risk of activities and projects and a system for monitoring entities consistent with this section, to ensure that the requirements of this part are met.” Participating jurisdictions have the flexibility to determine how best to engage in ongoing oversight of the project owners and projects that it funds, consistent with § 92.504 and the requirements of part 92. Consequently, additional regulatory language is not required to require or permit such oversight, and the Department is declining to make the change.
                    </P>
                    <HD SOURCE="HD3">O. HUD Should Clarify the Effect of the Revisions to § 92.300(b)</HD>
                    <P>A commenter requested clarification on the provision allowing up to 20 percent of the minimum CHDO set-aside to be committed to organizations that meet all but the capacity requirement.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department is revising § 92.300(b) to allow for new participating jurisdictions that do not have existing CHDOs with capacity to award up to 20 percent of the new participating jurisdiction's set-aside funds in each of the participating jurisdiction's first two years to organizations that meet all but the capacity requirements contained in paragraph (9) of the CHDO definition in § 92.2. This will enable the 12 new participating jurisdictions receiving their first HOME grants in Fiscal Year 2024 to use their CHDO set-aside funds effectively as they begin to establish their HOME programs.
                    </P>
                    <HD SOURCE="HD3">P. HUD Should Explain the Conditions for Using Set-Aside Funds for non-CHDO Projects</HD>
                    <P>Commenters stated that before redesignating uncommitted CHDO funds as non-CHDO funds, HUD should require a participating jurisdiction to demonstrate that it took all available actions to use the funds for CHDO-eligible projects. One commenter recommended that HUD require participating jurisdictions to document that it completed a specific set of actions, including: (1) provide the full five percent of CHDO operating funds under § 92.208; (2) provide the full amount of capacity building funding under § 92.300(b); and (3) implement “revolving CHDO fund” policies, sometimes known as “CHDO proceeds” policies, to make their CHDO program as attractive and additive to capacity building growth, as possible.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Congress via HUD Appropriations Acts annually provides relief to participating jurisdictions by enabling them without limitation to redesignate any CHDO set-aside funds that have not been committed to a project within 24 months for use in non-CHDO projects. As explained in the 
                        <PRTPAGE P="856"/>
                        following paragraphs, HUD is declining to add additional limitations beyond those contained in NAHA and HUD Appropriations Acts.
                    </P>
                    <P>The requirement in 42 U.S.C. 12771(b) states that if any CHDO funds “remain uninvested for a period of 24 months, then the Secretary shall deduct such funds from the line of credit in the participating jurisdiction's HOME Investment Trust Fund and make such funds available by direct reallocation . . . .” By statute, HUD is required to recapture and reallocate any funds that are not committed to projects developed, sponsored, or owned by CHDOs within 24 months.</P>
                    <P>
                        The requirement in 42 U.S.C. 12742 was suspended by section 233 of Division G of the Consolidated Appropriations Act, 2019 (Pub. L. 116-6). Specifically, section 233 of Public Law 116-6 stated, “[s]ection 231(b) of such Act shall not apply to any uninvested funds that otherwise were deducted or would be deducted from the line of credit in the participating jurisdiction's HOME Investment Trust Fund in 2018, 2019, 2020, or 2021 under that section.” The 2020, 2021, 2022, 2023, and 2024 appropriations acts added 2022, 2023, 2024, 2025, and 2026 respectively, to the years covered by the suspension.
                        <SU>70</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>70</SU>
                             Title II, Division H, Pub. L. 116-94 (133 Stat. 2989); Title II, Division L, Pub. L. 116-260, (134 Stat. 1881); Title II, Division L, Pub. L. 117-103 (136 Stat. 742); Title II, Division L, Pub. L. 117-328 (136 Stat. 5156); Title II, Division F, Pub. L. 118-42 (138 Stat. 361).
                        </P>
                    </FTNT>
                    <P>
                        Additionally, section 242 of Division K of the Consolidated Appropriations Act, 2017 (Pub. L. 115-31) suspended the 24-month commitment deadline requirement set forth in Section 218(g) of NAHA (42 U.S.C. 12748(g)). Section 242 of Public Law 115-31 stated that “Section 218(g) of the Cranston-Gonzalez National Affordable Housing Act (42 U.S.C. 12748(g)) shall not apply with respect to the right of a jurisdiction to draw funds from its HOME Investment Trust Fund that otherwise expired or would expire in 2016, 2017, 2018, or 2019 under that section.” The 2018, 2019, 2020, 2021, 2022, 2023, and 2024 appropriations acts added 2020, 2021, 2022, 2023, 2024, 2025, and 2026 respectively, to the years covered by the suspension.
                        <SU>71</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>71</SU>
                             Section 235, Title II, Division L, Pub. L. 115-141; Section 233, Title II, Division K, Pub. L. 116-6; Title II, Division H, Pub. L. 116-94 (133 Stat. 2988); Title II, Division L, Pub. L. 116-260, (134 Stat. 1881); Title II, Division L, Pub. L. 117-103 (136 Stat. 742); Title II, Division L, Pub. L. 117-328 (136 Stat. 5156); Title II, Division F, Pub. L. 118-42 (138 Stat. 361).
                        </P>
                    </FTNT>
                    <P>
                        The combined effect of the suspension of the 2-year commitment deadline at Section 218(g) of NAHA and the suspension of the 24-month CHDO reservation requirement at Section 231(b) of NAHA means that HUD will no longer deobligate a participating jurisdiction's CHDO set-aside funds that remain uncommitted to CHDO projects after 24 months of HUD obligating the participating jurisdiction's grant, or HOME funds that become uncommitted from a CHDO project after the 24-month deadline. Instead, a participating jurisdiction may continue to accumulate those funds for CHDO set-aside projects or may request HUD allow the funds to be used for non-CHDO projects consistent with its guidance.
                        <SU>72</SU>
                        <FTREF/>
                         HUD does not believe this is an area that it could or should further regulate, given the ongoing Congressional action taken in this area of the HOME requirements.
                    </P>
                    <FTNT>
                        <P>
                            <SU>72</SU>
                             
                            <E T="03">https://www.hud.gov/sites/dfiles/CPD/documents/HOMEfires-Vol-18-No1-CHDO-Setasidefunds.pdf.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">Q. HUD Should Create a Public-Facing List of CHDOs</HD>
                    <P>One commenter recommended that HUD create and maintain a publicly available annual list of organizations certified as CHDOs with the information already submitted to participating jurisdictions. The commenter noted that it is currently challenging for researchers, intermediaries, capacity building organizations, and others to research trends among CHDOs, target non-governmental capacity building resources to CHDOs, and evaluate the extent to which the CHDO Program is meeting its goals. A commenter stated that HUD should create, maintain, and make publicly available on its website the organizations certified as CHDOs based on already available information.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department does not have access to a list of designated and currently active CHDOs, as each participating jurisdiction is required to determine an organization's status on a project-by-project basis at the time of commitment (see § 92.2 and earlier responses to comment on this issue). Moreover, the Department is unsure of the merit of obtaining information relative to the burden of continuously obtaining and updating this information. There is no guarantee that an organization that has met the qualifications of a CHDO in a given year for a specific project will continue to meet those criteria continuously. As the HOME requirements are based on a single point in time, at project commitment, and do not convey a CHDO's status for a specific period of time, whatever information is reflected on a list may not prove to be accurate at the time the participating jurisdiction wishes to commit funds to the organization. The Department will continue to consider how to better facilitate the participation of CHDOs in the HOME program. However, this rulemaking is not the appropriate method to convey this information.
                    </P>
                    <HD SOURCE="HD3">R. CHDO Oversight</HD>
                    <P>A commenter requested additional clarity regarding how participating jurisdictions can use granted funds for the CHDO and how oversight will be conducted regarding this issue.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         In accordance with § 92.300, a participating jurisdiction may use up to 15 percent of its HOME allocation for CHDO set-aside activities including housing that is owned, developed or sponsored by the CHDO. The HOME regulations at § 92.504 require a participating jurisdiction to ensure that HOME funds are used in accordance with all program requirements and written agreements and take appropriate action when performance problems arise. In addition, the participating jurisdiction must have and follow written policies, procedures, and systems, including a system for assessing risk of activities and projects and a system for monitoring program partners, including CHDOs, to ensure all HOME requirements are met.
                    </P>
                    <HD SOURCE="HD3">S. Changes to the CHDO Set-Aside</HD>
                    <P>
                        Two commenters recommended that HUD expand the range of activities eligible for the CHDO set-aside (
                        <E T="03">i.e.,</E>
                         housing owned, developed, or sponsored by a CHDO). One commenter stated that HUD should allow CHDO operating funds to be used in conjunction with TBRA to encourage more utilization of this activity in the HOME program.
                    </P>
                    <P>Another commenter suggested that HUD permit participating jurisdictions to use CHDO set-aside funds to rehabilitate homes for existing low-income owner-occupants. The commenter explained that in areas without CHDOs, owner-occupied repair would be a low-barrier entry point for local nonprofit organizations to become CHDOs. The commenter stated that the ability of these nonprofits to move to administratively more difficult and costlier work, like new construction, is limited by their ability to grow their capacity.</P>
                    <P>
                        A commenter stated that HUD should eliminate the CHDO set-aside requirement and permit participating jurisdictions, whether in rural or urban areas, to exercise discretion in the amount of HOME funds they will award 
                        <PRTPAGE P="857"/>
                        to a CHDO. The commenter stated that HUD's CHDO set-aside requirement hinders communities who have unqualified and inexperienced CHDOs or no eligible CHDO and affect the timeliness of meeting the encumbrance and expenditure deadline. Another also recommended that HUD eliminate the CHDO set-aside, stating that many community development entities do not want to change their board composition and can still access the non-CHDO portion of their participating jurisdiction's HOME funds. This commenter opined that the 15 percent CHDO set-aside is too small to be useful.
                    </P>
                    <P>One commenter supported an increase in CHDO set asides for homeownership, not just rentals, as the current 10 percent leaves participating jurisdictions unable to assist CHDOs.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The CHDO set-aside is statutory. 42 U.S.C. 12771(a) states that “[f]or a period of 24 months after funds . . . are made available to a jurisdiction, the jurisdiction shall reserve not less than 15 percent of such funds for investment only in housing to be developed, sponsored, or owned by CHDOs . . .”
                    </P>
                    <P>The Department does not have the discretion to consider tenant-based rental assistance or homeowner rehabilitation activities to be eligible for the CHDO set-aside, even if they are administered by a CHDO. The participating jurisdiction must enter into a subrecipient agreement with the CHDO to perform those projects. The Department cannot eliminate or reduce the percentage of HOME funds that are set-aside nor require that an additional amount be set-aside beyond that which is required in the Act.</P>
                    <HD SOURCE="HD2">§ 92.352—Environmental Review</HD>
                    <P>One commenter requested HUD permit reliance on a single part 58 Environmental Review by multiple participating jurisdictions funding a project. For example, if a city and county are both providing HOME funds to a project and one of the jurisdictions completes a part 58 Environmental Review, HUD should allow the other jurisdiction to rely on this review for its determination and notification.</P>
                    <P>One commenter recommended that HUD add language to § 92.352 that would expressly permit upcoming guidance from HUD's Office of Environment and Energy regarding the Fiscal Responsibility Act of 2023 to be followed. The commenter recommended adding a paragraph (b)(4) that would read, “(4) HUD or the jurisdiction may utilize a Categorical Exclusion and environmental review from other Federal agencies under the Fiscal Responsibility Act of 2023 and implementing regulations adopted by The Council on Environmental Quality (CEQ) and guidance from HUD's Office of Environment and Energy, when issued.”</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The environmental review requirements contained in 24 CFR part 58 are outside the scope of this rulemaking. However, HUD notes that 24 CFR 58.14 allows cooperating responsible entities to prepare a single review for activities that require an Environmental Assessment or Environmental Impact Statement, if the coordinated and overall review responsibilities are established through a written agreement and the lead agency is responsible for preparing the review, coordinating consultation (including designating a lead agency for compliance with Section 106 of the National Historic Preservation Act pursuant to 36 CFR 800.2(a)(2)), and approving the review.
                    </P>
                    <HD SOURCE="HD2">§ 92.356—Conflict of Interest</HD>
                    <P>A commenter stated that they support the proposed change to the conflict of interest requirements.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department appreciates the commenter's review of the rule. The Department is making one minor revision for clarity to the conflict of interest requirements to state that of the publication methods, “a combination of at least two of” the list provided will be sufficient. The Department believes this will be clearer in what the Department means by “combination.”
                    </P>
                    <HD SOURCE="HD2">§ 92.502—Program Disbursement and Information System</HD>
                    <P>A commenter stated that they support the proposed removal of the requirement that participating jurisdictions enter HOME project completion within 120 days of the final project draw because the four-year project completion is already in place to ensure compliance.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for reviewing the rule and is moving forward with this change.
                    </P>
                    <HD SOURCE="HD2">§ 92.503—Program Income, Repayments, and Recaptured Funds</HD>
                    <HD SOURCE="HD3">A. Program Income Streamlining</HD>
                    <P>One commenter stated that HUD should create a narrow exception to the standard full review process for any use of program income. Specifically, the commenter proposed HUD streamline review for instances where there is no construction of a new unit and the participating jurisdiction, State, or local recipient is in good standing. This streamlining would allow HOME funds to recycle more rapidly and therefore support more low-income families.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD permits participating jurisdictions to allow Subrecipients and State Recipients to retain program income through the written agreement provisions of § 92.504. HUD believes this is the only time that a participating jurisdiction should be allowed to permit a streamlined process, as the State Recipient or Subrecipient already has an ongoing relationship under a written agreement with the participating jurisdiction. HUD also notes that the current HOME rule at § 92.503(d) permits participating jurisdictions to retain program income received during its program year, include program income on-hand in its next annual action plan, and commit the program income to specific projects.
                    </P>
                    <HD SOURCE="HD3">B. Recaptured Funds for CHDO Projects</HD>
                    <P>One commenter stated that § 92.503(c) refers to a participating jurisdiction allowing a CHDO to retain recaptured funds, which contradicts provisions in § 92.504(c)(3)(ii)(B) that require CHDOs to return recaptured funds. The commenter noted that this issue could be fixed by replacing “. . .unless the participating jurisdiction permits the State recipient, subrecipient, or CHDO to retain . . .” with “. . .unless the participating jurisdiction permits the State recipient or subrecipient to retain . . .”</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The commenter is mistaken. The current rule and this final rule permit CHDOs to retain funds recaptured when a HOME-assisted homebuyer sells their home during the period of affordability and use those funds for additional HOME projects pursuant to the written agreement required by § 92.504. There is no contradiction in the current regulations. Paragraph § 92.504(c)(3)(x), the current regulation addressing CHDO projects, states that “[r]ecaptured funds are subject to the requirements of § 92.503.” Paragraph § 92.503(c) of the current rule, as the commenter points out, states that CHDO may retain recaptured funds as follows: “Recaptured funds must be deposited in the participating jurisdiction's HOME Investment Trust Fund local account unless the participating jurisdiction permits the State recipient, subrecipient, or community housing development organization to retain the recaptured funds for additional HOME projects pursuant to the written agreement required by § 92.504.”
                        <PRTPAGE P="858"/>
                    </P>
                    <HD SOURCE="HD2">§ 92.504—Participating Jurisdiction Responsibilities; Written Agreements</HD>
                    <P>One commenter cited to the written agreement provisions in § 92.504 and stated that participating jurisdictions should be permitted to require subrecipients, include members of a consortium to establish and comply with their own requirements, including income determinations, underwriting and subsidy layering, rehabilitation standards, refinancing guidelines, homebuyer program policies, and affordability requirements. The commenter stated that this change is important because the subrecipient or consortium member may be serving a different area or population where the participating jurisdiction's requirements may not be appropriate.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD has established minimum requirements that participating jurisdictions must place into their written agreements with subrecipients in § 92.504(c)(2). In many of these cases, HUD permits participating jurisdictions to create policies and procedures and implement their own standards so long as those standards meet or exceed HUD's minimum requirements. This allows participating jurisdictions the discretion to create jurisdiction-specific requirements such as underwriting standards, income verification methods, rehabilitation standards, etc. This type of discretion is due to HOME's nature as a block grant program. This type of discretion is warranted under statute and regulations because HUD's relationship is with the participating jurisdiction, and the participating jurisdiction has both certified to comply with program requirements and executed a grant agreement with HUD that makes them ultimately responsible in the event of program violations. Subrecipients do not have a direct contractual relationship with HUD and so certain requirements must be created and enforced by the participating jurisdiction and cannot be delegated to a Subrecipient. HUD did not propose revisions to this portion of § 92.504(c)(2) and is declining to make this change to allow Subrecipients to create their own requirements. HUD notes that consortium members are not subrecipients to the consortium, as they are part of the participating jurisdiction (
                        <E T="03">i.e.,</E>
                         the consortium) itself. However, the lead entity of the consortium must enter into written agreements that meet the requirements of § 92.504(c)(2) with consortium members to which it is distributing funds.
                    </P>
                    <HD SOURCE="HD2">§ 92.551—Corrective and Remedial Actions</HD>
                    <P>A commenter stated that they support the proposed change that would allow participating jurisdictions to correct a deficiency in a HUD finding by taking a reduction in a HOME grant equal to the amount of HOME expenditures that were not in compliance with HOME requirements. Another commenter stated support for HUD's clarification on sanctions, in which HUD may permit a voluntary grant reduction in a participating jurisdiction's HOME grants, as long as the participating jurisdiction chooses which grant to reduce.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the comments and is adopting the proposed rule language without change.
                    </P>
                    <P>Specific solicitation of comment #1: The Department specifically solicits public comment about any additional changes it should consider, within statutory constraints, that will improve CHDO availability and capacity in rural areas.</P>
                    <HD SOURCE="HD3">A. Eligibility for Participants in USDA Mutual Help Housing and Homeownership Programs</HD>
                    <P>Commenters stated that CHDO rules should allow mutual self-help housing to be CHDO-eligible under the definition of owner, sponsor, or developer. The commenters stated that the proposed rule is not clear on whether a nonprofit can operate a USDA Rural Development Section 523 mutual self-help housing program as a CHDO, but the rule should allow this as CHDO eligible. Commenters recommended providing targeted technical assistance to CHDOs in rural areas hoping to access HOME CHDO set-aside funds.</P>
                    <P>One commenter further suggested that HUD should explicitly allow families to qualify for HOME funding based on the low-income limits of the USDA's Section 502 Homeownership Direct Loan Program, when the HOME project is either constructed via Section 523 Mutual Self-Help Housing or sold via the USDA Section 502 Loan Program.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD recognizes that nonprofits operating Section 523 mutual self-help housing programs successfully assist very low- and low-income households to build homes in rural areas. However, the Section 523 model does not qualify as homeownership housing developed by a CHDO under § 92.300(a)(6). As commenters noted, these nonprofit organizations do not maintain fee simple ownership of the land and housing throughout the construction period, as required by § 92.300(a)(6). Further, the Section 523 grantee's role managing homebuyers' mutual self-help activities is distinct from that of a housing developer with control of project financing and construction. HUD therefore declines to make a change to HOME CHDO regulations. HUD also notes that the income-banding approach used in USDA programs is not permissible under the HOME program statute. Consequently, HUD is not making changes to the final rule based on these comments.
                    </P>
                    <HD SOURCE="HD3">B. Technical Assistance on HOME Requirements May Assist Rural CHDOs and Participating Jurisdictions</HD>
                    <P>One commenter stated that rural CHDOs often require targeted and specific technical assistance to succeed in competitive funding cycles and can benefit from local partnerships and business relationships and urged HUD to consider what existing regulations may limit those partnerships and rectify the barriers. One commenter recommended provision of targeted technical assistance around HOME underwriting requirements such as pro-forma development to support rural CHDOs applying for competitively awarded State HOME funds. A commenter also suggested that HUD provide participating jurisdictions with training on how to proactively award CHDO capacity building funds, such as when they see multiple unawarded funding applications from a rural CHDO.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         One commenter recommended providing technical assistance on HOME underwriting requirements, such as pro forma development for rural CHDOs. The HOME statute states that if a participating jurisdiction is unable to identify a sufficient number of capable community housing development organizations within the first 24 months of their participation in the HOME program, the participating jurisdictions may allocate up to 20 percent of its funds—up to a maximum of $150,000—to activities that develop the capacity of CHDOs. In response, while training participating jurisdictions on how to award capacity-building funds to develop rural CHDOs is commendable, it will not assist many CHDOs since most participating jurisdictions have been in the program for more than 24 months. However, HUD has developed a CHDO training program that participating jurisdictions can use to train on CHDO requirements. Participating jurisdictions may also request direct technical assistance to build CHDO capacity, especially in rural areas where multiple applications go 
                        <PRTPAGE P="859"/>
                        unfunded due to organizational capacity limitations.
                    </P>
                    <P>HUD also appreciates the suggestion to expand eligible activities for rural CHDOs to include the rehabilitation of owner-occupied homes and USDA Section 523 mutual self-help housing. While these activities support rural housing initiatives, the entities involved do not develop, own, or sponsor housing investments, which does not align with the statutory intent for a CHDO under HOME. The statute requires CHDOs to develop, sponsor, or own housing as a core requirement for participating in the HOME program.</P>
                    <HD SOURCE="HD3">C. Change How a Person Is Determined as Low-Income for Purposes of Low-Income Board Representation Requirements in Paragraph (5) of the Definition of Community Housing Development Organization in § 92.2</HD>
                    <P>One commenter recommended that HUD factor in a county's median income rather than median incomes of counties State-wide and that the county's median income be considered in CHDO board representation requirements of low-income residents or organizations.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for reviewing the proposed rule. However, Title I of NAHA defines low-income families as “families whose incomes do not exceed 80 percent of the median income for the area, as determined by the Secretary with adjustments for smaller and larger families, except that the Secretary may establish income ceilings higher or lower than 80 percent of the median for the area on the basis of the Secretary's findings that such variations are necessary because of prevailing levels of construction costs or fair market rents, or unusually high or low family incomes.”
                    </P>
                    <P>HUD is declining to make this change because the current regulation faithfully implements the statute and introducing different standards for what constitutes low-income into the program will create confusion and potential noncompliance.</P>
                    <HD SOURCE="HD3">D. HUD Should Examine and Remove Barriers for Nonprofits in Rural Communities</HD>
                    <P>One commenter wants participating jurisdictions to make concerted efforts to remove barriers for nonprofit organizations in rural communities and encouraged HUD to examine barriers that maybe inadvertently be caused by participating jurisdiction policy and determine whether the barriers are disproportionately impacting rural areas.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for reviewing the proposed rule. HUD agrees that participating jurisdictions should take steps to remove unnecessary barriers to rural nonprofit organizations to become CHDOs. HOME is a block grant program, and participating jurisdictions are free to establish policies and procedures for their programs. HUD believes that a more appropriate role is for HUD to offer technical assistance to participating jurisdictions interested in facilitating the entry of CHDOs to their programs.
                    </P>
                    <HD SOURCE="HD2">§ 570.200—General Policies—Reimbursement for Pre-Award Costs</HD>
                    <P>A commenter stated that they do not support changing the effective date of the grant agreement to the date HUD executes the grant agreement. The commenter noted that this change would require them to front costs because HUD has timely executed grant agreements on only two occasions in the last twelve funding cycles.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the commenter's concern, especially since it originates from a grantee with a program year start date of July 1 or later, which accounts for more than 81 percent of Community Development Block Grant (CDBG) entitlement grantees. HUD's proposed change to the introductory text of 24 CFR 570.200(h), in conjunction with the proposed addition to § 92.212(b) for the HOME program, was designed to eliminate the need for the Department to issue annual waivers to assist the approximately 19 percent of grantees particularly hampered in recent years by late Congressional appropriations. However, HUD's proposed change to § 570.200(h) decoupled the effective date of a grant agreement from a grantee's program year start date and, as the commenter noted, would have subjected it and hundreds of other grantees with similar program year start dates to incurring pre-award costs on an annual basis. HUD sees the need to maintain the connection between the grant agreement effective date and program year start dates to reserve pre-award costs to those incurred before a program year start date. Therefore, HUD will retain the existing introductory text to § 570.200(h) and instead add a new § 570.200(h)(3) that makes the effective date of the grant agreement, in a year when an annual appropriation occurs less than 90 days before a grant recipient's program year start date, the earlier of either the program year start date or the date that the consolidated plan is received by HUD. This change addresses the commenter's concern, aligns CDBG better with the new HOME program regulation at § 91.212(b)(2), and continues practices implemented through annual waivers.
                    </P>
                    <HD SOURCE="HD2">Outside the Scope of the HOME Rulemaking</HD>
                    <HD SOURCE="HD3">A. HUD Should Commission a Study of CHDOs</HD>
                    <P>Commenters stated HUD should commission a study every three to five years on the universe of nonprofit organizations that could potentially become CHDOs, and the research could evaluate trends in CHDO certification, financial health, production, and organizational needs.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department thanks the commenters for reviewing but believes that the study that the commenters are requesting is beyond the scope of this rulemaking. The Department will consider this area as a research area in the future.
                    </P>
                    <HD SOURCE="HD3">B. HUD Should Consider Metrics To Evaluate Needs of Rural Communities and Tribes</HD>
                    <P>One commenter encouraged HUD to consider metrics to measure the needs of rural and Tribal communities, and to encourage States to use HOME funds for projects that meet those identified needs.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The Department is declining to develop metrics and measures on rural or Tribal needs as part of this rulemaking. Participating jurisdictions are required to engage in the consolidated planning process in 24 CFR part 91. This evaluation includes the consideration of the needs of rural communities within a participating jurisdiction, including rural homelessness. Separately, Tribes assisted under the Indian Housing Block Grant program engage in the preparation of an Indian Housing Plan in accordance with 24 CFR part 1000, subpart C. This includes an evaluation of housing needs for each assisted Tribe. Each of these planning processes enables HUD grantees to identify housing needs using their own data and metrics, as well as HUD-provided data, and determine how to best address the challenges within their jurisdictions. Additionally, these plans are public facing, thereby allowing the public to review the data as it sees fit.
                    </P>
                    <HD SOURCE="HD3">C. HUD Should Increase Section 8 Assistance</HD>
                    <P>
                        A commenter stated that HUD should increase funding allocations to HAP budgets to cover increased rents because of the expected increase of rent charged to PBVs and HCVs. The commenter 
                        <PRTPAGE P="860"/>
                        noted that this change is necessary so as not to reduce the number of vouchers available. Another commenter requested an increase in the HAP budget for Section 8 programs to account for the additional rent costs that will result from applying the HOME rent limit only to the tenant contribution to rent. Another commenter urged HUD to consider the impact of participating jurisdiction to regulate the HOME rent limits on units assisted by PBV that this issue will have on a PHA's overall per unit cost and the long-term consequences for PHA budgets.
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         While HUD is revising the rent reasonableness regulations for the Section 8 program, Section 8 funding is beyond the scope of this rulemaking.
                    </P>
                    <HD SOURCE="HD3">D. Lead-Based Paint Regulations in 24 CFR Part 35 Should Be Updated</HD>
                    <P>One commenter stated that HUD's current lead paint regulations are out-of-date given higher construction costs and extended requirements. The commenter recommended that the ranges that determine intervention level be updated to the following: (1) Lead-safe work practices less than $20,000; (2) interim controls between $20,001 and $50,000; and (3) abatement for more than $50,000.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Lead-based paint requirements are outside the scope of this rulemaking. HUD did not propose any revisions to 24 CFR part 35 or to how HUD applies lead-based paint requirements to the HOME program. Further, the dollar thresholds in the part 35 regulations are established in Section 1012 of Title X of the Housing and Community Development Act of 1992 and are statutory for the HOME program.
                        <SU>73</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>73</SU>
                             See 42 U.S.C. 12742(a)(5) and 42 U.S.C. 4822 for the lead-based paint requirements for HOME.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">E. Provide Build America, Buy America Guidance</HD>
                    <P>Commenters expressed frustration over the limited Buy America, Build America (BABA) waiver availability and increased cost incurred due to sourcing domestic materials. Commenters stated that the lack of guidance from HUD on BABA compliance has further compounded challenges for developers and contractors, hindering their ability to provide feedback and navigate problems. A commenter stated that HUD should clarify the impact of BABA on the green building standards because the impact is unclear at this time.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         BABA is beyond the scope of this rulemaking. The Department is developing guidance on how to implement BABA for HUD programs. Until this guidance is developed, HUD cannot determine the effect of BABA compliance on the green building incentive or overall compliance with the HOME final rule.
                    </P>
                    <HD SOURCE="HD3">F. Create a Risk-Lowering Pilot Program</HD>
                    <P>One commenter recommended that HUD should consider creating a “risk-lowering pilot program for nonprofit affordable housing developers.” The commenter suggested that the pilot program it suggests might offer a preapproval for nonprofits that enables those organization to bid for HOME funding with no or low environmental review process-based risk. The commenter stated that in the program it suggests that a limited number of nonprofits could enter an agreement with HUD that guarantees HUD reimbursed costs for environmental reviews for unsuccessful applicants. The commenter noted that the pilot program could be designed in a way that it would not cover overhead costs of the nonprofit but only cover the hard costs of specialists. The commenter stated that this design would lower the risk of high pre-development costs being lost. The commenter suggested that this pilot program could be targeted at CHDOs already partnering with HUD or else be based on nonprofit operating budgets, geographic targeting, or other community characteristics, such as persistent poverty counties.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         Establishing a pilot program of the nature contemplated by the commenter is beyond the scope of this rulemaking. The Department recognizes that environmental requirements can pose a challenge to many aspiring developers and owners. In recognition of those challenges, HUD revised the regulations in § 92.206(d) to allow HUD environmental review or other environmental studies or assessments to be reimbursable expenses if the participating jurisdiction agrees to pay for those costs in the written agreement.
                    </P>
                    <HD SOURCE="HD3">G. Issue Waivers To Better Enable HOME Homeownership Activities</HD>
                    <P>One commenter asked HUD to provide waivers to Habitat for Humanity chapters so that participating jurisdictions can assist more with following HOME guidelines.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the comment but is uncertain what types of waivers the commenter is recommending. Outside of Presidentially-declared disasters or national emergencies, the Department is declining to announce the availability of waivers for the HOME program. The Department will still consider waiver requests on a case-by-case basis and determine whether the waiver states good cause upon which relief can be granted in accordance with 24 CFR 5.110 and applicable law.
                    </P>
                    <HD SOURCE="HD3">H. Increase Opportunities for Persons With Disabilities</HD>
                    <P>Another commenter stated that opportunities for HUD loans for people with disabilities and those who may have medical needs should be explored in every State and territory and that HUD must support those who wish to rehabilitate homes in regard to accessibility. The commenter emphasized the need for access to universally designed housing for people with disabilities.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter for reviewing the proposed rule. The recommendation that HUD explore opportunities for HUD loans for people with disabilities or medical needs is outside the scope of this rulemaking. Other aspects of this rule are intended to provide clarity and enhance affordable housing opportunities for eligible beneficiaries, including individuals with disabilities. In addition, accessibility requirements for programs and activities apply to HUD recipients under HUD's existing Section 504 requirements, and housing may be subject to additional accessibility requirements under the Fair Housing Act and the Americans with Disabilities Act, as applicable.
                    </P>
                    <HD SOURCE="HD3">I. HUD Should Perform Additional Rulemaking on the Consolidated Planning Regulations at 24 CFR Part 91</HD>
                    <P>One commenter recommended that HUD issue a separate advance notice of proposed rulemaking (ANPR) regarding how the Consolidated Plan could be improved and simplified. The commenter stated that the ANPR should consider improvements to the Annual Action Plan (AAP) and Consolidated Annual Performance and Evaluation Report (CAPER) with a special focus on reducing redundancies across planning documents. The commenter also urged HUD to facilitate greater consistency among local HUD offices in how Consolidated Plans and related planning regulations and guidance are interpreted.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter. However, as the commenter notes, the suggestion would require a separate rulemaking process and is outside the scope of this rulemaking.
                        <PRTPAGE P="861"/>
                    </P>
                    <HD SOURCE="HD3">J. Incentivizing Use of Section 8 Housing Choice Vouchers in LIHTC Projects</HD>
                    <P>A commenter said HUD should help communities develop non-discriminatory language and potential administrative rules so that many in the LIHTC system can access HCVs and adopt inclusive low-income energy assistance standards. Generally, the commenter said HUD should incentivize renting through HCVs and assisting communities by incorporating sources of income discrimination.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         By statute, owners of HOME-assisted rental housing may not discriminate against persons with Section 8 voucher assistance (42 U.S.C. 12745(a)(1)(D)). HUD is expanding this protection to include a source of income protection for all forms of Federal tenant-based rental assistance provided to an applicant of HOME-assisted rental housing through this final rule. Incentivizing HCV utilization in LIHTC projects or in housing that is not HOME-assisted is beyond the scope of rulemaking.
                    </P>
                    <HD SOURCE="HD3">K. Provide Guidance on Participating Jurisdiction-Imposed Unit Caps in HOME Rental Housing Programs</HD>
                    <P>
                        One commenter suggested that HUD should provide guidance to participating jurisdictions on maximum unit counts. For example, the commenter stated in one State, there is a 56-unit maximum rule for HOME funds, and that maximum makes HOME projects ineligible for utilizing four percent tax credits. Additionally, the commenter explained that anything less than a 100-unit maximum creates additional barriers to building integrated, inclusive housing communities for people with and without disabilities (
                        <E T="03">i.e.,</E>
                         HUD Section 811 PRA).
                    </P>
                    <P>
                        <E T="03">HUD Response:</E>
                         The commenter's request for guidance is outside the scope of this rulemaking and HUD declines to make a change. The HOME regulations require that the HOME funds be cost-allocated in multi-unit properties to ensure that, at a minimum, an appropriate number of units are designated as HOME-assisted units; however, they do not cap the number of HOME-assisted units in a project. A participating jurisdiction imposed this cap as a matter of policy and any appeal should be handled at that level.
                    </P>
                    <HD SOURCE="HD3">L. Healthy Homes Requirements Should Be Integrated Into Environmental Review Requirements for HUD Programs</HD>
                    <P>One commenter stated HUD should integrate healthy home inspection requirements into environmental assessments as well as cover them under the eligible cost framework. The commenter recommended that HUD use the healthy homes standard under 42 U.S.C. 711, the Maternal, Infant, and Early Childhood Home Visit Program. The commenter stated this standard is useful because it focuses on those most at risk from poor indoor air quality and would capture the health effects on a significant number of residents in public housing.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD appreciates the comment. However, the required elements of environmental reviews conducted under 24 CFR part 58 are outside the scope of this rulemaking, and HUD declines to make any change.
                    </P>
                    <HD SOURCE="HD3">M. Rents Under Tenant-Based Rental Assistance</HD>
                    <P>One commenter asked if HUD has considered changing the requirement from the fair market rent to rent reasonableness.</P>
                    <P>
                        <E T="03">HUD Response:</E>
                         HUD thanks the commenter. While HUD is revising the rent reasonableness regulations for the Section 8 program, HUD is not revising the rent reasonable requirement used in HOME tenant-based rental assistance programs. This is beyond the scope of this rulemaking.
                    </P>
                    <HD SOURCE="HD1">V. Severability</HD>
                    <P>Consistent with the requirements of the Administrative Procedure Act, HUD has carefully responded to all public comments received in response to its notice of proposed rulemaking and acted within its statutorily delegated authority in the promulgation of regulations that are consistent with the Act. Nonetheless, if any provision of this final rule, or any provision of 24 CFR part 92, is held to be invalid or unenforceable as applied to any action, that provision should be construed so as to continue to give the maximum effect to the provision permitted by law. If such holding is that the provision of this part is invalid and unenforceable in all circumstances, then HUD views each provision as severable from the remainder of this part and a finding that a provision is invalid should not affect the remaining provisions. Additionally, if a provision should be held to be invalid or unenforceable, HUD would have its predecessor provision, the equivalent provision in effect prior to this rulemaking, come back into effect. As this rulemaking is comprehensive and concerns all aspects of the HOME program, the Department recognizes the need to maintain the regulations to the maximum effect, if permissible, and to sever them as necessary if a court challenge prevails. This provides stability for participating jurisdictions, which must rely upon regulations for all activities, regardless of litigation or court orders affecting certain provisions or for certain activities.</P>
                    <HD SOURCE="HD1">VI. Findings and Certifications</HD>
                    <HD SOURCE="HD2">Regulatory Review—Executive Orders 12866, 13563, and 14094</HD>
                    <P>Under Executive Order 12866 (Regulatory Planning and Review), a determination must be made regarding whether a regulatory action is significant and, therefore, subject to review by the Office of Management and Budget in accordance with the requirements of the order. Executive Order 13563 (Improving Regulations and Regulatory Review) directs executive agencies to analyze regulations that are “outmoded, ineffective, insufficient, or excessively burdensome, and to modify, streamline, expand, or repeal them in accordance with what has been learned.” Executive Order 13563 also directs that, where relevant, feasible, and consistent with regulatory objectives, and to the extent permitted by law, agencies identify and consider regulatory approaches that reduce burdens and maintain flexibility and freedom of choice for the public. Executive Order 14094 (Modernizing Regulatory Review) amends section 3(f) of Executive Order 12866, among other things. Updating the HOME program regulation is consistent with the objectives of Executive Order 13563 to reduce burden, as well as the goal of modifying and streamlining regulations that are outmoded and ineffective.</P>
                    <P>
                        This final rule revises the HOME program regulations, which were first promulgated in 1991, and have not been significantly updated since 2013. This final rule: revises CHDO qualification requirements for community-based non-profit housing organizations to access CHDO set-aside funds to own, develop, and sponsor affordable housing; revises HOME rent requirements to implement statutory changes made to the U.S. Housing Act of 1937 by section 2835(a)(2) of HERA; facilitates the use of HOME funds for small one-to-four-unit rental projects; incentivizes inclusion of ambitious Green Building standards in new construction, reconstruction, and rehabilitation projects; and expands flexibilities for community land trusts to participate in the HOME program. The final rule also provides enhanced flexibility in TBRA programs; strengthens and expands tenant protections; and clarifies the resale requirements for homeownership housing. The final rule also includes 
                        <PRTPAGE P="862"/>
                        technical amendments or simplifications to certain changes made in the 2013 HOME Final Rule, the HOTMA Final Rule, and the NSPIRE Final Rule. This final rule was determined to be a significant regulatory action under section 3(f) of Executive Order 12866, as amended by Executive Order 14094, but was not deemed to be significant under section 3(f)(1).
                    </P>
                    <HD SOURCE="HD2">Regulatory Impact Analysis</HD>
                    <P>
                        HUD prepared a regulatory impact analysis (RIA) that addresses the costs and benefits of the final rule. HUD's RIA is part of the docket file for this rule at 
                        <E T="03">https://www.regulations.gov.</E>
                    </P>
                    <P>As described in the RIA, HUD anticipates that the economic impact of the final rule will be almost entirely within the HOME program. In other words, the changes to the HOME program will affect what participating jurisdictions do with the HOME funds they receive from HUD and how projects that accept this funding source operate. Many of the policy adjustments will only have a practical impact if participating jurisdictions choose to respond to the policy adjustments by altering how they use HOME funds. HUD strongly encourages the public to view the docket file.</P>
                    <HD SOURCE="HD2">Regulatory Flexibility Act</HD>
                    <P>
                        The Regulatory Flexibility Act (RFA) (5 U.S.C. 601 
                        <E T="03">et seq.</E>
                        ) generally requires an agency to conduct a regulatory flexibility analysis of any rule subject to notice and comment rulemaking requirements unless the agency certifies that the rule will not have a significant economic impact on a substantial number of small entities. This rule aims to improve the HOME program by making several changes to the program's regulations through increasing flexibility for grantees in using their HOME grants, streamlining administrative requirements, implementing statutory changes regarding rent restrictions in HOME rental projects, and enhancing tenant protections for HOME-assisted rental households. As described in the RIA, HUD anticipates that the economic impacts of this rule will be almost entirely within the HOME program. In other words, the changes to the HOME program will affect what participating jurisdictions do with the HOME funds they receive from HUD and how projects that accept this funding source operate. Many of the policy adjustments will only have a practical impact if participating jurisdictions choose to respond to them by altering how they use HOME funds. For the reasons presented, the undersigned certifies that this rule will not have a significant economic impact on a substantial number of small entities.
                    </P>
                    <HD SOURCE="HD2">Environmental Impact</HD>
                    <P>
                        A Finding of No Significant Impact (FONSI) with respect to the environment was made, at the proposed rule stage, in accordance with HUD regulations in 24 CFR part 50 that implement section 102(2)(C) of the National Environmental Policy Act of 1969 (42 U.S.C. 4332(2)(C)). The FONSI remains applicable to this final rule and is available through the docket file at 
                        <E T="03">https://www.regulations.gov.</E>
                         The FONSI is also available for public inspection during regular business hours in the Regulations Division, Office of General Counsel, Room 10276, Department of Housing and Urban Development, 451 Seventh Street SW, Washington, DC 20410-0500. Due to security measures at the HUD Headquarters building, you must schedule an appointment in advance to review the FONSI by calling the Regulations Division at 202-708-3055 (this is not a toll-free number). HUD welcomes and is prepared to receive calls from individuals who are deaf or hard of hearing, as well as individuals with speech or communication disabilities. To learn more about how to make an accessible telephone call, please visit 
                        <E T="03">https://www.fcc.gov/consumers/guides/telecommunications-relay-service-trs.</E>
                    </P>
                    <HD SOURCE="HD2">Federalism—Executive Order 13132</HD>
                    <P>Executive Order 13132 (Federalism) prohibits an agency from publishing any rule that has Federalism implications if the rule either: (i) imposes substantial direct compliance costs on State and local governments and is not required by statute, or (ii) preempts State law, unless the agency meets the consultation and funding requirements of section 6 of the Executive Order. This final rule does not have Federalism implications and does not impose substantial direct compliance costs on State and local governments or preempt State law within the meaning of the Executive Order.</P>
                    <HD SOURCE="HD2">Unfunded Mandates Reform Act</HD>
                    <P>Title II of the Unfunded Mandates Reform Act of 1995 (2 U.S.C. 1531-1538) (UMRA) establishes requirements for Federal agencies to assess the effects of their regulatory actions on State, local, and Tribal governments, and on the private sector. This final rule does not impose any Federal mandates on any State, local, or Tribal governments, or on the private sector, within the meaning of the UMRA.</P>
                    <HD SOURCE="HD2">Paperwork Reduction Act</HD>
                    <P>The information collection requirements contained in this final rule have been approved by OMB in accordance with the Paperwork Reduction Act of 1995 (44 U.S.C. 3501-3520) and assigned the OMB control number 2506-0171. In accordance with the Paperwork Reduction Act, an agency may not conduct or sponsor, and a person is not required to respond to, a collection of information, unless the collection displays a currently valid OMB control number.</P>
                    <P>The final rule would change the annual income determination requirement for households assisted with HOME TBRA from annual to when a new rental assistance contract must be executed, which can be as long as 2 years, which reduces the burden hours. The final rule includes a new provision in 24 CFR 92.250 to increase the maximum subsidy limit allowed for HOME projects based on whether the project shall meet a more comprehensive property standard that includes Green Building criteria, which would lead to a slight increase in burden for participating jurisdictions with qualified projects. The final rule would amend 24 CFR 92.252 to eliminate the requirement that a participating jurisdiction must submit to HUD a marketing plan for any HOME-assisted rental units that have not achieved initial occupancy within six months of project completion in IDIS, which would reduce the reporting burden on participating jurisdictions with unoccupied HOME-assisted rental units. The final rule adds paragraph (g)(1) to 24 CFR 92.252 to permit an owner of small-scale housing to re-examine annual income every three years, rather than annually, therefore reducing burden for income determination. The tenancy lease addendum, described in 24 CFR 92.253, replaces multiple, separate functions, and results in a decrease in paperwork burden. The changes in 24 CFR 92.300 to define the qualifications for a CHDO result in increased applications and certification, which may lead to an increase of paperwork burden. Overall, the final rule results in a net decrease of burden by 28,852 total estimated annual burden hours.</P>
                    <P>
                        The burden of the information collections in this final rule is estimated as follows:
                        <PRTPAGE P="863"/>
                    </P>
                    <GPOTABLE COLS="6" OPTS="L2,i1" CDEF="s50,10,xs60,12,12,12">
                        <TTITLE>Reporting and Recordkeeping Burden</TTITLE>
                        <BOXHD>
                            <CHED H="1">24 CFR section reference</CHED>
                            <CHED H="1">Number of parties</CHED>
                            <CHED H="1">
                                Frequency of 
                                <LI>responses</LI>
                            </CHED>
                            <CHED H="1">
                                Number of 
                                <LI>responses </LI>
                                <LI>per party</LI>
                            </CHED>
                            <CHED H="1">
                                Estimated 
                                <LI>average time for requirements (hours)</LI>
                            </CHED>
                            <CHED H="1">
                                Total 
                                <LI>estimated </LI>
                                <LI>annual burden (hours)</LI>
                            </CHED>
                        </BOXHD>
                        <ROW>
                            <ENT I="01">§ 92.252(g)(1) Small scale housing income determination</ENT>
                            <ENT>2,000</ENT>
                            <ENT>Annual</ENT>
                            <ENT>1</ENT>
                            <ENT>2</ENT>
                            <ENT>4,000</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">§ 92.209(c)(1) Annual income determination for TBRA</ENT>
                            <ENT>72,000</ENT>
                            <ENT>Annual</ENT>
                            <ENT>1</ENT>
                            <ENT>0.75</ENT>
                            <ENT>54,000</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">§ 92.250 Increase maximum subsidy limits for ambitious green building</ENT>
                            <ENT>188</ENT>
                            <ENT>Annual</ENT>
                            <ENT>1</ENT>
                            <ENT>2</ENT>
                            <ENT>376</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">§ 92.253 Tenant protections (including lease addendum requirement)</ENT>
                            <ENT>6,667</ENT>
                            <ENT>Annual</ENT>
                            <ENT>1</ENT>
                            <ENT>3</ENT>
                            <ENT>20,001</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">§ 92.300 Designation of CHDOs</ENT>
                            <ENT>600</ENT>
                            <ENT>Annual</ENT>
                            <ENT>1</ENT>
                            <ENT>1.5</ENT>
                            <ENT>900</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">§ 92.251 Property standards and inspection requirements</ENT>
                            <ENT>6,000</ENT>
                            <ENT>Annual</ENT>
                            <ENT>1</ENT>
                            <ENT>3</ENT>
                            <ENT>18,000</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">§ 92.252 6-month marketing plan for unoccupied rental units</ENT>
                            <ENT>60</ENT>
                            <ENT>Annual</ENT>
                            <ENT>1</ENT>
                            <ENT>1</ENT>
                            <ENT>60</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">§ 92.507 Grant closeout procedures</ENT>
                            <ENT>652</ENT>
                            <ENT>Annual</ENT>
                            <ENT>1</ENT>
                            <ENT>1</ENT>
                            <ENT>652</ENT>
                        </ROW>
                    </GPOTABLE>
                    <LSTSUB>
                        <HD SOURCE="HED">List of Subjects</HD>
                        <CFR>24 CFR Part 91</CFR>
                        <P>Aged, Grant programs—housing and community development, Homeless, Individuals with disabilities, Low and moderate income housing, Reporting and recordkeeping requirements.</P>
                        <CFR>24 CFR Part 92</CFR>
                        <P>Administrative practice and procedure; Low and moderate income housing; Manufactured homes; Rent subsidies; Reporting and recordkeeping requirements.</P>
                        <CFR>24 CFR Part 570</CFR>
                        <P>Administrative practice and procedure; American Samoa; Community development block grants; Grant programs—education; Grant programs—housing and community development; Guam; Indians; Loan programs—housing and community development; Low and moderate income housing; Northern Mariana Islands; Pacific Islands Trust Territory; Puerto Rico; Reporting and recordkeeping requirements; Student aid; Virgin Islands.</P>
                        <CFR>24 CFR Part 982</CFR>
                        <P>Grant programs—housing and community development; Grant programs—Indians; Indians; Public housing; Rent subsidies; Reporting and recordkeeping requirements.</P>
                    </LSTSUB>
                    <P>For the reasons stated in the preamble, HUD amends 24 CFR parts 91, 92, 570, and 982 as follows:</P>
                    <PART>
                        <HD SOURCE="HED">PART 91—CONSOLIDATED SUBMISSIONS FOR COMMUNITY PLANNING AND DEVELOPMENT PROGRAMS</HD>
                    </PART>
                    <REGTEXT TITLE="24" PART="91">
                        <AMDPAR>1. The authority citation for part 91 continues to read as follows:</AMDPAR>
                        <AUTH>
                            <HD SOURCE="HED">Authority: </HD>
                            <P>42 U.S.C. 3535(d), 3601-3619, 5301-5315, 11331-11388, 12701-12711, 12741-12756, and 12901-12912. </P>
                        </AUTH>
                    </REGTEXT>
                    <SECTION>
                        <SECTNO>§ 91.220</SECTNO>
                        <SUBJECT>[Amended] </SUBJECT>
                    </SECTION>
                    <REGTEXT TITLE="24" PART="91">
                        <AMDPAR>2. Amend § 91.220 by:</AMDPAR>
                        <AMDPAR>a. Removing the words “affordability period” and adding in their place the words “period of affordability” in paragraph (l)(2)(iv)(B);</AMDPAR>
                        <AMDPAR>b. Removing “92.254(a)(2)(iii)” and adding in its place “92.254(a)(2)(iv)” in paragraph (l)(2)(v);</AMDPAR>
                        <AMDPAR>c. Removing “92.253(d)” and adding in its place “92.253(e)” in paragraph (l)(2)(vii)(D);</AMDPAR>
                        <AMDPAR>d. Removing paragraph (l)(2)(viii). </AMDPAR>
                    </REGTEXT>
                    <SECTION>
                        <SECTNO>§ 91.320</SECTNO>
                        <SUBJECT>[Amended] </SUBJECT>
                    </SECTION>
                    <REGTEXT TITLE="24" PART="91">
                        <AMDPAR>3. Amend § 91.320 by:</AMDPAR>
                        <AMDPAR>a. Removing the words “affordability period” and adding in their place the words “period of affordability” in paragraph (k)(2)(iv)(B);</AMDPAR>
                        <AMDPAR>b. Removing “92.254(a)(2)(iii)” and adding in its place “92.254(a)(2)(iv)” in paragraph (k)(2)(v);</AMDPAR>
                        <AMDPAR>c. Removing “92.253(d)” and adding in its place “92.253(e)” in paragraph (k)(2)(vii)(D);</AMDPAR>
                        <AMDPAR>d. Removing paragraph (k)(2)(viii). </AMDPAR>
                    </REGTEXT>
                    <PART>
                        <HD SOURCE="HED">PART 92—HOME INVESTMENT PARTNERSHIPS PROGRAM</HD>
                    </PART>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>4. The authority citation for part 92 continues to read as follows:</AMDPAR>
                        <AUTH>
                            <HD SOURCE="HED">Authority:</HD>
                            <P> 42 U.S.C. 3535(d) and 12701-12839; 12 U.S.C. 1701x. </P>
                        </AUTH>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>5. Amend § 92.2 by:</AMDPAR>
                        <AMDPAR>a. Removing the definition of “ADDI funds”;</AMDPAR>
                        <AMDPAR>b. In the definition of “Commitment” by removing the word “official” in paragraph (1) introductory text and adding in its place the word “officials”, by removing the word “downpayment” in paragraph (1)(i) and adding in its place the word “homeownership”, by removing the words “or subrecipient” wherever it appears in paragraph (2)(ii)(A), by removing the words “owner or the tenant” in paragraph (2)(iii) and adding in their place the words “owner and tenant”, and by adding paragraph (2)(ii)(C);</AMDPAR>
                        <AMDPAR>c. Revising paragraphs (4), (5), (8)(i), and (9) in the definition of “Community housing development organization”;</AMDPAR>
                        <AMDPAR>d. Adding a definition for “Community land trust” in alphabetical order;</AMDPAR>
                        <AMDPAR>e. Removing the definitions of “Displaced homemaker” and “First-time homebuyer”;</AMDPAR>
                        <AMDPAR>f. In the definition of “Homeownership” by revising the introductory text and paragraph (1) and by removing the words “Low Income Housing Tax Credits” in paragraph (4) and adding in their place the words “Low-Income Housing Credits (26 U.S.C. 42)”;</AMDPAR>
                        <AMDPAR>g. In the definition of “Housing” by removing the words “single-family dwellings” and adding in their place the words “single family housing units”;</AMDPAR>
                        <AMDPAR>h. Adding a definition for “Period of affordability” in alphabetical order;</AMDPAR>
                        <AMDPAR>i. Revising the introductory text and paragraphs (2) and (3) in the definition of “Program income”;</AMDPAR>
                        <AMDPAR>j. Revising the last sentence in the definition of “Reconstruction”;</AMDPAR>
                        <AMDPAR>k. Removing the words “one-to four-family” and adding in their place the words “one-to four-unit” in the definition of “Single family housing”;</AMDPAR>
                        <AMDPAR>l. Removing the definition of “Single parent”;</AMDPAR>
                        <AMDPAR>m. Removing the word “dwelling” and adding in its place the word “housing” the definition of “Single room occupancy (SRO) housing”;</AMDPAR>
                        <AMDPAR>n. Adding a definition for “Small-scale housing” in alphabetical order;</AMDPAR>
                        <AMDPAR>
                            o. Removing the semicolon after “this part” and the words “however, for purposes of the American Dream Downpayment Initiative (ADDI) described in subpart M of this part, the term “state” does not include the Commonwealth of Puerto Rico (except for FY2003 ADDI funds)” in the definition of “State”;
                            <PRTPAGE P="864"/>
                        </AMDPAR>
                        <AMDPAR>p. Revising the definition of “State recipient”;</AMDPAR>
                        <AMDPAR>q. In the definition of “Subrecipient” by removing the words “public agency” wherever they appear and adding in their place the words “governmental entity”, by removing the word “downpayment” and adding in its place the word “homeownership”, and by removing the word “solely”; and</AMDPAR>
                        <AMDPAR>r. Removing the word “dwelling” wherever it appears and adding in its place the word “housing” in the definition of “Tenant-based rental assistance”.</AMDPAR>
                        <P>The additions and revisions read as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.2</SECTNO>
                            <SUBJECT>Definitions.</SUBJECT>
                            <STARS/>
                            <P>
                                <E T="03">Commitment:</E>
                                 * * *
                            </P>
                            <P>(2) * * *</P>
                            <P>(ii) * * *</P>
                            <P>(C) If the participating jurisdiction (or State recipient or subrecipient) is providing HOME funds to a family to acquire single family housing for homeownership that does not meet the participating jurisdiction's property standards, as described in § 92.251(c)(3), then the commitment must meet the requirements of this paragraph (2)(ii)(C). The participating jurisdiction (or State recipient or subrecipient) and the family must have executed a written agreement under which HOME assistance will be provided for the purchase of the single family housing. The written agreement will require the property to meet the standards in accordance with § 92.251(c)(3) and will require the property title to be transferred to the family within six months of the agreement date.</P>
                            <STARS/>
                            <P>
                                <E T="03">Community housing development organization</E>
                                 * * *
                            </P>
                            <P>(4) Is tax exempt as follows:</P>
                            <P>(i) The private nonprofit organization has a tax exemption ruling from the Internal Revenue Service under section 501(c)(3) or (4) of the Internal Revenue Code of 1986 (26 CFR 1.501(c)(3)-1 or 1.501(c)(4)-1));</P>
                            <P>(ii) The private nonprofit organization is a subordinate organization that has been included in its 501(c)(3) or (4) central organization's group exemption letter by the Internal Revenue Service; or</P>
                            <P>(iii) The private nonprofit organization is wholly owned by the community housing development organization, as defined in this part, and is disregarded as an entity separate from its owner organization for Federal tax purposes.</P>
                            <P>(5) Is not a governmental entity (including the participating jurisdiction, other jurisdiction, Indian Tribe, public housing authority, Indian housing authority, housing finance agency, or redevelopment authority) and is not controlled by a governmental entity. An organization that is created by a governmental entity may qualify as a community housing development organization; however, no more than one-third of the board members of the organization may be officials or employees of the participating jurisdiction or governmental entity that created the community housing development organization. Further, no governmental entity may have the right to appoint more than one-third of the organization's board members. The board members appointed by a governmental entity and the board members that are officials or employees of the participating jurisdiction or governmental entity that created the organization may not appoint any of the remaining two-thirds of the board members. The officers or employees of a governmental entity may not be officers or employees of a community housing development organization;</P>
                            <STARS/>
                            <P>(8) * * *</P>
                            <P>(i) Maintaining at least one-third of its governing board's membership for residents of low-income neighborhoods, low-income beneficiaries of HUD programs, other low-income community residents, designees of low-income neighborhood organizations, or designees of nonprofit organizations in the community that address the housing or supportive service needs of low-income residents or residents of low-income neighborhoods, including homeless providers, Fair Housing Initiatives Program providers, Legal Aid, disability rights organizations, and victim service providers. For urban areas, “community” may be a neighborhood or neighborhoods, city, county, or metropolitan area; for rural areas, it may be a neighborhood or neighborhoods, town, village, county, or multi-county area (but not the entire State); and</P>
                            <STARS/>
                            <P>(9) Has a demonstrated capacity for carrying out housing projects assisted with Federal funds, Low-Income Housing Credits (26 U.S.C. 42), Federal Home Loan Bank Affordable Housing Program (12 U.S.C. 1430) funds, or local and State affordable housing funds.</P>
                            <P>(i) To satisfy this requirement and demonstrate capacity as a developer of a HOME-assisted project, the nonprofit organization must have paid employees with housing development experience who will work directly on the HOME-assisted project. Where the paid employees of the organization do not demonstrate capacity to develop a HOME-assisted project alone, the experience of paid employees may be supplemented by board members or officers of the organization that are volunteers. If a nonprofit organization is demonstrating capacity using a volunteer board member's or officer's experience, the volunteer may not be compensated by or have their services donated by another organization. For its first year of funding as a community housing development organization, an organization may satisfy this requirement through a contract with a consultant who has housing development experience to train appropriate key, paid staff of the organization;</P>
                            <P>(ii) An organization that will own housing must demonstrate capacity to act as owner of a project and meet the requirements of § 92.300(a)(2);</P>
                            <P>(iii) An organization that will sponsor housing must demonstrate capacity as a developer or capacity to act as owner, as described in paragraphs (9)(i) and (ii) of this definition; and</P>
                            <STARS/>
                            <P>
                                <E T="03">Community land trust</E>
                                 means a nonprofit organization that:
                            </P>
                            <P>(1) Has as its primary purposes acquiring, developing, or holding land to provide housing that is permanently affordable to low-income persons;</P>
                            <P>(2) Is not sponsored or controlled by a for-profit organization;</P>
                            <P>(3) Uses a lease, covenant, agreement, or other enforceable mechanisms to require housing and related improvements on land held by the community land trust to be affordable to low-income persons for at least 30 years; and</P>
                            <P>(4) Retains a right of first refusal or preemptive right to purchase the housing and related improvements on land held by the community land trust to maintain long-term affordability.</P>
                            <STARS/>
                            <P>
                                <E T="03">Homeownership</E>
                                 means ownership in fee simple title in single family housing or an equivalent form of ownership approved by HUD.
                            </P>
                            <P>(1) The land upon which the housing is located may be owned in fee simple or the homeowner may have a ground lease for the lowest of the following time periods, as applicable:</P>
                            <P>(i) For housing, the ground lease must be for 99 years or more;</P>
                            <P>(ii) For housing located in an insular area, the ground lease must be 40 years or more;</P>
                            <P>
                                (iii) For housing located on Indian trust or restricted Indian lands or a 
                                <PRTPAGE P="865"/>
                                Community Land Trust, the ground lease must be 50 years or more; or
                            </P>
                            <P>(iv) For manufactured housing, the ground lease must be for a period at least equal to the applicable period of affordability in § 92.254.</P>
                            <STARS/>
                            <P>
                                <E T="03">Period of affordability</E>
                                 means the period of time, as specified in §§ 92.252 and 92.254, that requirements under this part apply to HOME-assisted housing.
                            </P>
                            <STARS/>
                            <P>
                                <E T="03">Program income</E>
                                 means gross income received by the participating jurisdiction, State recipient, or a subrecipient at any time, generated from the use of HOME funds or matching contributions. When program income is generated by housing that is only partially assisted with HOME funds or matching funds, the program income shall be the amount prorated to reflect the percentage of HOME funds invested in the project. Program income includes, but is not limited to, the following:
                            </P>
                            <STARS/>
                            <P>
                                (2) Gross income from the use or rental of real property, owned by the participating jurisdiction or State recipient that was acquired, rehabilitated, or constructed, with HOME funds or matching contributions, less costs incidental to generation of the income. 
                                <E T="03">Program income</E>
                                 does not include gross income from the use, rental, or sale of real property received by the project owner or developer, unless all or a portion of the income must be paid to the participating jurisdiction, subrecipient, or State recipient, in which case, the amount that must be paid to the participating jurisdiction, subrecipient, or State recipient is program income;
                            </P>
                            <P>
                                (3) Payments and repayments on grants, loans (
                                <E T="03">i.e.,</E>
                                 principal and interest), or investments made using HOME funds or matching contributions, including such payments and repayments made after the period of affordability;
                            </P>
                            <STARS/>
                            <P>
                                <E T="03">Reconstruction</E>
                                 * * * Reconstruction is rehabilitation for purposes of this part, except that the property standards for new construction in § 92.251(a) apply to all reconstruction projects.
                            </P>
                            <STARS/>
                            <P>
                                <E T="03">Small-scale housing</E>
                                 means a rental housing project of no more than four units or a homeownership project with no more than three rental units on the same site.
                            </P>
                            <STARS/>
                            <P>
                                <E T="03">State recipient</E>
                                 means a unit of general local government designated by a State participating jurisdiction to receive HOME funds to administer all or some of the State participating jurisdiction's HOME programs, own or develop affordable housing, provide homeownership assistance, or provide tenant-based rental assistance.
                            </P>
                            <STARS/>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>6. Revise § 92.3 to read as follows:</AMDPAR>
                        <SECTION>
                            <SECTNO>§ 92.3 </SECTNO>
                            <SUBJECT>Applicability of 2025 regulatory changes.</SUBJECT>
                            <P>This part applies to projects based on when an income determination is made or when the HOME funds for the project were committed, as applicable. Projects where the HOME funds were committed before a certain date may be subject to previous versions of this part. This section provides instruction regarding which version of this part applies.</P>
                            <P>
                                (a) 
                                <E T="03">Effective date of this part as it exists on February 5, 2025.</E>
                                 Except as described in this section, this part, as it exists on February 5, 2025 is applicable to projects for which HOME funds are committed on or after February 5, 2025. A participating jurisdiction must perform income determinations in accordance with § 92.203 after February 5, 2025.
                            </P>
                            <P>
                                (b) 
                                <E T="03">One year compliance period.</E>
                                 Participating jurisdictions are permitted to choose to continue to comply with the requirements of this part as they existed on February 4, 2025 for commitments made on or before February 5, 2026.
                            </P>
                            <P>
                                (c) 
                                <E T="03">Delayed compliance date for income determinations.</E>
                                 Participating jurisdictions are permitted to continue to comply with the income determination requirements in accordance with § 92.203 that the participating jurisdiction was implementing on February 4, 2025 until February 5, 2026, or longer as determined by HUD.
                            </P>
                            <P>
                                (d) 
                                <E T="03">Applicability of this part as it exists on February 5, 2025</E>
                                  
                                <E T="03">to prior agreement</E>
                                s. A participating jurisdiction may choose to amend its written agreements for funds committed prior to February 5, 2025 to conform to the requirements of this part, except that:
                            </P>
                            <P>
                                (1)
                                <E T="03"> Certain cost</E>
                                s allowed to be reimbursable under 
                                <E T="03">§ 92.206(d)(1) and (2), as effective February 5, 2025</E>
                                 may only be included in written agreements for projects if the participating jurisdiction committed the HOME funds for the project on or after February 5, 2025.
                            </P>
                            <P>(2) Requesting an increase in maximum per-unit subsidy in accordance with § 92.250(c) is only permitted for projects if the participating jurisdiction committed the HOME funds for the project on or after February 5, 2025.</P>
                            <P>(3) Use of the revised dollar thresholds for the periods of affordability in §§ 92.252 and 92.254 is only permitted for projects if the participating jurisdiction committed the HOME funds for the project on or after February 5, 2025.</P>
                            <P>(4) Tenant protections provided in § 92.253, including the tenancy addenda requirements in § 92.253(b) through (d), apply for rental housing projects if the participating jurisdiction committed the HOME funds for the project, entered into the rental assistance contract, or entered into an agreement to provide security deposit assistance on or after February 5, 2025.</P>
                            <P>(5) The revisions to the roles of community housing development organizations in owning, developing, and sponsoring affordable housing in § 92.300 only apply if the participating jurisdiction committed the community housing development organization set-aside funds for the project on or after February 5, 2025.</P>
                            <P>(e) The following table summarizes the information provided in this section:</P>
                            <GPOTABLE COLS="2" OPTS="L2,nj,i1" CDEF="s100,r100">
                                <TTITLE>
                                    Table 1 to Paragraph (
                                    <E T="01">e</E>
                                    )—Summary of Effective Dates and Compliance Deadlines
                                </TTITLE>
                                <BOXHD>
                                    <CHED H="1">2025 Rule effective date</CHED>
                                    <CHED H="1">February 5, 2025</CHED>
                                </BOXHD>
                                <ROW>
                                    <ENT I="01">Applicability</ENT>
                                    <ENT>Rule applies to projects for which HOME funds are committed on or after February 5, 2025.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Compliance Date</ENT>
                                    <ENT>Participating jurisdictions must set compliance date: as early as February 5, 2025, and no later than February 5, 2026.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Exceptions for Income Determinations</ENT>
                                    <ENT>Participating jurisdictions must set compliance date: as early as February 5, 2025, and no later than February 5, 2026.</ENT>
                                </ROW>
                                <ROW>
                                    <PRTPAGE P="866"/>
                                    <ENT I="22"> </ENT>
                                    <ENT>Participating jurisdictions may continue to calculate income in accordance with the provisions that were being implemented by the participating jurisdiction on February 4, 2025 until compliance date set by the participating jurisdiction, or longer as determined by HUD.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Applicability Limitations</ENT>
                                    <ENT>Listed provisions are not applicable to commitments made to projects prior to February 5, 2025. Participating jurisdictions may not amend written agreements of projects with commitments existing prior to February 5, 2025 to incorporate any of the following provisions:</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT O="oi3">§ 92.206(d)(1) and (2).</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT O="oi3">§ 92.250(c).</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT O="oi3">§§ 92.252 and 92.254.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT O="oi3">§ 92.253.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT O="oi3">§ 92.300.</ENT>
                                </ROW>
                            </GPOTABLE>
                        </SECTION>
                    </REGTEXT>
                    <SECTION>
                        <SECTNO>§ 92.50</SECTNO>
                        <SUBJECT>[Amended] </SUBJECT>
                    </SECTION>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>7. Amend § 92.50 in paragraph (c)(3) by removing the words “poor households” and adding in their place the words “households below the poverty line”. </AMDPAR>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>8. Amend § 92.101 by revising paragraphs (a) introductory text and (d) and adding paragraph (g) to read as follows:</AMDPAR>
                        <SECTION>
                            <SECTNO>§ 92.101</SECTNO>
                            <SUBJECT>Consortia.</SUBJECT>
                            <P>(a) A consortium of geographically contiguous units of general local government is a unit of general local government for purposes of this part if the requirements of this section are met. A unit of general local government separated by a body of water that is only accessible by the public through a permanent means other than a connecting road, bridge, railway, or highway may be considered geographically contiguous if the consortium demonstrates that the unit of general local government separated by the body of water is part of the same housing market and local commuting area as one or more members of the consortium. A local commuting area is the geographic area that encompasses neighborhoods where people live and are reasonably expected to routinely travel back and forth to a common employment hub, population center, or worksite.</P>
                            <STARS/>
                            <P>(d) If the representative unit of general local government distributes HOME funds to member units of general local government, the representative unit is responsible for applying to the member units of general local government the same requirements as are applicable to subrecipients, including the written agreement requirements in § 92.504(c)(2).</P>
                            <STARS/>
                            <P>(g) If a consortium changes its representative unit of general local government but retains the same membership, the consortium shall still be considered the same unit of general local government for purposes of this part. If the representative unit of general local government changes and the composition of the consortium changes, either by adding or removing individual members, then the consortium shall be a new unit of general local government for purposes of this part and shall be required to comply with all applicable consolidated plan requirements in 24 CFR part 91.</P>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>9. Amend § 92.201 by:</AMDPAR>
                        <AMDPAR>a. Adding a sentence to the end of paragraph (a)(2);</AMDPAR>
                        <AMDPAR>b. Removing the last sentence of paragraph (b)(2); and</AMDPAR>
                        <AMDPAR>c. Removing the word “ensure” and adding in its place the word “require” in paragraph (b)(3)(i).</AMDPAR>
                        <P>The addition reads as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.201</SECTNO>
                            <SUBJECT>Distribution of assistance.</SUBJECT>
                            <P>(a) * * *</P>
                            <P>(2) * * * A participating jurisdiction may not commit HOME funds to a project outside its jurisdiction and within the boundaries of a contiguous local jurisdiction until it has secured the financial contribution of the jurisdiction in which the project is located.</P>
                            <STARS/>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>10. Amend § 92.203 by:</AMDPAR>
                        <AMDPAR>a. Revising the section heading and paragraph (a) introductory text;</AMDPAR>
                        <AMDPAR>b. Removing the words “must accept” and adding in their place the words “may accept” in paragraph (a)(1);</AMDPAR>
                        <AMDPAR>c. Redesignating paragraph (a)(3) as paragraph (a)(4);</AMDPAR>
                        <AMDPAR>d. Adding a new paragraph (a)(3);</AMDPAR>
                        <AMDPAR>e. Revising the paragraph (b) heading;</AMDPAR>
                        <AMDPAR>f. Removing the word “any”, adding the word “two” after the phrase “one of the following”, and removing “§ 92.252(h)” and adding in its place “§ 92.252(g)” in paragraph (b)(1) introductory text;</AMDPAR>
                        <AMDPAR>g. Revising paragraph (b)(1)(ii);</AMDPAR>
                        <AMDPAR>h Removing paragraph (b)(1)(iii);</AMDPAR>
                        <AMDPAR>i. Revising paragraph (b)(2);</AMDPAR>
                        <AMDPAR>j. Adding paragraph (b)(3);</AMDPAR>
                        <AMDPAR>k. Revising the paragraph (c) heading;</AMDPAR>
                        <AMDPAR>l. Removing “§§ 5.609(a) and (b) of this title” and adding in its place “24 CFR 5.609(a) and (b)” in paragraph (c)(1);</AMDPAR>
                        <AMDPAR>m. Revising paragraph (d);</AMDPAR>
                        <AMDPAR>n. In paragraph (e)(1), removing “§ 5.618 of this title” wherever it appears and adding in its place “24 CFR 5.618” and removing “§ 5.609(a)(2) of this title” and adding in its place “24 CFR 5.609(a)(2)”;</AMDPAR>
                        <AMDPAR>o. Revising paragraph (e)(2);</AMDPAR>
                        <AMDPAR>p. Removing “§ 5.617 of this title” and adding in its place “24 CFR 5.617” in paragraph (e)(3);</AMDPAR>
                        <AMDPAR>q. In paragraph (f)(1)(i), removing “§ 5.611(a) of this title” and adding in its place “24 CFR 5.611(a)” and removing “§§ 5.611(c) through (e) of this title” and adding in its place “24 CFR 5.611(c) through (e)”;</AMDPAR>
                        <AMDPAR>r. In paragraph (f)(1)(ii), removing “§ 92.252(b)(2)(i)” wherever it appears and adding in its place “§ 92.252(a)(2)(ii)”, removing “§ 5.611(a) of this title” and adding in its place “24 CFR 5.611(a)”, and removing “§§ 5.611(c) through (e) of this title” and adding in its place “24 CFR 5.611(c) through (e)”;</AMDPAR>
                        <AMDPAR>s. In paragraph (f)(1)(iii), removing “§ 92.252(i)(2)” and adding in its place “§ 92.252(h)(2)” and removing “§ 5.611(a) of this title” and adding in its place “24 CFR 5.611(a)”; and</AMDPAR>
                        <AMDPAR>t. Revising paragraph (f)(2).</AMDPAR>
                        <P>The revisions and additions read as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.203</SECTNO>
                            <SUBJECT>Income determinations.</SUBJECT>
                            <P>
                                (a) 
                                <E T="03">Income eligibility.</E>
                                 To determine a family is income eligible, the participating jurisdiction must determine the family's income as follows:
                            </P>
                            <STARS/>
                            <PRTPAGE P="867"/>
                            <P>
                                (3) If a family is applying, renewing, or entering into a new rental assistance contract for tenant-based rental assistance pursuant to § 92.209, or applying for or living in a HOME-assisted rental unit in accordance with § 92.252, and the family is assisted by a form of Federal, State, or local public assistance (
                                <E T="03">e.g.,</E>
                                 TANF, Medicaid, LIHTC, local rental subsidy programs, etc.) which examines the annual income of the family each year, then a participating jurisdiction may accept a written statement from a Federal or non-Federal entity administering the assistance. The statement must indicate the tenant's family size and state the amount of the family's annual income. When accepting the statement from a government administrator, the participating jurisdiction must still adjust income in accordance with paragraph (f) of this section. The statement must be for an income determination made within the previous 12-month period.
                            </P>
                            <STARS/>
                            <P>
                                (b) 
                                <E T="03">Determining and documenting annual income.</E>
                            </P>
                            <P>(1) * * *</P>
                            <P>(ii) Obtain from the family a written statement or, where needed due to disability, a statement in another format, of the amount of the family's annual income and family size, along with a certification that the information is complete and accurate. The certification must state that the family will provide source documents upon request. If there is evidence that a tenant's statement and certification provided in accordance with this paragraph (b)(1)(ii) failed to completely and accurately state information about the family's size or income, a tenant's income must be re-examined in accordance with paragraph (b)(1)(i) of this section.</P>
                            <P>
                                (2) For families applying for HOME homeownership activities (
                                <E T="03">i.e.,</E>
                                 homeowners receiving rehabilitation assistance, homebuyers), the participating jurisdiction must determine annual income by examining at least 2 months of source documents evidencing annual income (
                                <E T="03">e.g.,</E>
                                 wage statement, interest statement, unemployment compensation statement) for the family.
                            </P>
                            <P>(3) For families applying for or receiving tenant-based rental assistance, the participating jurisdiction may determine annual income for the family in accordance with either paragraph (a)(3) or (b)(1)(i) of this section, as applicable. Income must be calculated at the times described in § 92.209(e)(3).</P>
                            <P>
                                (c) 
                                <E T="03">Definitions of “annual income.”</E>
                                 * * *
                            </P>
                            <STARS/>
                            <P>
                                (d) 
                                <E T="03">Use of income definitions.</E>
                                 A participating jurisdiction may use either of the definitions of “annual income” in paragraph (c) of this section, however, the participating jurisdiction may use only one definition of “annual income” for each HOME-assisted program (
                                <E T="03">e.g.,</E>
                                 homeownership assistance program) that it administers and only one definition for each rental housing project. For rental housing projects containing units assisted by a Federal or State project-based rental subsidy program or tenants receiving Federal tenant-based rental assistance, where a participating jurisdiction is accepting a public housing agency, owner, or rental assistance provider's determination of annual and adjusted income, the participating jurisdiction must calculate annual income in accordance with paragraph (c)(1) of this section so that only one definition of annual income is used in the rental housing project.
                            </P>
                            <P>(e) * * *</P>
                            <P>
                                (2) The participating jurisdiction is not required to redetermine the family's income eligibility at the time the HOME assistance (
                                <E T="03">i.e.,</E>
                                 homeownership assistance and tenant-based rental assistance) is provided, unless more than six months has elapsed since the participating jurisdiction determined that the family is income eligible.
                            </P>
                            <STARS/>
                            <P>(f) * * *</P>
                            <P>(2) If a unit is assisted by a Federal or State project-based rental subsidy program, then a participating jurisdiction may accept the public housing agency, owner, or rental subsidy provider's determination of the family's adjusted income under that program's rules.</P>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>11. Amend § 92.205 by:</AMDPAR>
                        <AMDPAR>a. Revising paragraph (a)(2);</AMDPAR>
                        <AMDPAR>b. Removing the last sentence of paragraph (b)(1);</AMDPAR>
                        <AMDPAR>c. Adding paragraph (b)(3); and</AMDPAR>
                        <AMDPAR>d. Revising the first sentence of paragraph (e)(2).</AMDPAR>
                        <P>The revisions and addition read as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.205</SECTNO>
                            <SUBJECT>Eligible activities: General.</SUBJECT>
                            <P>(a) * * *</P>
                            <P>(2) Acquisition of vacant land or demolition may only be undertaken for a project that will provide affordable housing and meets the requirements for a specific local project in paragraph (2)(i) of the definition of “commitment” in § 92.2.</P>
                            <STARS/>
                            <P>(b) * * *</P>
                            <P>(3) The participating jurisdiction must establish the terms of assistance, subject to the requirements of this part.</P>
                            <STARS/>
                            <P>(e) * * *</P>
                            <P>(2) If project completion, as defined in § 92.2, does not occur within 4 years of the date of commitment of funds for a specific local project, the project is considered to be terminated, and the participating jurisdiction must repay all funds invested in the project to the participating jurisdiction's HOME Investment Trust Fund in accordance with § 92.503(b). * * *</P>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>12. Amend § 92.206 by:</AMDPAR>
                        <AMDPAR>a. Removing “§ 92.251” and adding in its place “§ 92.251(a)” in paragraph (a)(1);</AMDPAR>
                        <AMDPAR>b. Removing “§ 92.251” and adding in its place “§ 92.251(b)” in paragraph (a)(2);</AMDPAR>
                        <AMDPAR>c. Removing the word “single-family” and adding in its place the words “single family” in paragraph (b)(1);</AMDPAR>
                        <AMDPAR>d. Removing the words “affordability period” and adding in their place the words “period of affordability” in paragraph (b)(2) introductory text;</AMDPAR>
                        <AMDPAR>e. Revising paragraphs (b)(2)(ii), (c), and (d)(1), (2), and (8).</AMDPAR>
                        <P>The revisions read as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.206</SECTNO>
                            <SUBJECT>Eligible project costs.</SUBJECT>
                            <STARS/>
                            <P>(b) * * *</P>
                            <P>(2) * * *</P>
                            <P>(ii) Require a review of management practices to demonstrate that disinvestment in the property has not occurred, that the long-term needs of the project can be met, and that the feasibility of serving the targeted population over the minimum period of affordability of 15 years can be demonstrated;</P>
                            <STARS/>
                            <P>
                                (c) 
                                <E T="03">Acquisition costs.</E>
                                 Costs of acquiring improved or unimproved real property and costs for a long-term ground lease, including costs of acquisition by homebuyers.
                            </P>
                            <P>(d) * * *</P>
                            <P>
                                (1) Architectural, engineering, or related professional services required to prepare plans, drawings, specifications, work write-ups; for HUD environmental reviews or other environmental studies, assessments, or fees; and for certain costs to process and settle the financing for a project, such as private lender origination fees, credit reports, fees for title evidence, legal fees, accounting fees, filing fees for zoning or planning review and approval, private appraisal fees, fees for independent cost estimates, and other lender required third-party reporting fees. The costs may 
                                <PRTPAGE P="868"/>
                                be paid if they were incurred not more than 24 months before the date that HOME funds are committed to the project and the participating jurisdiction expressly permits HOME funds to be used to pay the costs in the written agreement committing the funds.
                            </P>
                            <P>(2) Fees for recordation and filing of legal documents, building permits, and builders or developers fees.</P>
                            <STARS/>
                            <P>(8) Cost of property insurance during development.</P>
                            <STARS/>
                        </SECTION>
                    </REGTEXT>
                    <SECTION>
                        <SECTNO>§ 92.207</SECTNO>
                        <SUBJECT>[Amended]</SUBJECT>
                    </SECTION>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>13. Amend § 92.207 in paragraph (e) by removing the words “under a cost allocation plan prepared”.</AMDPAR>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>14. Amend § 92.208 by adding paragraph (c) to read as follows:</AMDPAR>
                        <SECTION>
                            <SECTNO>§ 92.208</SECTNO>
                            <SUBJECT>Eligible community housing development organization (CHDO) operating expense and capacity building costs.</SUBJECT>
                            <STARS/>
                            <P>(c) An organization that meets the definition of “community housing development organization” in § 92.2, except for the requirements in paragraph (9) of the definition, may receive HOME funds for operating expenses in accordance with paragraph (a) of this section in order to develop demonstrated capacity and qualify as a community housing development organization.</P>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>15. Amend § 92.209 by:</AMDPAR>
                        <AMDPAR>a. Removing the last sentence of paragraph (c)(1);</AMDPAR>
                        <AMDPAR>b. Revising paragraphs (c)(2)(iv), (c)(3), (e), (g), (h)(2), (h)(3)(ii), and (i);</AMDPAR>
                        <AMDPAR>c. Removing the word “dwelling” and adding, in its place, the word “housing” in paragraph (j)(1);</AMDPAR>
                        <AMDPAR>d. Revising paragraph (j)(5);</AMDPAR>
                        <AMDPAR>e. Adding paragraph (j)(6);</AMDPAR>
                        <AMDPAR>f. Revising paragraph (k); and</AMDPAR>
                        <AMDPAR>g. Removing paragraph (l).</AMDPAR>
                        <P>The revisions and addition read as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.209</SECTNO>
                            <SUBJECT>Tenant-based rental assistance: Eligible costs and requirements.</SUBJECT>
                            <STARS/>
                            <P>(c) * * *</P>
                            <P>(2) * * *</P>
                            <P>
                                (iv) 
                                <E T="03">Homebuyer program.</E>
                                 HOME tenant-based rental assistance may assist a tenant who has been identified as a potential low-income homebuyer through a lease-purchase agreement, with monthly rental assistance payments for a period up to 36 months (
                                <E T="03">i.e.,</E>
                                 24 months, with a 12-month renewal in accordance with paragraph (e) of this section). The HOME tenant-based rental assistance payment may not be used to accumulate a downpayment or closing costs for the purchase; however, all or a portion of the homebuyer-tenant's monthly contribution toward rent may be set aside for this purpose, in accordance with the lease-purchase agreement. If a participating jurisdiction determines that the tenant has met the lease-purchase criteria and is ready to assume ownership, HOME funds may be provided for homeownership assistance in accordance with the requirements of this part.
                            </P>
                            <STARS/>
                            <P>
                                (3) 
                                <E T="03">Existing tenants in projects that will receive HOME assistance.</E>
                                 A participating jurisdiction may select low-income families currently residing in housing units that will be rehabilitated or acquired with HOME funds under the participating jurisdiction's HOME program. Participating jurisdictions using HOME funds for tenant-based rental assistance programs may establish local preferences for the provision of this assistance. Families so selected may use the tenant-based rental assistance in the rehabilitated or acquired housing unit or in other qualified housing.
                            </P>
                            <STARS/>
                            <P>
                                (e) 
                                <E T="03">Rental assistance contract</E>
                                —(1) 
                                <E T="03">Parties to the rental assistance contract.</E>
                                 A participating jurisdiction must enter into a rental assistance contract with the owner and the family. A participating jurisdiction may have one agreement with the owner and a separate agreement with the family, or one tri-party agreement with the participating jurisdiction, the owner, and the family.
                            </P>
                            <P>
                                (2) 
                                <E T="03">Term of the rental assistance contract.</E>
                                 The term of the rental assistance contract providing assistance with HOME funds may not exceed 24 months, but the rental assistance contract may be amended or renewed, subject to the availability of HOME funds. The term of the rental assistance contract must begin on the first day of the term of the lease or the beginning of the first month in which tenant-based rental assistance is provided.
                            </P>
                            <P>
                                (3) 
                                <E T="03">Amending or renewing a rental assistance contract.</E>
                                 (i) A rental assistance contract within its term may only be amended through the consent of all parties. A rental assistance contract may be amended:
                            </P>
                            <P>(A) Because the lease between the family and owner has been amended or renewed, if the lease term or amount charged under the lease are the only terms of the contract being changed.</P>
                            <P>(B) To extend its term up to 24 months from the original date of execution.</P>
                            <P>(C) When a tenant changes units within the same building or development if the parties to the lease, the family size, and the number of bedrooms in the housing remain the same.</P>
                            <P>(ii) Subject to the availability of HOME funds, a rental assistance contract may be renewed after the expiration of its initial term.</P>
                            <P>(iii) In all other instances, the participating jurisdiction must enter into a new rental assistance contract with the family and the owner in accordance with this paragraph (e).</P>
                            <P>
                                (4) 
                                <E T="03">Initial and subsequent income determinations.</E>
                                 (i) Before the participating jurisdiction enters into an initial or new rental assistance contract with the family, the participating jurisdiction must determine that the family is income eligible in accordance with § 92.203.
                            </P>
                            <P>(ii) When a rental assistance contract is amended, the participating jurisdiction will not be required to perform a new income examination in accordance with § 92.203.</P>
                            <P>(iii) Before a rental assistance contract is renewed, the participating jurisdiction must determine that the family is income eligible in accordance with § 92.203.</P>
                            <P>(iv) If a family is participating in a HOME lease-purchase program and receiving tenant-based rental assistance, then the participating jurisdiction is only required to determine the family's income at the time that the family enters into the lease-purchase agreement and does not need to engage in further income examination during the term of the lease-purchase agreement.</P>
                            <STARS/>
                            <P>
                                (g) 
                                <E T="03">Tenant protections.</E>
                                 The tenant must have a lease that complies with the requirements in § 92.253. Upon termination of the rental assistance contract, the HOME tenant-based rental assistance tenancy addendum shall automatically terminate.
                            </P>
                            <P>(h) * * *</P>
                            <P>(2) The participating jurisdiction must establish a minimum tenant contribution to rent, except that the participating jurisdiction may establish conditions in its written policies under which a tenant would be relieved of all or a portion of the minimum contribution due to financial hardship.</P>
                            <P>(3) * * *</P>
                            <P>(ii) The Section 8 Housing Choice Voucher Program payment standard as determined in accordance with 24 CFR 982.503(a) through (c).</P>
                            <P>
                                (i) 
                                <E T="03">Housing standards.</E>
                                 The participating jurisdiction must require the housing occupied by a family 
                                <PRTPAGE P="869"/>
                                receiving tenant-based rental assistance under this section to meet the participating jurisdiction's property standards under § 92.251. Initially and annually thereafter, the participating jurisdiction must determine the housing complies with its property standards and is decent, safe, sanitary, and in good repair in accordance with § 92.251(f).
                            </P>
                            <P>(j) * * *</P>
                            <P>(5) Paragraphs (b), (c), (d), (f), (g), and (i) of this section are applicable when HOME funds are provided for security deposit assistance, except that income determinations pursuant to paragraph (c)(1) of this section and inspections pursuant to paragraph (i) of this section are required only at the time the security deposit assistance is provided.</P>
                            <P>(6) Surety bonds, security deposit insurance, or instruments similar to surety bonds or security deposit insurance may not be used in lieu of or in addition to a security deposit in units occupied by tenants receiving tenant-based rental assistance.</P>
                            <P>
                                (k) 
                                <E T="03">Program operation.</E>
                                 A tenant-based rental assistance program must be operated consistent with the requirements of this section. The participating jurisdiction may operate the program itself or may contract with a PHA or other entity with the capacity to operate a rental assistance program. The tenant-based rental assistance may be provided through a rental assistance contract in accordance with paragraph (e) of this section. The participating jurisdiction (or entity operating the program) must approve the lease.
                            </P>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>16. Revise § 92.210 to read as follows:</AMDPAR>
                        <SECTION>
                            <SECTNO>§ 92.210 </SECTNO>
                            <SUBJECT>Troubled HOME-assisted rental housing projects.</SUBJECT>
                            <P>(a) The provisions of this section apply only to an existing HOME-assisted rental project that, within the HOME period of affordability, is no longer financially viable or its physical viability has substantively deteriorated due to unforeseen circumstances.</P>
                            <P>(1) For purposes of this section, a HOME-assisted rental project is no longer financially viable through the period of affordability if:</P>
                            <P>(i) The project's operating costs exceed its operating revenue, considering project reserves;</P>
                            <P>(ii) The owner is unable to pay for necessary capital repair costs or ongoing expenses for the project; or</P>
                            <P>(iii) The project reserves are insufficient to be able to operate the project.</P>
                            <P>(2) For purposes of this section, physical viability means a project's current or future ability to maintain affordability based on the physical characteristics and factors of the project's site and improvements.</P>
                            <P>(3) HUD may approve the actions described in paragraphs (b) and (c) of this section to strategically preserve the affordability of a rental project after consideration of market needs, available resources, and the likelihood of the long-term physical and financial viability of the project.</P>
                            <P>(b) Notwithstanding § 92.214, a participating jurisdiction may request and HUD may permit, pursuant to a written memorandum of agreement, a participating jurisdiction to invest additional HOME funds in the existing HOME-assisted rental project. The total HOME funding for the project (original investment plus additional investment) must be necessary to improve the physical and financial viability of the project and may not exceed the per-unit subsidy limit in § 92.250(a) in effect at the time of the additional investment. The use of HOME funds may include, but is not limited to, rehabilitation of the HOME units and recapitalization of project reserves for the HOME units (to fund capital costs). If additional HOME funds are invested, HUD may impose additional conditions, including requiring the participating jurisdiction to extend the period of affordability, increase the number of HOME-assisted units, and change the number or designation of Low HOME rent and High HOME rent units.</P>
                            <P>(c) HUD may, through written approval, permit the participating jurisdiction to reduce the total number of HOME-assisted units or change the designation of units from Low HOME rent units to High HOME rent units where there are more than the minimum number of Low HOME rent units in the project. In determining whether to permit a reduction in the number of HOME-assisted units, HUD will take into account the required period of affordability and the amount of HOME assistance provided to the project.</P>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>17. Amend § 92.212 by:</AMDPAR>
                        <AMDPAR>a. Removing “may incur costs” and adding in its place “may incur costs described in this section” in paragraph (a); and</AMDPAR>
                        <AMDPAR>b. Revising paragraph (b).</AMDPAR>
                        <P>The revision reads as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.212 </SECTNO>
                            <SUBJECT>Pre-award costs.</SUBJECT>
                            <STARS/>
                            <P>
                                (b) 
                                <E T="03">Administrative and planning costs.</E>
                                 (1) Eligible administrative and planning costs may be incurred as of the beginning of the participating jurisdiction's consolidated program year (see 24 CFR 91.10) or the date HUD receives the consolidated plan describing the HOME allocation to which the costs will be charged, whichever is later.
                            </P>
                            <P>(2) In any year in which an appropriation has not been enacted 90 days before a participating jurisdiction's program year start date, a participating jurisdiction may incur eligible administrative and planning costs as of the beginning of its program year or the date that HUD receives its consolidated plan describing the HOME allocation to which the costs will be charged, whichever is earlier.</P>
                            <STARS/>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>18. Amend § 92.214 by revising paragraphs (a)(6) through (9), adding paragraph (a)(10), revising paragraph (b)(3), and adding paragraph (b)(4) to read as follows.</AMDPAR>
                        <SECTION>
                            <SECTNO>§ 92.214 </SECTNO>
                            <SUBJECT>Prohibited activities and fees.</SUBJECT>
                            <P>(a) * * *</P>
                            <P>(6) Provide assistance (other than tenant-based rental assistance, assistance to a homebuyer to acquire housing previously assisted with HOME funds, assistance permitted under § 92.210, or assistance to preserve affordability of homeownership housing in accordance with § 92.254(b)) to a project previously assisted with HOME funds during the period of affordability. However, additional HOME funds may be committed to a project for up to one year after project completion (see § 92.502), but the amount of HOME funds in the project may not exceed the maximum per-unit subsidy amount established under § 92.250 at the time of underwriting;</P>
                            <P>(7) Pay for the acquisition of property owned by the participating jurisdiction, unless such property is acquired by the participating jurisdiction in anticipation of carrying out a HOME project;</P>
                            <P>(8) Pay delinquent taxes, fees, or charges on properties to be assisted with HOME funds;</P>
                            <P>(9) Pay for any cost that is not eligible under §§ 92.206 through 92.209; or</P>
                            <P>(10) Pay for surety bonds, security deposit insurance, or instruments similar to surety bonds or security deposit insurance, in lieu of or in addition to a security deposit in units occupied by tenants receiving tenant-based rental assistance (including assistance in paying security deposits).</P>
                            <P>(b) * * *</P>
                            <P>(3) The participating jurisdiction must prohibit project owners from charging for:</P>
                            <P>
                                (i) Surety bonds, security deposit insurance, or instruments similar to surety bonds or security deposit insurance, in lieu of or in addition to a security deposit in units;
                                <PRTPAGE P="870"/>
                            </P>
                            <P>
                                (ii) Fees that are not customarily charged in rental housing (
                                <E T="03">e.g.,</E>
                                 laundry room access fees); and
                            </P>
                            <P>(iii) Fees to inspect units or correct deficiencies in the property condition of units or common areas of the project that were not caused by the tenant or are only due to normal wear and tear.</P>
                            <P>(4) Rental project owners may charge:</P>
                            <P>(i) Reasonable application fees to prospective tenants;</P>
                            <P>(ii) Parking fees to tenants only if such fees are customary for rental housing projects in the neighborhood; and</P>
                            <P>(iii) Fees for services such as bus transportation or meals, as long as the services are voluntary and fees are charged for services provided. </P>
                        </SECTION>
                    </REGTEXT>
                    <SECTION>
                        <SECTNO>§ 92.216</SECTNO>
                        <SUBJECT>[Amended]</SUBJECT>
                    </SECTION>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>19. Amend § 92.216 in paragraphs (a)(2) and (b)(2) by removing the word “dwelling” and adding in its place the word “housing”.</AMDPAR>
                    </REGTEXT>
                    <SECTION>
                        <SECTNO>§ 92.217</SECTNO>
                        <SUBJECT>[Amended]</SUBJECT>
                    </SECTION>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>20. Amend § 92.217 by removing the word “dwelling” and adding in its place the word “housing”.</AMDPAR>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>21. Amend § 92.219 by:</AMDPAR>
                        <AMDPAR>a. Removing the word “dwelling” and adding in its place the word “housing” in paragraph (a)(4);</AMDPAR>
                        <AMDPAR>b. Revising the first sentences of paragraphs (b)(2)(ii) and (iii);</AMDPAR>
                        <P>The revisions read as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.219</SECTNO>
                            <SUBJECT>Recognition of matching contribution.</SUBJECT>
                            <STARS/>
                            <P>(b) * * *</P>
                            <P>(2) * * *</P>
                            <P>(ii) The participating jurisdiction must execute, with the owner of the housing (or, if the participating jurisdiction is the owner, with the manager or developer), a written agreement that imposes and enumerates all of the requirements applicable to the project, including affordability requirements in § 92.252 or § 92.254; tenant protection requirements in § 92.253; property standards requirements in § 92.251; and income determination requirements in § 92.203. * * *</P>
                            <P>(iii) A participating jurisdiction must establish a procedure to monitor HOME match-eligible housing to ensure continued compliance with the requirements of § 92.203 (Income determinations), § 92.252 (Qualification as affordable housing: Rental housing), § 92.253 (Tenant protections), and § 92.254 (Qualification as affordable housing: Homeownership). * * *</P>
                            <STARS/>
                        </SECTION>
                    </REGTEXT>
                    <SECTION>
                        <SECTNO>§ 92.220</SECTNO>
                        <SUBJECT>[Amended]</SUBJECT>
                    </SECTION>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>22. Amend § 92.220 by removing the words “single-family” and adding in their place “single family” in paragraph (a)(5)(ii).</AMDPAR>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>23. Amend § 92.221 by adding paragraphs (b)(1) and (2) to read as follows:</AMDPAR>
                        <SECTION>
                            <SECTNO>§ 92.221</SECTNO>
                            <SUBJECT>Match credit.</SUBJECT>
                            <STARS/>
                            <P>
                                (b) 
                                <E T="03">* * *</E>
                            </P>
                            <P>(1) To apply an excess matching contribution to a future fiscal year's match liability, the participating jurisdiction must have documentation, at the time of application, demonstrating the matching contribution complied with the matching requirements at §§ 92.218 through 92.221 at the time it was made. Documentation must include project records of the type and amount of the matching contribution.</P>
                            <P>(2) A participating jurisdiction must maintain the records in paragraph (b)(1) of this section for five years from the date of application of the excess matching contribution to the liability.</P>
                            <STARS/>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>24. Amend § 92.250 by:</AMDPAR>
                        <AMDPAR>a. Revising paragraphs (a) and (b)(3)(i);</AMDPAR>
                        <AMDPAR>b. Removing the words “downpayment assistance” and in their place adding in their place the words “homeownership assistance” in paragraph (b)(4); and</AMDPAR>
                        <AMDPAR>c. Adding paragraph (c).</AMDPAR>
                        <P>The revisions and addition read as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.250</SECTNO>
                            <SUBJECT>Maximum per-unit subsidy amount, underwriting, and subsidy layering.</SUBJECT>
                            <P>
                                (a) 
                                <E T="03">Maximum per-unit subsidy amount.</E>
                                 The total amount of HOME funds that a participating jurisdiction may invest on a per-unit basis in affordable housing may not exceed the per-unit dollar limits established by HUD in accordance with section 212(e) of the Act. HUD will publish the per-unit dollar limits for the area in which the housing is located annually. HUD will publish its methodology for determining maximum per-unit dollar limits through a publication in the 
                                <E T="04">Federal Register</E>
                                 with the opportunity for comment.
                            </P>
                            <P>(b) * * *</P>
                            <P>(3) * * *</P>
                            <P>(i) An underwriting analysis of the homeowner's ability to repay the HOME-funded rehabilitation loan is required only if the loan is an amortizing loan; and</P>
                            <STARS/>
                            <P>
                                (c) A participating jurisdiction may exceed the per-unit dollar limits described in paragraph (a) of this section by up to 10 percent if the project meets one of the green building standards identified by HUD and published in the 
                                <E T="04">Federal Register</E>
                                .
                            </P>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>25. Amend § 92.251 by:</AMDPAR>
                        <AMDPAR>a. Revising the section heading and paragraph (a)(2);</AMDPAR>
                        <AMDPAR>b. Adding paragraph (a)(3);</AMDPAR>
                        <AMDPAR>c. Revising paragraph (b)(1)(vi);</AMDPAR>
                        <AMDPAR>d. Adding paragraphs (b)(1)(viii)(A) and (B);</AMDPAR>
                        <AMDPAR>e. Adding paragraphs (b)(1)(xi) and (xii);</AMDPAR>
                        <AMDPAR>f. Removing the words “must ensure” and adding in their place the words “must require” and by removing the words “The construction documents” and adding in their place the words “The construction contract and documents” in paragraph (b)(2);</AMDPAR>
                        <AMDPAR>g. Revising paragraph (b)(3), the first sentence of paragraph (c)(1), and paragraph (c)(3);</AMDPAR>
                        <AMDPAR>h. Adding paragraph (d);</AMDPAR>
                        <AMDPAR>i. Revising the paragraph (f) heading;</AMDPAR>
                        <AMDPAR>j. Removing the words “affordability period” and adding in their place the words “period of affordability” and by removing the words “each of the following” and adding in their place the words “all of the following” in paragraph (f)(1) introductory text;</AMDPAR>
                        <AMDPAR>k. Revising paragraph (f)(1)(i);</AMDPAR>
                        <AMDPAR>l. Adding paragraph (f)(1)(iv);</AMDPAR>
                        <AMDPAR>m. Revising paragraphs (f)(3) through (5); and</AMDPAR>
                        <AMDPAR>n. Adding paragraph (g).</AMDPAR>
                        <P>The revisions and additions read as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.251 </SECTNO>
                            <SUBJECT>Property standards and inspections.</SUBJECT>
                            <P>(a) * * *</P>
                            <P>
                                (2) 
                                <E T="03">Construction progress and final inspections.</E>
                                 The participating jurisdiction must conduct on-site progress and final inspections of construction to ensure that work is done in accordance with the applicable codes, the construction contract, and construction documents. Before completing the project in the disbursement and information system established by HUD, the participating jurisdiction must perform an on-site inspection of the project to determine that all contracted work has been completed and that the project complies with the property standards and requirements in this paragraph (a). All inspections performed by the participating jurisdiction must be conducted in accordance with the participating jurisdiction's inspection procedures.
                            </P>
                            <P>
                                (3) 
                                <E T="03">HUD requirements.</E>
                                 All new construction projects must also meet the following requirements upon project 
                                <PRTPAGE P="871"/>
                                completion, unless an earlier deadline is otherwise required by the applicable statute, regulation, or standard:
                            </P>
                            <P>
                                (i) 
                                <E T="03">Accessibility.</E>
                                 The housing must meet the accessibility requirements of 24 CFR part 8, which implements section 504 of the Rehabilitation Act of 1973 (29 U.S.C. 794), and Titles II and III of the Americans with Disabilities Act (42 U.S.C. 12131-12189) implemented at 28 CFR parts 35 and 36, as applicable. Covered multifamily dwellings, as defined at 24 CFR 100.201, must also meet the design and construction requirements at 24 CFR 100.205, which implements the Fair Housing Act (42 U.S.C. 3601-3619).
                            </P>
                            <P>
                                (ii) 
                                <E T="03">Energy efficiency standards.</E>
                                 Newly constructed housing shall qualify as affordable housing under this part only if it meets the energy efficiency standards promulgated by the Secretary in accordance with section 109 of the Cranston-Gonzalez National Affordable Housing Act (42 U.S.C. 12709).
                            </P>
                            <P>
                                (iii) 
                                <E T="03">Disaster mitigation.</E>
                                 Where relevant, the housing must be constructed to mitigate the impact of future disasters (
                                <E T="03">e.g.,</E>
                                 earthquakes, hurricanes, flooding, and wildfires) in accordance with State and local codes, ordinances, and requirements, and such other requirements that HUD may establish.
                            </P>
                            <P>
                                (iv) 
                                <E T="03">Written cost estimates, construction contracts, and construction documents.</E>
                                 The participating jurisdiction must require the construction contract(s) and construction documents to describe the work to be undertaken in adequate detail so that inspections can be conducted. The participating jurisdiction must review and approve written cost estimates for construction and determine that costs are reasonable.
                            </P>
                            <P>
                                (v) 
                                <E T="03">Broadband infrastructure.</E>
                                 For new commitments made after January 19, 2017, for a new construction housing project of a building with more than 4 rental units, the construction must include installation of broadband infrastructure, as this term is defined in 24 CFR 5.100, except where the participating jurisdiction determines and, in accordance with § 92.508(a)(3)(iv), documents the determination that:
                            </P>
                            <P>(A) The location of the new construction makes installation of broadband infrastructure infeasible; or</P>
                            <P>(B) The cost of installing the infrastructure would result in a fundamental alteration in the nature of its program or activity or in an undue financial burden.</P>
                            <P>
                                (vi) 
                                <E T="03">Carbon monoxide and smoke detection</E>
                                —(A) 
                                <E T="03">Carbon monoxide detection.</E>
                                 A carbon monoxide alarm must be installed in the housing unit in a manner that meets or exceeds the carbon monoxide detection standards set by HUD through 
                                <E T="04">Federal Register</E>
                                 publication.
                            </P>
                            <P>
                                (B) 
                                <E T="03">Smoke detection.</E>
                                 (
                                <E T="03">1</E>
                                ) A hardwired smoke alarm must be installed:
                            </P>
                            <P>
                                (
                                <E T="03">i</E>
                                ) On each level of each housing unit;
                            </P>
                            <P>
                                (
                                <E T="03">ii</E>
                                ) In or near each sleeping area in each housing unit;
                            </P>
                            <P>
                                (
                                <E T="03">iii</E>
                                ) In the basement of each housing unit and in each common area of a project. A hardwired smoke alarm is not required in crawl spaces or unfinished attics of housing units;
                            </P>
                            <P>
                                (
                                <E T="03">iv</E>
                                ) Within 21 feet of any door to a sleeping area measured along a path of travel; and
                            </P>
                            <P>
                                (
                                <E T="03">v</E>
                                ) Where a smoke alarm installed outside a sleeping area is separated from an adjacent living area by a door, a smoke alarm must also be installed on the living area side of the door.
                            </P>
                            <P>
                                (
                                <E T="03">2</E>
                                ) Each hardwired smoke alarm must have an alarm system designed for hearing-impaired persons.
                            </P>
                            <P>
                                (
                                <E T="03">3</E>
                                ) The Secretary may establish additional standards through 
                                <E T="04">Federal Register</E>
                                 publication.
                            </P>
                            <P>
                                (
                                <E T="03">4</E>
                                ) Following the relevant specifications of the International Code Council (ICC) or the National Fire Protection Association Standard (NFPA) 72 satisfies the requirements of this paragraph (a)(3)(vi)(B).
                            </P>
                            <P>
                                (vii) 
                                <E T="03">Green building standards.</E>
                                 If a participating jurisdiction exceeds the maximum per-unit subsidy limit pursuant to § 92.250(c), then upon completion, the housing must meet one of the green building standards established by HUD through 
                                <E T="04">Federal Register</E>
                                 publication.
                            </P>
                            <P>(b) * * *</P>
                            <P>(1) * * *</P>
                            <P>
                                (vi) 
                                <E T="03">Disaster mitigation.</E>
                                 Where relevant, the participating jurisdiction's standards must require the housing to be improved to mitigate the impact of future disasters (
                                <E T="03">e.g.,</E>
                                 earthquake, hurricanes, flooding, and wildfires) in accordance with State and local codes, ordinances, and requirements, and such other requirements that HUD may establish.
                            </P>
                            <STARS/>
                            <P>
                                (viii) 
                                <E T="03">* * *</E>
                            </P>
                            <P>
                                (A) The participating jurisdiction may accept a determination in satisfaction of another funding source's requirements that, upon the completion of the rehabilitation, the HOME-assisted project and units are decent, safe, sanitary, and in good repair in an inspection conducted under the National Standards for the Condition of HUD housing (24 CFR part 5, subpart G) or an alternative inspection standard, which HUD may establish through 
                                <E T="04">Federal Register</E>
                                 publication.
                            </P>
                            <P>(B) If a participating jurisdiction is accepting a determination pursuant to paragraph (b)(1)(viii)(A) of this section, then the participating jurisdiction must document the determination in accordance with § 92.508(a)(3)(iv) and is not required to perform a HOME inspection of the project and units for compliance with 24 CFR 5.703.</P>
                            <STARS/>
                            <P>
                                (xi) 
                                <E T="03">Carbon monoxide and smoke detection—</E>
                                (A) 
                                <E T="03">Carbon monoxide detection.</E>
                                 A carbon monoxide alarm must be installed in the housing unit in a manner that meets or exceeds the carbon monoxide detection standards set by HUD through 
                                <E T="04">Federal Register</E>
                                 publication.
                            </P>
                            <P>
                                (B) 
                                <E T="03">Smoke detection.</E>
                                 (
                                <E T="03">1</E>
                                ) A hardwired smoke alarm must be installed:
                            </P>
                            <P>
                                (
                                <E T="03">i</E>
                                ) On each level of each housing unit;
                            </P>
                            <P>
                                (
                                <E T="03">ii</E>
                                ) In or near each sleeping area in each housing unit;
                            </P>
                            <P>
                                (
                                <E T="03">iii</E>
                                ) In the basement of each housing unit, and in each common area of a project. A hardwired smoke alarm is not required in crawl spaces or unfinished attics of housing units;
                            </P>
                            <P>
                                (
                                <E T="03">iv</E>
                                ) Within 21 feet of any door to a sleeping area measured along a path of travel; and
                            </P>
                            <P>
                                (
                                <E T="03">v</E>
                                ) Where a smoke alarm installed outside a sleeping area is separated from an adjacent living area by a door, a smoke alarm must also be installed on the living area side of the door.
                            </P>
                            <P>
                                (
                                <E T="03">2</E>
                                ) Each hardwired smoke alarm must have an alarm system designed for hearing-impaired persons.
                            </P>
                            <P>
                                (
                                <E T="03">3</E>
                                ) The Secretary may establish additional standards through 
                                <E T="04">Federal Register</E>
                                 publication.
                            </P>
                            <P>
                                (
                                <E T="03">4</E>
                                ) Where the use of hardwired smoke detectors places an undue financial burden on the owner or is infeasible, a participating jurisdiction may provide a written exception to allow the owner to install a smoke detector that uses 10-year non rechargeable, nonreplaceable primary batteries. The smoke detector must be sealed, tamper-resistant, contain a means to silence the alarm, and otherwise comply with the requirements of this section.
                            </P>
                            <P>
                                (
                                <E T="03">5</E>
                                ) Following the relevant specification of the International Code Council (ICC) or the National Fire Protection Association Standard (NFPA) 72 satisfies the requirements of this paragraph (b)(1)(xi)(B).
                            </P>
                            <P>
                                (xii) 
                                <E T="03">Green building standards.</E>
                                 If a participating jurisdiction exceeds the maximum per-unit subsidy limit pursuant to § 92.250(c), then upon completion of the rehabilitation the housing must meet one of the green 
                                <PRTPAGE P="872"/>
                                building standards established by HUD through 
                                <E T="04">Federal Register</E>
                                 publication.
                            </P>
                            <STARS/>
                            <P>
                                (3) 
                                <E T="03">Frequency of inspections.</E>
                                 The participating jurisdiction must conduct an initial property inspection to identify the deficiencies that must be addressed and must conduct on-site progress and final inspections to determine that work was done in accordance with the construction contract and construction documents. Before completing the project in the disbursement and information system established by HUD, the participating jurisdiction must perform an on-site inspection of the project to determine that all contracted work has been completed and that the project complies with the property standards and requirements in this paragraph (b). All inspections performed by the participating jurisdiction must be conducted in accordance with the participating jurisdiction's inspection procedures.
                            </P>
                            <P>(c) * * *</P>
                            <P>(1) Existing housing that is acquired with HOME assistance for rental housing, and that was newly constructed or rehabilitated less than 12 months before the date of commitment of HOME funds, must meet the property standards for new construction in paragraph (a) or rehabilitation in paragraph (b) of this section, as applicable. * * *</P>
                            <STARS/>
                            <P>
                                (3) Existing housing that is acquired for homeownership using homeownership assistance must be decent, safe, sanitary, and in good repair. The participating jurisdiction must establish standards to determine that the housing is decent, safe, sanitary, and in good repair. At minimum, the standards must provide that the housing meets all applicable State and local housing quality standards and code requirements, and the housing does not contain the specific deficiencies established by HUD based on the applicable standards in 24 CFR 5.703 and published in the 
                                <E T="04">Federal Register</E>
                                 for HOME-assisted projects and units. The housing must also meet or exceed the carbon monoxide and smoke detection standards contained in the participating jurisdiction's rehabilitation standards pursuant to paragraph (b) of this section. If the use of hardwired smoke detectors places an undue financial burden on the homebuyer or is infeasible, a participating jurisdiction may provide a written exception to the homebuyer consistent with the requirements contained in paragraph (b) of this section.
                            </P>
                            <P>(i) The participating jurisdiction must inspect the housing and document compliance with this paragraph (c)(3) based upon an inspection that is conducted no earlier than 90 days before the commitment of HOME assistance. If the housing does not meet these standards, the housing must be rehabilitated to meet the standards of this paragraph (c)(3) before the acquisition, except as provided in paragraph (c)(3)(ii) of this section.</P>
                            <P>(ii) If the housing is not rehabilitated to meet the standards in this paragraph (c)(3) before acquisition, then the housing may still be acquired if all of the following conditions are satisfied:</P>
                            <P>(A) The written agreement between the participating jurisdiction and the homebuyer requires the property to meet the standards within 6 months of acquisition with HOME assistance;</P>
                            <P>(B) Funding is secured to complete the rehabilitation necessary to comply with the standards; and</P>
                            <P>(C) Unless an extension is provided pursuant to paragraph (c)(3)(ii)(D) of this section, the participating jurisdiction conducts a final inspection within six months after acquisition and determines that the property meets the standards.</P>
                            <P>(D) The participating jurisdiction may provide the homebuyer with an extension of up to 12 months from acquisition to meet the standards. If the participating jurisdiction provides an extension, the participating jurisdiction must amend the written agreement to reflect the extension and conduct a final inspection within 12 months of acquisition and determine that the property meets the standards.</P>
                            <P>(iii) All inspections performed by the participating jurisdiction must be conducted in accordance with the participating jurisdiction's inspection procedures.</P>
                            <P>
                                (d) 
                                <E T="03">Projects involving a combination of rehabilitation and either new construction or reconstruction.</E>
                                 If a project includes both rehabilitation of housing units and either new construction or reconstruction of housing units, then the participating jurisdiction must apply the rehabilitation standards to the housing units that are rehabilitated and the new construction requirements to housing that is either newly constructed or reconstructed.
                            </P>
                            <STARS/>
                            <P>
                                (f) 
                                <E T="03">Ongoing property condition standards and inspections: Rental housing and housing occupied by tenants receiving HOME tenant-based rental assistance.</E>
                                 * * *
                            </P>
                            <P>(1) * * *</P>
                            <P>
                                (i) 
                                <E T="03">Compliance with State and local codes, ordinances, and requirements.</E>
                                 The participating jurisdiction's standards must require the housing to meet all applicable State and local code requirements and ordinances. In the absence of existing applicable State or local code requirements and ordinances, at a minimum, the participating jurisdiction's ongoing property standards must provide that the property does not contain the specific deficiencies established by HUD based on the applicable standards in 24 CFR 5.703 and published in the 
                                <E T="04">Federal Register</E>
                                 for HOME rental housing (including manufactured housing) and housing occupied by tenants receiving HOME tenant-based rental assistance, except that the carbon monoxide detection requirements at 24 CFR 5.703(b)(2) and (d)(6) shall not apply. The participating jurisdiction's property standards are not required to comply with 24 CFR 5.705 through 5.713.
                            </P>
                            <STARS/>
                            <P>
                                (iv) 
                                <E T="03">Carbon monoxide and smoke detection</E>
                                —(A) 
                                <E T="03">Carbon monoxide detection.</E>
                                 A carbon monoxide alarm must be installed in the housing unit in a manner that meets or exceeds the carbon monoxide detection standards set by HUD through 
                                <E T="04">Federal Register</E>
                                 publication.
                            </P>
                            <P>
                                (B) 
                                <E T="03">Smoke detection.</E>
                                 The participating jurisdiction's standards must require housing to contain smoke detectors in accordance with the requirements contained in 24 CFR 5.703(b) and (d).
                            </P>
                            <STARS/>
                            <P>
                                (3) 
                                <E T="03">Ongoing inspections of HOME-assisted rental housing.</E>
                                 During the period of affordability, the participating jurisdiction must perform on-site inspections of HOME-assisted rental housing to determine compliance with the property standards in paragraph (f)(1) of this section and to verify the information submitted by owners in accordance with the requirements of § 92.252. The participating jurisdiction must perform inspections in accordance with its established inspection procedures. These procedures, at minimum, must include the following requirements:
                            </P>
                            <P>
                                (i) 
                                <E T="03">Frequency of inspections.</E>
                                 The participating jurisdiction must perform an on-site inspection within 12 months after project completion and complete one of the following every 3 years during the period of affordability:
                            </P>
                            <P>
                                (A) Perform an on-site inspection in accordance with the participating jurisdiction's inspection procedures to determine compliance with the property standards; or
                                <PRTPAGE P="873"/>
                            </P>
                            <P>
                                (B) Accept a determination made within the past 12 months in satisfaction of another funding source's requirements, that the HOME-assisted project and units are decent, safe, sanitary, and in good repair in an inspection conducted under the National Standards for the Condition of HUD housing (24 CFR part 5, subpart G) or an alternative inspection standard, which HUD may establish through 
                                <E T="04">Federal Register</E>
                                 publication. If a participating jurisdiction is accepting a determination, then the participating jurisdiction must document the determination in accordance with § 92.508(a)(3)(iv) and is not required to perform an on-site HOME inspection of the project and the units for compliance with 24 CFR 5.703.
                            </P>
                            <P>
                                (ii) 
                                <E T="03">Annual certification.</E>
                                 The owner must annually certify to the participating jurisdiction that each building and all HOME-assisted units in the project are suitable for occupancy, taking into account State and local health, safety, and other applicable codes, ordinances, and requirements, and the ongoing property standards established by the participating jurisdiction.
                            </P>
                            <P>
                                (iii) 
                                <E T="03">Units inspected.</E>
                                 Inspections must be based on a random sample of the HOME-assisted units in the project with a mix of unit sizes (
                                <E T="03">e.g.,</E>
                                 a mix of one-bedroom, two-bedroom, and three-bedroom units) in accordance with the chart contained in this paragraph. All inspections must include the inspectable areas for each building containing HOME-assisted units. For projects with one-to-four HOME-assisted units, the participating jurisdiction must inspect 100 percent of the HOME-assisted units and the inspectable areas for each building with HOME-assisted units.
                            </P>
                            <GPOTABLE COLS="2" OPTS="L2,i1" CDEF="s50,12">
                                <TTITLE>
                                    Table 1 to Paragraph (
                                    <E T="01">f</E>
                                    )(3)(
                                    <E T="01">iii</E>
                                    )—Minimum Inspection Sample Size for HOME Rental Housing Projects
                                </TTITLE>
                                <BOXHD>
                                    <CHED H="1"> Number of HOME-assisted units in the HOME project</CHED>
                                    <CHED H="1">
                                        Number of units that must be selected in the random sample (
                                        <E T="03">i.e.</E>
                                        , minimum unit sample size)
                                    </CHED>
                                </BOXHD>
                                <ROW>
                                    <ENT I="01">1-20</ENT>
                                    <ENT>4</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">21-25</ENT>
                                    <ENT>5</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">26-30</ENT>
                                    <ENT>6</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">31-35</ENT>
                                    <ENT>7</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">36-40</ENT>
                                    <ENT>8</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">41-45</ENT>
                                    <ENT>9</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">46-50</ENT>
                                    <ENT>10</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">51-55</ENT>
                                    <ENT>11</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">56-60</ENT>
                                    <ENT>12</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">61-65</ENT>
                                    <ENT>13</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">66-70</ENT>
                                    <ENT>14</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">71-75</ENT>
                                    <ENT>15</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">76-80</ENT>
                                    <ENT>16</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">81-85</ENT>
                                    <ENT>17</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">86-90</ENT>
                                    <ENT>18</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">91-95</ENT>
                                    <ENT>19</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">96-100</ENT>
                                    <ENT>20</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">101-105</ENT>
                                    <ENT>21</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">106-110</ENT>
                                    <ENT>22</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">111-115</ENT>
                                    <ENT>23</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">116-120</ENT>
                                    <ENT>24</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">121-125</ENT>
                                    <ENT>25</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">126-130</ENT>
                                    <ENT>26</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">131-166</ENT>
                                    <ENT>27</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">167-214</ENT>
                                    <ENT>28</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">215-295</ENT>
                                    <ENT>29</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">296-455</ENT>
                                    <ENT>30</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">456-920</ENT>
                                    <ENT>31</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">921+</ENT>
                                    <ENT>32</ENT>
                                </ROW>
                            </GPOTABLE>
                            <P>
                                (iv) 
                                <E T="03">Financial oversight.</E>
                                 During the period of affordability, the participating jurisdiction must at least annually examine the financial condition of projects with 10 or more HOME-assisted units to determine the continued financial viability of the housing and must take actions to correct problems, to the extent feasible.
                            </P>
                            <P>
                                (4) 
                                <E T="03">Annual inspections for housing with tenants receiving HOME tenant-based rental assistance.</E>
                                 All housing occupied by tenants receiving HOME tenant-based rental assistance must meet the property standards of paragraph (f)(1) of this section. The participating jurisdiction must annually determine that the housing is decent, safe, sanitary, and in good repair through one of the following methods:
                            </P>
                            <P>(i) An annual on-site inspection in accordance with its inspection procedures for annual inspections to determine the housing meets the property standards in paragraph (f)(1) of this section; or</P>
                            <P>
                                (ii) An inspection conducted within the past 3 months in satisfaction of another funding source's requirements under the National Standards for the Condition of HUD housing (24 CFR part 5, subpart G) or an alternative inspection standard, which HUD may establish through 
                                <E T="04">Federal Register</E>
                                 publication. A participating jurisdiction may move its inspection cycle to align with an inspection covered by this paragraph. If a participating jurisdiction is accepting an inspection pursuant to this paragraph, then the participating jurisdiction must document the inspection's determination that the housing is decent, safe, sanitary, and in good repair in accordance with § 92.508(a)(3)(iv) and is not required to perform a HOME inspection of the project and units for compliance with 24 CFR 5.703.
                            </P>
                            <P>
                                (5) 
                                <E T="03">Corrective and remedial actions.</E>
                                 The participating jurisdiction must have procedures for requiring that timely corrective and remedial actions are taken by the owner to address identified deficiencies.
                            </P>
                            <P>
                                (i) 
                                <E T="03">Health and safety deficiencies.</E>
                                 Health and safety deficiencies must be corrected immediately. Except for small-scale housing, the participating jurisdiction must adopt a more frequent inspection schedule for properties that have been found to have health and safety deficiencies. For small-scale housing, the participating jurisdiction may adopt a more frequent inspection schedule if the small-scale housing is found to have health and safety deficiencies, as described in its inspection procedures.
                            </P>
                            <P>
                                (ii) 
                                <E T="03">Other deficiencies.</E>
                                 If there are observed deficiencies for any of the inspectable areas in the property standards established by the participating jurisdiction, in accordance with the inspection procedures, a follow-up on-site inspection to verify that deficiencies are corrected must occur within 12 months. The participating jurisdiction may establish a list of non-hazardous deficiencies for which correction can be verified by third party documentation (
                                <E T="03">e.g.,</E>
                                 paid invoice for work order) rather than re-inspection.
                            </P>
                            <P>
                                (g) 
                                <E T="03">Inspection procedures.</E>
                                 The participating jurisdiction must establish written inspection procedures. The procedures must include detailed inspection checklists, a description of how and by whom inspections will be carried out, and procedures for training and certifying qualified inspectors. For ongoing property inspections, the procedures must also describe how frequently the property will be inspected, consistent with this section and § 92.209.
                            </P>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>26. Revise § 92.252 to read as follows:</AMDPAR>
                        <SECTION>
                            <SECTNO>§ 92.252 </SECTNO>
                            <SUBJECT>Qualification as affordable housing: Rental housing.</SUBJECT>
                            <P>
                                The HOME-assisted units in a rental housing project must be occupied by households that are eligible as low-income families and must meet the requirements of this section to qualify as affordable housing. If the housing is not occupied by eligible tenants within six months following the date of project 
                                <PRTPAGE P="874"/>
                                completion, the participating jurisdiction must revise its marketing plan to enable the project to reach required occupancy. The participating jurisdiction must repay HOME funds invested in any housing unit that has not been rented to eligible tenants within 18 months after the date of project completion. The affordability requirements in this section also apply to the HOME-assisted non-owner-occupied units in single family housing purchased with HOME funds in accordance with § 92.254. A tenant must have a written lease that complies with § 92.253.
                            </P>
                            <P>
                                (a) 
                                <E T="03">HOME rent limits.</E>
                                 The rent for a HOME-assisted unit must not exceed the rent limits in this section. HUD will publish the HOME rent limits on an annual basis, with adjustments for number of bedrooms in the unit. The rent limits do not apply to any rental assistance or subsidy payment provided under a Federal, State, or local rental assistance or subsidy program. Regardless of changes in fair market rents and in median income over time, the rents for a project are not required to be lower than the HOME rent limits for the project in effect at the time of project commitment. The participating jurisdiction may designate (in its written agreement with the owner) more than the minimum HOME units in a rental housing project, regardless of project size. The rent limits apply to the rent plus the utilities or utility allowance.
                            </P>
                            <P>
                                (1) 
                                <E T="03">High HOME rent limits.</E>
                                 If a low-income family is participating in a program where the family pays as a contribution toward rent no more than 30 percent of the family's monthly adjusted income or 10 percent of the family's monthly income, then the maximum rent due from the family is the family's contribution. For all other cases, the rent does not exceed the lesser of:
                            </P>
                            <P>(i) The fair market rent for existing housing for comparable units in the area as established by HUD under 24 CFR 888.111; or</P>
                            <P>(ii) 30 percent of the adjusted income of a family whose annual income equals 65 percent of the median income for the area, as determined by HUD.</P>
                            <P>
                                (2) 
                                <E T="03">Low HOME rent limits.</E>
                                 In rental projects with five or more HOME-assisted rental units, at least 20 percent of the HOME-assisted units must be occupied by very low-income families. If a very low-income family is participating in a program where the family pays as a contribution toward rent no more than 30 percent of the family's monthly adjusted income or 10 percent of the family's monthly income, then the maximum rent due from the family is the family's contribution. All other Low HOME Rent units must have rent that meet one of the following requirements:
                            </P>
                            <P>(i) The rent does not exceed 30 percent of the annual income of a family whose income equals 50 percent of the median income for the area, as determined by HUD. If the rent determined under this paragraph is higher than the fair market rent under paragraph (a)(1)(i) of this section, then the maximum rent for units under this paragraph is the fair market rent under paragraph (a)(1)(i);</P>
                            <P>(ii) The rent contribution of the family is not more than 30 percent of the family's adjusted income; or</P>
                            <P>(iii) The unit is a LIHTC unit and has rents not greater than the gross rent for rent-restricted residential units as determined under 26 U.S.C. 42(g)(2).</P>
                            <P>
                                (3) 
                                <E T="03">HOME rent limits for SRO projects.</E>
                                 (i) For SRO units that have both sanitary and food preparation facilities, the rent limit is the zero-bedroom fair market rent as established by HUD under 24 CFR part 888. The project must meet the requirements of paragraphs (a)(1) and (2) of this section.
                            </P>
                            <P>(ii) For SRO units that have no sanitary or food preparation facilities or only one of the two, the rent limit is 75 percent of the zero-bedroom fair market rent as established by HUD under 24 CFR part 888. The project must be occupied by very low-income tenants.</P>
                            <P>
                                (b) 
                                <E T="03">Utility allowances.</E>
                                 The participating jurisdiction must establish maximum monthly allowances for utilities and services (excluding telephone, cable, and broadband) and update the allowances annually. The participating jurisdiction may determine the utility allowance for the project based on the type of utilities and services paid by the tenant, including any energy efficiency measures. The participating jurisdiction may use any of the following for its maximum monthly allowances: the HUD Utility Schedule Model, the utility allowance established by the applicable local public housing authority, or another method approved by HUD.
                            </P>
                            <P>
                                (c) 
                                <E T="03">Review and approval of rents.</E>
                                 The participating jurisdiction must review and approve rents proposed by the owner for units, subject to the rent limits in paragraph (a) of this section. For all units subject to the rent limits in paragraph (a) for which the tenant is paying utilities and services, the participating jurisdiction must require that the rents do not exceed the rent limits in paragraph (a) minus the monthly allowances for utilities and services in paragraph (b) of this section.
                            </P>
                            <P>
                                (d) 
                                <E T="03">Period of affordability.</E>
                                 The HOME-assisted units must meet requirements under this part for the applicable period specified in the table in this paragraph (d), beginning from project completion.
                            </P>
                            <P>(1) The affordability requirements, including the applicable rent limits, period of affordability, and income requirements:</P>
                            <P>(i) Apply without regard to the term of any loan or mortgage, repayment of the HOME investment, or the transfer of ownership;</P>
                            <P>(ii) Must be imposed by a deed or use restriction, lien on real property, a covenant running with the land, a recorded agreement restricting the use of the property, or other mechanisms approved by HUD in writing, under which the participating jurisdiction has the right to require specific performance (except that the participating jurisdiction may provide that the affordability requirements may terminate upon foreclosure or transfer in lieu of foreclosure); and</P>
                            <P>(iii) Must be recorded in accordance with State recordation laws.</P>
                            <P>(2) The participating jurisdiction may use purchase options, rights of first refusal, or other preemptive rights to purchase the housing before foreclosure or deed in lieu of foreclosure in order to preserve affordability.</P>
                            <P>(3) The affordability restrictions shall be revived according to the original terms if, during the original period of affordability, the owner of record before the foreclosure, or deed in lieu of foreclosure, or any entity that includes the former owner or those with whom the former owner has or had family or business ties, obtains an ownership interest in the project or property.</P>
                            <P>(4) The termination of the affordability requirements on the project does not terminate the participating jurisdiction's repayment obligation under § 92.503(b).</P>
                            <GPOTABLE COLS="2" OPTS="L2,i1" CDEF="s50,12">
                                <TTITLE>
                                    Table 1 to Paragraph (
                                    <E T="01">d</E>
                                    )(4)—Minimum Period of Affordability for Rental Housing
                                </TTITLE>
                                <BOXHD>
                                    <CHED H="1">Rental housing activity</CHED>
                                    <CHED H="1">
                                        Minimum 
                                        <LI>period of </LI>
                                        <LI>affordability </LI>
                                        <LI>in years</LI>
                                    </CHED>
                                </BOXHD>
                                <ROW>
                                    <ENT I="01">Rehabilitation or acquisition of existing housing per-unit amount of HOME funds: Under $25,000</ENT>
                                    <ENT>5</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="02">$25,000 to $50,000</ENT>
                                    <ENT>10</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="02">Over $50,000 or rehabilitation involving refinancing</ENT>
                                    <ENT>15</ENT>
                                </ROW>
                                <ROW>
                                    <PRTPAGE P="875"/>
                                    <ENT I="02">New construction or acquisition of newly constructed housing</ENT>
                                    <ENT>20</ENT>
                                </ROW>
                            </GPOTABLE>
                            <P>
                                (e) 
                                <E T="03">Subsequent rents during the period of affordability.</E>
                                 (1) The HOME rent limits are recalculated on a periodic basis after HUD determines fair market rents and median incomes. HUD then publishes the updated HOME rent limits.
                            </P>
                            <P>(2) The participating jurisdiction must provide project owners with information on updated HOME rent limits so that rents may be adjusted (not to exceed the rent limits in paragraph (a) of this section) in accordance with the written agreement between the participating jurisdiction and the owner. Owners must annually provide the participating jurisdiction with information on rents and occupancy of HOME-assisted units to demonstrate compliance with this section. The participating jurisdiction must review rents for compliance and approve or disapprove them every year.</P>
                            <P>(3) Any increase in rents for HOME-assisted units is subject to the provisions of outstanding leases, and in any event, the owner must provide tenants of those units not less than 60 days prior written notice before implementing any increase in rents.</P>
                            <P>
                                (f) 
                                <E T="03">Adjustment of HOME rent limits for an existing project.</E>
                                 (1) Changes in fair market rents and in median income over time should be sufficient to maintain the financial viability of a project within the HOME rent limits in this section.
                            </P>
                            <P>(2) HUD may adjust the HOME rent limits for a project, only if HUD finds that an adjustment is necessary to support the continued financial viability of the project and only by an amount that HUD determines is necessary to maintain continued financial viability of the project. HUD expects that this authority will be used sparingly.</P>
                            <P>
                                (g) 
                                <E T="03">Tenant Income.</E>
                                 The income of each tenant must be determined initially in accordance with § 92.203(b)(1)(i) unless the participating jurisdiction accepts an annual income determination pursuant to § 92.203(a)(1), (2), or (3) or determines income in accordance with § 92.203(b)(3). In addition, each year during the period of affordability, the participating jurisdiction must require the project owner to re-examine each tenant's annual income in accordance with the option in § 92.203(b)(1) selected by the participating jurisdiction and included in the written agreement, except as follows:
                            </P>
                            <P>(1) A participating jurisdiction may permit an owner of small-scale housing to re-examine each tenant's annual income in accordance with the chart in this paragraph (g)(1), instead of annually, during the period of affordability.</P>
                            <GPOTABLE COLS="2" OPTS="L2,p1,8/9,i1" CDEF="s100,r200">
                                <TTITLE>
                                    Table 2 to Paragraph (
                                    <E T="01">g</E>
                                    )(1)—Alternative Income Examination Cycle for Small-Scale Rental Housing Projects
                                </TTITLE>
                                <BOXHD>
                                    <CHED H="1"> </CHED>
                                    <CHED H="1"> </CHED>
                                </BOXHD>
                                <ROW>
                                    <ENT I="01">
                                        Initial Examination
                                        <LI>(All Projects)</LI>
                                    </ENT>
                                    <ENT>The income of each tenant must be determined initially in accordance with § 92.203(b)(1)(i) unless the participating jurisdiction accepts an annual income determination pursuant to § 92.203(a)(1), § 92.203(a)(2), or § 92.203(a)(3), or determines income in accordance with § 92.203(b)(3).</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Year 3</ENT>
                                    <ENT>The income of each tenant must be examined in accordance with the option selected by the participating jurisdiction in § 92.203(b)(1) and included in the written agreement between the owner and the participating jurisdiction pursuant to § 92.504(c)(3).</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">
                                        Year 6
                                        <LI>(Projects with a period of affordability of greater than 5 years)</LI>
                                    </ENT>
                                    <ENT>The income of each tenant must be examined in accordance with § 92.203(b)(1)(i).</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">
                                        Year 9
                                        <LI>(Projects with a period of affordability of greater than 5 years)</LI>
                                    </ENT>
                                    <ENT>The income of each tenant must be examined in accordance with the option selected by the participating jurisdiction in § 92.203(b)(1) and included in the written agreement between the owner and the participating jurisdiction pursuant to § 92.504(c)(3).</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">
                                        Year 12
                                        <LI>(Projects with a period of affordability of greater than 10 years)</LI>
                                    </ENT>
                                    <ENT>The income of each tenant must be examined in accordance with § 92.203(b)(1)(i).</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">
                                        Year 15
                                        <LI>(Projects with a period of affordability of 20 years)</LI>
                                    </ENT>
                                    <ENT>The income of each tenant must be examined in accordance with the option selected by the participating jurisdiction in § 92.203(b)(1) and included in the written agreement between the owner and the participating jurisdiction pursuant to § 92.504(c)(3).</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">
                                        Year 18
                                        <LI>(Projects with a period of affordability of 20 years)</LI>
                                    </ENT>
                                    <ENT>The income of each tenant must be examined in accordance with § 92.203(b)(1)(i).</ENT>
                                </ROW>
                            </GPOTABLE>
                            <P>(2) A participating jurisdiction that permits an owner of a rental project (including small-scale housing projects) with a period of affordability of ten years or more to re-examine a tenant's annual income through a statement and certification in accordance with § 92.203(b)(1)(ii), must require the owner to re-examine the income of each tenant, in accordance with § 92.203(b)(1)(i), at minimum, every sixth year during the period of affordability; and,</P>
                            <P>(3) If the participating jurisdiction accepts an annual income determination pursuant to § 92.203(a)(1), (2), or (3), an owner is not required to re-examine a tenant's annual income in accordance with § 92.203(b) for HOME.</P>
                            <P>
                                (h) 
                                <E T="03">Over-income tenants.</E>
                                 (1) HOME-assisted units continue to qualify as affordable housing despite a temporary noncompliance caused by increases in the incomes of existing tenants if actions satisfactory to HUD are being taken to ensure that all vacancies are filled in accordance with this section until the noncompliance is corrected.
                            </P>
                            <P>(2) A tenant who no longer qualifies as low-income must pay a rent amount equal to the lesser of the amount payable by the tenant under State or local law or 30 percent of the family's adjusted income, except that:</P>
                            <P>(i) A tenant of a HOME-assisted unit subject to rent restrictions under section 42 of the Internal Revenue Code of 1986 (26 U.S.C. 42) must pay a rent amount that complies with that section;</P>
                            <P>
                                (ii) A tenant in a HOME-assisted unit designated as floating pursuant to paragraph (j) of this section shall pay a rent amount no greater than the fair market rent for comparable, unassisted units in the neighborhood; and
                                <PRTPAGE P="876"/>
                            </P>
                            <P>(iii) The rent limits do not apply to any rental assistance or subsidy payment provided under a Federal, State, or local rental assistance or subsidy program.</P>
                            <P>
                                (i) 
                                <E T="03">Surety bonds.</E>
                                 Surety bonds, security deposit insurance, or instruments similar to surety bonds and security deposit insurance may not be used in lieu of or in addition to a security deposit in HOME-assisted units.
                            </P>
                            <P>
                                (j) 
                                <E T="03">Fixed and floating HOME units.</E>
                                 In a project containing HOME-assisted and other units, the participating jurisdiction may designate fixed or floating HOME units. This designation must be made at the time of project commitment in the written agreement between the participating jurisdiction and the owner, and the HOME units must be identified not later than the time of initial unit occupancy. Fixed units remain the same throughout the period of affordability. Floating units are changed to maintain conformity with the requirements of this section during the period of affordability so that the total number of housing units meeting the requirements of this section remains the same, and each substituted unit is comparable in terms of size, features, and number of bedrooms to the originally designated HOME-assisted unit.
                            </P>
                            <P>
                                (k) 
                                <E T="03">Tenant selection.</E>
                                 The tenants must be selected in accordance with § 92.253(e).
                            </P>
                            <P>
                                (l) 
                                <E T="03">Ongoing responsibilities.</E>
                                 The participating jurisdiction's responsibilities for on-site inspections and financial oversight of rental projects are set forth in § 92.251(f).
                            </P>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>27. Revise § 92.253 to read as follows:</AMDPAR>
                        <SECTION>
                            <SECTNO>§ 92.253 </SECTNO>
                            <SUBJECT>Tenant protections and selection.</SUBJECT>
                            <P>
                                (a) 
                                <E T="03">Lease contents.</E>
                                 (1) For rental housing assisted with HOME funds and tenant-based rental assistance, there must be a written lease between the tenant and the owner that is for a period of not less than 1 year, unless by mutual agreement between the tenant and the owner, a shorter period is specified. Any changes to the lease must be in writing. The owner must provide the participating jurisdiction with a written lease or a revision to a written lease before it is executed. The lease shall contain:
                            </P>
                            <P>(i) More than one convenient and accessible method to communicate directly with the owner or the property management staff, including in person, by telephone, email, or through a web portal;</P>
                            <P>(ii) The participating jurisdiction's contact information for the HOME program;</P>
                            <P>(iii) The VAWA lease term/addendum required under § 92.359(e), except as otherwise provided by § 92.359(b); and</P>
                            <P>(iv)(A) For rental housing, the HOME rental housing tenancy addendum described in paragraph (b) of this section;</P>
                            <P>(B) For tenant-based rental assistance, the HOME tenant-based rental assistance tenancy addendum described in paragraph (c) of this section.</P>
                            <P>(2) For tenants receiving security deposit assistance only, there must be a written lease between the tenant and the owner that is for a period of not less than 1 year, unless by mutual agreement between the tenant and the owner, a shorter period is specified. The owner must provide the participating jurisdiction with a copy of the written lease before security deposit assistance is provided. The lease shall contain the HOME security deposit assistance tenancy addendum in paragraph (d) of this section.</P>
                            <P>
                                (b) 
                                <E T="03">HOME rental housing tenancy addendum.</E>
                                 The terms of the HOME rental housing tenancy addendum shall prevail over any conflicting provisions of the lease. The terms and conditions of the written lease, the HOME rental housing tenancy addendum, the VAWA addendum listed in paragraph (a) of this section, and any addendum required by another Federal, State, or local affordable housing program shall constitute and contain the sole and entire agreement between the owner and the tenant and no prior or contemporaneous oral or written representation or agreement between the owner or tenant shall have legal effect. The HOME rental housing tenancy addendum shall contain the following minimum requirements:
                            </P>
                            <P>
                                (1) 
                                <E T="03">Physical condition of unit and project.</E>
                                 (i) The owner shall maintain the physical condition of the unit and project so that it meets the participating jurisdiction's property standards and State and local code requirements in accordance with § 92.251(f);
                            </P>
                            <P>(ii) With respect to maintenance and repairs to a housing unit, the owner shall:</P>
                            <P>(A) Provide tenants with written expected time frames for maintaining or repairing units as soon as practicable;</P>
                            <P>(B) Professionally maintain and repair units and the common areas of the project in accordance with the participating jurisdiction's property standards as soon as practicable; and</P>
                            <P>(C) Not charge a tenant for normal wear and tear or damage to the unit or common areas of a project unless due to negligence, recklessness, or intentional acts by the tenant.</P>
                            <P>(iii) If the owner is required to repair a life-threatening deficiency impacting the tenant, and the repairs cannot be completed on the day the life-threatening deficiency is identified, the tenant shall promptly be relocated into housing that is decent, safe, sanitary, and in good repair and that provides the same or a greater level of accessibility, or other physically suitable lodging, at no additional cost to the tenant, until the repairs are completed and where it may be necessary, reasonable accommodations must continue to be provided during the relocation;</P>
                            <P>
                                (iv) The owner shall provide tenants with continued, uninterrupted utility service in projects with owner-controlled utility services unless the interruption is not within the control of the owner (
                                <E T="03">e.g.,</E>
                                 a general power outage).
                            </P>
                            <P>
                                (2) 
                                <E T="03">Use and occupancy of the unit and project.</E>
                                 (i) Subject to applicable occupancy requirements under Federal, State or local law, a family may reside in the unit with a foster child, foster adult, and/or live-in aide;
                            </P>
                            <P>(ii) Except for shared housing, the tenant's household shall have the right to exclusive use and occupancy of the leased unit;</P>
                            <P>(iii) The owner may only enter the housing unit:</P>
                            <P>(A) When the owner provides reasonable advance notification to the tenant and enters during reasonable hours for the purpose of performing routine inspections and maintenance, for making improvement or repairs, or to show the housing unit for re-leasing. A written statement specifying the purpose of the owner's entry delivered to the housing unit at least 2 days before such entry is reasonable advance notification;</P>
                            <P>(B) At any time without advance notification when there is reasonable cause to believe that an emergency requiring entry to the unit exists; and</P>
                            <P>(C) The owner shall provide the tenant a written statement specifying the date, time, and purpose of entry if the tenant and all adult members of the household are absent from the housing unit at the time of entry or if the owner is entering the housing unit pursuant to paragraph (b)(2)(iii)(B) of this section.</P>
                            <P>(iv) The tenant's household shall have reasonable access to and use of the common areas of the project;</P>
                            <P>(v) Tenants shall be able to organize, create tenant associations, convene meetings, distribute literature, and post information; and</P>
                            <P>
                                (vi) A tenant may not be required to accept supportive services that are offered unless the tenant is living in transitional housing and such supportive services are required in 
                                <PRTPAGE P="877"/>
                                connection with the transitional housing.
                            </P>
                            <P>
                                (3) 
                                <E T="03">Notice.</E>
                                 (i) Before an owner may take an adverse action against a tenant, the tenant must be notified in writing, or where necessary to accommodate an individual with a disability or language access needs, must be provided a statement that is accessible and understandable to the tenant, of the specific grounds for any proposed adverse action by the owner. Such notice should be provided in a translated format when needed to ensure meaningful access for limited English proficient (LEP) persons. Such adverse action includes, but is not limited to, imposition of charges for damages that require maintenance and repair;
                            </P>
                            <P>(ii) An owner must notify tenants about changes affecting property ownership and management as follows:</P>
                            <P>(A) 30 calendar days before a sale or foreclosure, tenants must be notified of the impending sale or foreclosure of the property;</P>
                            <P>(B) Within 5 business days of any changes of ownership, tenants must be notified of the change in ownership;</P>
                            <P>(C) Within 5 business days of any change in the property management company managing the property, tenants must be notified of the change in management company; and</P>
                            <P>(iii) The owner may not institute a lawsuit against the tenant without providing notice to the tenant.</P>
                            <P>
                                (4) 
                                <E T="03">A tenant's rights to available legal proceedings and remedies.</E>
                                 (i) The tenant shall not be required by the owner to agree to be sued, to admit guilt, or agree to a judgment in favor of the owner in a lawsuit brought in connection with the lease;
                            </P>
                            <P>(ii) The owner may not take, hold, or sell personal property of a household member without notice to the tenant and a court decision on the rights of the parties. This prohibition, however, does not apply to an agreement by the tenant concerning disposition of personal property remaining in the housing unit after the tenant has moved out of the unit. The owner may dispose of this personal property in accordance with State law;</P>
                            <P>(iii) The tenant may hold the owner or the owner's agents legally responsible for any action or failure to act, whether intentional or negligent;</P>
                            <P>(iv) In any legal proceedings involving tenant and owner, the owner and tenant agree that the tenant shall be able to exercise the tenant's right to:</P>
                            <P>(A) Obtain independent legal representation in any legal proceedings in connection with the lease, including in any non-binding arbitration or alternative dispute resolution process;</P>
                            <P>(B) Have a trial by jury where such right is available to a tenant under Federal, State, or local law; and</P>
                            <P>(C) Appeal, or to otherwise challenge in court, a court decision in connection with the lease where such right is available to the tenant under Federal, State, or local law;</P>
                            <P>(v) The tenant may only be required to pay the owner's attorney's fees or other legal costs if the tenant loses in a court proceeding between the owner and the tenant and the court so orders.</P>
                            <P>
                                (5) 
                                <E T="03">Protection against unreasonable interference or retaliation.</E>
                                 (i) An owner may not unreasonably interfere with the tenant's safety or peaceful enjoyment of a rental housing unit or the common areas of the rental housing project.
                            </P>
                            <P>(ii) An owner may not retaliate against a tenant for taking any action allowable under the lease and applicable law.</P>
                            <P>(iii) Actions that evidence unreasonable interference or retaliation against a tenant include actions taken for the purpose of causing the housing to become vacant or otherwise, including but not limited to:</P>
                            <P>(A) Recovery of, or attempt to recover, possession of the housing unit in a manner that is not in accordance with paragraph (b)(10) of this section;</P>
                            <P>
                                (B) Decreasing services to the housing unit (
                                <E T="03">e.g.,</E>
                                 trash removal, maintenance) or increasing the obligations of a tenant (
                                <E T="03">e.g.,</E>
                                 new or increased monetary obligations, etc.) in a manner that is not in accordance with the requirements of this part;
                            </P>
                            <P>(C) Interfering with a tenant's right to privacy under applicable State or local law;</P>
                            <P>(D) Harassing a household or their lawful guests; and</P>
                            <P>(E) Refusing to honor the terms of the lease.</P>
                            <P>(iv) If an owner unreasonably interferes or retaliates against a tenant, then this shall constitute a material breach under the lease, a violation of HOME program requirements, and a breach of the written agreement between the owner and the participating jurisdiction. A tenant may use evidence of such unreasonable interference or retaliation in a court of law, and the participating jurisdiction must take reasonable actions to address any violation in accordance with the participating jurisdiction's responsibilities under § 92.504(a) and (c).</P>
                            <P>
                                (6) 
                                <E T="03">Exercise of rights under tenancy.</E>
                                 A tenant may exercise any right of tenancy and assert any protection under their lease and any applicable Federal, State, local tenant protections including but not limited to:
                            </P>
                            <P>(i) Reporting inadequate housing conditions of the housing unit or project to the owner, the participating jurisdiction, code enforcement officials, or HUD;</P>
                            <P>(ii) Reporting lease violations and requesting enforcement of the written lease or any protections guaranteed under this part; and</P>
                            <P>(iii) Requesting or obtaining enforcement of any applicable protections under Federal, State, or local law.</P>
                            <P>
                                (7) 
                                <E T="03">Confidentiality.</E>
                                 An owner will keep all records containing personally identifying information of any individual or family who applies for or lives in a HOME-assisted rental unit secure and confidential.
                            </P>
                            <P>
                                (8) 
                                <E T="03">Prohibition on discrimination.</E>
                                 The owner shall operate housing assisted under this part in accordance with all applicable nondiscrimination and equal opportunity requirements pursuant to § 92.350 and the Violence Against Women Act (VAWA) requirements at § 92.359;
                            </P>
                            <P>
                                (9) 
                                <E T="03">Security deposits.</E>
                                 Security deposits must be refundable and no greater than two months' rent. Surety bonds, security deposit insurance, and instruments similar to surety bonds and security deposit insurance may not be used in lieu of or in addition to a security deposit. Upon termination of tenancy by the owner or tenant, if the owner charges any amount against a tenant's security deposit, the owner must give the tenant a list of all items charged against the security deposit and the amount of each item. After deducting the amount, if any, used to reimburse the owner, the owner must promptly refund the full amount of the unused balance to the tenant.
                            </P>
                            <P>
                                (10) 
                                <E T="03">Termination of tenancy.</E>
                                 (i) An owner may not terminate the tenancy of any tenant or household member or refuse to renew the lease of a tenant of rental housing assisted with HOME funds, except for serious or repeated violation of the material terms and conditions of the lease; for violation of applicable Federal, State, or local law; for completion of the tenancy period for transitional housing or failure to follow any required transitional housing supportive services plan; or for other good cause. The owner is permitted to terminate the tenancy of any tenant or household member or refuse to renew the lease of a tenant of rental housing assisted with HOME funds if the owner is permitted to do so pursuant to the provisions contained in 24 CFR part 5, subpart I; 24 CFR 882.511; or 24 CFR 982.310.
                                <PRTPAGE P="878"/>
                            </P>
                            <P>(A) Other good cause does not include a change in the tenant's income or assets or the amount or type of income or assets the tenant possesses. Good cause does not include refusal of the tenant to purchase the housing unless the tenant is refusing to purchase the housing pursuant to their lease-purchase agreement.</P>
                            <P>(B) Other good cause includes:</P>
                            <P>
                                (
                                <E T="03">1</E>
                                ) When a tenant or household member is a direct threat to the safety of the tenants or employees of the housing or an imminent and serious threat to the property;
                            </P>
                            <P>
                                (
                                <E T="03">2</E>
                                ) When a tenant unreasonably refuses to provide the owner access to the unit to allow the owner to repair the unit;
                            </P>
                            <P>
                                (
                                <E T="03">3</E>
                                ) When an owner must terminate a tenancy to comply with an order issued by a governmental entity or court that requires the tenant vacate the project or unit;
                            </P>
                            <P>
                                (
                                <E T="03">4</E>
                                ) When an owner must terminate a tenancy to comply with a local ordinance that necessitates vacating the project or unit; or
                            </P>
                            <P>
                                (
                                <E T="03">5</E>
                                ) When a tenant fails to purchase a housing unit within the timeframes listed within the tenant's lease-purchase agreement.
                            </P>
                            <P>(C) An owner may establish good cause for a violation of an applicable Federal, State, or local law through a record of conviction of a crime that directly threatens the health, safety, or right to peaceful enjoyment of the premises by other tenants in the project. The owner shall not use a record of arrest, parole or probation, or current indictment to establish such a violation.</P>
                            <P>(ii) To terminate or refuse to renew tenancy, the owner must serve written notice upon the tenant specifying the grounds for the action at least 30 days before the termination of tenancy and provide a copy of the notice to vacate to the participating jurisdiction within 5 business days of issuing notice to the tenant. The minimum 30-day period is not required if the termination of tenancy or refusal to renew is due to a direct threat to the safety of the tenants or employees of the housing or an imminent and serious threat to the property and the termination of tenancy or refusal to renew is in accordance with the requirements of § 92.253(b)(10)(iii).</P>
                            <P>(iii) The termination of tenancy or refusal to renew must be in accordance with Federal, State, local law, and the requirements of this part, including but not limited to requirements regarding fair housing, nondiscrimination, and VAWA;</P>
                            <P>(iv) An owner may not terminate the tenancy or evict the tenant or household members without instituting a civil court proceeding in which the tenant or household member has the opportunity to present a defense, or before a court decision on the rights of the parties; and</P>
                            <P>(v) An owner may not perform a constructive eviction such as locking a tenant out of their unit or stopping service on utilities servicing the tenant's unit. An owner may not create a hostile living environment or refuse to provide a reasonable accommodation in order to cause a tenant to terminate their tenancy in a HOME-assisted unit.</P>
                            <P>
                                (c) 
                                <E T="03">HOME tenant-based rental assistance tenancy addendum.</E>
                                 The terms of the HOME tenant-based rental assistance tenancy addendum shall prevail over any conflicting provisions of the lease. The terms and conditions of the written lease, the HOME tenant-based rental assistance tenancy addendum, the VAWA addendum listed in paragraph (a) of this section, and any addendum required by another Federal, State, or local affordable housing program shall constitute and contain the sole and entire agreement between the owner and the tenant and no prior or contemporaneous oral or written representation or agreement between the owner or tenant shall have legal effect. The terms of the HOME tenant-based rental assistance tenancy addendum shall terminate upon termination of the rental assistance contract. The HOME tenant-based rental assistance tenancy addendum shall contain the following minimum requirements:
                            </P>
                            <P>
                                (1) 
                                <E T="03">Physical condition of unit and project.</E>
                                 (i) The owner shall maintain the physical condition of the unit and property so that it meets the participating jurisdiction's property standards and State and local code requirements in accordance with § 92.251(f);
                            </P>
                            <P>(ii) With respect to maintenance and repairs to a housing unit, the owner shall:</P>
                            <P>(A) Provide the tenant with written expected time frames for maintaining or repairing units as soon as practicable;</P>
                            <P>(B) Professionally maintain and repair units in accordance with the participating jurisdiction's property standards as soon as practicable; and</P>
                            <P>(C) Not charge the tenant for normal wear and tear or damage to the unit or common areas of the property unless due to negligence, recklessness, or intentional acts by the tenant.</P>
                            <P>
                                (iii) The owner shall provide the tenant with continued, uninterrupted utility service in a property with owner-controlled utility services unless the interruption is not within the control of the owner (
                                <E T="03">e.g.,</E>
                                 a general power outage).
                            </P>
                            <P>
                                (2) 
                                <E T="03">Use and occupancy of the unit and property.</E>
                                 (i) Subject to applicable occupancy requirements under Federal, State or local law, a family may reside in the unit with a foster child, foster adult, and/or live-in aide;
                            </P>
                            <P>(ii) Except for shared housing, the tenant's household shall have the right to exclusive use and occupancy of the leased unit;</P>
                            <P>(iii) The owner may only enter the housing unit:</P>
                            <P>(A) When the owner provides reasonable advance notification to the tenant and enters during reasonable hours for the purpose of performing routine inspections and maintenance, for making improvement or repairs, or to show the housing unit for re-leasing. A written statement specifying the purpose of the owner's entry delivered to the housing unit at least 2 days before such entry is reasonable advance notification;</P>
                            <P>(B) At any time without advance notification when there is reasonable cause to believe that an emergency requiring entry to the unit exists; and</P>
                            <P>(C) The owner shall provide the tenant a written statement specifying the date, time, and purpose of entry if the tenant and all adult members of the household are absent from the housing unit at the time of entry or if the owner is entering the housing unit pursuant to paragraph (c)(2)(iii)(B) of this section;</P>
                            <P>(iv) The tenant's household shall have reasonable access to and use of the common areas of the property; and</P>
                            <P>(v) A tenant may not be required to accept supportive services that are offered unless the tenant is living in transitional housing and such supportive services are required in connection with the transitional housing.</P>
                            <P>
                                (3) 
                                <E T="03">Notice.</E>
                                 (i) Before an owner may take an adverse action against the tenant, the tenant must be notified in writing, or where necessary to accommodate an individual with a disability or language access needs, must be provided a statement that is accessible and understandable to the tenant, of the specific grounds for any proposed adverse action by the owner. Such notice should be provided in a translated format when needed to ensure meaningful access for limited English proficient (LEP) persons. Such adverse action includes, but is not limited to, imposition of charges for damages that require maintenance and repair;
                            </P>
                            <P>(ii) An owner must notify the tenant about changes affecting property ownership and management as follows:</P>
                            <P>
                                (A) Thirty (30) calendar days before a sale or foreclosure, tenants must be 
                                <PRTPAGE P="879"/>
                                notified of the impending sale or foreclosure of the property;
                            </P>
                            <P>(B) Within 5 business days of any changes of ownership, tenants must be notified of the change in ownership;</P>
                            <P>(C) Within 5 business days of any change in the property management company managing the property, tenants must be notified of the change in management company; and</P>
                            <P>(iii) The owner may not institute a lawsuit against the tenant without providing notice to the tenant.</P>
                            <P>
                                (4) 
                                <E T="03">A Tenant's rights to available legal proceedings and remedies.</E>
                                 (i) The tenant shall not be required by the owner to agree to be sued, to admit guilt, or agree to a judgment in favor of the owner in a lawsuit brought in connection with the lease;
                            </P>
                            <P>(ii) The owner may not take, hold, or sell personal property of a household member without notice to the tenant and a court decision on the rights of the parties. This prohibition, however, does not apply to an agreement by the tenant concerning disposition of personal property remaining in the housing unit after the tenant has moved out of the unit. The owner may dispose of this personal property in accordance with State law;</P>
                            <P>(iii) The tenant may hold the owner or the owner's agents legally responsible for any action or failure to act, whether intentional or negligent;</P>
                            <P>(iv) In any legal proceedings involving tenant and owner, the owner and tenant agree that the tenant shall be able to exercise the tenant's right to:</P>
                            <P>(A) Obtain independent legal representation in any legal proceedings in connection with the lease, including in any non-binding arbitration or alternative dispute resolution process;</P>
                            <P>(B) Have a trial by jury where such right is available to a tenant under Federal, State, or local law; and</P>
                            <P>(C) Appeal, or to otherwise challenge in court, a court decision in connection with the lease where such right is available to the tenant under Federal, State, or local law;</P>
                            <P>(v) The tenant may only be required to pay the owner's attorney's fees or other legal costs if the tenant loses in a court proceeding between the owner and the tenant and the court so orders.</P>
                            <P>
                                (5) 
                                <E T="03">Protection against unreasonable interference or retaliation.</E>
                                 (i) An owner may not unreasonably interfere with the tenant's safety or peaceful enjoyment of a rental unit or the common areas of the property.
                            </P>
                            <P>(ii) An owner may not retaliate against a tenant for taking any action allowable under the lease and applicable law.</P>
                            <P>(iii) Actions that evidence unreasonable interference or retaliation against a tenant include actions taken for the purpose of causing the housing to become vacant or otherwise, including but not limited to:</P>
                            <P>(A) Recovery of, or attempt to recover, possession of the housing unit in a manner that is not in accordance with paragraph (c)(10) of this section;</P>
                            <P>
                                (B) Decreasing services to the housing unit (
                                <E T="03">e.g.,</E>
                                 trash removal, maintenance) or increasing the obligations of a tenant (
                                <E T="03">e.g.,</E>
                                 new or increased monetary obligations, etc.) in a manner that is not in accordance with the requirements of this part;
                            </P>
                            <P>(C) Interfering with a tenant's right to privacy under applicable State or local law;</P>
                            <P>(D) Harassing a household or their lawful guests; and</P>
                            <P>(E) Refusing to honor the terms of the lease.</P>
                            <P>(iv) If an owner unreasonably interferes or retaliates against a tenant, then this shall constitute a material breach under the lease, a violation of HOME program requirements, and a breach of the written agreement between the owner and the participating jurisdiction. A tenant may use evidence of such unreasonable interference or retaliation in a court of law, and the participating jurisdiction must take reasonable actions to address any violation in accordance with the participating jurisdiction's responsibilities under § 92.504(a) and (c).</P>
                            <P>
                                (6) 
                                <E T="03">Exercise of rights under tenancy.</E>
                                 A tenant may exercise any right of tenancy and assert any protection under their lease and any applicable Federal, State, or local tenant protections including but not limited to:
                            </P>
                            <P>(i) Reporting inadequate housing conditions of the housing unit or property to the owner, the participating jurisdiction, code enforcement officials, or HUD;</P>
                            <P>(ii) Reporting lease violations and requesting enforcement of the written lease or any protections guaranteed under this part; and</P>
                            <P>(iii) Requesting or obtaining enforcement of any applicable protections under Federal, State, or local law.</P>
                            <P>
                                (7) 
                                <E T="03">Confidentiality.</E>
                                 An owner will keep all records containing personally identifying information of any family who is assisted with tenant-based rental assistance secure and confidential.
                            </P>
                            <P>
                                (8) 
                                <E T="03">Prohibition on discrimination.</E>
                                 The owner shall operate housing assisted under this part in accordance with all applicable nondiscrimination and equal opportunity requirements pursuant to § 92.350 and the VAWA requirements at § 92.359;
                            </P>
                            <P>
                                (9) 
                                <E T="03">Security deposits.</E>
                                 (i) Security deposits must be refundable and no greater than two months' rent. Surety bonds, security deposit insurance, and instruments similar to surety bonds or security deposit insurance may not be used in lieu of or in addition to a security deposit. Upon termination of tenancy by the owner or tenant, if the owner charges any amount against a tenant's security deposit, the owner must give the tenant a list of all items charged against the security deposit and the amount of each item. After deducting the amount, if any, used to reimburse the owner, the owner must promptly refund the full amount of the unused balance to the tenant.
                            </P>
                            <P>(ii) For tenants that are already under a lease and have already fulfilled the security deposit requirements under the lease before entering into a rental assistance contract to receive tenant-based rental assistance, the provisions of paragraph (c)(9)(i) of this section do not apply.</P>
                            <P>
                                (10) 
                                <E T="03">Termination of tenancy.</E>
                                 (i) An owner may not terminate the tenancy of any tenant or household member or refuse to renew the lease of a tenant with tenant-based rental assistance, except for serious or repeated violation of the material terms and conditions of the lease; for violation of applicable Federal, State, or local law; for completion of the tenancy period for transitional housing or failure to follow any required transitional housing supportive services plan; or for other good cause.
                            </P>
                            <P>(A) Other good cause does not include a change in the tenant's income or assets or the amount or type of income or assets the tenant possesses. Good cause does not include refusal of the tenant to purchase the housing unless the tenant is refusing to purchase the housing pursuant to their lease-purchase agreement.</P>
                            <P>(B) Good cause includes:</P>
                            <P>
                                (
                                <E T="03">1</E>
                                ) When a tenant or household member is a direct threat to the safety of the tenants or employees of the housing or an imminent and serious threat to the property;
                            </P>
                            <P>
                                (
                                <E T="03">2</E>
                                ) Serious or repeated violation of the terms and conditions of the lease;
                            </P>
                            <P>
                                (
                                <E T="03">3</E>
                                ) Violation of applicable Federal, State, or local law through a tenant's record of conviction of a crime that directly threatens the health, safety, or right to peaceful enjoyment of the premises by other tenants in the property. The owner shall not use a record of arrest, parole or probation, or current indictment to establish such a violation;
                            </P>
                            <P>
                                (
                                <E T="03">4</E>
                                ) When a tenant unreasonably refuses to provide the owner access to 
                                <PRTPAGE P="880"/>
                                the unit to allow the owner to repair the unit;
                            </P>
                            <P>
                                (
                                <E T="03">5</E>
                                ) When an owner intends to withdraw the unit from the rental market to occupy the unit; allow an owner's family member to occupy the unit; or demolish or substantially rehabilitate the unit;
                            </P>
                            <P>
                                (
                                <E T="03">6</E>
                                ) When an owner must terminate a tenancy to comply with an order issued by a governmental entity or court that requires the tenant vacate the project or unit;
                            </P>
                            <P>
                                (
                                <E T="03">7</E>
                                ) When an owner must terminate a tenancy to comply with a local ordinance that necessitates vacating the residential real property; or
                            </P>
                            <P>
                                (
                                <E T="03">8</E>
                                ) When a tenant fails to purchase a housing unit within the timeframes listed within the tenant's lease-purchase agreement.
                            </P>
                            <P>(ii) To terminate or refuse to renew tenancy, the owner must serve a written notice to vacate upon the tenant specifying the grounds for the action at least 30 days before the termination of tenancy and provide a copy of the notice to vacate to the participating jurisdiction in accordance with the rental assistance contract or the participating jurisdiction's policies and procedures. The minimum 30-day period is not required if the termination of tenancy or refusal to renew is due to a direct threat to the safety of the tenants or employees of the housing or an imminent and serious threat to the property and the termination of tenancy or refusal to renew is in accordance with the requirements of § 92.253(c)(10)(iii).</P>
                            <P>(iii) The termination of tenancy or refusal to renew must be in accordance with Federal, State, local law, and the requirements of this part, including but not limited to requirements regarding fair housing, nondiscrimination, and VAWA.</P>
                            <P>(iv) An owner may not perform a constructive eviction such as locking a tenant out of their unit or stopping service on utilities servicing the tenant's unit. An owner may not create a hostile living environment or refuse to provide a reasonable accommodation in order to cause a tenant to terminate their tenancy in a HOME-assisted unit.</P>
                            <P>
                                (d) 
                                <E T="03">HOME security deposit assistance tenancy addendum.</E>
                                 The terms of the HOME security deposit assistance tenancy addendum shall prevail over any conflicting provisions of the lease. The terms and conditions of the written lease, the HOME security deposit assistance tenancy addendum, and any addendum required by another Federal, State, or local affordable housing program shall constitute and contain the sole and entire agreement between the owner and the tenant and no prior or contemporaneous oral or written representation or agreement between the owner or tenant shall have legal effect. The lease for a tenant receiving security deposit assistance shall contain a security deposit tenancy addendum that prohibits the following terms from being present in the lease:
                            </P>
                            <P>
                                (1) 
                                <E T="03">Agreement to be sued.</E>
                                 Agreement by the tenant to be sued, to admit guilt, or to a judgment in favor of the owner in a lawsuit brought in connection with the lease;
                            </P>
                            <P>
                                (2) 
                                <E T="03">Treatment of property.</E>
                                 Agreement by the tenant that the owner may take, hold, or sell personal property of household members without notice to the tenant and a court decision on the rights of the parties. This prohibition, however, does not apply to an agreement by the tenant concerning disposition of personal property remaining in the housing unit after the tenant has moved out of the unit. The owner may dispose of this personal property in accordance with State law;
                            </P>
                            <P>
                                (3) 
                                <E T="03">Excusing owner from responsibility.</E>
                                 Agreement by the tenant not to hold the owner or the owner's agents legally responsible for any action or failure to act, whether intentional or negligent;
                            </P>
                            <P>
                                (4) 
                                <E T="03">Waiver of notice.</E>
                                 Agreement of the tenant that the owner may institute a lawsuit without notice to the tenant;
                            </P>
                            <P>
                                (5) 
                                <E T="03">Waiver of legal proceedings.</E>
                                 Agreement by the tenant that the owner may evict the tenant or household members without instituting a civil court proceeding in which the tenant has the opportunity to present a defense, or before a court decision on the rights of the parties;
                            </P>
                            <P>
                                (6) 
                                <E T="03">Waiver of a jury trial.</E>
                                 Agreement by the tenant to waive any right to a trial by jury;
                            </P>
                            <P>
                                (7) 
                                <E T="03">Waiver of right to appeal court decision.</E>
                                 Agreement by the tenant to waive the tenant's right to appeal, or to otherwise challenge in court, a court decision in connection with the lease;
                            </P>
                            <P>
                                (8) 
                                <E T="03">Tenant chargeable with cost of legal actions regardless of outcome.</E>
                                 Agreement by the tenant to pay attorney's fees or other legal costs even if the tenant wins in a court proceeding by the owner against the tenant. The tenant, however, may be obligated to pay costs if the tenant loses and the court so orders; and
                            </P>
                            <P>
                                (9) 
                                <E T="03">Mandatory supportive services.</E>
                                 Agreement by the tenant (other than a tenant in transitional housing) to accept supportive services that are offered.
                            </P>
                            <P>
                                (e) 
                                <E T="03">Tenant selection.</E>
                                 An owner of rental housing assisted with HOME funds must comply with the affirmative marketing requirements established by the participating jurisdiction pursuant to § 92.351(a). The owner must adopt and follow written tenant selection policies and criteria that:
                            </P>
                            <P>(1) Limit the housing to very low-income and low-income families;</P>
                            <P>
                                (2) Are reasonably related to the applicants' ability to perform the obligations of the lease (
                                <E T="03">i.e.,</E>
                                 to pay the rent, not to damage the housing; not to interfere with the rights and quiet enjoyment of other tenants);
                            </P>
                            <P>(3) Limit eligibility or give a preference to a particular segment of the population if permitted in its written agreement with the participating jurisdiction (and only if the limitation or preference is described in the participating jurisdiction's consolidated plan).</P>
                            <P>
                                (i) Any limitation or preference must not violate nondiscrimination requirements in § 92.350. A limitation or preference does not violate nondiscrimination requirements if the housing also receives funding from a Federal program that limits eligibility to a particular segment of the population (
                                <E T="03">e.g.,</E>
                                 the Housing Opportunity for Persons with AIDS program under 24 CFR part 574, the Shelter Plus Care program under 24 CFR part 582, the Supportive Housing program under 24 CFR part 583, supportive housing for the elderly or persons with disabilities under 24 CFR part 891), and the limit or preference is tailored to serve that segment of the population.
                            </P>
                            <P>(ii) If a project does not receive funding from a Federal program that limits eligibility to a particular segment of the population, the project may have a limitation or preference for persons with disabilities who need services offered at a project only if:</P>
                            <P>(A) The limitation or preference is limited to the population of families (including individuals) with disabilities that significantly interfere with their ability to obtain and maintain housing;</P>
                            <P>(B) Such families will not be able to obtain or maintain themselves in housing without appropriate supportive services; and</P>
                            <P>(C) The families must not be required to accept the services offered at the project. The owner may advertise the project as offering various supportive services, including a description of the specific supportive services available. The project must be open to all eligible persons with disabilities.</P>
                            <P>
                                (4) Do not exclude an applicant with Federal, State, or local tenant-based rental assistance, such as an applicant with a voucher under the Housing Choice Voucher Program (24 CFR part 982) or an applicant participating in a HOME tenant-based rental assistance 
                                <PRTPAGE P="881"/>
                                program, because of the status of applicant as a holder of such type of assistance;
                            </P>
                            <P>(5) Except for small-scale housing, provide for the selection of tenants from a written waiting list in the chronological order of their application, insofar as is practicable. The participating jurisdiction may establish alternative procedures to a written waiting list for the selection of tenants in small-scale housing;</P>
                            <P>(6) Give prompt written notification to any rejected applicant of the grounds for any rejection;</P>
                            <P>(7) Comply with the VAWA requirements prescribed in § 92.359; and</P>
                            <P>(8) Comply with the nondiscrimination requirements prescribed in § 92.350.</P>
                            <P>
                                (f) 
                                <E T="03">Health and safety.</E>
                                 In addition to the requirements in § 92.355, if a participating jurisdiction has actual knowledge of an environmental, health, or safety hazard affecting a project, unit, or HOME tenants, the participating jurisdiction must contact the affected owner and tenants in writing and provide them with a summary of the nature, date, and scope of such hazards. If an owner has actual knowledge of an environmental, health, or safety hazard affecting their project, units within their project, or tenants residing within their projects, the owner must inform the participating jurisdiction and HOME-assisted tenants in writing and provide them with a summary of the nature, date, and scope of such hazards. This notification requirement only applies to environmental, health, and safety hazards that are discovered after an environmental review performed pursuant to § 92.352 has already taken place. When either the participating jurisdiction or the owner notifies the tenants of the housing, this satisfies the requirement for the other party.
                            </P>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>28. Amend § 92.254 by:</AMDPAR>
                        <AMDPAR>a. Revising paragraph (a)(2)(iii);</AMDPAR>
                        <AMDPAR>b. Adding paragraph (a)(2)(iv);</AMDPAR>
                        <AMDPAR>c. Revising paragraphs (a)(3) and (4), (a)(5)(i) and (ii), and (a)(6) through (8);</AMDPAR>
                        <AMDPAR>d. Redesignating paragraphs (b) through (f) as paragraphs (c) through (g) and redesignating paragraph (a)(9) as paragraph (b);</AMDPAR>
                        <AMDPAR>e. Revising newly redesignated paragraph (b); and</AMDPAR>
                        <AMDPAR>f. Revising newly redesignated paragraphs (f) introductory text and (g)(1) and (3),</AMDPAR>
                        <P>The revisions and additions read as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.254</SECTNO>
                            <SUBJECT>Qualification as affordable housing: Homeownership.</SUBJECT>
                            <P>(a) * * *</P>
                            <P>(2) * * *</P>
                            <P>(iii) If a participating jurisdiction intends to use HOME funds for homebuyer assistance or for the rehabilitation of owner-occupied single family properties, the participating jurisdiction must use the HOME affordable homeownership limits provided by HUD for newly constructed housing and for existing housing.</P>
                            <P>(A) HUD will provide limits for affordable newly constructed housing based on 95 percent of the median purchase price for the area using Federal Housing Administration (FHA) single family mortgage program data for newly constructed housing, with a minimum limit based on 95 percent of the U.S. median purchase price for new construction for nonmetropolitan areas.</P>
                            <P>(B) HUD will provide limits for affordable existing housing based on 95 percent of the median area purchase price for the area using FHA single family mortgage program data for existing housing and other appropriate data that are available Nation-wide for purchase of existing housing, with a minimum limit based on 95 percent of the State-wide nonmetropolitan area median area purchase price using this data.</P>
                            <P>(iv) In lieu of the limits provided by HUD, the participating jurisdiction may determine 95 percent of the median area purchase price for single family housing in the jurisdiction annually, as follows:</P>
                            <P>(A) The participating jurisdiction must set forth the limits for single family housing of one, two, three, and four units, for the jurisdiction. The participating jurisdiction may determine separate limits for existing housing and newly constructed housing.</P>
                            <P>(B) For the limits on housing located outside of metropolitan areas, a State may aggregate sales data from more than one county if the counties are contiguous and similarly situated.</P>
                            <P>(C) The participating jurisdiction must include the following information in the annual action plan of the Consolidated Plan submitted to HUD for review and must update the information in each action plan.</P>
                            <P>
                                (
                                <E T="03">1</E>
                                ) The 95 percent of median area purchase price must be established in accordance with a market analysis that ensured that a sufficient number of recent housing sales are included in the survey;
                            </P>
                            <P>
                                (
                                <E T="03">2</E>
                                ) Sales must cover the requisite number of months based on volume: For 500 or more sales per month, a 1-month reporting period; for 250 through 499 sales per month, a 2-month reporting period; for less than 250 sales per month, at least a 3-month reporting period. The data must be listed in ascending order of purchase price;
                            </P>
                            <P>
                                (
                                <E T="03">3</E>
                                ) The address of the listed properties must include the location within the participating jurisdiction. Lot, square, and subdivision data may be substituted for the street address;
                            </P>
                            <P>
                                (
                                <E T="03">4</E>
                                ) The housing sales data must reflect all, or nearly all, of the single family housing sales in the entire participating jurisdiction; and.
                            </P>
                            <P>
                                (
                                <E T="03">5</E>
                                ) To determine the median area purchase price, a participating jurisdiction must take the middle sale on the list if an odd number of sales, and if an even number, take the higher of the middle numbers and consider it the median. After identifying the median area purchase price, the amount should be multiplied by 0.95 to determine the 95 percent of the median area purchase price.
                            </P>
                            <P>(3) The housing must be acquired by a homebuyer whose family qualifies as a low-income family, and the housing must be the principal residence of the family throughout the period described in paragraph (a)(4) of this section. If there is no ratified sales contract with an eligible homebuyer for the housing within 12 months of the date of completion of construction or rehabilitation, the housing must be rented to an eligible tenant as affordable rental housing and must comply with the requirements in § 92.252, including the period of affordability in § 92.252(d). In determining the income eligibility of the family, the participating jurisdiction must include the income of all persons living in the housing. The homebuyer must receive housing counseling. If housing is being purchased by an in-place tenant pursuant to § 92.255, then the housing may be acquired if the homebuyer's family was low-income at the time the homebuyer's family began occupying the HOME rental housing unit. If the housing does not meet the participating jurisdiction's property standards in § 92.251 at the time of acquisition, then the housing may still be acquired if the written agreement between the participating jurisdiction and the homebuyer requires the property to meet the standards within the period specified in § 92.251(c)(3)(ii) and funding is secured to complete the rehabilitation necessary to comply with the standards.</P>
                            <P>
                                (4) 
                                <E T="03">Periods of affordability.</E>
                                 The HOME-assisted housing must meet the affordability requirements for not less than the applicable period specified in the following table, beginning after execution of the instrument that requires the recapture of the HOME investment or recordation of the resale restrictions for sale to the next 
                                <PRTPAGE P="882"/>
                                homebuyer. Execution of the instrument that requires the recapture of the HOME investment or recordation of the resale restrictions for sale to the next homebuyer may only occur after the housing meets the participating jurisdiction's property standards in accordance with § 92.251(c)(3) and the property title is transferred to the homebuyer. The per unit amount of HOME funds and the period of affordability that they trigger are described more fully in paragraphs (a)(5)(i) (resale) and (ii) (recapture) of this section. The period of affordability is based on the total amount of HOME funds invested in the housing.
                            </P>
                            <GPOTABLE COLS="2" OPTS="L2,i1" CDEF="s50,12">
                                <TTITLE>
                                    Table 1 to Paragraph (
                                    <E T="01">a</E>
                                    )(4)
                                </TTITLE>
                                <BOXHD>
                                    <CHED H="1">Homeownership assistance HOME amount per-unit</CHED>
                                    <CHED H="1">
                                        Minimum 
                                        <LI>period of </LI>
                                        <LI>affordability in years</LI>
                                    </CHED>
                                </BOXHD>
                                <ROW>
                                    <ENT I="01">Under $25,000</ENT>
                                    <ENT>5</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">$25,000 to $50,000</ENT>
                                    <ENT>10</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Over $50,000</ENT>
                                    <ENT>15</ENT>
                                </ROW>
                            </GPOTABLE>
                            <P>(5) * * *</P>
                            <P>
                                (i) 
                                <E T="03">Resale.</E>
                                 Resale requirements must ensure, if the housing does not continue to be the principal residence of the family for the duration of the period of affordability, that the housing is made available for subsequent purchase only to a buyer whose family qualifies as a low-income family and will use the property as the family's principal residence. The resale requirement must also ensure that the price at resale provides the HOME-assisted homeowner a fair return on investment (including the homeowner's investment and any improvements) and ensure the housing will remain affordable to a reasonable range of low-income homebuyers. The resale price is the fair return on investment added to the original sales price of the property, subject to market conditions. The participating jurisdiction must specifically define “fair return on investment” and “affordability to a reasonable range of low-income homebuyers,” and specifically address how it will make the housing affordable to a low-income homebuyer in the event that the resale price necessary to provide a fair return is not affordable to the subsequent homebuyer. The period of affordability is based on the total amount of HOME funds invested in the housing.
                            </P>
                            <P>(A) Permissible methods of determining fair return and the resale price include but are not limited to the following:</P>
                            <P>
                                (
                                <E T="03">1</E>
                                ) 
                                <E T="03">Itemized formula.</E>
                                 To determine fair return on investment and resale price, the participating jurisdiction may use an itemized formula to add or subtract common, clearly defined factors that increase or decrease the value of a homeowner's investment in the property over the term of ownership. This formula must include the value of capital improvements and the sum of the downpayment and all principal payments by the homeowner on the loan secured by the property. The formula may depreciate the value of the capital improvements and may take into consideration any reduction in value due to property damage or delayed or deferred maintenance of the property condition. The fair return on a homeowner's investment under this formula is calculated by taking the sum of the defined factors for the homeowner's investment in the property over the term of ownership and multiplying this amount by a clearly defined, publicly accessible index or standard.
                            </P>
                            <HD SOURCE="HD1">
                                Formula 1 to Paragraph (a)(5)(i)(A)(
                                <E T="03">1</E>
                                )
                            </HD>
                            <GPH SPAN="3" DEEP="105">
                                <GID>ER06JA25.000</GID>
                            </GPH>
                            <P>
                                (
                                <E T="03">2</E>
                                ) 
                                <E T="03">Appraisal formula.</E>
                                 The participating jurisdiction may use an appraisal formula to determine fair return on investment and resale price based on the amount of market appreciation, if any, over the term of ownership. Under this method, the appraisals must be conducted by a State licensed or certified third-party appraiser. The amount of market appreciation over the term of ownership is determined by subtracting the appraised value at the time of initial purchase from the appraised value of the property at the time of resale. The fair return on a homeowner's investment under this formula is calculated by multiplying a clearly defined, publicly accessible standard or index by the amount of market appreciation over the term of homeownership.
                            </P>
                            <HD SOURCE="HD1">
                                Formula 2 to Paragraph (a)(5)(i)(A)(
                                <E T="03">2</E>
                                )
                            </HD>
                            <GPH SPAN="3" DEEP="29">
                                <GID>ER06JA25.001</GID>
                            </GPH>
                            <P>
                                (
                                <E T="03">3</E>
                                ) 
                                <E T="03">Index formula.</E>
                                 The participating jurisdiction may use an index formula to determine fair return on investment and resale price based on the change in value of a homeowner's investment over the term of ownership. Index formulas adjust the value of the homeowner's investment in proportion to changes in an index, such as the change in median household income. To determine the homeowner's fair return using this model, the sum of the property's original purchase price and the value of any capital improvements to the property is multiplied by the change in the specified index during the term of ownership. The formula may also depreciate the value of the capital improvements and may take into consideration any reduction in value due to property damage or delayed or 
                                <PRTPAGE P="883"/>
                                deferred maintenance of the property condition.
                            </P>
                            <HD SOURCE="HD1">
                                Formula 3 to Paragraph (a)(5)(i)(A)(
                                <E T="03">3</E>
                                )
                            </HD>
                            <GPH SPAN="3" DEEP="105">
                                <GID>ER06JA25.002</GID>
                            </GPH>
                            <P>
                                (
                                <E T="03">4</E>
                                ) 
                                <E T="03">Fixed-rate formula.</E>
                                 The participating jurisdiction may use a fixed-rate formula to determine the homeowner's fair return on investment. Fixed-rate formulas adjust the value of the homeowner's investment by a fixed percentage (rate) per year (
                                <E T="03">e.g.,</E>
                                 3.5 percent). To determine the fair return on investment using this model, the fixed rate is multiplied by the number of years the homeowner owned and occupied the home (
                                <E T="03">e.g.,</E>
                                 3.5 percent × 10 years = 35%). The resulting rate is then multiplied by the sum of the original purchase price of the home and the value of any capital improvements to the property to calculate the fair return to the homeowner. The formula may also depreciate the value of the capital improvements and may take into consideration any reduction in value due to property damage or delayed or deferred maintenance of the property condition.
                            </P>
                            <HD SOURCE="HD1">
                                Formula 4 to Paragraph (a)(5)(i)(A)(
                                <E T="03">4</E>
                                )
                            </HD>
                            <GPH SPAN="3" DEEP="105">
                                <GID>ER06JA25.003</GID>
                            </GPH>
                            <P>(B) Except as provided in paragraph (a)(5)(i)(C) of this section, deed or use restrictions, a recorded agreement restricting the use of the property, liens on real property, covenants running with the land, or other similar mechanisms approved by HUD in writing must be used to impose the resale requirements.</P>
                            <P>(C) The affordability restrictions may terminate upon occurrence of any of the following termination events: foreclosure, transfer in lieu of foreclosure, or assignment of an FHA-insured mortgage to HUD. If the owner of record before the termination event obtains an ownership interest in the property after the termination event, then the affordability restrictions shall be revived under the same terms prior to the termination event, including a minimum period of affordability equal to the terminated period of affordability.</P>
                            <P>
                                (D) Certain housing may be presumed to meet the resale restrictions (
                                <E T="03">i.e.,</E>
                                 the housing will be available and affordable to a reasonable range of low-income homebuyers; a low-income homebuyer will occupy the housing as the family's principal residence; and the original owner will be afforded a fair return on investment) during the period of affordability without the imposition of enforcement mechanisms by the participating jurisdiction. The presumption must be based upon a market analysis of the neighborhood in which the housing is located. The market analysis must include an evaluation of the location and characteristics of the housing and residents in the neighborhood (
                                <E T="03">e.g.,</E>
                                 sale prices, age and amenities of the housing stock, incomes of residents, percentage of owner-occupants) in relation to housing and incomes in the housing market area. An analysis of the current and projected incomes of neighborhood residents for an average period of affordability for homebuyers in the neighborhood must support the conclusion that a reasonable range of low-income families will continue to qualify for mortgage financing. For example, an analysis shows that the housing is modestly priced within the housing market area and that families with incomes of 65 percent to 80 percent of the area median income can afford monthly payments under average FHA terms without other government assistance and housing will remain affordable at least during the next five to seven years compared to other housing in the market area; the size and amenities of the housing are modest and substantial rehabilitation will not significantly increase the market value; the neighborhood has housing that is not currently owned by the occupants, but the participating jurisdiction is encouraging homeownership in the neighborhood by providing homeownership assistance and by making improvements to the streets, sidewalks, and other public facilities and services. If a participating jurisdiction in preparing a neighborhood revitalization strategy under § 91.215(e)(2) of its Consolidated Plan has incorporated the type of market data described above, that submission may serve as the required analysis under this section. If the participating jurisdiction continues to provide homeownership assistance for housing in the neighborhood, it must 
                                <PRTPAGE P="884"/>
                                periodically update the market analysis to verify the original presumption of continued affordability.
                            </P>
                            <P>
                                (ii) 
                                <E T="03">Recapture.</E>
                                 (A) Recapture provisions must require that the participating jurisdiction recoups all or a portion of the HOME assistance provided to the homebuyers if the housing does not continue to be the principal residence of the family for the duration of the period of affordability. The participating jurisdiction may structure its recapture provisions based on its program design and market conditions. The period of affordability is based upon the amount of HOME funds that directly assisted the homebuyer to buy the housing unit. This amount includes any HOME assistance that assisted the homebuyer to purchase the housing or reduced the purchase price paid by the homebuyer from fair market value to an affordable price but excludes the amount of HOME assistance provided to develop the unit that does not assist the homebuyer or reduce the purchase price paid by the homebuyer. Recapture provisions may permit the subsequent homebuyer to assume the HOME assistance (subject to the HOME requirements for the remainder of the period of affordability) if the subsequent homebuyer is low-income and no additional HOME assistance is provided.
                            </P>
                            <P>(B) The following options for recapture requirements are acceptable to HUD. The participating jurisdiction may adopt, modify, or develop its own recapture requirements for HUD approval. In establishing its recapture requirements, the participating jurisdiction is subject to the limitation that when the recapture requirement is triggered by a sale (voluntary or involuntary) of the housing unit, the amount recaptured cannot exceed the net proceeds, if any. The net proceeds are the sales price minus superior loan repayment (other than HOME funds) and any closing costs.</P>
                            <P>
                                (
                                <E T="03">1</E>
                                ) 
                                <E T="03">Recapture entire amount.</E>
                                 The participating jurisdiction may recapture the entire amount of the HOME investment from the homeowner.
                            </P>
                            <P>
                                (
                                <E T="03">2</E>
                                ) 
                                <E T="03">Reduction during period of affordability.</E>
                                 The participating jurisdiction may reduce the HOME investment amount to be recaptured on a pro rata basis for the time the homeowner has owned and occupied the housing measured against the required period of affordability.
                            </P>
                            <P>
                                (
                                <E T="03">3</E>
                                ) 
                                <E T="03">Shared net proceeds.</E>
                                 If the net proceeds are not sufficient to recapture the full HOME investment (or a reduced amount as provided for in paragraph (a)(5)(ii)(A)(
                                <E T="03">2</E>
                                ) of this section) plus enable the homeowner to recover the amount of the homeowner's downpayment and any capital improvement investment made by the owner since purchase, the participating jurisdiction may share the net proceeds. The net proceeds are the sales price minus loan repayment (other than HOME funds) and closing costs. The net proceeds may be divided proportionally as set forth in the following mathematical formulas:
                            </P>
                            <HD SOURCE="HD1">
                                Formula 5 to Paragraph (a)(5)(ii)(A)(
                                <E T="03">2</E>
                                )
                            </HD>
                            <GPH SPAN="3" DEEP="62">
                                <GID>ER06JA25.004</GID>
                            </GPH>
                            <P>
                                (
                                <E T="03">4</E>
                                ) 
                                <E T="03">Owner investment returned first.</E>
                                 The participating jurisdiction may permit the homebuyer to recover the homebuyer's entire investment (downpayment and capital improvements made by the owner since purchase) before recapturing the HOME investment.
                            </P>
                            <P>
                                (
                                <E T="03">5</E>
                                ) 
                                <E T="03">Amount subject to recapture.</E>
                                 The HOME investment subject to recapture is the amount of HOME funds that directly assisted the homebuyer to buy the housing. This includes the amount that assisted the homebuyer to purchase the housing or reduced the purchase price paid by the homebuyer from fair market value to an affordable price but excludes the amount of HOME assistance provided to develop the unit that did not assist the homebuyer or reduce the purchase price paid by the homebuyer. The recaptured funds must be used to carry out HOME-eligible activities in accordance with the requirements of this part. If the HOME assistance is only used for the development subsidy and therefore not subject to recapture, the resale option must be used.
                            </P>
                            <P>
                                (6) 
                                <E T="03">Special considerations for single family properties with more than one unit.</E>
                                 If the HOME funds are only used to assist a low-income homebuyer to acquire one unit in single family housing containing more than one unit and the assisted unit will be the principal residence of the homebuyer, the affordability requirements of this section apply only to the assisted unit. If HOME funds are also used to assist the low-income homebuyer to acquire one or more rental units in the single-family housing, the affordability requirements of § 92.252 apply to the assisted rental units, except that the participating jurisdiction may impose resale or recapture restrictions on all assisted units (owner-occupied and rental units) in the single-family housing. If resale restrictions are used, the affordability requirements on all assisted units continue for the period of affordability. If recapture restrictions are used, the affordability requirements on the assisted rental units may be terminated, at the discretion of the participating jurisdiction, upon recapture of the HOME investment. If HOME funds are used to assist only the rental units in a single-family property, then the requirements of § 92.252 would apply and the owner-occupied unit would not be subject to the income targeting or affordability provisions of § 92.254.
                            </P>
                            <P>
                                (7) 
                                <E T="03">Lease-purchases in the HOME program.</E>
                                 A homeownership project may consist of acquisition, rehabilitation, or new construction of housing to be sold to an eligible low-income homebuyer through a lease-purchase program.
                            </P>
                            <P>(i) The homebuyer must qualify as a low-income family at the time of signing the lease-purchase agreement. In determining the income eligibility of the family, the participating jurisdiction must include the income of all persons living in the housing. If a family is also receiving HOME tenant-based rental assistance, the participating jurisdiction is not required to reexamine the family's income during the term of the lease-purchase agreement.</P>
                            <P>
                                (ii) The owner and homebuyer must execute a lease-purchase agreement under an existing lease-purchase program prior to occupancy of the unit. The lease-purchase agreement must require the purchase of the housing within 36 months of execution. Owners and homebuyers that have entered into a lease-purchase agreement pursuant to the requirements in this paragraph are 
                                <PRTPAGE P="885"/>
                                subject to the affordability requirements in this section unless the housing is not purchased within the required timeframes in this paragraph in accordance with the lease-purchase agreement.
                            </P>
                            <P>(iii) If the first homebuyer does not acquire the housing in accordance with the lease-purchase agreement, the owner must sell the housing to another eligible low-income homebuyer within 48 months from the execution of the original lease-purchase agreement. The next homebuyer is eligible for homeownership assistance from the participating jurisdiction. The owner is not permitted to sell the unit through another lease-purchase agreement. When the next homebuyer purchases the housing, the homebuyer shall be subject to the affordability requirements in this section.</P>
                            <P>(iv) If the owner is unable to sell the unit within 48 months from the execution of the lease-purchase agreement, the housing is subject to the requirements for affordable rental housing in § 92.252.</P>
                            <P>
                                (8) 
                                <E T="03">Contract to purchase.</E>
                                 If HOME funds are used to assist a homebuyer who has entered into a contract to purchase housing to be constructed, the homebuyer must qualify as a low-income family at the time the contract is signed.
                            </P>
                            <P>
                                (b) 
                                <E T="03">Preserving affordability of housing assisted with HOME funds.</E>
                                 When there is a termination event for affordability restrictions, a participating jurisdiction may take the following actions to preserve the affordability of the property:
                            </P>
                            <P>(1) The participating jurisdiction may exercise purchase options, rights of first refusal, or other preemptive rights to obtain ownership of the housing before foreclosure to preserve affordability, subject to the following requirements:</P>
                            <P>(i) The housing must be sold to an eligible homebuyer in accordance with paragraph (a)(3) of this section within 12 months of the date the participating jurisdiction obtains ownership;</P>
                            <P>
                                (ii) The period of affordability for the eligible homebuyer must be equal to the remaining period of affordability of the former homeowner unless additional HOME funds are used to directly assist the eligible homebuyer (
                                <E T="03">i.e.,</E>
                                 homeownership assistance);
                            </P>
                            <P>(iii) If the participating jurisdiction directly assists the eligible homebuyer with additional HOME funds, then the period of affordability must be recalculated in accordance with the table in § 92.254(a)(4) based on the total amount of additional HOME funds invested. The additional investment must be treated as a new project; and</P>
                            <P>(iv) The total HOME funds for a project (original investment plus additional investment) must not exceed the per-unit subsidy limit in § 92.250(a) in effect at the time of the additional investment, subject to HUD approval.</P>
                            <P>(2) The participating jurisdiction may use additional HOME funds for the following costs:</P>
                            <P>(i) The cost for the participating jurisdiction to obtain ownership of the HOME-assisted housing through a purchase option, right of first refusal, or other preemptive right before foreclosure or at the foreclosure sale. This cost must be treated as an amendment to the original project. The foreclosure costs to acquire housing with a HOME loan in default is an eligible cost; however, HOME funds may not be used to repay a loan made with HOME funds.</P>
                            <P>(ii) The cost of the participating jurisdiction to undertake any necessary rehabilitation for the housing acquired. This includes the rehabilitation required for the housing to meet applicable property standards in § 92.251. This cost must be treated as an amendment to the original project.</P>
                            <P>(iii) The cost to the participating jurisdiction of owning the housing pending resale to another homebuyer. This cost must be treated as an amendment to the original project.</P>
                            <P>(iv) The cost to assist an eligible homebuyer in purchasing the housing. This cost must be treated as a cost for a new project and not as an amendment to the original project.</P>
                            <P>(v) As an alternative to charging costs to the HOME program under § 92.206, the participating jurisdiction may charge the costs to the HOME program under § 92.207 as a reasonable administrative cost of its HOME program. To the extent administrative funds are used, they may be reimbursed, in whole or in part, when the housing is sold to a new eligible homebuyer. If the housing is sold for more than the amount of administrative funds that the participating jurisdiction expended to preserve the affordability, then the excess sale proceeds shall be program income.</P>
                            <P>(3) The participating jurisdiction may permit the Community Land Trust, as defined in § 92.2, that originally developed the HOME-assisted housing, to exercise a purchase option, right of first refusal, or other preemptive right to obtain ownership of the housing to preserve affordability, including but not limited to the right to purchase the housing in lieu of foreclosure, under the following conditions:</P>
                            <P>(i) The Community Land Trust obtains ownership of the housing, subject to existing HOME affordability restrictions;</P>
                            <P>(ii) The housing must be resold to an eligible homebuyer in accordance with paragraph (a)(3) of this section within 12 months;</P>
                            <P>
                                (iii) The period of affordability for the eligible homebuyer is equal to the remaining period of affordability of the former homeowner, unless the participating jurisdiction provides additional HOME funds to directly assist the eligible homebuyer in accordance with subparagraph (b)(3)(iv) below (
                                <E T="03">i.e.,</E>
                                 homeownership assistance); and,
                            </P>
                            <P>(iv) The participating jurisdiction may not provide additional HOME funds to the Community Land Trust to obtain ownership, rehabilitate the housing, own/hold the housing pending resale to the next homebuyer, or provide homeownership assistance to the next eligible homebuyer. The participating jurisdiction may provide homeownership assistance to the next eligible homebuyer and the period of affordability shall be based upon the homeownership assistance provided to the homebuyer, in accordance with subparagraphs (b)(1)(iii) and (b)(1)(iv) of this section.</P>
                            <STARS/>
                            <P>
                                (f) 
                                <E T="03">Providing homeownership assistance through lenders.</E>
                                 Subject to the requirements of paragraph (f) of this section, the participating jurisdiction may provide homeownership assistance through a lending institution that is a contractor or nonprofit lending institution that is a subrecipient that also provides the first mortgage loan to a low-income family.
                            </P>
                            <STARS/>
                            <P>(g) * * *</P>
                            <P>(1) Underwriting standards for homeownership assistance to determine the amount of assistance necessary to achieve sustainable homeownership. These standards must evaluate the projected overall debt of the family after the purchase of the housing, the maximum amount that a participating jurisdiction may provide a family, the appropriateness of the amount of assistance, assets available to a family to acquire the housing, and financial resources to sustain homeownership. A participating jurisdiction may not provide a single, fixed amount of assistance to each homebuyer that participates in the participating jurisdiction's homebuyer program;</P>
                            <STARS/>
                            <P>(3) Refinancing loans to which HOME loans are subordinated to require that the terms of the new loan are reasonable.</P>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <PRTPAGE P="886"/>
                        <AMDPAR>29. Revise § 92.255 to read as follows:</AMDPAR>
                        <SECTION>
                            <SECTNO>§ 92.255</SECTNO>
                            <SUBJECT>Purchase of HOME units by in-place tenants.</SUBJECT>
                            <P>(a) During a HOME-assisted rental unit's period of affordability, the participating jurisdiction may permit an owner to sell or otherwise convey a HOME-assisted rental unit to an existing tenant in accordance with the requirements of § 92.254. However, refusal by the tenant to purchase the housing does not constitute good cause for termination of tenancy or failure to renew the lease. The participating jurisdiction may not permit the use of a lease-purchase program under this section.</P>
                            <P>(b) If no additional HOME funds are used to enable the tenants to become homeowners, the homeownership units are subject to a period of affordability equal to the remaining period of affordability if the units continued as rental units. The participating jurisdiction must impose resale requirements that comply with § 92.254(a) for the required period of affordability. The period of affordability and resale restrictions must be applied to the property regardless of the income of the family at purchase. If the tenant's family is no longer low-income at the time of the purchase, then the family must occupy the housing as a principal residence in accordance with § 92.254(a)(3) and must agree to the imposition of resale restrictions on the housing, in accordance with § 92.254(a)(5), for the period of affordability specified in this paragraph (b).</P>
                            <P>(c) If additional HOME funds are used to directly assist the tenants to become homeowners, the period of affordability is the remaining period of affordability if the unit had remained a rental unit or the required period under § 92.254(a)(4) for the amount of direct homeownership assistance provided, whichever is longer. No additional HOME funds may be provided to an in-place tenant to become a homebuyer if the tenant's family is no longer low-income at the time of the purchase.</P>
                        </SECTION>
                    </REGTEXT>
                    <SECTION>
                        <SECTNO>§ 92.258</SECTNO>
                        <SUBJECT>[Amended]</SUBJECT>
                    </SECTION>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>30. Amend § 92.258 by:</AMDPAR>
                        <AMDPAR>a. Removing the words “single-family dwelling” and adding in their place the words “single family housing units” in paragraph (a);</AMDPAR>
                        <AMDPAR>b. Removing the word “single-family” and adding in their place the words “single family” paragraph (b)(1); and</AMDPAR>
                        <AMDPAR>c. Removing the words “affordability period” and adding in their place the words “period of affordability” paragraphs (c) and (d)(3) introductory text; and</AMDPAR>
                        <AMDPAR>d. Removing “§ 92.252(e)” and adding in its place “§ 92.252(d)” in paragraph (d)(3) introductory text.</AMDPAR>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>31. Amend § 92.300 by:</AMDPAR>
                        <AMDPAR>a. Removing the words “developed or sponsored” and adding in their place the words “developed, or sponsored” in the first sentence of paragraph (a) introductory text;</AMDPAR>
                        <AMDPAR>b. Revise paragraphs (a)(2) through (4) and (a)(5) introductory text;</AMDPAR>
                        <AMDPAR>c. Removing the word “nonprofit” and adding in its place the words “private nonprofit” in paragraph (a)(5)(iii) introductory text;</AMDPAR>
                        <AMDPAR>d. Removing “community development housing organization” and adding in its place “community housing development organization” and by removing the word “new” in paragraph (a)(6) introductory text;</AMDPAR>
                        <AMDPAR>e. Revising paragraphs (a)(6)(i), (a)(6)(ii)(A), and (a)(7) and the last sentence of paragraph (b);</AMDPAR>
                        <AMDPAR>f. Removing the words “developed or sponsored” and adding in their place the words “developed, or sponsored” and by removing the words “and specifies” and adding in their place the words “and must specify” in paragraph (e); and</AMDPAR>
                        <AMDPAR>g. Revising the first sentence of paragraph (f).</AMDPAR>
                        <P>The revisions read as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.300</SECTNO>
                            <SUBJECT>Set-aside for community housing development organizations (CHDOs).</SUBJECT>
                            <P>(a) * * *</P>
                            <P>(2) Rental housing is “owned” by the community housing development organization if the community housing development organization is the owner in fee simple absolute of rental housing (or has a long term ground lease running for the full period of affordability in § 92.252) leased to low-income families in accordance with § 92.252. If the housing is to be rehabilitated or constructed, the community housing development organization hires and oversees the developer that rehabilitates or constructs the housing. The community housing development organization must oversee or hire and contract with an experienced project manager to oversee all aspects of the development, including obtaining zoning, securing non-HOME financing, selecting a developer or general contractor, overseeing the progress of the work, and determining the reasonableness of costs. The community housing development organization must own the rental housing during development and for a period at least equal to the period of affordability in § 92.252. If the CHDO acquires housing that meets the property standards in § 92.251, the CHDO must own the rental housing for a period at least equal to the period of affordability in § 92.252.</P>
                            <P>
                                (3) Rental housing is “developed” by the community housing development organization if the community housing development organization is the owner in fee simple absolute (or has a long term ground lease running for the full period of affordability in § 92.252) and the developer of new housing that will be constructed or existing substandard housing that will be rehabilitated for rent to low-income families in accordance with § 92.252. To be the “developer,” the community housing development organization may share developer responsibilities with another entity but must be in charge of all aspects of the development process, including selecting the site, obtaining permit approvals and all project financing, selecting architects, engineers, and general contractors, overseeing project progress, and determining the reasonableness of costs. The requirement that a community housing development organization is in charge of all aspects of the development process must be enforceable through a written agreement (
                                <E T="03">e.g.,</E>
                                 a joint venture agreement or master development agreement). At a minimum, the community housing development organization must own the housing during development and for a period at least equal to the period of affordability in § 92.252. The participating jurisdiction may permit the community housing development organization to sell or otherwise convey the housing to a nonprofit organization other than a community housing development organization, subject to all applicable requirements of this part, if the participating jurisdiction determines and documents that the community housing development organization no longer has the capacity to own and manage the housing for the full period of affordability and there are no other community housing development organizations within the jurisdiction with capacity to own and manage the project for the full period of affordability.
                            </P>
                            <P>
                                (4) Rental housing is “sponsored” by the community housing development organization if it is rental housing “owned” or “developed” in accordance with paragraph (a)(2) or (3) of this section, as applicable, by a subsidiary of a community housing development organization, a limited partnership of which the community housing development organization or its subsidiary is the managing general partner, or a limited liability company 
                                <PRTPAGE P="887"/>
                                of which the community housing development organization or its subsidiary is the managing member.
                            </P>
                            <P>(i) The subsidiary of the community housing development organization may be a for-profit or nonprofit organization and must be wholly owned by the community housing development organization. If the limited partnership or limited liability company agreement permits the community housing development organization or its subsidiary to be removed as the managing general partner or managing member, the agreement must provide that the removal must be for cause and that the community housing development organization must be replaced with another community housing development organization.</P>
                            <P>(ii) The HOME funds must be provided by the participating jurisdiction directly to the entity that owns the project.</P>
                            <P>(5) HOME-assisted rental housing is also “sponsored” by a community housing development organization if the community housing development organization “developed” the rental housing project in accordance with paragraph (a)(3) of this section and agrees to convey the project to an identified private nonprofit organization at a predetermined time after completion of the project. Sponsored rental housing, as provided in this paragraph (a)(5), is subject to the following requirements:</P>
                            <STARS/>
                            <P>(6) * * *</P>
                            <P>
                                (i) To be the “developer,” the community housing development organization may share the developer role with another entity but must be in charge of all aspects of the development process, including selecting the site, obtaining permit approvals and all project financing, selecting architects, engineers, and general contractors, overseeing project progress, determining the reasonableness of costs, identifying eligible homebuyers, and overseeing the sale of homeownership units. The community housing development organization may provide direct homeownership assistance (
                                <E T="03">e.g.,</E>
                                 assistance with a downpayment, payment of closing costs, mortgage rate buy-downs, etc.) when it sells the housing to low-income families and the community housing development organization will not be considered a subrecipient. The HOME funds for homeownership assistance shall not be greater than 10 percent of the amount of HOME funds for development of the housing.
                            </P>
                            <P>(ii) * * *</P>
                            <P>(A) While proceeds retained by the community housing development organization are not subject to the requirements of this part, the participating jurisdiction must specify in the written agreement with the community housing development organization whether the proceeds are to be used for HOME-eligible activities or other housing activities to benefit low-income families.</P>
                            <STARS/>
                            <P>
                                (7) The participating jurisdiction must determine the form of assistance (
                                <E T="03">e.g.,</E>
                                 grant or loan) in accordance with § 92.205(b) that it will provide to the community housing development organization for a rental housing project under paragraph (a)(4) of this section and must provide the assistance directly to the entity that owns the project.
                            </P>
                            <P>(b) * * * If during the first 24 months of its participation in the HOME Program a participating jurisdiction cannot identify a sufficient number of capable community housing development organizations, up to 20 percent of the minimum community housing development organization set aside specified in paragraph (a) of this section (but not more than $150,000 during the 24 month period) may be committed to an organization that meets the definition of “community housing development organization” in § 92.2, except for the requirements in paragraph (9) of the definition, in order to develop demonstrated capacity and qualify as a community housing development organization in the jurisdiction.</P>
                            <STARS/>
                            <P>(f) The participating jurisdiction must ensure that a community housing development organization does not receive HOME funding for any fiscal year in an amount that provides more than $50,000 or 50 percent of the community housing development organization's total operating expenses in that fiscal year, whichever is greater. * * *</P>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>32. Revise § 92.302 to read as follows:</AMDPAR>
                        <SECTION>
                            <SECTNO>§ 92.302</SECTNO>
                            <SUBJECT>Housing education and organizational support.</SUBJECT>
                            <P>HUD is authorized to provide education and organizational support assistance, in conjunction with HOME funds made available to community housing development organizations in accordance with section 233 of the Act.</P>
                            <P>
                                (a) HUD will issue a publication in the 
                                <E T="04">Federal Register</E>
                                 announcing the availability of funding under this section, as appropriate. The publication need not include funding for each of the eligible activities but may target funding from among the eligible activities.
                            </P>
                            <P>(b) Notwithstanding the definition of “community land trust” in § 92.2, HUD may provide housing education and organizational support assistance under this section to a community land trust only if the following requirements are met:</P>
                            <P>(1) The community land trust meets the definition of a “community housing development organization” at § 92.2, except for the requirements in paragraphs (9) and (10) of the definition.</P>
                            <P>(2) The community land trust is established to complete the activities in paragraph (b)(3) of this section.</P>
                            <P>(3) The community land trust:</P>
                            <P>(i) Acquires land to hold in perpetuity and primarily for conveyance under long-term ground leases;</P>
                            <P>(ii) Transfers ownership of any structural improvements located on such leased land to the lessees; and</P>
                            <P>(iii) Retains a preemptive option to purchase any such structural improvement at a price determined by formula that is designed to ensure that the improvement remains affordable to low- and moderate-income families in perpetuity;</P>
                            <P>(4) The community land trust's corporate membership is open to residents of a particular geographic area, as specified in the organization's bylaws; and</P>
                            <P>(5) The board of directors:</P>
                            <P>(i) Includes a majority of members who are elected by the corporate membership; and</P>
                            <P>(ii) Is composed of equal numbers of lessees pursuant to paragraph (b)(2)(ii), members who are not lessees, and any other category of persons described in the organization's bylaws.</P>
                        </SECTION>
                    </REGTEXT>
                    <SECTION>
                        <SECTNO>§ 92.351</SECTNO>
                        <SUBJECT>[Amended]</SUBJECT>
                    </SECTION>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>33. Amend § 92.351 by removing the words “downpayment assistance” and adding in their place the words “homeownership assistance” and removing the words “If participating” and adding in their place the words “If the participating”, and by removing the citation “§ 92.253(d)(3)” and adding in its place the citation “§ 92.253(e)(3)” in in paragraph (a)(1).</AMDPAR>
                    </REGTEXT>
                    <SECTION>
                        <SECTNO>§ 92.352</SECTNO>
                        <SUBJECT>[Amended]</SUBJECT>
                    </SECTION>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>34. Amend § 92.352 by:</AMDPAR>
                        <AMDPAR>a. Removing the words “the cost” and adding in their place the word “cost” in paragraph (a); and</AMDPAR>
                        <AMDPAR>b. Removing the word “decisionmaking” and adding in its place the words “decision making” in paragraph (b)(1).</AMDPAR>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>35. Amend § 92.353 by:</AMDPAR>
                        <AMDPAR>
                            a. Removing the words “preceded by at least 30 days advance written notice 
                            <PRTPAGE P="888"/>
                            to the tenant specifying the grounds for the action” and adding in their place the words “in accordance with § 92.253” in paragraph (c)(2)(ii)(A); and
                        </AMDPAR>
                        <AMDPAR>b. Revising paragraph (c)(2)(ii)(C).</AMDPAR>
                        <P>The revision reads as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.353 </SECTNO>
                            <SUBJECT>Displacement, relocation, and acquisition.</SUBJECT>
                            <STARS/>
                            <P>(c) * * *</P>
                            <P>(2) * * *</P>
                            <P>(ii) * * *</P>
                            <P>(C) For purposes of the URA, the person meets the definition of “persons not displaced” as defined in 49 CFR 24.2; or</P>
                            <STARS/>
                        </SECTION>
                    </REGTEXT>
                    <SECTION>
                        <SECTNO>§ 92.354</SECTNO>
                        <SUBJECT>[Amended]</SUBJECT>
                    </SECTION>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>36. Amend § 92.354 in paragraph (a)(2) by removing the word “single-family” and adding in its place the words “single family”.</AMDPAR>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>37. Amend § 92.356 by:</AMDPAR>
                        <AMDPAR>a. Revising paragraph (d)(1);</AMDPAR>
                        <AMDPAR>b. Redesignating paragraphs (e)(2) through (6) as paragraphs (e)(3) through (7), respectively;</AMDPAR>
                        <AMDPAR>c. Adding new paragraph (e)(2); and</AMDPAR>
                        <AMDPAR>d. Removing the citation “§ 92.252(e)” and adding in its place the citation “§ 92.252(d)” in paragraph (f)(1).</AMDPAR>
                        <P>The revisions and additions read as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.356</SECTNO>
                            <SUBJECT>Conflict of interest.</SUBJECT>
                            <STARS/>
                            <P>(d) * * *</P>
                            <P>(1) A disclosure of the nature of the conflict, accompanied by an assurance that there has been public disclosure of the conflict (public disclosure is considered a combination of at least two of the following: publication on the recipient's website, including social media; electronic mailings; media advertisements; public service announcements; and display in public areas such as libraries, grocery store bulletin boards, and neighborhood centers), evidence of the public disclosure, and a description of how the public disclosure was made; and</P>
                            <STARS/>
                            <P>(e) * * *</P>
                            <P>(2) Whether an opportunity was provided for open competitive bidding or negotiation;</P>
                            <STARS/>
                        </SECTION>
                    </REGTEXT>
                    <SECTION>
                        <SECTNO>§ 92.359</SECTNO>
                        <SUBJECT>[Amended]</SUBJECT>
                    </SECTION>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>38. Amend § 92.359 in paragraph (f) by removing the words “affordability period” and adding in their place the words “period of affordability”.</AMDPAR>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>39. Amend § 92.454 by:</AMDPAR>
                        <AMDPAR>a. Removing the word “and” in paragraph (a)(3);</AMDPAR>
                        <AMDPAR>b. Removing the text “participating jurisdiction.” and adding in its place the text “participating jurisdiction; and” in paragraph (a)(4);</AMDPAR>
                        <AMDPAR>c. Adding paragraph (a)(5); and</AMDPAR>
                        <AMDPAR>d. Removing the words “participating jurisdictions that” and adding in their place the words “participating jurisdictions whose funds were reduced under § 92.551 or that” in paragraph (b).</AMDPAR>
                        <P>The addition reads as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.454</SECTNO>
                            <SUBJECT>Reallocations by formula.</SUBJECT>
                            <P>(a) * * *</P>
                            <P>(5) Any HOME funds available for reallocation as a result of any reductions under 24 CFR 92.551 or 92.552.</P>
                            <STARS/>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>40. Amend § 92.500 by revising paragraph (c)(2)(ii) to read as follows:</AMDPAR>
                        <SECTION>
                            <SECTNO>§ 92.500</SECTNO>
                            <SUBJECT>The HOME Investment Trust Fund.</SUBJECT>
                            <STARS/>
                            <P>(c) * * *</P>
                            <P>(2) * * *</P>
                            <P>(ii) The statute or local ordinance requires repayments from its own affordable housing trust fund to be made to the local account;</P>
                            <STARS/>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>41. Amend § 92.502 by:</AMDPAR>
                        <AMDPAR>a. Revising paragraph (b);</AMDPAR>
                        <AMDPAR>b. Removing the words “set-up” in paragraph (c)(1); and</AMDPAR>
                        <AMDPAR>c. Revising paragraphs (d)(1) and (2).</AMDPAR>
                        <P>The revisions read as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.502</SECTNO>
                            <SUBJECT>Program disbursement and information system.</SUBJECT>
                            <STARS/>
                            <P>
                                (b) 
                                <E T="03">Project funding.</E>
                                 After the participating jurisdiction executes the HOME Investment Partnership Agreement, submits the applicable banking and security documents, complies with the environmental requirements under 24 CFR part 58 for release of funds, and commits funds to a specific local project, the participating jurisdiction may provide funding to an activity by identifying specific investments in the disbursement and information system. The participating jurisdiction is required to enter complete project set-up information before providing funding to the project.
                            </P>
                            <STARS/>
                            <P>(d) * * *</P>
                            <P>(1) Complete project completion information must be entered into the disbursement and information system, or otherwise provided to HUD.</P>
                            <P>(2) Additional HOME funds may be committed to a project up to one year after project completion, but the amount of HOME funds in the project may not exceed the maximum per-unit subsidy amount established under § 92.250 at the time of underwriting.</P>
                            <STARS/>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>42. Amend § 92.504 by:</AMDPAR>
                        <AMDPAR>a. Revising the section heading and paragraph (b) and revising and republishing paragraph (c); and</AMDPAR>
                        <AMDPAR>b. Removing paragraph (d).</AMDPAR>
                        <P>The revisions and republication read as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.504</SECTNO>
                            <SUBJECT>Participating jurisdiction responsibilities; written agreements.</SUBJECT>
                            <STARS/>
                            <P>
                                (b) 
                                <E T="03">Executing a written agreement.</E>
                                 Before disbursing any HOME funds to any entity, the participating jurisdiction must enter into a legally binding written agreement with that entity. Before disbursing any HOME funds to any entity, a State recipient, subrecipient, or contractor that is administering all or a part of the HOME program on behalf of the participating jurisdiction, must also enter into a legally binding written agreement with that entity. The written agreement must ensure compliance with the requirements of this part and be a separate agreement from project financing documents (
                                <E T="03">e.g.,</E>
                                 mortgage or deed of trust, regulatory agreement, or promissory note).
                            </P>
                            <P>
                                (c) 
                                <E T="03">Provisions in written agreements.</E>
                                 The contents of the agreement may vary depending upon the role the entity is asked to assume or the type of project undertaken. This section details basic requirements and the minimum provisions by role and type of entity that must be included in a written agreement.
                            </P>
                            <P>
                                (1) 
                                <E T="03">State recipient.</E>
                                 The provisions in the written agreement between the State and a State recipient will depend on the program functions that the State specifies the State recipient will carry out in accordance with § 92.201(b). In accordance with § 92.201, the written agreement must either require the State recipient to comply with the requirements established by the State or require the State recipient to establish its own requirements to comply with this part, including requirements for income determinations and underwriting subsidy layering guidelines, rehabilitation standards, refinancing guidelines, homebuyer program policies, and affordability.
                            </P>
                            <P>
                                (i) 
                                <E T="03">Use of the HOME funds.</E>
                                 The agreement must describe the amount and use of the HOME funds to administer one or more programs to produce affordable housing, provide homeownership assistance, or provide tenant-based rental assistance, including the anticipated type and number of housing projects to be funded (
                                <E T="03">e.g.,</E>
                                 the number of single family homeowner 
                                <PRTPAGE P="889"/>
                                loans to be made or number of homebuyers to receive homeownership assistance), tasks to be performed, a schedule for completing the tasks (including a schedule for committing funds to projects that meet the deadlines established by this part), a budget for each program, and any requirement for matching contributions. These items must be in sufficient detail to provide a sound basis for the State to effectively monitor performance under the agreement.
                            </P>
                            <P>
                                (ii) 
                                <E T="03">Affordability.</E>
                                 The agreement must require housing assisted with HOME funds to meet the affordability requirements of § 92.252 or § 92.254, as applicable, and must require repayment of the funds if the housing does not meet the affordability requirements for the period of affordability. The agreement must require a means of enforcement of the affordability requirements by the State participating jurisdiction or, if the State recipient will be the owner at project completion of the affordable housing, the intended beneficiaries. The means of enforcement may include liens on real property, deed or use restrictions, a recorded agreement restricting the use of the property, covenants running with the land, or other mechanisms approved by HUD in writing, under which the participating jurisdiction has the right to require specific performance. The agreement must establish whether repayment of HOME funds must be remitted to the State or retained by the State recipient for additional eligible activities.
                            </P>
                            <P>
                                (iii) 
                                <E T="03">Program income.</E>
                                 The agreement must state whether program income is to be remitted to the State or retained by the State recipient for additional eligible activities.
                            </P>
                            <P>
                                (iv) 
                                <E T="03">Uniform administrative requirements.</E>
                                 The agreement must require the State recipient to comply with applicable uniform administrative requirements, as described in § 92.505.
                            </P>
                            <P>
                                (v) 
                                <E T="03">Project requirements.</E>
                                 The agreement must require compliance with project requirements in subpart F of this part, as applicable in accordance with the type of project assisted. For any projects involving HOME rental housing, tenant-based rental assistance, or security deposit assistance, the agreement must require that the applicable HOME tenancy addendum is used in accordance with § 92.253 for all HOME-assisted units or tenants.
                            </P>
                            <P>
                                (vi) 
                                <E T="03">Other program requirements.</E>
                                 The agreement must require the State recipient to carry out each activity in compliance with all Federal laws and regulations described in subpart H of this part, except that the State recipient does not assume the State's responsibilities for release of funds under § 92.352 and the intergovernmental review process in § 92.357 does not apply to the State recipient. If HOME funds are provided for development of rental housing or provision of tenant-based rental assistance, the agreement must set forth all obligations the State imposes on the State recipient in order to meet the Violence Against Women Act (VAWA) requirements under § 92.359, including notice obligations and any obligations with respect to the emergency transfer plan (including whether the State recipient must develop its own plan or follow the State's plan).
                            </P>
                            <P>
                                (vii) 
                                <E T="03">Affirmative marketing.</E>
                                 The agreement must specify the State recipient's affirmative marketing responsibilities in accordance with § 92.351.
                            </P>
                            <P>
                                (viii) 
                                <E T="03">Requests for disbursement of funds.</E>
                                 The agreement must specify that the State recipient may not request disbursement of HOME funds under this agreement until the funds are needed for payment of eligible costs. The amount of each request must be limited to the amount needed. Program income must be disbursed before the State recipient requests funds from the State.
                            </P>
                            <P>
                                (ix) 
                                <E T="03">Records and reports.</E>
                                 The agreement must specify the particular records that must be maintained and the information or reports that must be submitted in order to assist the State in meeting its recordkeeping and reporting requirements.
                            </P>
                            <P>
                                (x) 
                                <E T="03">Enforcement of the written agreement.</E>
                                 The agreement must specify remedies for breach of the provisions of the written agreement. The agreement must specify that, in accordance with 2 CFR 200.339, suspension or termination may occur if the State recipient materially fails to comply with any term of the agreement. The State may permit the agreement to be terminated in whole or in part in accordance with 2 CFR 200.340.
                            </P>
                            <P>
                                (xi) 
                                <E T="03">Written agreement.</E>
                                 Before providing HOME funds to any owner, community housing development organization, subrecipient, homeowner, homebuyer, tenant (or landlord) receiving tenant-based rental assistance, or contractor providing services to or on behalf of the State recipient, the State recipient must have a fully executed written agreement with such person or entity that meets the requirements of this section. For affordable housing assisted with HOME funds, the State recipient must provide HOME funds directly to the owner under the terms and conditions of the written agreement. The agreement must establish that any repayment on any form of assistance of HOME funds must be remitted to the State or, if permitted by the State, retained by the State recipient for additional eligible activities.
                            </P>
                            <P>
                                (xii) 
                                <E T="03">Duration of the agreement.</E>
                                 The duration of the agreement will depend on which functions the State recipient performs (
                                <E T="03">e.g.,</E>
                                 whether the State recipient or the State has responsibility for monitoring rental projects for the period of affordability) and which activities are funded under the agreement.
                            </P>
                            <P>
                                (xiii) 
                                <E T="03">Fees.</E>
                                 The agreement must prohibit the State recipient and its subrecipients and community housing development organizations from charging for any of the prohibited costs listed in § 92.214, including but not limited to servicing, origination, processing, inspection, or other fees for the costs of administering a HOME program.
                            </P>
                            <P>
                                (2) 
                                <E T="03">Subrecipient.</E>
                                 The agreement must set forth and require the subrecipient to follow the participating jurisdiction's requirements, including requirements for income determinations, underwriting and subsidy layering guidelines, rehabilitation standards, refinancing guidelines, homebuyer program policies, and affordability requirements. The agreement between the participating jurisdiction and the subrecipient must include the following:
                            </P>
                            <P>
                                (i) 
                                <E T="03">Use of the HOME funds.</E>
                                 The agreement must describe the amount and use of the HOME funds for one or more programs, including the anticipated type and number of housing projects to be funded (
                                <E T="03">e.g.,</E>
                                 the number of single family homeowner loans to be made or the number of homebuyers to receive homeownership assistance), tasks to be performed, a schedule for completing the tasks (including a schedule for committing funds to projects in accordance with deadlines established by this part), a budget, any requirement for matching contributions, and the period of the agreement. These items must be in sufficient detail to provide a sound basis for the participating jurisdiction to effectively monitor performance under the agreement.
                            </P>
                            <P>
                                (ii) 
                                <E T="03">Program income.</E>
                                 The agreement must state if program income is to be remitted to the participating jurisdiction or retained by the subrecipient for additional eligible activities.
                            </P>
                            <P>
                                (iii) 
                                <E T="03">Uniform administrative requirements.</E>
                                 The agreement must require the subrecipient to comply with applicable uniform administrative requirements, as described in § 92.505.
                            </P>
                            <P>
                                (iv) 
                                <E T="03">Other program requirements.</E>
                                 The agreement must require the subrecipient 
                                <PRTPAGE P="890"/>
                                to carry out each activity in compliance with all Federal laws and regulations described in subpart H of this part, except that the subrecipient does not assume the participating jurisdiction's responsibilities for environmental review under § 92.352 and the intergovernmental review process in § 92.357 does not apply. The agreement must set forth the requirements the subrecipient must follow to enable the participating jurisdiction to carry out environmental review responsibilities before HOME funds are committed to a project. If the subrecipient is administering a HOME rental housing program or tenant-based rental assistance program on behalf of the participating jurisdiction, the participating jurisdiction must set forth in the written agreement all obligations of the subrecipient to meet the VAWA requirements under § 92.359, including notice obligations and obligations under the emergency transfer plan.
                            </P>
                            <P>
                                (v) 
                                <E T="03">Affirmative marketing.</E>
                                 The agreement must specify the subrecipient's affirmative marketing responsibilities in accordance with § 92.351.
                            </P>
                            <P>
                                (vi) 
                                <E T="03">Requests for disbursement of funds.</E>
                                 The agreement must specify that the subrecipient may not request disbursement of funds under the agreement until the funds are needed for payment of eligible costs. The amount of each request must be limited to the amount needed. Program income must be disbursed before the subrecipient requests funds from the participating jurisdiction.
                            </P>
                            <P>
                                (vii) 
                                <E T="03">Reversion of assets.</E>
                                 The agreement must specify that upon expiration of the agreement, the subrecipient must transfer to the participating jurisdiction any HOME funds on hand at the time of expiration and any accounts receivable attributable to the use of HOME funds.
                            </P>
                            <P>
                                (viii) 
                                <E T="03">Records and reports.</E>
                                 The agreement must specify the particular records that must be maintained and the information or reports that must be submitted in order to assist the participating jurisdiction in meeting its recordkeeping and reporting requirements.
                            </P>
                            <P>
                                (ix) 
                                <E T="03">Enforcement of the written agreement.</E>
                                 The agreement must specify remedies for breach of the provisions of the written agreement. The agreement must specify that, in accordance with 2 CFR 200.339, suspension or termination may occur if the subrecipient materially fails to comply with any term of the agreement. The participating jurisdiction may permit the agreement to be terminated in whole or in part in accordance with 2 CFR 200.340.
                            </P>
                            <P>
                                (x) 
                                <E T="03">Written agreement.</E>
                                 Before the subrecipient provides HOME funds to any owner, community housing development organization, subrecipient, homeowner, homebuyer, tenant (or landlord) receiving tenant-based rental assistance, or contractor providing services to or on behalf of the subrecipient, the subrecipient must have a fully executed written agreement with such entity that meets the requirements of this section. For housing projects assisted with HOME funds, the subrecipient must provide HOME funds directly to the owner under the terms and conditions of the written agreement. The agreement must establish whether repayment of HOME funds must be remitted to the participating jurisdiction or may be retained by the subrecipient for additional eligible activities.
                            </P>
                            <P>
                                (xi) 
                                <E T="03">Fees.</E>
                                 The agreement must prohibit the subrecipient from charging for any of the prohibited costs listed in § 92.214, including but not limited to servicing, origination, or other fees for the costs of administering the HOME program.
                            </P>
                            <P>
                                (xii) 
                                <E T="03">Project requirements.</E>
                                 The agreement must require enforcement of project requirements in subpart F of this part, as applicable in accordance with the type of project assisted. For any projects involving HOME rental housing, tenant-based rental assistance, or security deposit assistance, the agreement must require that the applicable HOME tenancy addendum is used in accordance with § 92.253 for all HOME-assisted units or tenants.
                            </P>
                            <P>
                                (3) 
                                <E T="03">For-profit or nonprofit housing owner (other than a community housing development organization or single family owner-occupant).</E>
                                 The participating jurisdiction may preliminarily award HOME funds for a proposed project, contingent on conditions such as obtaining other financing for the project. This preliminary award is not a commitment to a project. The written agreement committing the HOME funds to the project must meet the requirements of “commit to a specific local project” in the definition of “commitment” in § 92.2. The HOME assistance must be provided directly to the owner under the terms and conditions of a written agreement that complies with the requirements of this part and contains the following:
                            </P>
                            <P>
                                (i) 
                                <E T="03">Use of the HOME funds.</E>
                                 The agreement between the participating jurisdiction and a for-profit or nonprofit housing owner must include the address of the project or the legal description of the property if a street address has not been assigned to the property, the specific amount and use of the HOME funds and other funds for the project, including the tasks to be performed for the project, a schedule for completing the tasks and the project, and a complete budget. These items must be in sufficient detail to provide a sound basis for the participating jurisdiction to effectively monitor performance under the agreement to achieve project completion and compliance with the HOME requirements. If HOME funds are being used to reimburse costs incurred not more than 24 months before the date that the HOME funds are committed to the project, the written agreement must explicitly permit the use of HOME funds for costs described in § 92.206(d)(1). The agreement must state that any and all repayments made by the owner on HOME assistance (
                                <E T="03">e.g.,</E>
                                 grants or loans) must be remitted to the participating jurisdiction, unless the participating jurisdiction permits a subrecipient or State recipient to retain the funds.
                            </P>
                            <P>
                                (ii) 
                                <E T="03">Affordability.</E>
                                 The agreement must require housing assisted with HOME funds to meet the affordability requirements of § 92.252 or § 92.254, as applicable, and must require repayment of the funds if the housing does not meet the affordability requirements for the specified period of affordability. The agreement must require a means of enforcement of the affordability requirements by the participating jurisdiction and the intended beneficiaries. The means of enforcement may include liens on real property, deed or use restrictions, a recorded agreement restricting the use of the property, covenants running with the land, or other mechanisms approved by HUD in writing, under which the participating jurisdiction has the right to require specific performance.
                            </P>
                            <P>
                                (A) If an owner is undertaking a rental project, the agreement must establish the initial rents, the procedures for rent increases pursuant to § 92.252(e)(2), the number of HOME units, the size of the HOME units, the designation of the HOME units as fixed or floating, and include the requirement that the owner provide the address (
                                <E T="03">e.g.,</E>
                                 street address and apartment number) of each HOME unit no later than the time of initial occupancy. In accordance with § 92.252(g), the written agreement must specify the option in § 92.203(b)(1) that the participating jurisdiction selected for calculating annual income.
                            </P>
                            <P>
                                (B) If the owner is undertaking a homeownership project for sale to homebuyers in accordance with § 92.254(a), the agreement must set forth the resale or recapture requirements that must be imposed on the housing, the 
                                <PRTPAGE P="891"/>
                                sales price or the basis upon which the sales price will be determined, and the disposition of the sales proceeds. Recaptured funds must be returned to the participating jurisdiction. If the owner is a Community Land Trust, as defined in § 92.2, the Community Land Trust may preserve affordability in accordance with § 92.254.
                            </P>
                            <P>
                                (iii) 
                                <E T="03">Project requirements.</E>
                                 As applicable and in accordance with the type of project assisted, the agreement must require compliance with the project requirements in subpart F of this part, including compliance with tenant protections in 24 CFR 92.253. The agreement may permit the owner to limit eligibility or give a preference to a particular segment of the population in accordance with § 92.253(e).
                            </P>
                            <P>
                                (iv) 
                                <E T="03">Property standards.</E>
                                 The agreement must require the housing to meet the property requirements as specified in § 92.251. The agreement must also require owners of rental housing assisted with HOME funds to maintain the housing in compliance with § 92.251 for the duration of the period of affordability.
                            </P>
                            <P>
                                (v) 
                                <E T="03">Other program requirements.</E>
                                 The agreement must require the owner to carry out each project in compliance with the following requirements of subpart H of this part:
                            </P>
                            <P>(A) The agreement must specify the owner's affirmative marketing responsibilities as enumerated by the participating jurisdiction in accordance with § 92.351.</P>
                            <P>(B) The Federal and nondiscrimination requirements in § 92.350.</P>
                            <P>(C) Any displacement, relocation, and acquisition requirements imposed by the participating jurisdiction consistent with § 92.353.</P>
                            <P>(D) The labor requirements in § 92.354.</P>
                            <P>(E) The conflict of interest provisions prescribed in § 92.356(f).</P>
                            <P>(F) If HOME funds are being provided to develop rental housing, the agreement must set forth all obligations the participating jurisdiction imposes on the owner in order to meet the VAWA requirements under § 92.359, including the owner's notice obligations and owner obligations under the emergency transfer plan.</P>
                            <P>
                                (vi) 
                                <E T="03">Records and reports.</E>
                                 The agreement must specify the particular records that must be maintained and the information or reports that must be submitted in order to assist the participating jurisdiction in meeting its recordkeeping and reporting requirements. The written agreement must require the owner of rental housing to annually provide the participating jurisdiction with information on rents (including rental amounts charged to the tenant), and occupancy of HOME-assisted units to demonstrate compliance with § 92.252. If the rental housing project has floating HOME units, the written agreement must require that the owner provide the participating jurisdiction with information regarding unit substitution and filling vacancies so that the project remains in compliance with § 92.252. The agreement must specify the reporting requirements (including copies of financial statements) to enable the participating jurisdiction to determine the financial condition (and continued financial viability) of the rental project.
                            </P>
                            <P>
                                (vii) 
                                <E T="03">Enforcement of the written agreement.</E>
                                 The agreement must specify remedies for breach of the provisions of the written agreement. The agreement must require a means of enforcement of the affordability requirements by the participating jurisdiction and the intended beneficiaries. The means of enforcement may include liens on real property, deed or use restrictions, a recorded agreement restricting the use of the property, covenants running with the land, or other mechanisms approved by HUD in writing, under which the participating jurisdiction has the right to require specific performance.
                            </P>
                            <P>
                                (viii) 
                                <E T="03">Requests for disbursement of funds.</E>
                                 The agreement must specify that the owner may not request disbursement of funds under the agreement until the funds are needed for payment of eligible costs. The amount of each request must be limited to the amount needed.
                            </P>
                            <P>
                                (ix) 
                                <E T="03">Duration of the agreement.</E>
                                 The agreement must specify the duration of the agreement. If the housing assisted under this agreement is rental housing, the agreement must be in effect through the period of affordability required by the participating jurisdiction under § 92.252. If the housing assisted under this agreement is homeownership housing, the agreement must be in effect at least until completion of the project and ownership by the low-income family.
                            </P>
                            <P>
                                (x) 
                                <E T="03">Fees.</E>
                                 The agreement must state the fees that may be charged by the owner in accordance with § 92.214(b)(4) and prohibit owners from charging tenants for any of the prohibited charges listed in § 92.214(b), including but not limited to fees that are not customarily charged in rental housing, such as laundry room access fees. The agreement must also prohibit the owner undertaking a homeownership project from charging servicing, origination, processing, inspection, or other fees for the costs of providing homeownership assistance.
                            </P>
                            <P>
                                (4) 
                                <E T="03">Contractor.</E>
                                 The participating jurisdiction selects a contractor through applicable procurement procedures and requirements. The contractor provides goods or services in accordance with a written agreement (the contract). For contractors who are administering any of the participating jurisdiction's HOME programs or specific services for one or more programs, the contract must include at a minimum the following provisions:
                            </P>
                            <P>
                                (i) 
                                <E T="03">Use of the HOME funds.</E>
                                 The agreement must describe the use of the HOME funds, including the tasks to be performed, a schedule for completing the tasks, and budget.
                            </P>
                            <P>
                                (ii) 
                                <E T="03">Program requirements.</E>
                                 The agreement must provide that the contractor is subject to the requirements in this part that are applicable to the participating jurisdiction, except for §§ 92.505 and 92.506, and the contractor cannot assume the participating jurisdiction responsibilities for environmental review, decision making, and action under § 92.352. The agreement must provide that the requirements at 2 CFR part 200 applicable to a contractor apply. The agreement must list the requirements applicable to the activities the contractor is administering. If applicable to the work under the contract, the agreement must set forth all obligations the participating jurisdiction imposes on the contractor in order to meet the VAWA requirements under § 92.359, including any notice obligations and any obligations under the emergency transfer plan.
                            </P>
                            <P>
                                (iii) 
                                <E T="03">Duration of agreement.</E>
                                 The agreement must specify the duration of the contract.
                            </P>
                            <P>
                                (5) 
                                <E T="03">Homebuyer, homeowner, tenant, or owner receiving tenant-based rental or security deposit assistance.</E>
                                 When a participating jurisdiction provides assistance to a homebuyer, homeowner, tenant, or owner for tenant-based rental assistance, the written agreement may take many forms depending upon the nature of assistance. At minimum, it must include the following:
                            </P>
                            <P>(i) For homebuyers, the agreement must contain the requirements in § 92.254(a), the value of the property, principal residence, lease-purchase, if applicable, and the resale or recapture provisions.</P>
                            <P>
                                (A) The agreement must specify the amount of HOME funds, the form of assistance, (
                                <E T="03">e.g.,</E>
                                 grant, amortizing loan, deferred payment loan), the use of the funds (
                                <E T="03">e.g.,</E>
                                 downpayment, closing costs, rehabilitation), and the time by which the housing must be acquired.
                                <PRTPAGE P="892"/>
                            </P>
                            <P>(B) For existing housing that is acquired for homeownership, the agreement must require the participating jurisdiction to inspect the housing to determine that the project meets the property standards in § 92.251 and require compliance with the requirements in § 92.251(c)(3).</P>
                            <P>(ii) For homeowners, the agreement must contain the requirements in § 92.254(b) and specify the amount and form of HOME assistance, rehabilitation work to be undertaken, date for completion, and property standards to be met.</P>
                            <P>(iii) For tenants or owners receiving payments under a HOME tenant-based rental assistance program, the rental assistance contract or the security deposit assistance contract must meet the requirements in § 92.209 and applicable requirements in § 92.253.</P>
                            <P>
                                (6) 
                                <E T="03">Community housing development organization.</E>
                                 When HOME funds are provided to a community housing development organization, the requirements in the written agreement depend upon the type of HOME assistance. At minimum, the agreement must comply with the following requirements for the type of HOME assistance:
                            </P>
                            <P>
                                (i) 
                                <E T="03">Using set-aside funds under § 92.300 for affordable housing.</E>
                                 The written agreement must contain the requirements described in paragraph (c)(3) of this section and the following additional requirements:
                            </P>
                            <P>
                                (A) 
                                <E T="03">Role of community housing development organization.</E>
                                 The agreement must state whether the community housing development organization will own, develop, or sponsor rental housing, as described in § 92.300(a)(2) through (5), and require the community housing development organization to comply with the applicable requirements in § 92.300(a), based on its role.
                            </P>
                            <P>
                                (B) 
                                <E T="03">Developer of homeownership housing</E>
                                —(
                                <E T="03">1</E>
                                ) 
                                <E T="03">Retaining proceeds and recaptured funds.</E>
                                 If the community development organization is a “developer” of homeownership housing, as defined in § 92.300(a)(6), the agreement must specify whether the organization may retain proceeds from the sale of the housing and whether the proceeds are to be used for HOME-eligible or other housing activities to benefit low-income families. A participating jurisdiction may permit a community housing development organization to retain recaptured funds for additional HOME projects pursuant to the written agreement required under this paragraph.
                            </P>
                            <P>
                                (
                                <E T="03">2</E>
                                ) 
                                <E T="03">Providing homeownership assistance.</E>
                                 If a community housing development organization is providing homeownership assistance, then the agreement between the participating jurisdiction and the community housing development organization must describe the amount and use of the HOME funds for homeownership assistance, the number of homebuyers to receive homeownership assistance, any requirement for matching contributions, and the period of the agreement. The HOME funds for homeownership assistance shall not be greater than 10 percent of the amount of HOME funds for development of the housing. The community housing development organization must enter into agreements with homebuyers that meet the requirements in paragraph (c)(5)(i) of this section.
                            </P>
                            <P>
                                (C) 
                                <E T="03">Sharing of developer responsibilities.</E>
                                 If the community housing development organization will share developer responsibilities with another entity pursuant to § 92.300(a)(3) or (6), the participating jurisdiction must enter into a written agreement only with the community housing development organization. The written agreement must require the community housing development organization to enter into a separate agreement with the co-developer. At minimum, the agreement between the community housing development organization and its co-developer must contain the following:
                            </P>
                            <P>
                                (
                                <E T="03">1</E>
                                ) The responsibilities of the community housing development organization and co-developer with descriptions of the responsibilities in sufficient detail to demonstrate compliance with § 92.300(a)(3) or (a)(6), as applicable;
                            </P>
                            <P>
                                (
                                <E T="03">2</E>
                                ) A description of the amount of developer fee and other compensation, if any, to be paid to the co-developer;
                            </P>
                            <P>
                                (
                                <E T="03">3</E>
                                ) A description of any ownership interest in the community housing development organization and, if applicable, any membership or partnership interest in the owner held by the co-developer; and
                            </P>
                            <P>
                                (
                                <E T="03">4</E>
                                ) A provision that the agreement's terms and conditions are subject to review by the participating jurisdiction and if such terms and conditions affect a project's compliance with HOME requirements, the terms and conditions are subject to approval by the participating jurisdiction.
                            </P>
                            <P>
                                (ii) 
                                <E T="03">Receiving assistance for operating expenses.</E>
                                 The agreement must describe the use of HOME funds for operating expenses (
                                <E T="03">e.g.,</E>
                                 salaries, wages, and other employee compensation and benefits); employee education, training, and travel; rent; utilities; communication costs; taxes; insurance; equipment; and materials and supplies. If the community housing development organization is not also receiving funds for a housing project to be developed, sponsored, or owned by the community housing development organization, the agreement must provide that the community housing development organization is expected to receive funds for a project within 24 months of the date of receiving the funds for operating expenses, and must specify the terms and conditions upon which this expectation is based and the consequences of failure to receive funding for a project. If the community housing development organization is also receiving funds for a project, there must be a separate written agreement that complies with this section for the use of HOME funds for the project and the agreement must contain the applicable requirements in paragraph (c)(6)(i) of this section.
                            </P>
                            <P>
                                (iii) 
                                <E T="03">Receiving assistance for project-specific technical assistance and site control loans or project-specific seed money loans.</E>
                                 The agreement must identify the specific site or sites and describe the amount and use of the HOME funds (in accordance with § 92.301), including a budget for work, a period of performance, and a schedule for completion. The agreement must also set forth the basis upon which the participating jurisdiction may waive repayment of the loans, consistent with § 92.301, if applicable.
                            </P>
                            <P>
                                (7) 
                                <E T="03">Technical assistance provider to develop the capacity of community housing development organizations in the jurisdiction.</E>
                                 The agreement must identify the specific nonprofit organization(s) to receive capacity building assistance. The agreement must describe the amount and use (scope of work) of the HOME funds, including a budget, a period of performance, and a schedule for completion.
                            </P>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>43. Amend § 92.505 by revising the first sentence to read as follows:</AMDPAR>
                        <SECTION>
                            <SECTNO>§ 92.505 </SECTNO>
                            <SUBJECT>Applicability of uniform administrative requirements.</SUBJECT>
                            <P>The requirements of 2 CFR part 200 apply to participating jurisdictions, State recipients, and subrecipients receiving HOME funds, except for the following provisions: §§ 200.306, 200.307, 200.308 (not applicable to participating jurisdictions), 200.311 (except as provided in § 92.257), 200.312, 200.328, 200.330, 200.334, 200.335, and 200.344 (except as provided in § 92.507). * * *</P>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>44. Revise § 92.507 to read as follows:</AMDPAR>
                        <SECTION>
                            <PRTPAGE P="893"/>
                            <SECTNO>§ 92.507</SECTNO>
                            <SUBJECT>Closeout.</SUBJECT>
                            <P>This section specifies the procedure and actions that must be completed by a participating jurisdiction and HUD to closeout a grant. The requirements of 2 CFR 200.344 apply to closeouts, except to the extent that such requirements conflict with the following:</P>
                            <P>
                                (a) 
                                <E T="03">Closeout process.</E>
                                 (1) HUD will close out a grant after the period of performance has ended. A participating jurisdiction must complete all required activities and closeout actions for the grant, as required by HUD. If the participating jurisdiction fails to complete the requirements in accordance with this section, HUD may close out the Federal award with the information available. HUD may close out individual grants or multiple grants simultaneously.
                            </P>
                            <P>(2) To prepare for closeout, before the end of the budget period of the grant, the participating jurisdiction shall. review all eligible activities under the grant and reconcile its accounts as follows:</P>
                            <P>(i) For any eligible costs incurred under the grant and not yet drawn down from the U.S. Treasury account, the grantee must draw down those funds in a timely manner.</P>
                            <P>(ii) The participating jurisdiction must promptly refund to the proper accounts any previously disbursed balances of unobligated cash paid in advance. All such refunds must be completed prior to submission of the information and reports required in paragraph (b) of this section.</P>
                            <P>(3) At the end of the grant budget period, no additional eligible activities may be undertaken by the participating jurisdiction using the grant funds and no additional eligible costs incurred after the budget period may be submitted by the participating jurisdiction. Unused funds remaining on the grant will be returned to the U.S. Treasury by HUD. The participating jurisdiction must promptly refund any unused grant funds not authorized to be retained, consistent with HUD's instructions.</P>
                            <P>(4) HUD will initiate closeout actions in the computerized disbursement and information system when the participating jurisdiction has met the requirements established in paragraph (b) of this section.</P>
                            <P>(i) If the participating jurisdiction does not submit and enter all required data, information, and reports or complete the actions described in paragraph (b) of this section, HUD will proceed to close out the grant with the information available within one year of the period of performance end date.</P>
                            <P>
                                (ii) HUD may report the participating jurisdiction's material failure to comply with the terms and conditions of the award or requirements or the requirements of this section in 
                                <E T="03">SAM.gov.</E>
                                 HUD may also pursue other enforcement actions in 2 CFR 200.339.
                            </P>
                            <P>(5) A participating jurisdiction may request, and HUD may provide an extension of the period of performance or closeout deadlines provided good cause is demonstrated.</P>
                            <P>
                                (b) 
                                <E T="03">Actions required for closeout.</E>
                                 A participating jurisdiction must complete the following actions for closeout of the grant:
                            </P>
                            <P>(1) Submit a complete and final Federal Financial Report for the grant to HUD within 120 days of the end date of the period of performance, as indicated in the grant agreement;</P>
                            <P>
                                (2) Demonstrate that it has fulfilled all programmatic and administrative requirements for the project (
                                <E T="03">i.e.,</E>
                                 property inspections, obtaining certificates of occupancy, etc.) within the period of performance in accordance with 2 CFR 200.344(a);
                            </P>
                            <P>(3) Enter all data for activities in the computerized disbursement and information system established by HUD, within one year from the end of the period of performance, as required by the grant agreement;</P>
                            <P>(4) Demonstrate that all HOME-assisted units are occupied by eligible occupants by entering accurate beneficiary data in the computerized disbursement and information system established by HUD, within one year from the end of the period of performance, as required by the grant agreement;</P>
                            <P>(5) Comply with the requirements in 2 CFR 200.313(e) for the disposition of any equipment acquired under one or more HOME grants, that is no longer needed for the HOME program, or for other activities previously supported by a Federal agency;</P>
                            <P>(6) Resolve and close all HOME monitoring findings for the grant (if applicable);</P>
                            <P>(7) Resolve and close all OIG audit findings for the grant (if applicable);</P>
                            <P>(8) Resolve and close all Single Audit findings for the grant (if applicable);</P>
                            <P>(9) Carry out all other responsibilities under the grant agreement and applicable laws and regulations satisfactorily; and</P>
                            <P>(10) Complete a closeout certification prepared by HUD. The certification shall identify the grant being closed out and include provisions with respect to the following:</P>
                            <P>(i) Identification of any unused grant funds that were returned to the U.S. Treasury by HUD;</P>
                            <P>(ii) Compliance with the recordkeeping requirements in § 92.508, including maintaining program, project, financial, program administration, community housing development organization records, records concerning other Federal requirements, and such other records as necessary to carry out responsibilities for the grant by the participating jurisdiction, its State recipients, and subrecipients;</P>
                            <P>(iii) Monitoring and enforcement of the requirements for all HOME-assisted units set forth in this part for the period specified in the HOME written agreement with the property owner;</P>
                            <P>(iv) Compliance with use of program income, recaptured funds, and repayments in accordance with § 92.503. If the jurisdiction is not a participating jurisdiction (as a State, metropolitan city, urban county, consortium, or consortium member) when it receives funds, the funds are not subject to the requirements of this part;</P>
                            <P>(v) All actions required in 2 CFR 200.344 applicable to the grant have been taken by the participating jurisdiction;</P>
                            <P>(vi) All actions required in 2 CFR 200.344 applicable to the participating jurisdiction's subrecipients have been taken;</P>
                            <P>(vii) Other provisions appropriate to any special circumstances of the grant closeout, in modification of or in addition to the obligations in paragraphs (c)(1) and (2) of this section;</P>
                            <P>(viii) Acknowledge future monitoring by HUD, including that findings of noncompliance may be taken into account by HUD as unsatisfactory performance of the participating jurisdiction and in any risk-based assessment of a future grant award under this part; and</P>
                            <P>(ix) Unless otherwise provided in a closeout certification, the Consolidated Plan will remain in effect after closeout until the expiration of the program year covered by the most recent Consolidated Plan.</P>
                            <P>
                                (c) 
                                <E T="03">Post closeout adjustments and continuing responsibilities.</E>
                                 The closeout of a grant does not affect any of the obligations required under this part and under 2 CFR 200.345, including:
                            </P>
                            <P>(1) The right of HUD to disallow costs and recover funds on the basis of a later audit or other review. HUD must make any cost disallowance determination and notify the participating jurisdiction within the record retention period;</P>
                            <P>(2) Compliance with the requirements in § 92.508;</P>
                            <P>
                                (3) Compliance with the requirements in § 92.509;
                                <PRTPAGE P="894"/>
                            </P>
                            <P>(4) Records retention as required in 2 CFR 200.345, as applicable;</P>
                            <P>(5) Monitoring and enforcement of the requirements for all HOME-assisted units set forth in this part for the period of affordability specified in the HOME written agreement with the property owner;</P>
                            <P>(6) Compliance with use of program income, recaptured funds, and repayments in accordance with § 92.503. If the jurisdiction is not a participating jurisdiction (as a metropolitan city, urban county, State, consortium, or consortium member) when it receives funds, the funds are not subject to the requirements of this part;</P>
                            <P>(7) Compliance with the requirement in 2 CFR 200.345(a)(2) that the participating jurisdiction return any funds due as a result of a later refund, corrections, or other transactions including final indirect cost rate adjustments; and</P>
                            <P>(8) Compliance with the audit requirements at 2 CFR part 200, subpart F).</P>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>45. Amend § 92.508 by:</AMDPAR>
                        <AMDPAR>a. Adding a sentence to the end of paragraph (a)(2)(ix);</AMDPAR>
                        <AMDPAR>b. Revising paragraph (a)(3)(iii);</AMDPAR>
                        <AMDPAR>c. Removing the citation “§ 92.504(d)” and adding in its place the citation “§ 92.251(f)” in paragraph (a)(3)(iv);</AMDPAR>
                        <AMDPAR>d. Revising paragraph (a)(3)(vi);</AMDPAR>
                        <AMDPAR>e. Revising the first sentence of paragraph (a)(3)(vii);</AMDPAR>
                        <AMDPAR>f. Revising paragraph (a)(3)(ix);</AMDPAR>
                        <AMDPAR>g. Removing the citation to “2 CFR 200.302” and adding in its place a citation to “2 CFR 200.302 and 200.303” in paragraph (a)(5)(iv); and</AMDPAR>
                        <AMDPAR>h. Removing the words “affordability period” and adding in their place the words “period of affordability” in paragraphs (c)(1) and (2).</AMDPAR>
                        <P>The revisions and additions read as follows:</P>
                        <SECTION>
                            <SECTNO>§ 92.508</SECTNO>
                            <SUBJECT>Recordkeeping.</SUBJECT>
                            <P>(a) * * *</P>
                            <P>(2) * * *</P>
                            <P>(ix) * * * If the participating jurisdiction will apply excess matching contribution to a future fiscal year's liability, records demonstrating compliance with the matching requirements of §§ 92.218 through 92.221 for the excess amount applied, as described in § 92.221(b)(1), must be provided at the time of application and maintained for five years from the date of application.</P>
                            <STARS/>
                            <P>(3) * * *</P>
                            <P>(iii) Records demonstrating that each rental housing or homeownership project meets the minimum per-unit subsidy amount of § 92.205(c), the maximum per-unit subsidy amount in accordance with the requirement in § 92.250(a), the subsidy layering and underwriting evaluation adopted in accordance with § 92.250(b), and, if applicable, compliance with a green building standard established by HUD in accordance with the requirements in § 92.250(c).</P>
                            <STARS/>
                            <P>(vi) Records demonstrating that each tenant-based rental assistance project meets the written tenant selection policies and criteria of § 92.209(c), including any targeting requirements, the rent reasonableness requirements of § 92.209(f), the maximum subsidy provisions of § 92.209(h), housing standards of § 92.209(i) (including property inspection reports), security deposit requirements of § 92.209(j), and calculation of the HOME subsidy.</P>
                            <P>(vii) Records demonstrating that each rental housing project met the affordability and income targeting requirements of § 92.252 for the required period or met the requirements in § 92.255 for conversion to homeownership for in-place tenants. * * *</P>
                            <STARS/>
                            <P>(ix) Records demonstrating that each lease for a tenant receiving tenant-based rental assistance, security deposit assistance, and for an assisted rental housing unit complies with the applicable tenant and participant protections of § 92.253. Records must be kept for each family.</P>
                            <STARS/>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>46. Amend § 92.551 by adding paragraph (c)(3) to read as follows:</AMDPAR>
                        <SECTION>
                            <SECTNO>§ 92.551</SECTNO>
                            <SUBJECT>Corrective and remedial actions.</SUBJECT>
                            <STARS/>
                            <P>(c) * * *</P>
                            <P>(3) A participating jurisdiction may request HUD reduce grant payments by an amount equal to the amount of expenditures that did not comply with the requirements of this part. The amount of a reduction may be for the entire grant amount.</P>
                        </SECTION>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>47. Amend § 92.552 by removing the period at the end of paragraph (a)(2)(iv) and adding in its place a semicolon and adding paragraphs (a)(2)(v) through (vii) to read as follows:</AMDPAR>
                        <SECTION>
                            <SECTNO>§ 92.552</SECTNO>
                            <SUBJECT>Notice and opportunity for hearing; sanctions.</SUBJECT>
                            <P>(a) * * *</P>
                            <P>(2) * * *</P>
                            <P>(v) Reduce grant amounts paid to the participating jurisdiction by an amount equal to the amount of any expenditures that did not comply with the requirements of this part. The amount of a reduction may be for the entire grant amount;</P>
                            <P>(vi) Revoke a jurisdiction's designation as a participating jurisdiction; and</P>
                            <P>(vii) Terminate the assistance in whole or in part in accordance with 2 CFR 200.340.</P>
                            <STARS/>
                        </SECTION>
                    </REGTEXT>
                    <SUBPART>
                        <HD SOURCE="HED">Subpart M [Removed]</HD>
                    </SUBPART>
                    <REGTEXT TITLE="24" PART="92">
                        <AMDPAR>48. Remove subpart M, consisting of §§ 92.600 through 92.618.</AMDPAR>
                    </REGTEXT>
                    <PART>
                        <HD SOURCE="HED">PART 570—COMMUNITY DEVELOPMENT BLOCK GRANTS</HD>
                    </PART>
                    <REGTEXT TITLE="24" PART="570">
                        <AMDPAR>49. The authority citation for part 570 continues to read as follows:</AMDPAR>
                        <AUTH>
                            <HD SOURCE="HED">Authority:</HD>
                            <P> 12 U.S.C. 1701x, 1701 x-1; 42 U.S.C. 3535(d) and 5301-5320.</P>
                        </AUTH>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="570">
                        <AMDPAR>50. Amend § 570.200 by adding paragraph (h)(3) to read as follows:</AMDPAR>
                        <SECTION>
                            <SECTNO>§ 570.200</SECTNO>
                            <SUBJECT>General policies.</SUBJECT>
                            <STARS/>
                            <P>(h) * * *</P>
                            <P>(3) In a Federal fiscal year when an annual appropriation is signed into law less than 90 days before a grant recipient's program year start date, the effective date of the grant agreement will be the earlier of the recipient's program year start date or the date that the Consolidated Plan incorporating the recipient's allocation amount for the Federal fiscal year is received by HUD.</P>
                            <STARS/>
                        </SECTION>
                    </REGTEXT>
                    <PART>
                        <HD SOURCE="HED">PART 982—SECTION 8 TENANT-BASED ASSISTANCE: HOUSING CHOICE VOUCHER PROGRAM</HD>
                    </PART>
                    <REGTEXT TITLE="24" PART="982">
                        <AMDPAR>51. The authority citation for part 982 continues to read as follows:</AMDPAR>
                        <AUTH>
                            <HD SOURCE="HED">Authority: </HD>
                            <P>42 U.S.C. 1437f and 3535(d).</P>
                        </AUTH>
                    </REGTEXT>
                    <REGTEXT TITLE="24" PART="982">
                        <AMDPAR>52. Amend § 982.507 by revising paragraphs (c)(2) and (3) to read as follows:</AMDPAR>
                        <SECTION>
                            <SECTNO>§ 982.507</SECTNO>
                            <SUBJECT>Rent to owner: Reasonable rent.</SUBJECT>
                            <STARS/>
                            <P>(c) * * *</P>
                            <P>
                                (2) 
                                <E T="03">LIHTC.</E>
                                 If the rent requested by the owner exceeds the LIHTC rents for non-voucher families, the PHA must determine the rent to owner is a reasonable rent in accordance with paragraph (b) of this section and the rent shall not exceed the lesser of the:
                            </P>
                            <P>(i) Reasonable rent; and</P>
                            <P>(ii) The payment standard established by the PHA for the unit size involved.</P>
                            <PRTPAGE P="895"/>
                            <P>
                                (3) 
                                <E T="03">HOME program.</E>
                                 If the rent requested by the owner exceeds the HOME rents for non-voucher families, the PHA must determine the rent to owner is a reasonable rent in accordance with paragraph (b) of this section and the rent shall not exceed the lesser of the:
                            </P>
                            <P>(i) Reasonable rent; and</P>
                            <P>(ii) The payment standard established by the PHA for the unit size involved.</P>
                            <STARS/>
                        </SECTION>
                    </REGTEXT>
                    <SIG>
                        <NAME>Adrianne R. Todman,</NAME>
                        <TITLE>Deputy Secretary Performing the Duties of the Secretary of HUD.</TITLE>
                    </SIG>
                </SUPLINF>
                <FRDOC>[FR Doc. 2024-29824 Filed 1-3-25; 8:45 am]</FRDOC>
                <BILCOD>BILLING CODE 4210-67-P</BILCOD>
            </RULE>
        </RULES>
    </NEWPART>
    <VOL>90</VOL>
    <NO>3</NO>
    <DATE>Monday, January 6, 2025</DATE>
    <UNITNAME>Proposed Rules</UNITNAME>
    <NEWPART>
        <PTITLE>
            <PRTPAGE P="897"/>
            <PARTNO>Part III</PARTNO>
            <AGENCY TYPE="P"> Department of Health and Human Services</AGENCY>
            <CFR>45 CFR Parts 160 and 164</CFR>
            <TITLE>HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information; Proposed Rule</TITLE>
        </PTITLE>
        <PRORULES>
            <PRORULE>
                <PREAMB>
                    <PRTPAGE P="898"/>
                    <AGENCY TYPE="S">DEPARTMENT OF HEALTH AND HUMAN SERVICES</AGENCY>
                    <SUBAGY>Office of the Secretary</SUBAGY>
                    <CFR>45 CFR Parts 160 and 164</CFR>
                    <RIN>RIN 0945-AA22</RIN>
                    <SUBJECT>HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information</SUBJECT>
                    <AGY>
                        <HD SOURCE="HED">AGENCY:</HD>
                        <P>Office for Civil Rights (OCR), Office of the Secretary, Department of Health and Human Services.</P>
                    </AGY>
                    <ACT>
                        <HD SOURCE="HED">ACTION:</HD>
                        <P>Notice of proposed rulemaking; notice of Tribal consultation.</P>
                    </ACT>
                    <SUM>
                        <HD SOURCE="HED">SUMMARY:</HD>
                        <P>The Department of Health and Human Services (HHS or “Department”) is issuing this notice of proposed rulemaking (NPRM) to solicit comment on its proposal to modify the Security Standards for the Protection of Electronic Protected Health Information (“Security Rule”) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act). The proposed modifications would revise existing standards to better protect the confidentiality, integrity, and availability of electronic protected health information (ePHI). The proposals in this NPRM would increase the cybersecurity for ePHI by revising the Security Rule to address: changes in the environment in which health care is provided; significant increases in breaches and cyberattacks; common deficiencies the Office for Civil Rights has observed in investigations into Security Rule compliance by covered entities and their business associates (collectively, “regulated entities”); other cybersecurity guidelines, best practices, methodologies, procedures, and processes; and court decisions that affect enforcement of the Security Rule.</P>
                    </SUM>
                    <DATES>
                        <HD SOURCE="HED">DATES:</HD>
                        <P/>
                        <P>
                            <E T="03">Comments:</E>
                             Submit comments on or before March 7, 2025.
                        </P>
                        <P>
                            <E T="03">Meeting:</E>
                             Pursuant to Executive Order 13175, Consultation and Coordination with Indian Tribal Governments, the Department of Health and Human Services' Tribal Consultation Policy, and the Department's Plan for Implementing Executive Order 13175, the Office for Civil Rights solicits input from Tribal officials as the Department develops the modifications to the HIPAA Security Rule at 45 CFR part 160 and subparts A and C of 45 CFR part 164. The Tribal consultation meeting will be held on February 6, 2025, at 2 p.m. to 3:30 p.m. eastern time.
                        </P>
                    </DATES>
                    <ADD>
                        <HD SOURCE="HED">ADDRESSES:</HD>
                        <P>You may submit comments, identified by RIN Number 0945-AA22, by any of the following methods. Please do not submit duplicate comments.</P>
                        <P>
                            • 
                            <E T="03">Federal eRulemaking Portal:</E>
                             You may submit electronic comments at 
                            <E T="03">https://www.regulations.gov</E>
                             by searching for the Docket ID number HHS-OCR-0945-AA22. Follow the instructions at 
                            <E T="03">https://www.regulations.gov</E>
                             for submitting electronic comments. Attachments should be in Microsoft Word or Portable Document Format (PDF).
                        </P>
                        <P>
                            • 
                            <E T="03">Regular, Express, or Overnight Mail:</E>
                             You may mail written comments to the following address only: U.S. Department of Health and Human Services, Office for Civil Rights, Attention: HIPAA Security Rule NPRM, Hubert H. Humphrey Building, Room 509F, 200 Independence Avenue SW, Washington, DC 20201. Please allow sufficient time for mailed comments to be timely received in the event of delivery or security delays.
                        </P>
                        <P>Please note that comments submitted by fax or email and those submitted after the comment period will not be accepted.</P>
                        <P>
                            <E T="03">Inspection of Public Comments:</E>
                             All comments received by the accepted methods and due date specified above may be posted without change to content to 
                            <E T="03">https://www.regulations.gov,</E>
                             which may include personal information provided about the commenter, and such posting may occur after the closing of the comment period. However, the Department may redact certain non-substantive content from comments or attachments to comments before posting, including: threats, hate speech, profanity, sensitive health information, graphic images, promotional materials, copyrighted materials, or individually identifiable information about a third-party individual other than the commenter. In addition, comments or material designated as confidential or not to be disclosed to the public will not be accepted. Comments may be redacted or rejected as described above without notice to the commenter, and the Department will not consider in rulemaking any redacted or rejected content that would not be made available to the public as part of the administrative record.
                        </P>
                        <P>
                            <E T="03">Docket:</E>
                             For complete access to background documents, the plain-language summary of the proposed rule of not more than 100 words in length required by the Providing Accountability Through Transparency Act of 2023, or posted comments, go to 
                            <E T="03">https://www.regulations.gov</E>
                             and search for Docket ID number HHS-OCR-0945-AA22.
                        </P>
                        <P>
                            <E T="03">Tribal consultation meeting:</E>
                             To participate in the Tribal consultation meeting, you must register in advance at 
                            <E T="03">https://hhsgov.zoomgov.com/meeting/register/vJItdOyhrjgoHxJWMDxozrxT98yXyCO3lks.</E>
                        </P>
                    </ADD>
                    <FURINF>
                        <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD>
                        <P>
                            Marissa Gordon-Nguyen at (202) 240-3110 or (800) 537-7697 (TDD), or by email at 
                            <E T="03">OCRPrivacy@hhs.gov.</E>
                        </P>
                    </FURINF>
                </PREAMB>
                <SUPLINF>
                    <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD>
                    <P>The discussion below includes an Executive Summary, a description of relevant statutory and regulatory authority and history, the justification for this proposed regulation, a section-by-section description of the proposed modifications, and a regulatory impact analysis and other required regulatory analyses. The Department solicits public comment on all aspects of the proposed rule. The Department requests that persons commenting on the provisions of the proposed rule label their discussion of any particular provision or topic with a citation to the section of the proposed rule being addressed and identify the particular request for comment being addressed, if applicable.</P>
                    <HD SOURCE="HD1">Table of Contents</HD>
                    <EXTRACT>
                        <FP SOURCE="FP-2">I. Executive Summary</FP>
                        <FP SOURCE="FP1-2">A. Overview</FP>
                        <FP SOURCE="FP1-2">B. Applicability</FP>
                        <FP SOURCE="FP1-2">C. Table of Abbreviations/Commonly Used Acronyms in This Document</FP>
                        <FP SOURCE="FP-2">II. Statutory Authority and Regulatory History</FP>
                        <FP SOURCE="FP1-2">A. Statutory Authority and History</FP>
                        <FP SOURCE="FP1-2">1. Health Insurance Portability and Accountability Act of 1996 (HIPAA)</FP>
                        <FP SOURCE="FP1-2">2. Health Information Technology for Economic and Clinical Health (HITECH) Act</FP>
                        <FP SOURCE="FP1-2">B. Regulatory History</FP>
                        <FP SOURCE="FP1-2">1. 1998 Security Rule Notice of Proposed Rulemaking</FP>
                        <FP SOURCE="FP1-2">2. 2003 Final Rule</FP>
                        <FP SOURCE="FP1-2">3. 2009 Delegation of Authority</FP>
                        <FP SOURCE="FP1-2">4. 2013 Omnibus Rulemaking</FP>
                        <FP SOURCE="FP-2">III. Justification for This Proposed Rulemaking</FP>
                        <FP SOURCE="FP1-2">A. Strong Security Standards Are Essential to Protecting the Confidentiality, Integrity, and Availability of ePHI and Ensuring Quality and Efficiency in the Health Care System</FP>
                        <FP SOURCE="FP1-2">B. The Health Care Environment Has Changed Since the Security Rule Was Last Revised and Will Continue To Evolve</FP>
                        <FP SOURCE="FP1-2">C. Regulated Entities' Compliance With the Requirements of the Security Rule Is Inconsistent</FP>
                        <FP SOURCE="FP1-2">D. It Is Reasonable and Appropriate To Strengthen the Security Rule To Address the Changes in the Health Care Environment and Clarify the Compliance Obligations of Regulated Entities</FP>
                        <FP SOURCE="FP1-2">
                            1. Congress and the Department Anticipated That Security Standards 
                            <PRTPAGE P="899"/>
                            Safeguards Would Evolve To Address Changes in the Health Care Environment
                        </FP>
                        <FP SOURCE="FP1-2">2. NCVHS Believes That the Security Standards Evolve To Address Changes in the Health Care Environment</FP>
                        <FP SOURCE="FP1-2">3. A Strengthened Security Rule Would Continue To Be Flexible and Scalable While Providing Regulated Entities With Greater Clarity</FP>
                        <FP SOURCE="FP1-2">4. Small and Rural Health Care Providers Must Implement Strong Security Measures To Provide Efficient and Effective Health Care</FP>
                        <FP SOURCE="FP1-2">5. A Strengthened Security Rule Is Critical to an Efficient and Effective Health Care System</FP>
                        <FP SOURCE="FP1-2">E. The Secretary Must Develop Standards for the Security of ePHI Because None Have Been Developed by an ANSI-Accredited Standard Setting Organization</FP>
                        <FP SOURCE="FP-2">IV. Section-by-Section Description of the Proposed Amendments to the Security Rule</FP>
                        <FP SOURCE="FP1-2">A. Section 160.103—Definitions</FP>
                        <FP SOURCE="FP1-2">1. Current Provision</FP>
                        <FP SOURCE="FP1-2">2. Issues To Address</FP>
                        <FP SOURCE="FP1-2">3. Proposals</FP>
                        <FP SOURCE="FP1-2">4. Request for Comment</FP>
                        <FP SOURCE="FP1-2">B. Section 164.304—Definitions</FP>
                        <FP SOURCE="FP1-2">1. Clarifying the Definition of “Access”</FP>
                        <FP SOURCE="FP1-2">2. Clarifying the Definition of “Administrative Safeguards”</FP>
                        <FP SOURCE="FP1-2">3. Clarifying the Definition of “Authentication”</FP>
                        <FP SOURCE="FP1-2">4. Clarifying the Definition of “Availability”</FP>
                        <FP SOURCE="FP1-2">5. Clarifying the Definition of “Confidentiality”</FP>
                        <FP SOURCE="FP1-2">6. Adding Definitions of “Deploy” and “Implement”</FP>
                        <FP SOURCE="FP1-2">7. Adding a Definition of “Electronic Information System”</FP>
                        <FP SOURCE="FP1-2">8. Modifying the Definition of “Information System”</FP>
                        <FP SOURCE="FP1-2">9. Modifying the Definition of “Malicious software”</FP>
                        <FP SOURCE="FP1-2">10. Adding a Definition of “Multi-factor Authentication” (MFA)</FP>
                        <FP SOURCE="FP1-2">11. Clarifying the Definition of “Password”</FP>
                        <FP SOURCE="FP1-2">12. Clarifying the Definition of “Physical Safeguards”</FP>
                        <FP SOURCE="FP1-2">13. Adding a Definition of “Relevant Electronic Information System”</FP>
                        <FP SOURCE="FP1-2">14. Adding a Definition of “Risk”</FP>
                        <FP SOURCE="FP1-2">15. Clarifying the Definitions of “Security or Security Measures” and “Security Incident”</FP>
                        <FP SOURCE="FP1-2">16. Adding Definitions of “Technical Controls”</FP>
                        <FP SOURCE="FP1-2">17. Modifying the Definition of “Technical Safeguards”</FP>
                        <FP SOURCE="FP1-2">18. Adding a Definition of “Technology Asset”</FP>
                        <FP SOURCE="FP1-2">19. Adding a Definition of “Threat”</FP>
                        <FP SOURCE="FP1-2">20. Clarifying the Definition of “User”</FP>
                        <FP SOURCE="FP1-2">21. Adding a Definition of “Vulnerability”</FP>
                        <FP SOURCE="FP1-2">22. Clarifying the Definition of “Workstation”</FP>
                        <FP SOURCE="FP1-2">23. Request for Comment</FP>
                        <FP SOURCE="FP1-2">C. Section 164.306—Security Standards: General Rules</FP>
                        <FP SOURCE="FP1-2">1. Current Provisions</FP>
                        <FP SOURCE="FP1-2">2. Issues To Address</FP>
                        <FP SOURCE="FP1-2">3. Proposals</FP>
                        <FP SOURCE="FP1-2">4. Request for Comment</FP>
                        <FP SOURCE="FP1-2">D. Section 164.308—Administrative Safeguards</FP>
                        <FP SOURCE="FP1-2">1. Current Provisions</FP>
                        <FP SOURCE="FP1-2">2. Issues To Address</FP>
                        <FP SOURCE="FP1-2">3. Proposals</FP>
                        <FP SOURCE="FP1-2">4. Request for Comment</FP>
                        <FP SOURCE="FP1-2">E. Section 164.310—Physical Safeguards</FP>
                        <FP SOURCE="FP1-2">1. Current Provisions</FP>
                        <FP SOURCE="FP1-2">2. Issues To Address</FP>
                        <FP SOURCE="FP1-2">3. Proposals</FP>
                        <FP SOURCE="FP1-2">4. Request for Comment</FP>
                        <FP SOURCE="FP1-2">F. Section 164.312—Technical Safeguards</FP>
                        <FP SOURCE="FP1-2">1. Current Provisions</FP>
                        <FP SOURCE="FP1-2">2. Issues To Address</FP>
                        <FP SOURCE="FP1-2">3. Proposals</FP>
                        <FP SOURCE="FP1-2">4. Request for Comment</FP>
                        <FP SOURCE="FP1-2">G. Section 164.314—Organizational Requirements</FP>
                        <FP SOURCE="FP1-2">1. Section 164.314(a)(1)—Standard: Business Associate Contracts or Other Arrangements</FP>
                        <FP SOURCE="FP1-2">2. Section 164.314(b)(1)—Standard: Requirements for Group Health Plans</FP>
                        <FP SOURCE="FP1-2">3. Request for Comment</FP>
                        <FP SOURCE="FP1-2">H. Section 164.316—Documentation Requirements</FP>
                        <FP SOURCE="FP1-2">1. Current Provisions</FP>
                        <FP SOURCE="FP1-2">2. Issues To Address</FP>
                        <FP SOURCE="FP1-2">3. Proposals</FP>
                        <FP SOURCE="FP1-2">4. Request for Comment</FP>
                        <FP SOURCE="FP1-2">I. Section 164.318—Transition Provisions</FP>
                        <FP SOURCE="FP1-2">1. Current Provisions and Issues To Address</FP>
                        <FP SOURCE="FP1-2">2. Proposal</FP>
                        <FP SOURCE="FP1-2">3. Request for Comment</FP>
                        <FP SOURCE="FP1-2">J. Section 164.320—Severability</FP>
                        <FP SOURCE="FP1-2">K. New and Emerging Technologies Request for Information</FP>
                        <FP SOURCE="FP1-2">1. Quantum Computing</FP>
                        <FP SOURCE="FP1-2">2. Artificial Intelligence (AI)</FP>
                        <FP SOURCE="FP1-2">3. Virtual and Augmented Reality (VR and AR)</FP>
                        <FP SOURCE="FP1-2">4. Request for Comment</FP>
                        <FP SOURCE="FP-2">V. Regulatory Impact Analysis</FP>
                        <FP SOURCE="FP1-2">A. Executive Order 12866 and Related Executive Orders on Regulatory Review</FP>
                        <FP SOURCE="FP1-2">1. Summary of Costs and Benefits</FP>
                        <FP SOURCE="FP1-2">2. Baseline Conditions</FP>
                        <FP SOURCE="FP1-2">3. Costs of the Proposed Rule</FP>
                        <FP SOURCE="FP1-2">4. Benefits of the Proposed Rule</FP>
                        <FP SOURCE="FP1-2">5. Comparison of Benefits and Costs</FP>
                        <FP SOURCE="FP1-2">B. Regulatory Alternatives to the Proposed Rule</FP>
                        <FP SOURCE="FP1-2">C. Regulatory Flexibility Act—Small Entity Analysis</FP>
                        <FP SOURCE="FP1-2">D. Executive Order 13132—Federalism</FP>
                        <FP SOURCE="FP1-2">E. Assessment of Federal Regulation and Policies on Families</FP>
                        <FP SOURCE="FP1-2">F. Paperwork Reduction Act of 1995</FP>
                        <FP SOURCE="FP1-2">1. Explanation of Estimated Annualized Burden Hours</FP>
                    </EXTRACT>
                    <HD SOURCE="HD1">I. Executive Summary</HD>
                    <HD SOURCE="HD2">A. Overview</HD>
                    <P>
                        In this notice of proposed rulemaking (NPRM), the Department of Health and Human Services (HHS or “Department”) proposes modifications to the Security Standards for the Protection of Electronic Protected Health Information (“Security Rule”), issued pursuant to section 262(a) of the Administrative Simplification provisions of title II, subtitle F, of the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
                        <SU>1</SU>
                        <FTREF/>
                         The Security Rule 
                        <SU>2</SU>
                        <FTREF/>
                         is one of several rules, collectively known as the HIPAA Rules,
                        <SU>3</SU>
                        <FTREF/>
                         that protect the privacy and security of individuals' protected health information 
                        <SU>4</SU>
                        <FTREF/>
                         (PHI), which is individually identifiable health information 
                        <SU>5</SU>
                        <FTREF/>
                         (IIHI) transmitted by or maintained in electronic media or any other form or medium, with certain exceptions.
                        <SU>6</SU>
                        <FTREF/>
                         The Security Rule applies only to electronic PHI (ePHI), which is IIHI that is transmitted by or maintained in electronic media.
                        <SU>7</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>1</SU>
                             Subtitle F of title II of HIPAA (Pub. L. 104-191, 110 Stat. 1936 (Aug. 21, 1996)) added a new part C to title XI of the Social Security Act of 1935 (SSA), Public Law 74-271, 49 Stat. 620 (Aug. 14, 1935), (
                            <E T="03">see</E>
                             sections 1171-1179 of the SSA (codified at 42 U.S.C. 1320d-1320d-8)), as well as promulgating section 264 of HIPAA (codified at 42 U.S.C. 1320d-2 note), which authorizes the Secretary to promulgate regulations with respect to the privacy of individually identifiable health information. The Privacy Rule has subsequently been amended pursuant to the Genetic Information Nondiscrimination Act of 2008, title I, section 105, Public Law 110-233, 122 Stat. 881 (May 21, 2008) (codified at 42 U.S.C. 2000ff), and the Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009, Public Law 111-5, 123 Stat. 226 (Feb. 17, 2009) (codified at 42 U.S.C. 139w-4(0)(2)).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>2</SU>
                             45 CFR part 160 subparts A and C of 45 CFR part 164. For a history of the Security Rule, 
                            <E T="03">see</E>
                             section II.B, “Regulatory History.”
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>3</SU>
                             
                            <E T="03">See also</E>
                             the HIPAA Privacy Rule, 45 CFR part 160 and subparts A and E of 45 CFR part 164; HIPAA Breach Notification Rule, 45 CFR part 164, subpart D; and the HIPAA Enforcement Rule, 45 CFR part 160, subparts C through E.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>4</SU>
                             45 CFR 160.103 (definition of “Protected health information”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>5</SU>
                             45 CFR 160.103 (definition of “Individually identifiable health information”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>6</SU>
                             At times throughout this NPRM, the Department uses the terms “health information” or “individuals' health information” to refer generically to health information pertaining to an individual or individuals. In contrast, the Department's use of the term “IIHI” refers to a category of health information defined in HIPAA, and “PHI” is used to refer specifically to a category of IIHI that is defined by and subject to the requirements of the HIPAA Rules. The HIPAA Rules exclude from the definition of PHI: IIHI in employment records held by a covered entity in its role as employer; IIHI in education records and certain treatment records covered by the Family Educational Rights and Privacy Act (codified at 20 U.S.C. 1232g); and IIHI regarding a person who has been deceased for more than 50 years. 45 CFR 160.103 (definition of “Protected health information”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>7</SU>
                             45 CFR 160.103 (definition of “Electronic protected health information”).
                        </P>
                    </FTNT>
                    <P>
                        The Security Rule was initially published in 2003 and most recently revised in 2013.
                        <SU>8</SU>
                        <FTREF/>
                         Since its publication, there have been significant changes to the environment in which health care is provided and how the health care industry operates. Today, cybersecurity is a concern that touches nearly every facet of modern health care, certainly more than it did in 2003 or even 2013. 
                        <PRTPAGE P="900"/>
                        Almost every stage of modern health care relies on stable and secure computer and network technologies, including, but not limited to, the following: appointment scheduling, prescription orders, telehealth visits, medical devices, patient records, medical and pharmacy claims submissions and billing, insurance coverage verifications, payroll, facilities access and management, internal and external communications, and clinician resources. These tools and technologies are an integral part of the modern health care system, but they also present opportunities for bad actors to cause harm through hacking, ransomware, and other means. Covered entities and business associates (collectively, “regulated entities”) may also experience malfunctions and inadvertent errors that threaten the confidentiality, integrity, or availability of ePHI. Thus, cyberattacks, malfunctions, and inadvertent errors can negatively affect the provision of health care, as well as the efficiency and effectiveness of the health care system.
                    </P>
                    <FTNT>
                        <P>
                            <SU>8</SU>
                             
                            <E T="03">See</E>
                             68 FR 8334 (Feb. 20, 2003) and 78 FR 5566 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <P>
                        As discussed in greater detail below, in recent years, there has been an alarming growth in the number of breaches affecting 500 or more individuals reported to the Department, the overall number of individuals affected by such breaches, and the rampant escalation of cyberattacks using hacking and ransomware. The Department is concerned by the increasing numbers of breaches and other cybersecurity incidents experienced by regulated entities. We 
                        <SU>9</SU>
                        <FTREF/>
                         are also increasingly concerned by the upward trend in the numbers of individuals affected by such incidents and the magnitude of the potential harms from such incidents.
                        <SU>10</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>9</SU>
                             In this NPRM, “we” and “our” denote the Department.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>10</SU>
                             
                            <E T="03">See</E>
                             “Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information,” Office for Civil Rights, U.S. Department of Health and Human Services, 
                            <E T="03">https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf.</E>
                        </P>
                    </FTNT>
                    <P>
                        In recognition of those potential harms and the health care sector's importance to the economy and security of the U.S., the President has designated “Healthcare and Public Health” as a critical infrastructure sector 
                        <SU>11</SU>
                        <FTREF/>
                         and the Department as the Sector Risk Management Agency (SRMA).
                        <SU>12</SU>
                        <FTREF/>
                         In addition, to address concerns about the increasing level of cybercrime, the President has charged Federal agencies with “establishing and implementing minimum requirements for risk management” and robustly enforcing those requirements and Federal laws to help manage that risk.
                        <SU>13</SU>
                        <FTREF/>
                         We believe that a comprehensive and updated Security Rule is critical to accomplishing these directives and to the Department's effectiveness as the SRMA for the Healthcare and Public Health sector.
                    </P>
                    <FTNT>
                        <P>
                            <SU>11</SU>
                             Presidential Memorandum on National Security Memorandum on Critical Infrastructure Security and Resilience, National Security Memorandum/NSM-22, The White House (Apr. 30, 2024), 
                            <E T="03">https://www.whitehouse.gov/briefing-room/presidential-actions/2024/04/30/national-security-memorandum-on-critical-infrastructure-security-and-resilience/</E>
                             (“Critical infrastructure comprises the physical and virtual assets and systems so vital to the Nation that their incapacity or destruction would have a debilitating impact on national security, national economic security, or national public health or safety.”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>12</SU>
                             
                            <E T="03">Id.</E>
                             (charging an SRMA with serving as the primary Federal liaison to their designated critical infrastructure and “conduct[ing] sector-specific risk management and resilience activities”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>13</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        In further recognition of these concerns, States have promulgated or are in the process of promulgating regulations that would require the adoption of certain standards or measures for the protection of sensitive information, such as PHI.
                        <SU>14</SU>
                        <FTREF/>
                         While these proposed regulations may contain helpful guidance for regulated entities, none specifically focus on ensuring the security of ePHI and the information systems that create, receive, maintain, or transmit ePHI. Additionally, a patchwork of State-specific laws may create difficulties for regulated entities that are located or operate in multiple States. Several entities, including Federal agencies, have published and maintained guidelines, best practices, methodologies, procedures, and processes for protecting the security of sensitive information, including PHI. Some examples of these resources include the National Institute of Standards and Technology's (NIST's) “Cybersecurity Framework,” 
                        <SU>15</SU>
                        <FTREF/>
                         the HHS 405(d) Program's “Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients,” 
                        <SU>16</SU>
                        <FTREF/>
                         the Federal Trade Commission's (FTC's) “Start with Security: A Guide for Business,” 
                        <SU>17</SU>
                        <FTREF/>
                         and the Department's “Cybersecurity Performance Goals” (CPGs).
                        <SU>18</SU>
                        <FTREF/>
                         We believe that the proliferation of such documents in recent years has been helpful, and we have considered them in the development of this NPRM. However, in light of the increasing number and sophistication of cybersecurity incidents, we do not believe that these documents are sufficiently instructive for regulated entities to help improve their compliance with the Security Rule.
                    </P>
                    <FTNT>
                        <P>
                            <SU>14</SU>
                             
                            <E T="03">See, e.g.,</E>
                             “New York State Register,” 46 N.Y. Reg. 7-10, Division of Administrative Rules, New York State Department of State (Oct. 2, 2024), 
                            <E T="03">https://dos.ny.gov/system/files/documents/2024/10/100224.pdf;</E>
                             “Invitation for Preliminary Comments on Proposed Rulemaking: Cybersecurity Audits, Risk Assessments, and Automated Decisionmaking,” California Privacy Protection Agency (Feb. 10, 2023), 
                            <E T="03">https://cppa.ca.gov/regulations/pdf/invitation_for_comments_pr_02-2023.pdf; see also</E>
                             Cal. Civ. Code Section 1798.185.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>15</SU>
                             “The NIST Cybersecurity Framework (CSF) 2.0,” National Institute of Standards and Technology, U.S. Department of Commerce (Feb. 26, 2024), 
                            <E T="03">https://doi.org/10.6028/NIST.CSWP.29.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>16</SU>
                             “Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients,” U.S. Department of Health and Human Services and the Healthcare &amp; Public Health Sector Coordinating Council (2023), 
                            <E T="03">https://405d.hhs.gov/Documents/HICP-Main-508.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>17</SU>
                             “Start with Security: A Guide for Business,” Federal Trade Commission (Aug. 2023), 
                            <E T="03">https://www.ftc.gov/system/files/ftc_gov/pdf/920a_start_with_security_en_aug2023_508_final_0.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>18</SU>
                             “Cybersecurity Performance Goals,” U.S. Department of Health and Human Services (Jan. 2024), 
                            <E T="03">https://hphcyber.hhs.gov/performance-goals.html.</E>
                        </P>
                    </FTNT>
                    <P>
                        Under its statutory authority to administer and enforce the HIPAA Rules, the Department modifies the HIPAA Rules as needed, but does not modify a standard or implementation specification more than once every 12 months.
                        <SU>19</SU>
                        <FTREF/>
                         The Department makes the determination that such modifications may be needed using information it receives on an ongoing basis—from the Department's Federal advisory committee on HIPAA, the public, regulated entities, media reports, and its own analysis of the state of privacy and security for IIHI. As referenced above, and discussed in greater detail below, while the Department believes that the Security Rule generally continues to accomplish the goals of HIPAA,
                        <SU>20</SU>
                        <FTREF/>
                         we believe that it would be appropriate to consider modifying the Security Rule to address the following:
                    </P>
                    <FTNT>
                        <P>
                            <SU>19</SU>
                             Sec. 1174(b)(1) of the SSA; 45 CFR 160.104.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>20</SU>
                             
                            <E T="03">See</E>
                             sec. 261 of Public Law 104-191, 110 Stat. 1936 (codified at 42 U.S.C. 1320d note).
                        </P>
                    </FTNT>
                    <P>• Significant changes in technology.</P>
                    <P>• Changes in breach trends and cyberattacks.</P>
                    <P>• HHS' Office for Civil Rights' (OCR's) enforcement experience.</P>
                    <P>• Other guidelines, best practices, methodologies, procedures, and processes for protecting ePHI.</P>
                    <P>• Court decisions that affect enforcement of the Security Rule.</P>
                    <HD SOURCE="HD2">B. Applicability</HD>
                    <P>
                        The effective date of a final rule would be 60 days after publication.
                        <SU>21</SU>
                        <FTREF/>
                         Regulated entities would have until the “compliance date” to establish and implement policies, procedures, and practices to achieve compliance with any new or modified standards. 
                        <PRTPAGE P="901"/>
                        Regulated entities would be permitted to comply earlier than the compliance date, but the Department would not take action against them for noncompliance with the proposed changes that occurs before the compliance date. Except as otherwise provided, 45 CFR 160.105 provides that regulated entities must comply with the applicable new or modified standards or implementation specifications no later than 180 days from the effective date of any such change. The Department has previously noted that the 180-day general compliance period for new or modified standards would not apply where a different compliance period is provided in the regulation for one or more provisions.
                        <SU>22</SU>
                        <FTREF/>
                         However, the compliance period cannot be less than the statutory minimum of 180 days.
                        <SU>23</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>21</SU>
                             
                            <E T="03">See</E>
                             “A Guide to the Rulemaking Process,” Office of the Federal Register (2011), p. 8, 
                            <E T="03">https://www.federalregister.gov/uploads/2011/01/the_rulemaking_process.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>22</SU>
                             
                            <E T="03">See</E>
                             78 FR 5566, 5569 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>23</SU>
                             
                            <E T="03">See</E>
                             42 U.S.C. 1320d-4(b)(2).
                        </P>
                    </FTNT>
                    <P>While we recognize that we are proposing to substantially revise the regulatory text, the Department believes that most of the existing Security Rule's obligations for regulated entities would not be substantially changed by the proposed modifications. Instead, the proposed modifications would explicitly codify those activities that are critical to protecting the security of ePHI as requirements and provide greater detail for such requirements in the regulatory text. For example, regulated entities are already required to conduct an accurate and thorough risk analysis. While not specified in the regulatory text of the Security Rule, an accurate and thorough risk analysis requires a regulated entity to perform an inventory of its technology assets, determine how ePHI moves through its information systems, and identify the locations within its information systems (or components thereof) where ePHI may be created, received, maintained, or transmitted. Applying such an approach protects ePHI across all phases of the data lifecycle consistent with the purpose of the Security Rule. The proposals to require a regulated entity to inventory its technology assets and map the movement of ePHI through its information systems would illuminate considerations to be included in the regulated entity's risk analysis.</P>
                    <P>
                        As another example, implementing a mechanism to encrypt ePHI is an addressable implementation specification under the standard for access control at 45 CFR 164.312(a)(2)(iv). Under the existing Security Rule, a regulated entity must assess whether encryption is a reasonable and appropriate safeguard in its environment, when analyzed with reference to its likely contribution to protecting ePHI, and implement encryption if reasonable and appropriate.
                        <SU>24</SU>
                        <FTREF/>
                         If encryption is not reasonable and appropriate, a regulated entity must document why it would not be reasonable and appropriate for it to implement the safeguard and must implement an equivalent alternative measure if reasonable and appropriate.
                        <SU>25</SU>
                        <FTREF/>
                         As discussed in greater detail below, encryption is built into most software today, and where it is not, there are affordable and easily implemented solutions that can encrypt sensitive information. Thus, it generally would be reasonable and appropriate for regulated entities to implement a mechanism to encrypt ePHI, and regulated entities should already have done so in most circumstances. By expressly requiring regulated entities to encrypt ePHI, with limited exceptions, the Department's proposal would reflect our expectations in the current cybersecurity environment and eliminate the need for regulated entities to perform an analysis of whether encryption is reasonable and appropriate.
                    </P>
                    <FTNT>
                        <P>
                            <SU>24</SU>
                             45 CFR 164.306(d)(3)(i) and (d)(3)(ii)(A).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>25</SU>
                             45 CFR 164.306(d)(3)(ii)(B).
                        </P>
                    </FTNT>
                    <P>Thus, most of the modifications we are proposing would provide regulated entities with greater clarity and specificity regarding how to fulfill their obligations and the Department's expectations.</P>
                    <P>
                        Accordingly, we do not believe that the proposed rule would pose unique implementation challenges that would justify an extended compliance period (
                        <E T="03">i.e.,</E>
                         a period longer than the standard 180 days provided in 45 CFR 160.105). Further, the Department believes that adherence to the standard compliance period is necessary to timely address the circumstances described in this NPRM. Thus, the Department proposes to apply the standard compliance date of 180 days after the effective date of a final rule.
                        <SU>26</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>26</SU>
                             
                            <E T="03">See</E>
                             45 CFR 160.104(c)(1), which requires the Secretary to provide at least a 180-day period for regulated entities to comply with modifications to standards and implementation specifications in the HIPAA Rules.
                        </P>
                    </FTNT>
                    <P>
                        To help reduce administrative burdens on regulated entities, the Department proposes to add a provision at 45 CFR 164.318 affording regulated entities a transition period (beyond the 180-day compliance period) to modify business associate contracts (herein referred to as “business associate agreements”) or other written arrangements 
                        <SU>27</SU>
                        <FTREF/>
                         that would qualify for the longer transition period, as discussed further below.
                    </P>
                    <FTNT>
                        <P>
                            <SU>27</SU>
                             45 CFR 164.314(a)(1).
                        </P>
                    </FTNT>
                    <P>The Department seeks comment on the proposed compliance period and transition period.</P>
                    <HD SOURCE="HD2">C. Table of Abbreviations/Commonly Used Acronyms in This Document</HD>
                    <P>As used in this preamble, the following terms and abbreviations have the meanings noted below.</P>
                    <GPOTABLE COLS="2" OPTS="L2,tp0,i1" CDEF="s50,r150">
                        <TTITLE> </TTITLE>
                        <BOXHD>
                            <CHED H="1">Term</CHED>
                            <CHED H="1">Meaning</CHED>
                        </BOXHD>
                        <ROW>
                            <ENT I="01">AI</ENT>
                            <ENT>Artificial Intelligence.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">ANSI</ENT>
                            <ENT>American National Standards Institute.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">AR</ENT>
                            <ENT>Augmented Reality.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">ARRA</ENT>
                            <ENT>American Recovery and Reinvestment Act of 2009.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">ASTP/ONC</ENT>
                            <ENT>Assistant Secretary for Technology Policy and Office of the National Coordinator for Health Information Technology.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">CISA</ENT>
                            <ENT>Cybersecurity &amp; Infrastructure Security Agency.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">CMS</ENT>
                            <ENT>Centers for Medicare &amp; Medicaid Services.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">CPG</ENT>
                            <ENT>Cybersecurity Performance Goal.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Department or HHS</ENT>
                            <ENT>Department of Health and Human Services.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">EHR</ENT>
                            <ENT>Electronic Health Record.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">E.O.</ENT>
                            <ENT>Executive Order.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">ePHI</ENT>
                            <ENT>Electronic Protected Health Information.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">FDA</ENT>
                            <ENT>Food &amp; Drug Administration.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">FISMA</ENT>
                            <ENT>Federal Information Security Modernization Act.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">FTC</ENT>
                            <ENT>Federal Trade Commission.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Health IT</ENT>
                            <ENT>Health Information Technology.</ENT>
                        </ROW>
                        <ROW>
                            <PRTPAGE P="902"/>
                            <ENT I="01">HIPAA</ENT>
                            <ENT>Health Insurance Portability and Accountability Act of 1996.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">HITECH Act</ENT>
                            <ENT>Health Information Technology for Economic and Clinical Health Act of 2009.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">ICR</ENT>
                            <ENT>Information Collection Request.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">IIHI</ENT>
                            <ENT>Individually Identifiable Health Information.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">IT</ENT>
                            <ENT>Information Technology.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">MFA</ENT>
                            <ENT>Multi-factor Authentication.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">NAICS</ENT>
                            <ENT>North American Industry Classification System.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">NCVHS</ENT>
                            <ENT>National Committee on Vital and Health Statistics.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">NIST</ENT>
                            <ENT>National Institute of Standards and Technology.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">NPRM</ENT>
                            <ENT>Notice of Proposed Rulemaking.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">OCR</ENT>
                            <ENT>Office for Civil Rights.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">OMB</ENT>
                            <ENT>Office of Management and Budget.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">ONC</ENT>
                            <ENT>Office of the National Coordinator for Health Information Technology.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">PHI</ENT>
                            <ENT>Protected Health Information.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">PRA</ENT>
                            <ENT>Paperwork Reduction Act of 1995.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">PSAO</ENT>
                            <ENT>Pharmacy Services Administration Organizations.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">RFA</ENT>
                            <ENT>Regulatory Flexibility Act.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">RIA</ENT>
                            <ENT>Regulatory Impact Analysis.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">SBA</ENT>
                            <ENT>Small Business Administration.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">SRMA</ENT>
                            <ENT>Sector Risk Management Agency.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">SSA</ENT>
                            <ENT>Social Security Act of 1935.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">UMRA</ENT>
                            <ENT>Unfunded Mandates Reform Act of 1995.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">VR</ENT>
                            <ENT>Virtual Reality.</ENT>
                        </ROW>
                    </GPOTABLE>
                    <HD SOURCE="HD1">II. Statutory Authority and Regulatory History</HD>
                    <HD SOURCE="HD2">A. Statutory Authority and History</HD>
                    <HD SOURCE="HD3">1. Health Insurance Portability and Accountability Act of 1996 (HIPAA)</HD>
                    <P>
                        In 1996, Congress enacted HIPAA 
                        <SU>28</SU>
                        <FTREF/>
                         to reform the health care delivery system to “improve portability and continuity of health insurance coverage in the group and individual markets” 
                        <SU>29</SU>
                        <FTREF/>
                         and “to simplify the administration of health insurance.” 
                        <SU>30</SU>
                        <FTREF/>
                         Through subtitle F of HIPAA, Congress amended title XI of the Social Security Act of 1935 (SSA) by adding part C, entitled “Administrative Simplification.” 
                        <SU>31</SU>
                        <FTREF/>
                         A primary purpose of part C is to improve the Medicare and Medicaid programs and “the efficiency and effectiveness of the health care system, by encouraging the development of a health information system through the establishment of uniform standards and requirements for the electronic transmission of certain health information.” 
                        <SU>32</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>28</SU>
                             Public Law 104-191, 110 Stat. 1936 (Aug. 21, 1996) (codified at 42 U.S.C. 201 note).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>29</SU>
                             
                            <E T="03">See</E>
                             H.R. Rep. No. 104-496, at 66-67 (1996).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>30</SU>
                             Public Law 104-191, 110 Stat. 1936 (Aug. 21, 1996).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>31</SU>
                             Sec. 262(a) of Public Law 104-191, 110 Stat. 2021 (Aug. 21, 1996) (codified at 42 U.S.C. 1320d).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>32</SU>
                             Sec. 261 of Public Law 104-191, 110 Stat. 2021 (Aug. 21, 1996), as amended by sec. 1104(a) of Public Law 111-148, 124 Stat. 146 (Mar. 23, 2010) (codified at 42 U.S.C. 1320d note).
                        </P>
                    </FTNT>
                    <P>
                        Congress recognized that the development of a health information system that enabled the electronic transmission of IIHI as required by HIPAA would pose risks to the privacy of confidential health information and viewed individual privacy, confidentiality, and data security as critical to support the shift from a paper-based recordkeeping system for health information to a digital one.
                        <SU>33</SU>
                        <FTREF/>
                         Congress intended for the law to enhance individuals' trust in health care providers, which required that the law provide additional protection for the confidentiality of IIHI. As described by a Member of Congress at the time of the law's passage: “[t]his standardization, however, accelerates the creation of large databases containing personally identifiable information. All this information is transmitted over electronic networks. We need to be very careful about how safe and secure that information is from prying eyes. Some of it may be extremely sensitive and could be used in a malicious or discriminatory manner.” 
                        <SU>34</SU>
                        <FTREF/>
                         Moreover, Congress considered that health care reform required an approach that would not compromise privacy as health information became more accessible.
                        <SU>35</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>33</SU>
                             On a resolution waiving points of order against the Conference Report to H.R. 3103, members debated an “erosion of privacy” balanced against the administrative simplification provisions. Thus, from HIPAA's inception, privacy has been a central concern to be addressed as legislative changes eased disclosures of PHI. 
                            <E T="03">See</E>
                             142 Cong. Rec. H9777 and H9780.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>34</SU>
                             142 Cong. Rec. S9515-16 (daily ed. Aug. 2, 1996) (statement of Sen. Simon).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>35</SU>
                             
                            <E T="03">See</E>
                             H.R. Rep. No. 104-496 Part 1, at 99-100 (Mar. 25, 1996).
                        </P>
                    </FTNT>
                    <P>
                        Congress applied the Administrative Simplification provisions directly to three types of persons referred to in regulation as covered entities: health plans, health care clearinghouses, and health care providers who transmit information electronically in connection with a transaction for which HHS has adopted a standard.
                        <SU>36</SU>
                        <FTREF/>
                         Under HIPAA, covered entities are required to maintain reasonable and appropriate administrative, physical, and technical safeguards 
                        <SU>37</SU>
                        <FTREF/>
                         to: (1) ensure the integrity and confidentiality of information; 
                        <SU>38</SU>
                        <FTREF/>
                         (2) protect against any reasonably anticipated threats or hazards to the security or integrity of the information and unauthorized uses or disclosures of the information; 
                        <SU>39</SU>
                        <FTREF/>
                         and (3) otherwise ensure compliance with HIPAA by the officers and employees of covered entities.
                        <SU>40</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>36</SU>
                             
                            <E T="03">See</E>
                             sec. 262(a) of Public Law 104-191, 110 Stat. 2021, adding section 1172 to the SSA (codified at 42 U.S.C. 1320d-1); 
                            <E T="03">see also</E>
                             section 13404 of the American Recovery and Reinvestment Act (ARRA) of 2009, Public Law 111-5, 123 Stat. 115 (Feb. 17, 2009) (codified at 42 U.S.C. 17934) (applying privacy provisions and penalties to business associates of covered entities). The Department codified the term “covered entity” and defined it using these three categories of persons. 45 CFR 164.103.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>37</SU>
                             42 U.S.C. 1320d-2(d)(2).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>38</SU>
                             42 U.S.C. 1320d-2(d)(2)(A).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>39</SU>
                             42 U.S.C. 1320d-2(d)(2)(B).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>40</SU>
                             42 U.S.C. 1320d-2(d)(2)(C).
                        </P>
                    </FTNT>
                    <P>
                        HIPAA required the Secretary to adopt uniform standards “to enable health information to be exchanged electronically.” 
                        <SU>41</SU>
                        <FTREF/>
                         Congress also directed the Secretary to, among other things, adopt standards for the security of IIHI.
                        <SU>42</SU>
                        <FTREF/>
                         The statute also directed the Secretary to adopt initial security standards within 18 months of its 
                        <PRTPAGE P="903"/>
                        enactment.
                        <SU>43</SU>
                        <FTREF/>
                         In adopting security standards for health information, HIPAA requires the Secretary to consider all of the following: 
                        <SU>44</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>41</SU>
                             Sec. 262(a) of Public Law 104-191, 110 Stat. 2024, adding sec. 1173(a) (codified at 42 U.S.C. 1320d-2(a)(1)).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>42</SU>
                             Sec. 262(a) of Public Law 104-191, 110 Stat. 2025, adding sec. 1173(d) (codified at 42 U.S.C. 1320d-2(d)).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>43</SU>
                             Sec. 262(a) of Public Law 104-191, 110 Stat. 2026, adding sec. 1174(a) (codified at 42 U.S.C. 1320d-3(a)).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>44</SU>
                             Sec. 262(a) of Public Law 104-191, 110 Stat. 2025, adding sec. 1173(d)(1) (codified at 42 U.S.C. 1320d-2(d)(1)).
                        </P>
                    </FTNT>
                    <P>• The technical capabilities of record systems used to maintain health information.</P>
                    <P>• The costs of security measures.</P>
                    <P>• Training for persons who have access to health information.</P>
                    <P>• The value of audit trails in computerized record systems.</P>
                    <P>
                        • The needs and capabilities of small health care providers and rural health care providers.
                        <SU>45</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>45</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Congress contemplated that the Department's rulemaking authorities under HIPAA would not be static. In fact, Congress specifically built in a mechanism to adapt such regulations as technology and health care evolve, directing the Secretary to review and adopt modifications to the Administrative Simplification standards, including the security standards, as determined appropriate, but not more frequently than once every 12 months.
                        <SU>46</SU>
                        <FTREF/>
                         That statutory directive complements the Secretary's general rulemaking authority to make and publish such rules and regulations as may be necessary to the efficient administration of the functions with which the Secretary is charged.
                        <SU>47</SU>
                        <FTREF/>
                         The Secretary may adopt either a standard developed, adopted, or modified by a standard setting organization that relates to a standard that the Secretary is authorized or required to adopt under the Administrative Simplification provisions, or a standard that is different if the different standard will substantially reduce administrative costs to health care providers and health plans.
                        <SU>48</SU>
                        <FTREF/>
                         If no standard has been adopted by any standard setting organization, the Secretary shall rely on the recommendations of the National Committee on Vital and Health Statistics (NCVHS) and consult with Federal and State agencies and private organizations.
                        <SU>49</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>46</SU>
                             Sec. 262(a) of Public Law 104-191, 110 Stat. 2026, adding sec. 1174(b)(1) (codified at 42 U.S.C. 1320d-3).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>47</SU>
                             Sec. 1102 of the SSA (codified at 42 U.S.C. 1302).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>48</SU>
                             Sec. 262(a) of Public Law 104-191, 110 Stat. 2023, adding sec. 1172 (codified at 42 U.S.C. 1320d-1).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>49</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">2. Health Information Technology for Economic and Clinical Health (HITECH) Act</HD>
                    <P>
                        On February 17, 2009, Congress enacted the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act), part of the American Recovery and Reinvestment Act of 2009 (ARRA),
                        <SU>50</SU>
                        <FTREF/>
                         promoting the nationwide adoption and standardization of health information technology (health IT) to support the electronic sharing of clinical data. The HITECH Act created financial incentives for health IT use among health care practitioners by providing funding for investing in health IT infrastructure, purchasing certified electronic health records (EHRs), and training on and the dissemination of best practices to integrate health IT.
                        <SU>51</SU>
                        <FTREF/>
                         The Purpose statement of an accompanying House of Representatives report 
                        <SU>52</SU>
                        <FTREF/>
                         on the Energy and Commerce Recovery and Reinvestment Act 
                        <SU>53</SU>
                        <FTREF/>
                         recognizes that widespread health IT adoption “has the potential to ameliorate many of the quality and efficiency problems endemic to our health care system.” Congress also understood that “[e]nsuring the privacy and security of electronic health information is critical to the success” of this immense effort to promote health IT adoption.
                        <SU>54</SU>
                        <FTREF/>
                         As a result, the HITECH Act also introduced substantial changes to the HIPAA regulations by mandating stronger safeguards for the privacy and security of ePHI.
                        <SU>55</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>50</SU>
                             Title XIII of Division A and title IV of Division B of ARRA of 2009, Public Law 111-5, 123 Stat. 115 (Feb. 17, 2009) (codified at 42 U.S.C. 201 note).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>51</SU>
                             
                            <E T="03">Id.; see also</E>
                             Subtitle B of title XIII of the HITECH Act (codified at 42 U.S.C. 17911-17912), 42 U.S.C. 300jj-31-38.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>52</SU>
                             
                            <E T="03">See</E>
                             H.R. Rep. No. 111-7, at 74 (2009), accompanying H.R. 629, 111th Cong.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>53</SU>
                             H.R. 629, Energy and Commerce Recovery and Reinvestment Act of 2009, introduced in the House on Jan. 22, 2009, contained nearly identical provisions to subtitle D of the HITECH Act.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>54</SU>
                             C. Stephen Redhead, “The Health Information Technology for Economic and Clinical Health (HITECH) Act,” Congressional Research Service, p. 8 (2009), 
                            <E T="03">https://crsreports.congress.gov/product/pdf/R/R40161/9; id.</E>
                             at 9 (“[Health IT], which generally refers to the use of computer applications in medical practice, is widely viewed as a necessary and vital component of health care reform.”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>55</SU>
                             Subtitle D of title XIII of the HITECH Act (codified at 42 U.S.C. 17921, 42 U.S.C. 17931-17941, and 42 U.S.C. 17951-17953).
                        </P>
                    </FTNT>
                    <P>
                        The HITECH Act's security requirements focused on safeguarding an individual's health information while allowing covered entities to rapidly adopt new technologies to improve the quality and efficiency of patient care.
                        <SU>56</SU>
                        <FTREF/>
                         Specifically, the HITECH Act extends the application of the Security Rule's provisions on administrative, physical, and technical safeguards and documentation requirements to business associates of covered entities, making those business associates subject to civil and criminal liability for violations of the Security Rule.
                        <SU>57</SU>
                        <FTREF/>
                         The HITECH Act also requires existing business associate agreements to incorporate new security requirements.
                        <SU>58</SU>
                        <FTREF/>
                         Additionally, the HITECH Act requires the Secretary to regularly issue guidance on the most effective and appropriate technical safeguards.
                        <SU>59</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>56</SU>
                             
                            <E T="03">See</E>
                             S. Rept. 111-3, 111th Cong. accompanying S. 336, 111th Cong., at 59 (2009).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>57</SU>
                             Sec. 13401 of Public Law 111-5, 123 Stat. 260 (codified at 42 U.S.C. 17931).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>58</SU>
                             Sec. 13401(a) of Public Law 111-5, 123 Stat. 260 (codified at 42 U.S.C. 17931).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>59</SU>
                             Sec. 13401(c) of Public Law 111-5, 123 Stat. 260 (codified at 42 U.S.C. 17931).
                        </P>
                    </FTNT>
                    <P>
                        In enacting the HITECH Act, Congress affirmed that the existing HIPAA Rules were to remain in effect to the extent that they are consistent with the HITECH Act and directed the Secretary to revise the HIPAA Rules as necessary for consistency with the HITECH Act.
                        <SU>60</SU>
                        <FTREF/>
                         Congress confirmed that the new law was not intended to have any effect on authorities already granted under HIPAA to the Department, including part C of title XI of the SSA.
                        <SU>61</SU>
                        <FTREF/>
                         Thus, Congress affirmed the Secretary's ongoing rulemaking authority to modify the Security Rule's standards and implementation specifications as often as every 12 months when appropriate, including to strengthen security protections for IIHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>60</SU>
                             Sec. 13421(b) of the HITECH Act (codified at 42 U.S.C. 17951).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>61</SU>
                             Sec. 3009(a)(1)(A) of the PHSA, as added by sec. 13101 of the HITECH Act (codified at 42 U.S.C. 300jj-19(a)(1)).
                        </P>
                    </FTNT>
                    <P>
                        In 2021, the HITECH Act was amended to require the HHS Secretary to further encourage regulated entities to bolster their cybersecurity practices.
                        <SU>62</SU>
                        <FTREF/>
                         The amendment requires the Department to consider certain recognized security practices of regulated entities when making determinations relating to certain Security Rule compliance and enforcement activities.
                        <SU>63</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>62</SU>
                             
                            <E T="03">See</E>
                             Public Law 116-321, 134 Stat. 5072, adding sec. 13412 (Jan. 5, 2021) (codified at 42 U.S.C. 17941); 
                            <E T="03">see also</E>
                             42 U.S.C. 17931 
                            <E T="03">et seq.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>63</SU>
                             
                            <E T="03">See</E>
                             Public Law 116-321, 134 Stat. 5072, adding sec. 13412 (Jan. 5, 2021) (codified at 42 U.S.C. 17941); 
                            <E T="03">see also</E>
                             sec. 13401 of Public Law 111-5, 123 Stat. 260 (codified at 42 U.S.C. 17931) (The HITECH Act adopts the same definition of business associate as the HIPAA Rules.); 45 CFR 160.103 (definition of “Business associate”).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD2">B. Regulatory History</HD>
                    <P>
                        The Security Rule requires regulated entities to implement administrative, physical, and technical safeguards to 
                        <PRTPAGE P="904"/>
                        protect ePHI.
                        <SU>64</SU>
                        <FTREF/>
                         Specifically, regulated entities must ensure the confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit; 
                        <SU>65</SU>
                        <FTREF/>
                         protect against reasonably anticipated threats or hazards to the security or integrity of the information 
                        <SU>66</SU>
                        <FTREF/>
                         and reasonably anticipated impermissible uses or disclosures; 
                        <SU>67</SU>
                        <FTREF/>
                         and ensure compliance by their workforce.
                        <SU>68</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>64</SU>
                             The Security Rule is codified at 45 CFR part 160 and subparts A and C of 45 CFR part 164.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>65</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.306(a)(1).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>66</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.306(a)(2).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>67</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.306(a)(3).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>68</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.306(a)(4).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">1. 1998 Security Rule Notice of Proposed Rulemaking</HD>
                    <P>
                        The Administrative Simplification provisions of HIPAA instructed the Secretary to adopt several standards concerning electronic transmission of health information, including those for the security of health information.
                        <SU>69</SU>
                        <FTREF/>
                         In accordance with these provisions, the Department published the Security and Electronic Signature Standards; Proposed Rule (“1998 Proposed Rule”) on August 12, 1998.
                        <SU>70</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>69</SU>
                             
                            <E T="03">See</E>
                             sec. 262(a) of Public Law 104-191, 110 Stat. 2025 (Aug. 21, 1996), adding sec. 1173(d) (codified at 42 U.S.C. 1320d-2(d)).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>70</SU>
                             63 FR 43242 (Aug. 12, 1998).
                        </P>
                    </FTNT>
                    <P>
                        In support of developing the national standards mandated under HIPAA's Administrative Simplification provisions, the Secretary, with significant input from the health care industry, defined a set of principles for guiding choices for the standards to be adopted by the Secretary.
                        <SU>71</SU>
                        <FTREF/>
                         The principles were based on direct specifications in HIPAA and also took the purpose of the law and generally desirable principles into account. Based on this work, the Department proposed that each HIPAA standard should be clear and unambiguous but technology neutral, improve the efficiency and effectiveness of the health care system, meet the needs of covered entities related to ease of use and affordability of adoption, and maintain consistency or alignment with other HIPAA standards adopted by an organization accredited by the American National Standards Institute (ANSI) and using the ANSI process for adopting such standards.
                        <SU>72</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>71</SU>
                             
                            <E T="03">Id.</E>
                             at 43244.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>72</SU>
                             
                            <E T="03">Id.</E>
                             at 43244, 43249, 43260-61.
                        </P>
                    </FTNT>
                    <P>
                        In describing its general approach to the 1998 Proposed Rule, the Department defined the security standard as a set of requirements with implementation features that covered entities must include in their operations to assure the security of individuals' ePHI.
                        <SU>73</SU>
                        <FTREF/>
                         The security standard was based on three basic concepts that were derived from the Administrative Simplification provisions of HIPAA and consistent with the characteristics the Department identified as appropriate for all HIPAA Rules.
                        <SU>74</SU>
                        <FTREF/>
                         First, the standard should be comprehensive and coordinated to address all aspects of security. Second, it should be scalable, so that it could be effectively implemented by covered entities of all types and sizes. Third, it should not be linked to specific technologies, allowing covered entities the flexibility to make use of future technology advancements.
                        <SU>75</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>73</SU>
                             
                            <E T="03">Id.</E>
                             at 43249.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>74</SU>
                             
                            <E T="03">See</E>
                             68 FR 8334, 8335 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>75</SU>
                             
                            <E T="03">Id.; see also</E>
                             63 FR 43242, 43249 (Aug. 12, 1998).
                        </P>
                    </FTNT>
                    <P>The 1998 Proposed Rule included four categories of requirements that a covered entity would have to address to safeguard the confidentiality, integrity, and availability of ePHI. They were as follows:</P>
                    <P>• Administrative procedures.</P>
                    <P>• Physical safeguards.</P>
                    <P>• Technical security services.</P>
                    <P>• Technical mechanisms.</P>
                    <P>
                        The implementation specifications described some of the requirements in greater detail, based on our determination regarding the level of instruction necessary to implement such requirements.
                        <SU>76</SU>
                        <FTREF/>
                         The Department viewed all categories as equally important.
                        <SU>77</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>76</SU>
                             63 FR 43242, 43250 (Aug. 12, 1998).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>77</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        The proposed standard did not address the extent to which a covered entity should implement the specifications.
                        <SU>78</SU>
                        <FTREF/>
                         Instead, the Department proposed to require that each covered entity assess its own security needs and risks and devise, implement, and maintain appropriate security to address its business requirements. The Department believed that this approach would leave a significant amount of flexibility for covered entities and balance the needs of securing health data against risk with the economic cost of doing so.
                        <SU>79</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>78</SU>
                             
                            <E T="03">Id.</E>
                             at 43249-50.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>79</SU>
                             
                            <E T="03">Id.</E>
                             at 43250.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">2. 2003 Final Rule</HD>
                    <P>
                        The Department issued the final Security Rule 
                        <SU>80</SU>
                        <FTREF/>
                         on February 20, 2003 (“2003 Final Rule”). In accordance with the Administrative Simplification provisions of HIPAA, the 2003 Final Rule adopted standards for the security of ePHI to be implemented by covered entities.
                    </P>
                    <FTNT>
                        <P>
                            <SU>80</SU>
                             45 CFR parts 160 and subparts A and C of 45 CFR part 164; 68 FR 8334 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <P>
                        The Department reiterated the purposes and guiding principles it articulated in the 1998 Proposed Rule and repeated that the protection of the privacy of information depends in large part on the existence of security measures to protect that information.
                        <SU>81</SU>
                        <FTREF/>
                         The Department noted that there were still no standard measures in the health care industry that address all aspects of the security of ePHI while it is being stored or during the exchange of that information between entities.
                        <SU>82</SU>
                        <FTREF/>
                         The Department explained that the use of the security standards would improve the Medicare and Medicaid programs, other Federal health programs and private health programs, and the effectiveness and efficiency of the health care industry in general by establishing a level of protection for ePHI.
                        <SU>83</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>81</SU>
                             68 FR 8334, 8335, 8371-72 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>82</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>83</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Provisions of the 2003 Final Rule did not mirror the 1998 Proposed Rule; rather, the Department finalized only certain changes. The Department noted, for example, that to maintain consistency with the use of terms as they appear in the statute and other previously released HIPAA Rules (
                        <E T="03">i.e.,</E>
                         the HIPAA Privacy and Transactions Rules), it was changing some terminology from the 1998 Proposed Rule, replacing the terms “requirement” with “standard” and “implementation feature” with “implementation specification.” 
                        <SU>84</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>84</SU>
                             
                            <E T="03">Id.</E>
                             at 8335.
                        </P>
                    </FTNT>
                    <P>
                        According to the Department, the comments received in response to the 1998 Proposed Rule overwhelmingly validated its basic assumptions that the covered entities were so varied in terms of installed technology, size, resources, and relative risk, that it would be impossible to dictate a specific solution or set of solutions that would be usable by all covered entities.
                        <SU>85</SU>
                        <FTREF/>
                         Similarly, we received numerous comments expressing the view that the security standards should not be overly prescriptive because the speed with which technology is evolving could make specific requirements obsolete and might in fact deter technological progress. Accordingly, the Department framed the standards in the 2003 Final Rule in terms that were as generic as possible and that could generally be met through a variety of approaches or technologies.
                        <SU>86</SU>
                        <FTREF/>
                         The standards, we 
                        <PRTPAGE P="905"/>
                        explained, do not allow organizations to make their own rules, only their own technology choices.
                        <SU>87</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>85</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>86</SU>
                             
                            <E T="03">Id.</E>
                             at 8336.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>87</SU>
                             
                            <E T="03">Id.</E>
                             at 8343.
                        </P>
                    </FTNT>
                    <P>
                        We also recognized that entities could minimize risk through their security practices, but likely could never completely eliminate all risk. In the preamble to the 2003 Final Rule, the Department acknowledged that there is no such thing as a totally secure system that carries no risks to security.
                        <SU>88</SU>
                        <FTREF/>
                         The Department opined that Congress' intent in the use of the word “ensure” in section 1173(d) of the SSA was to set an exceptionally high goal for the security of ePHI. However, we also recognized that Congress anticipated that some trade-offs would be necessary, and that “ensuring” protection did not mean doing so without any regard to the cost.
                        <SU>89</SU>
                        <FTREF/>
                         As such, the Department explained that we expected a covered entity to protect that information to the best of its ability.
                        <SU>90</SU>
                        <FTREF/>
                         Thus, a covered entity would be expected to balance the identifiable risks to and vulnerabilities of ePHI with the cost of various protective measures, while also taking into consideration the size, complexity, and capabilities of the covered entity.
                        <SU>91</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>88</SU>
                             
                            <E T="03">Id.</E>
                             at 8346.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>89</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>90</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>91</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        In the 2003 Final Rule, the Department introduced the concept of “addressable” implementation specifications, which it distinguished from “required” implementation specifications. The goal was to provide covered entities with even more flexibility.
                        <SU>92</SU>
                        <FTREF/>
                         While none of the implementation specifications were optional, designating some of the implementation specifications as addressable provided each covered entity with the ability to determine whether certain implementation specifications were reasonable and appropriate safeguards for that entity, based on its risk analysis, risk mitigation strategy, previously implemented security measures, and the cost of implementation.
                        <SU>93</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>92</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>93</SU>
                             
                            <E T="03">Id.</E>
                             at 8336.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD2">3. 2009 Delegation of Authority</HD>
                    <P>
                        On October 7, 2003, the Secretary delegated authority for administering and enforcing the Security Rule to the Administrator of the Centers for Medicare &amp; Medicaid Services (CMS).
                        <SU>94</SU>
                        <FTREF/>
                         The Secretary issued a notice on August 4, 2009, superseding the previous delegation and replacing it with a delegation authority to the Director of OCR effective July 27, 2009.
                        <SU>95</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>94</SU>
                             “Statement of Organization, Functions, and Delegations of Authority,” Centers for Medicare &amp; Medicaid Services, 68 FR 60694 (Oct. 23, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>95</SU>
                             “Office for Civil Rights; Delegation of Authority,” U.S. Department of Health and Human Services, 74 FR 38630 (Aug. 4, 2009); 
                            <E T="03">see also</E>
                             “Statement of Organization, Functions, and Delegations of Authority,” Centers for Medicare &amp; Medicaid Services, 74 FR 38663 (Aug. 4, 2009).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD2">4. 2013 Omnibus Rulemaking</HD>
                    <P>
                        Following the enactment of the HITECH Act, the Department issued an NPRM, entitled “Modifications to the HIPAA Privacy, Security, and Enforcement Rules Under the Health Information Technology for Economic and Clinical Health [HITECH] Act” (“2010 Proposed Rule”),
                        <SU>96</SU>
                        <FTREF/>
                         to propose implementation of certain HITECH Act requirements. In the 2010 Proposed Rule, the Department noted that it had not amended the Security Rule since 2003.
                        <SU>97</SU>
                        <FTREF/>
                         We further explained that information gleaned from contact with the public since that time, OCR's enforcement experience, and technical corrections needed to eliminate ambiguity provided the impetus for the Department's actions to propose certain regulatory changes beyond those required by the HITECH Act.
                        <SU>98</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>96</SU>
                             75 FR 40868 (July 14, 2010).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>97</SU>
                             
                            <E T="03">Id.</E>
                             at 40871.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>98</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        In 2013, the Department issued the final rule “Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the Health Information Technology for Economic and Clinical Health [HITECH] Act and the Genetic Information Nondiscrimination Act, and Other Modifications to the HIPAA Rules” (“2013 Omnibus Rule”),
                        <SU>99</SU>
                        <FTREF/>
                         which implemented applicable provisions of the HITECH Act to strengthen security protections for individuals' health information maintained in EHRs.
                    </P>
                    <FTNT>
                        <P>
                            <SU>99</SU>
                             78 FR 5565 (Jan. 25, 2013). In addition to finalizing requirements of the HITECH Act that were proposed in the NPRM, the Department adopted modifications to the Enforcement Rule not previously adopted in an earlier interim final rule, 74 FR 56123 (Oct. 30, 2009), and to the Breach Notification Rule not previously adopted in an interim final rule, 74 FR 42739 (Aug. 24, 2009). The Department also finalized previously proposed Privacy Rule modifications as required by the Genetic Information Nondiscrimination Act of 2008, 74 FR 51698 (Oct. 7, 2009).
                        </P>
                    </FTNT>
                    <P>
                        For example, the Department modified the Security Rule to implement the HITECH Act's provisions that extended direct liability for compliance with the Security Rule to business associates.
                        <SU>100</SU>
                        <FTREF/>
                         We explained that before the enactment of the HITECH Act, the Security Rule did not directly apply to business associates of covered entities. The HITECH Act extended the application of the Security Rule's administrative, physical, and technical safeguards requirements, as well as the rule's policies and procedures and documentation requirements, to business associates in the same manner as the requirements apply to covered entities, making those business associates civilly and criminally liable for violations of the Security Rule.
                        <SU>101</SU>
                        <FTREF/>
                         The Department noted that the Security Rule requires a covered entity to establish business associate agreements that obligate business associates to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI that they create, receive, maintain, or transmit on behalf of the covered entity.
                        <SU>102</SU>
                        <FTREF/>
                         Accordingly, we reasoned that business associates and subcontractors should already have security practices in place that comply with the Security Rule, or require only modest improvement to come into compliance with the Security Rule requirements.
                        <SU>103</SU>
                        <FTREF/>
                         Like the 2003 Final Rule,
                        <SU>104</SU>
                        <FTREF/>
                         the 2013 Omnibus Rule highlighted that the Security Rule was designed to be technology neutral and scalable and reiterated that regulated entities have the flexibility to choose security measures appropriate for their size, resources, and the nature of the security risks they face.
                        <SU>105</SU>
                        <FTREF/>
                         Accordingly, regulated entities have the flexibility to choose appropriate security measures considering their size, capabilities, the costs of the specific security measures, and the operational impact, enabling them to reasonably implement the standards of the Security Rule.
                    </P>
                    <FTNT>
                        <P>
                            <SU>100</SU>
                             78 FR 5565, 5589 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>101</SU>
                             Sec. 13401 of Public Law 111-5, 123 Stat. 260 (Feb. 17, 2009) (codified at 42 U.S.C. 17931).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>102</SU>
                             78 FR 5565, 5590 (Jan. 25, 2013); 
                            <E T="03">see also</E>
                             45 CFR 164.314(a).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>103</SU>
                             78 FR 5565, 5589 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>104</SU>
                             68 FR 8334, 8341 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>105</SU>
                             78 FR 5565, 5589 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <P>
                        The Department also adopted technical revisions to 45 CFR 164.306(e) to clarify that regulated entities must review and modify security measures as needed to ensure reasonable and appropriate protection of ePHI, and update documentation of security measures accordingly.
                        <SU>106</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>106</SU>
                             
                            <E T="03">Id.</E>
                             at 5590.
                        </P>
                    </FTNT>
                    <P>
                        Finally, because the HITECH Act made business associates directly liable for compliance with the Security Rule, the 2013 Omnibus Rule modified the Security Rule to clarify that a covered entity is not required to obtain satisfactory assurance from a business associate that is a subcontractor that the subcontractor will appropriately safeguard its ePHI. Rather, the business 
                        <PRTPAGE P="906"/>
                        associate of the covered entity must obtain the required satisfactory assurances from the subcontractor to protect the security of ePHI.
                        <SU>107</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>107</SU>
                             
                            <E T="03">Id.</E>
                             (citing 45 CFR 164.308(b)).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD1">III. Justification for This Proposed Rulemaking</HD>
                    <P>
                        HIPAA and the HIPAA Rules promote access to high-quality and effective health care by establishing standards for the security of ePHI. The standards, when implemented appropriately by regulated entities, protect the confidentiality, integrity, and availability of individuals' health information. Such protections promote the electronic transmission of PHI through a national health information system. To ensure access to high-quality health care services, regulated entities must assure their customers (
                        <E T="03">e.g.,</E>
                         individuals, health care providers, and health plans) of the security of the sensitive and confidential health information the regulated entities electronically create, receive, maintain, or transmit.
                    </P>
                    <P>
                        As discussed above, the Security Rule carefully balances the benefits of safeguarding against security risks with the burdens of implementing protective measures by permitting regulated entities to consider several factors, including costs and available technology for preventing and mitigating security risks,
                        <SU>108</SU>
                        <FTREF/>
                         when determining which security measures are reasonable and appropriate for protecting the security of individuals' ePHI.
                        <SU>109</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>108</SU>
                             As technology has evolved and cybercriminals have become more sophisticated, protective measures, including technology, have been developed to prevent and mitigate such risks. For example, certain health IT may be certified through the ONC Health IT Certification Program as meeting certain criteria that address the security of information created, received, maintained, or transmitted by that health IT. 
                            <E T="03">See</E>
                             45 CFR 170.550(h).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>109</SU>
                             45 CFR 164.306(b).
                        </P>
                    </FTNT>
                    <P>
                        For example, the Security Rule requires that a regulated entity implement policies and procedures to limit physical access to its electronic information systems and the facilities in which they are housed, while ensuring that users who are authorized to access such information systems and facilities are permitted to do so.
                        <SU>110</SU>
                        <FTREF/>
                         The implementation specifications associated with this standard only address the need for operationalized policies and procedures related to specific aspects of physical security.
                        <SU>111</SU>
                        <FTREF/>
                         They do not dictate the specifics of such policies and procedures because we recognize that the nature of the physical safeguards should depend on the type of regulated entity, its size, its level of access to ePHI, and a number of other factors.
                    </P>
                    <FTNT>
                        <P>
                            <SU>110</SU>
                             45 CFR 164.310(a)(1).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>111</SU>
                             45 CFR 164.310(a)(2).
                        </P>
                    </FTNT>
                    <P>
                        Since the Security Rule's promulgation in 2003, the environment in which health care is provided and in which regulated entities operate has changed significantly, including transformative changes in how regulated entities create, receive, maintain, and transmit ePHI. For example, as of 2021, almost 80 percent of physician offices and 96 percent of hospitals had adopted certified EHRs.
                        <SU>112</SU>
                        <FTREF/>
                         The use of health IT, including EHRs (certified or otherwise), has led to enormous advancements in the fields of medicine and public health, not only improving outcomes for individuals, but also assisting in addressing the social, economic, and environmental factors that affect health on an individual and community level.
                        <SU>113</SU>
                        <FTREF/>
                         And the electronic exchange of health information, spurred by HIPAA, the HITECH Act, and the 21st Century Cures Act (“Cures Act”),
                        <SU>114</SU>
                        <FTREF/>
                         has enabled regulated entities and others to more quickly and efficiently share individuals' health information, increasing the quality and efficiency of health care, increasing patient engagement, and reducing administrative burden.
                        <SU>115</SU>
                        <FTREF/>
                         However, the widespread use of health IT systems makes it even more critical for regulated entities, regardless of their size or location, to fully assess the risks and vulnerabilities to ePHI and their information systems and implement strong security measures to address those risks and vulnerabilities.
                    </P>
                    <FTNT>
                        <P>
                            <SU>112</SU>
                             “National Trends in Hospital and Physician Adoption of Electronic Health Records,” The Office of the National Coordinator for Health Information Technology, U.S. Department of Health and Human Services, 
                            <E T="03">https://www.healthit.gov/data/quickstats/national-trends-hospital-and-physician-adoption-electronic-health-records.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>113</SU>
                             
                            <E T="03">See</E>
                             “2020-2025 Federal Health IT Strategic Plan,” The Office of the National Coordinator for Health Information Technology, U.S. Department of Health and Human Services, p. 6 (Oct. 2020), 
                            <E T="03">https://www.healthit.gov/sites/default/files/page/2020-10/Federal%20Health%20IT%20Strategic%20Plan_2020_2025.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>114</SU>
                             Among other things, the Cures Act provided ONC, in collaboration with NIST and other relevant agencies within the Department, with the authority to convene public-private and public-public partnerships to build consensus and develop or support a trusted exchange framework, including a common agreement among health information networks nationally. The purpose of this work is to ensure full network-to-network exchange of health information. Sec. 4003(b) of Public Law 114-255, 130 Stat. 1165 (Dec. 13, 2016) (codified at 42 U.S.C. 300jj-11(c)). The Cures Act also provides penalties for any developer of certified health IT, health information exchange or network, and appropriate disincentives for any health care provider, determined by the Inspector General to have committed information blocking. Sec. 4004(b)(2) of Public Law 114-255, 130 Stat. 1165 (Dec. 13, 2016) (codified at 42 U.S.C. 300jj-52).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>115</SU>
                             
                            <E T="03">See</E>
                             “Frequently Asked Question: Health Information Exchange: The Benefits,” The Office of the National Coordinator for Health Information Technology, U.S. Department of Health and Human Services, 
                            <E T="03">https://www.healthit.gov/faq/why-health-information-exchange-important.</E>
                        </P>
                    </FTNT>
                    <P>
                        Experts repeatedly have expressed concern regarding the state of cybersecurity in the health care industry.
                        <SU>116</SU>
                        <FTREF/>
                         For example, in a 2017 report to Congress, experts convened by the Department pronounced, “Now more than ever, all health care delivery organizations [. . .] have a greater responsibility to secure their systems, medical devices, and patient data.” 
                        <SU>117</SU>
                        <FTREF/>
                         This responsibility has only increased as the delivery of health care and the exchange of PHI have increasingly shifted to cyberspace.
                    </P>
                    <FTNT>
                        <P>
                            <SU>116</SU>
                             
                            <E T="03">See</E>
                             Genevieve P. Kanter, et al., “Beyond Security Patches—Fundamental Incentive Problems in Health Care Cybersecurity,” JAMA Health Forum, Volume 2, Issue 10, p. e212969 (Oct. 8, 2021), 
                            <E T="03">https://jamanetwork.com/journals/jama-health-forum/fullarticle/2784981;</E>
                             Chon Abraham, et al., “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, Volume 62, Issue 4, p. 539-548, p. 539 (July-Aug. 2019), 
                            <E T="03">https://www.sciencedirect.com/science/article/abs/pii/S0007681319300436;</E>
                             Eric Perakslis, “Responding to the Escalating Cybersecurity Threat to Health Care,” The New England Journal of Medicine, Volume 387, Issue 9 (Sept. 1, 2022), 
                            <E T="03">https://www.nejm.org/doi/abs/10.1056/NEJMp2205144;</E>
                             Anthony James Cartwright, “The elephant in the room: cybersecurity in healthcare,” Journal of Clinical Monitoring and Computing, Volume 37, Issue 5, p. 1123-1132 (Apr. 24, 2023), 
                            <E T="03">https://link.springer.com/article/10.1007/s10877-023-01013-5.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>117</SU>
                             “Report on Improving Cybersecurity In The Health Care Industry,” Health Care Industry Cybersecurity Task Force, p. 1 (June 2017), 
                            <E T="03">https://www.phe.gov/preparedness/planning/cybertf/documents/report2017.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        Despite advancements in technology, including health IT, the core requirements of the Security Rule remain relevant and applicable today. In fact, they serve as a foundation for more recently promulgated cybersecurity guidelines, best practices, processes, and procedures. Security management, regular monitoring and review of information system activity, information access management, security awareness and training, contingency planning, encryption, and authentication all continue to be represented in the most well-known cybersecurity frameworks, including the NIST's Cybersecurity Framework,
                        <SU>118</SU>
                        <FTREF/>
                         the HHS 405(d) Program's “Health Industry Cybersecurity Practices: Managing 
                        <PRTPAGE P="907"/>
                        Threats and Protecting Patients,” 
                        <SU>119</SU>
                        <FTREF/>
                         and the Department's CPGs.
                        <SU>120</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>118</SU>
                             “The NIST Cybersecurity Framework (CSF) 2.0,” 
                            <E T="03">supra</E>
                             note 15.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>119</SU>
                             “Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients,” 
                            <E T="03">supra</E>
                             note 16.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>120</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <P>
                        While these concepts remain highly relevant and applicable, the Department has concerns regarding the sufficiency of the security measures implemented by regulated entities. OCR's experience investigating allegations of Security Rule violations, reports received by OCR of breaches of unsecured PHI, and the results of the audits conducted by OCR in 2016-2017 demonstrate that regulated entities are not consistently complying with the Security Rule's requirements.
                        <SU>121</SU>
                        <FTREF/>
                         Additionally, the Department is concerned about the extent to which regulated entities have updated their security measures to adjust to the changes in the health care environment and their operations, including new and emerging threats to the confidentiality, integrity, and availability of ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>121</SU>
                             
                            <E T="03">See</E>
                             “2016-2017 HIPAA Audits Industry Report,” Office for Civil Rights, U.S. Department of Health and Human Services (Dec. 2020), 
                            <E T="03">https://www.hhs.gov/sites/default/files/hipaa-audits-industry-report.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        And the Department is not alone in its concerns. NCVHS serves as the Department's advisory body for HIPAA.
                        <SU>122</SU>
                        <FTREF/>
                         Given the increase in cybersecurity incidents affecting the health care sector, NCVHS held a series of public hearings on cybersecurity to better understand how to protect ePHI and individuals. In response to those hearings, NCVHS submitted several recommendations to the Department regarding the importance of strengthening the Security Rule.
                        <SU>123</SU>
                        <FTREF/>
                         As discussed above, HIPAA requires the Secretary to rely on NCVHS' recommendations 
                        <SU>124</SU>
                        <FTREF/>
                         with respect to standards promulgated under the statute.
                    </P>
                    <FTNT>
                        <P>
                            <SU>122</SU>
                             
                            <E T="03">See</E>
                             sec. 262 of Public Law 104-191, 110 Stat. 2023 (Aug. 21, 1996) (codified at 42 U.S.C. 1320d-1(f)), added sec. 1172(f) of the SSA; 
                            <E T="03">see also</E>
                             “About NCVHS,” National Committee on Vital and Health Statistics, 
                            <E T="03">www.ncvhs.hhs.gov.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>123</SU>
                             
                            <E T="03">See</E>
                             Letter from NCVHS Chair Jacki Monson to HHS Secretary Xavier Becerra (May 10, 2022), 
                            <E T="03">https://ncvhs.hhs.gov/wp-content/uploads/2022/05/NCVHS-Recommendations-to-Strengthen-Cybersecurity-in-HC-05-10-2022-508.pdf; see also</E>
                             Letter from NCVHS Chair Jacki Monson to HHS Secretary Xavier Becerra (Nov. 29, 2023), 
                            <E T="03">https://ncvhs.hhs.gov/wp-content/uploads/2024/01/Letter-to-the-Secretary-Recommendations-to-Strengthen-the-HIPAA-Security-Rule_508.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>124</SU>
                             42 U.S.C. 1320d-1(f).
                        </P>
                    </FTNT>
                    <P>Given the importance of strong security measures, the changed environment and operations for health care, uncertainty expressed by regulated entities regarding their compliance obligations, deficiencies identified by OCR in its investigations of regulated entities, and the recommendations of NCVHS, we believe that it is necessary and appropriate for the Department to propose modifications to clarify and strengthen the Security Rule.</P>
                    <HD SOURCE="HD2">A. Strong Security Standards Are Essential to Protecting the Confidentiality, Integrity, and Availability of ePHI and Ensuring Quality and Efficiency in the Health Care System</HD>
                    <P>
                        A primary purpose of HIPAA's Administrative Simplification provisions 
                        <SU>125</SU>
                        <FTREF/>
                         is to, among other things, “improve [. . .] the efficiency and effectiveness of the health care system, by encouraging the development of a health information system through the establishment of uniform standards and requirements for the electronic transmission of certain health information.” 
                        <SU>126</SU>
                        <FTREF/>
                         As Congress recognized when it enacted HIPAA, protecting the security of ePHI is essential for accomplishing this goal. Members of Congress acknowledged at that time that the provisions of HIPAA would create electronic databases of PHI, enabling the PHI to be transmitted electronically with both the benefits and risks that accompany such electronic transactions.
                        <SU>127</SU>
                        <FTREF/>
                         Congressional statements leading up to HIPAA's enactment demonstrate Congress' recognition of the potential risks of the shift from paper recordkeeping to electronic: “We need to be very careful about how safe and secure that information is from prying eyes. Some of it may be extremely sensitive and could be used in a malicious or discriminatory manner.” 
                        <SU>128</SU>
                        <FTREF/>
                         Accordingly, HIPAA required the establishment of strict security standards for health information.
                    </P>
                    <FTNT>
                        <P>
                            <SU>125</SU>
                             Subtitle F of title II of HIPAA, Public Law 104-191, 110 Stat. 1936 (Aug. 21, 1996).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>126</SU>
                             Sec. 261 of Public Law 104-191, 110 Stat. 2021 (Aug. 21, 1996), as amended by sec. 1104(a) of Public Law 111-148, 124 Stat. 146 (Mar. 23, 2010) (codified at 42 U.S.C. 1320d note).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>127</SU>
                             
                            <E T="03">See</E>
                             statement of Sen. Simon, 
                            <E T="03">supra</E>
                             note 34; 
                            <E T="03">see also</E>
                             155 Cong. Rec. H1562 (statement of Rep. Markey) (stating that ARRA includes provisions for health IT with built-in privacy and security); Implementation of the Health Information Technology for Economic and Clinical Health (HITECH) Act: Hearing Before the House Committee on Energy and Commerce Subcommittee on Health, 111th Cong. 11-12 (2010) (statement of Rep. Schakowsky) (explaining that the HITECH Act strengthened Federal privacy and security laws to protect personal identifying information from misuse to ensure that individuals would be willing to use electronic records).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>128</SU>
                             Statement of Sen. Simon, 
                            <E T="03">supra</E>
                             note 34.
                        </P>
                    </FTNT>
                    <P>
                        As discussed above, the Security Rule, as amended by the HITECH Act, specifically requires regulated entities to maintain reasonable and appropriate administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of ePHI; to protect against any reasonably anticipated threats or hazards to the security or integrity of ePHI and unauthorized uses or disclosures of ePHI; and ensure compliance with the Administrative Simplification provisions by officers and workforce members of regulated entities.
                        <SU>129</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>129</SU>
                             
                            <E T="03">See</E>
                             section 1173(d)(2) of HIPAA (codified at 42 U.S.C. 1320d-2(d)(2)) and section 13401 of ARRA (codified at 42 U.S.C. 17931(a)) and 45 CFR 164.306.
                        </P>
                    </FTNT>
                    <P>
                        It is reasonable to anticipate that regulated entities will need to protect ePHI against cyberattacks and unauthorized uses and disclosures of ePHI by their workforce members. Experts estimate the costs to the U.S. from cyberattacks on health care facilities to be significant.
                        <SU>130</SU>
                        <FTREF/>
                         According to one study, health care data breach costs to affected organizations have increased by more than 50 percent since 2020, making health care data breaches more expensive than data breaches in any other sector, at an average cost of almost $10.1 million per breach.
                        <SU>131</SU>
                        <FTREF/>
                         Yet these costs, though sizeable, do not fully take into account the practical implications of poor or ineffective cybersecurity protocols. A failure to implement adequate security measures may lead to: financial loss; reputational harm for affected individuals and affected regulated entities; privacy loss; and safety concerns.
                        <SU>132</SU>
                        <FTREF/>
                         Additionally, breaches of unsecured PHI may lead to identity theft, fraud, stock manipulation, and competitive disadvantage.
                        <SU>133</SU>
                        <FTREF/>
                         According to a study funded by the Institute for Critical Infrastructure Technology, victims of medical identity theft incur on average costs of $13,500 to recover from that theft.
                        <SU>134</SU>
                        <FTREF/>
                         Unlike financial information, much of an individual's PHI is 
                        <PRTPAGE P="908"/>
                        immutable. For example, an individual's date and location of birth and their health history will not change, even if their address might. In contrast, an individual's passwords, bank account numbers, and other financial information can all be changed. Thus, PHI can continue to be exploited throughout an individual's lifetime, making PHI likely to be far more valuable than an individual's credit card information.
                        <SU>135</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>130</SU>
                             
                            <E T="03">See</E>
                             Hadi Ghayoomi, et al., “Assessing resilience of hospitals to cyberattack,” Digital Health, p. 2 (2021), 
                            <E T="03">https://doi.org/10.1177/20552076211059366;</E>
                             “Beyond Security Patches-Fundamental Incentive Problems in Health Care Cybersecurity,” 
                            <E T="03">supra</E>
                             note 116; Jessica Brewer, et al., “An Insight into the Current Security Posture of Healthcare IT: A National Security Concern,” The Institute for Critical Infrastructure Technology, p. 3 (2019), 
                            <E T="03">https://www.icitech.org/post/an-insight-into-the-current-security-posture-of-healthcare-it-a-national-security-concern.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>131</SU>
                             “Cost of a Data Breach Report 2023,” IBM, p. 13 (2023) (explaining that the average cost of a health care data breach was $7.13 million in 2020), 
                            <E T="03">https://www.ibm.com/reports/data-breach.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>132</SU>
                             “Report on Improving Cybersecurity In The Health Care Industry,” 
                            <E T="03">supra</E>
                             note 117, p. 14-15.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>133</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>134</SU>
                             “An Insight into the Current Security Posture of Healthcare IT: A National Security Concern,” 
                            <E T="03">supra</E>
                             note 130, p. 3.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>135</SU>
                             
                            <E T="03">See, e.g., Caleb J. Kumar, “New Dangers in the New World: Cyber Attacks in the Healthcare Industry,” Intersect, Volume 10, No. 3, p. 3 (2017).</E>
                        </P>
                    </FTNT>
                    <P>
                        On the surface, the harms that result from a breach of ePHI or a cyberattack on a regulated entity's electronic information systems, as discussed above, are not significantly different than those that would result from a breach of information in another sector. However, the reality is, as discussed above, that the implications of such harms are far greater in the health care sector because of their potential to adversely affect an individual's health or quality of life, or even to cost an individual their life.
                        <SU>136</SU>
                        <FTREF/>
                         As stated by the Health Care Industry Cybersecurity Task Force in its 2017 report on the state of cybersecurity in health care: “The health care system cannot deliver effective and safe care without deeper digital connectivity. If the health care system is connected, but insecure, this connectivity could betray patient safety, subjecting them to unnecessary risk and forcing them to pay unaffordable personal costs.” 
                        <SU>137</SU>
                        <FTREF/>
                         In the event of a cybersecurity incident, patients' health, including their lives, may be at risk where such incident creates impediments to the provision of health care, such as interference with the operations of a critical medical device, or to the administrative or clinical operations of a regulated entity, such as preventing the scheduling of appointments or viewing of an individual's health history.
                        <SU>138</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>136</SU>
                             “An Insight into the Current Security Posture of Healthcare IT: A National Security Concern,” 
                            <E T="03">supra</E>
                             note 130, p. 3.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>137</SU>
                             “Report on Improving Cybersecurity In The Health Care Industry,” 
                            <E T="03">supra</E>
                             note 117, p. 2.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>138</SU>
                             
                            <E T="03">Id.</E>
                             at 18.
                        </P>
                    </FTNT>
                    <P>
                        According to a Cybersecurity &amp; Infrastructure Security Agency (CISA) statistical analysis of the effects of a hypothetical cyberattack on a model hospital, a hospital's relative performance will suffer amidst a cyberattack.
                        <SU>139</SU>
                        <FTREF/>
                         The analysis found that the hypothetical cyberattack would lead to hospital strain from inaccessible patient schedules and records, disrupted communication, and delays in processing and communicating test results in time to effectively treat individuals.
                        <SU>140</SU>
                        <FTREF/>
                         While the analysis did not find any deaths directly attributable to the hypothetical attack, it is logical to conclude that deaths—or at least worsened outcomes—are a significant risk where there are disruptions in communications, as well as delays in processing and communicating test results, especially for emergent or acute medical cases. For example, an inability to access an individual's pharmacy records could affect the ability of a pharmacist to identify known interactions between newly prescribed medications and an existing medication list, potentially leading to an individual's injury or death. Other studies have similarly found that cyberattacks can have a substantial effect on access to health care, and potentially mortality.
                        <SU>141</SU>
                        <FTREF/>
                         In fact, a more recent study found that cyberattacks had disproportionately negative effects on in-hospital mortality rates for Black patients who were already admitted to the hospital at the time of the cyberattack.
                        <SU>142</SU>
                        <FTREF/>
                         A recent survey found that 92 percent of surveyed health care organizations had experienced a cyberattack in the past year 
                        <SU>143</SU>
                        <FTREF/>
                         and almost three-quarters of the respondents who had experienced a cyberattack reported negative effects on patient care, including delays in tests or procedures, longer stays, and increased mortality rates complications from medical procedures, and patient transfers or diversions to other facilities.
                        <SU>144</SU>
                        <FTREF/>
                         A recent letter from NCVHS referenced anecdotal accounts of patient deaths that have been attributed to ransomware attacks.
                        <SU>145</SU>
                        <FTREF/>
                         For example, in 2019, a ransomware attack may have contributed to a baby's death at an Alabama hospital. A change in the baby's fetal heart rate went unnoticed because the large digital display that normally would have displayed the information was affected by the attack. The baby, born with her umbilical cord wrapped around her neck, suffered severe brain damage and died nine months later.
                        <SU>146</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>139</SU>
                             “CISA INSIGHTS: Provide Medical Care Is In Critical Condition: Analysis and Stakeholder Decision Support to Minimize Further Harm,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security, p. 12-15 (Sept. 2021), 
                            <E T="03">https://www.cisa.gov/sites/default/files/publications/CISA_Insight_Provide_Medical_Care_Sep2021.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>140</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>141</SU>
                             
                            <E T="03">See</E>
                             “Assessing resilience of hospitals to cyberattack,” 
                            <E T="03">supra</E>
                             note 130; Claire C. McGlave, et al., “Hacked to Pieces? The Effects of Ransomware Attacks on Hospitals and Patients,” SSRN (Oct. 4, 2023), 
                            <E T="03">https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4579292.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>142</SU>
                             “Hacked to Pieces? The Effects of Ransomware Attacks on Hospitals and Patients,” 
                            <E T="03">supra</E>
                             note 141, p. 14.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>143</SU>
                             “The 2024 Study on Cyber Insecurity In Healthcare: The Cost and Impact on Patient Safety and Care,” Ponemon Institute, p. 3 (2024) (The report, sponsored by Proofpoint, Inc., included survey responses from 648 IT and IT security practitioners at U.S.-based health care organizations.).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>144</SU>
                             
                            <E T="03">Id.</E>
                             at p. 5.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>145</SU>
                             
                            <E T="03">See</E>
                             Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, p. 1 (citing several media reports that attributed patient deaths to cybersecurity attacks).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>146</SU>
                             
                            <E T="03">Id.</E>
                             (citing Joseph Marks, “Ransomware attack might have caused another death,” The Washington Post (Oct. 1, 2021), 
                            <E T="03">https://www.washingtonpost.com/politics/2021/10/01/ransomware-attack-might-have-caused-another-death/</E>
                            ).
                        </P>
                    </FTNT>
                    <P>
                        Cyberattacks can divert both human and machine resources, leading to process slowdowns, cancelled procedures, delayed hospital or unit lockdowns and transfers, increases in wait times for individuals, both increases and decreases in staff utilization, and a decrease in a health care provider's capacity.
                        <SU>147</SU>
                        <FTREF/>
                         A 2020 cyberattack on a large integrated academic health system, attributed to malicious software embedded in an email attachment opened by an employee on their laptop, affected more than 5,000 end-user devices across 1,300 servers and led to revenue losses of more than $63 million.
                        <SU>148</SU>
                        <FTREF/>
                         Though the health care provider's EHR was not infected, it elected to shut the EHR down proactively. Ultimately, the covered entity “experienced 39 days of downtime in outpatient imaging.” 
                        <SU>149</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>147</SU>
                             “Assessing resilience of hospitals to cyberattack,” 
                            <E T="03">supra</E>
                             note 130, p. 2.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>148</SU>
                             Kerri Reeves, “Cyberattacks: Not a Matter of If, but When,” Radiology Matters (Mar./Apr. 2024), 
                            <E T="03">https://www.proquest.com/scholarly-journals/cyberattacks-not-matter-if-when/docview/2957757956/se-2?accountid=12786.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>149</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        In another example, a ransomware attack on an academic level 1 trauma center caused it to go without access to its EHR for 25 days,
                        <SU>150</SU>
                        <FTREF/>
                         and the attack affected 5,000 computers and destroyed the trauma center's electronic information systems that contained ePHI. The hospital lost access to its EHR, internet, and intranet, which also “removed functionality of hospital phones, [EHR] integrated office and surgical scheduling, access to digitized radiology studies, and network account access through local and remote computers.” 
                        <SU>151</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>150</SU>
                             Mitchell Tarka, et al., “The crippling effects of a cyberattack at an academic level 1 trauma center: An orthopedic perspective,” Injury, p. 1095-1101 (2023), 
                            <E T="03">https://pubmed.ncbi.nlm.nih.gov/36801172/.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>151</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        These serious incidents and resulting effects demonstrate the importance of planning and preparing for a potential 
                        <PRTPAGE P="909"/>
                        cyberattack or other event that adversely affects a regulated entity's information systems. While such planning and preparation may not prevent all cyberattacks, it can reduce the number of successful incidents and mitigate their effects. In fact, studies have suggested that such preparation may allow for at least close to real-time recovery.
                        <SU>152</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>152</SU>
                             “Assessing resilience of hospitals to cyberattack,” 
                            <E T="03">supra</E>
                             note 130, p. 13.
                        </P>
                    </FTNT>
                    <P>
                        The effects of a cyberattack are not limited to the regulated entity that experiences it and the individuals whose ePHI is compromised. Surveys conducted by various organizations representing health care providers indicate that an overwhelming majority of health care providers in the U.S. were affected by a ransomware attack on a large health care clearinghouse.
                        <SU>153</SU>
                        <FTREF/>
                         A study published in 2023 examined the effects on the of a cyberattack at a neighboring, unaffiliated hospital on a large academic medical center.
                        <SU>154</SU>
                        <FTREF/>
                         The study found that the academic medical center experienced, among other things, significant increases in the number of patients admitted, ambulance arrivals, waiting room times, and patients leaving without being seen. The study's authors concluded that their findings suggested “that health care cyberattacks such as ransomware are associated with greater disruptions to regional hospitals and should be treated as disasters, necessitating coordinated planning and response efforts.” 
                        <SU>155</SU>
                        <FTREF/>
                         Thus, implementing reasonable and appropriate security measures better protects not only the regulated entity and its ePHI, but other regulated entities with whom it interacts, and may reduce the effects of cyberattacks and other security incidents that adversely affect the confidentiality, integrity, or availability of ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>153</SU>
                             
                            <E T="03">See</E>
                             Paige Minemyer, “AMA: 80% of docs have lost revenue amid disruptions from Change Healthcare cyberattack,” Fierce Healthcare (Apr. 10, 2024), 
                            <E T="03">https://www.fiercehealthcare.com/practices/ama-80-docs-have-lost-revenue-amid-disruptions-change-healthcare-cyberattack;</E>
                             “AHA survey: Change Healthcare cyberattack having significant disruptions on patient care, hospitals' finances” (Mar. 15, 2024), 
                            <E T="03">https://www.aha.org/news/news/2024-03-15-aha-survey-change-healthcare-cyberattack-having-significant-disruptions-patient-care-hospitals-finances; see also</E>
                             Sean Lyngaas, “ `We're hemorrhaging money': US health clinics try to stay open after unprecedented cyberattack,” CNN (Mar. 9, 2024), 
                            <E T="03">https://www.cnn.com/2024/03/09/tech/medical-supply-chain-cybersecurity/index.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>154</SU>
                             Christian Dameff, et al., “Ransomware Attack Associated With Disruptions at Adjacent Emergency Departments in the U.S.,” JAMA Network Open (May 8, 2023), 
                            <E T="03">https://jamanetwork.com/journals/jamanetworkopen/fullarticle/2804585.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>155</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        As discussed above, several industry organizations have published and maintained compilations of voluntary standards, guidelines, best practices, methodologies, procedures, and processes for protecting the security of sensitive and confidential information, including PHI. Additionally, certain Federal health programs now either require or recommend the adoption of specific criteria that are intended to protect the confidentiality, integrity, and availability of ePHI. For example, the Health IT Certification Program maintained by the Assistant Secretary for Technology Policy and Office of the National Coordinator for Health Information Technology (ASTP/ONC) 
                        <SU>156</SU>
                        <FTREF/>
                         sets minimum requirements for certified health IT, including criteria that pertain to cybersecurity.
                        <SU>157</SU>
                        <FTREF/>
                         These criteria are included in the Health IT Certification Program's Health IT Privacy and Security Framework,
                        <SU>158</SU>
                        <FTREF/>
                         which identifies
                        <E T="03"> when technical capabilities to support</E>
                         the privacy and security of electronic health information 
                        <SU>159</SU>
                        <FTREF/>
                         must be included in certified health IT products. Additionally, health care providers that participate in certain Federal health programs must use health IT certified to these requirements.
                        <SU>160</SU>
                        <FTREF/>
                         Regulated entities also may want to consider adoption of certified health IT because it could contribute to compliance with the Security Rule. We will continue to work across the Department to ensure the adoption of consistent requirements for Federal programs that support the secure electronic exchange of health information to the extent that such consistency is appropriate. Throughout this preamble, we provide examples of how a regulated entity's participation in other Federal programs that require the use of health IT certified through the ONC Health IT Certification Program, or adoption of other Federal recommendations, such as the HHS CPGs, might support their compliance with the proposals in this NPRM.
                    </P>
                    <FTNT>
                        <P>
                            <SU>156</SU>
                             On July 29, 2024, the Department announced that the Office of the National Coordinator for Health Information Technology was being renamed the Assistant Secretary for Technology Policy and Office of the National Coordinator for Health Information Technology. In this NPRM, we continue to use ONC for publications cited that predate the renaming of that office. 89 FR 60903 (July 29, 2024).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>157</SU>
                             
                            <E T="03">See, e.g.,</E>
                             45 CFR 170.315(d)(6), (7), (12), and (13). For more information on the ONC Health IT Certification Program, visit 
                            <E T="03">https://www.healthit.gov/topic/certification-ehrs/certification-health-it.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>158</SU>
                             The ONC Health IT Certification Program specifies at 45 CFR 170.550(h) the privacy and security certification framework for Health IT Modules. Section 170.550(h) identifies a mandatory minimum set of the certification criteria that ONC-Authorized Certification Bodies (ONC ACBs) must ensure are also included as part of specific Health IT Modules that are presented for certification. 
                            <E T="03">See</E>
                             “Certification Companion Guide Privacy and Security,” The Office of the National Coordinator for Health Information Technology, U.S. Department of Health and Human Services (May 7, 2024), 
                            <E T="03">https://www.healthit.gov/sites/default/files/2015Ed_CCG_Privacy_and_Security.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>159</SU>
                             
                            <E T="03">See</E>
                             45 CFR 171.102 (definition of “Electronic health information”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>160</SU>
                             
                            <E T="03">See, e.g.,</E>
                             Medicare Promoting Interoperability Program, 42 CFR 495.24 (eligible hospitals and critical access hospitals must use certified electronic health record technology (CEHRT), with limited exceptions, to comply with the program's meaningful use requirements); Merit-based Incentive Payment System (MIPS) Promoting Interoperability performance category, 42 CFR 414.1375 (requiring MIPS eligible clinicians to use CEHRT, as defined in 42 CFR 414.1305, to comply with reporting requirements for the Promoting Interoperability performance category).
                        </P>
                    </FTNT>
                    <P>
                        Additionally, as discussed above, several organizations have published and maintained compilations of voluntary standards, guidelines, best practices, methodologies, procedures, and processes for protecting the security of sensitive and confidential information, including PHI. These compilations and the State regulations discussed above range from granular 
                        <SU>161</SU>
                        <FTREF/>
                         to high-level 
                        <SU>162</SU>
                        <FTREF/>
                         and from health care-specific 
                        <SU>163</SU>
                        <FTREF/>
                         to industry agnostic.
                        <SU>164</SU>
                        <FTREF/>
                         Despite these differences, these compilations and regulations have a great deal in common with each other—and with the Security Rule, its longevity notwithstanding. In fact, the foundational elements of the Security Rule, promulgated more than 20 years ago, can still be found in cybersecurity compilations published today. They generally either require or recommend administrative, physical, and technical safeguards to identify and mitigate risks and vulnerabilities, implement authentication and access controls, conduct security awareness and training for information system users, and plan for contingencies and incident response.
                        <SU>165</SU>
                        <FTREF/>
                         Additionally, these compilations all require or recommend the designation of a specific individual who is accountable for implementing the requirements or recommendations. And, importantly, they all ultimately address how to maintain the 
                        <PRTPAGE P="910"/>
                        confidentiality, integrity, and availability of sensitive and confidential information, including ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>161</SU>
                             
                            <E T="03">See, e.g.,</E>
                             “Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients,” 
                            <E T="03">supra</E>
                             note 16.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>162</SU>
                             
                            <E T="03">See, e.g.,</E>
                             “The NIST Cybersecurity Framework (CSF) 2.0,” 
                            <E T="03">supra</E>
                             note 15.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>163</SU>
                             
                            <E T="03">See, e.g.,</E>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>164</SU>
                             
                            <E T="03">See, e.g.,</E>
                             “Cross-Sector Cybersecurity Performance Goals,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security (Mar. 2023), 
                            <E T="03">https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>165</SU>
                             
                            <E T="03">See generally</E>
                             45 CFR 164.308(a); “The NIST Cybersecurity Framework (CSF) 2.0,” 
                            <E T="03">supra</E>
                             note 15; “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <P>A major distinguishing factor between the content of the Security Rule and these compilations and regulations is the Security Rule's scope. The compilations and regulations are designed to protect various types of data and information systems broadly. In comparison, a defining quality of the Security Rule's requirements is that they focus specifically on the protection of ePHI and the information systems that create, receive, maintain, or transmit ePHI. Thus, while the foundational elements of various cybersecurity compilations and State regulations and the Security Rule may be the same, the Security Rule alone addresses the application of those elements to ePHI and all of the components of information systems that create, receive, maintain, or transmit ePHI. Thus, while the standards of the Security Rule generally align with those of other cybersecurity standards, frameworks, best practices, guidelines, processes, and procedures, the specific implementation specifications of the Security Rule reflect the particular sensitivities of the health care industry, particularly small and rural health care providers, in a way that is necessary to ultimately improve the efficiency and effectiveness of the health care system and avoid imposing unreasonable compliance burdens on regulated entities.</P>
                    <HD SOURCE="HD2">B. The Health Care Environment Has Changed Since the Security Rule Was Last Revised and Will Continue To Evolve</HD>
                    <P>
                        The health care sector has undergone a dramatic transformation over the last 24 years, and particularly in the past 10 years, spurred at least in part by the Department's implementation of HIPAA, the HITECH Act, and the Cures Act. The industry has shifted from one that generally relied upon a system of paper-based recordkeeping and siloed devices to one that depends on interconnected information systems to maintain and exchange patient records, conduct research, run health care provider facility management systems, and provide patient care.
                        <SU>166</SU>
                        <FTREF/>
                         This shift is largely the result of HIPAA's emphasis on the development and use of standards and the EHR incentive funds made available under the HITECH Act for health care providers.
                        <SU>167</SU>
                        <FTREF/>
                         Data from ASTP/ONC offer clear and convincing evidence of this shift. In 2008, before the enactment of the HITECH Act, less than 10 percent of non-Federal acute hospitals had implemented what was referred to at the time as a “Basic EHR” (
                        <E T="03">i.e.,</E>
                         an electronic health record).
                        <SU>168</SU>
                        <FTREF/>
                         By 2015, six years after the enactment of the HITECH Act, almost 84 percent had adopted a Basic EHR while 96 percent had adopted a certified EHR.
                        <SU>169</SU>
                        <FTREF/>
                         The transformation was further enabled by the Cures Act, which encouraged the development of a trusted exchange framework for the nationwide exchange of health information and provided penalties for health care providers, health information exchanges and networks, and developers of certified health IT that engage in information blocking.
                        <SU>170</SU>
                        <FTREF/>
                         In 2014, 41 percent of such hospitals routinely had electronic access to clinical information from outside providers or sources when treating a patient.
                        <SU>171</SU>
                        <FTREF/>
                         By 2023, 70 percent of non-Federal acute care hospitals engaged in all domains of interoperable exchange routinely or sometimes, a significant leap forward.
                        <SU>172</SU>
                        <FTREF/>
                         In 2017, only 38 percent of hospitals enabled patients to access their health information using an application and in 2018, 57 percent enabled patient access to their clinical notes in their patient portal; by 2021, 70 percent of hospitals enabled patients to access their health information using an application and 82 percent enabled patients to view their clinical notes in their patient portal.
                        <SU>173</SU>
                        <FTREF/>
                         And just a year later, the percentage of hospitals that supported patient access through applications increased to 86 percent.
                        <SU>174</SU>
                        <FTREF/>
                         Based on this data, it is clear that HIPAA, coupled with the HITECH Act and the Cures Act, has successfully encouraged the development of a nationwide electronic health information system.
                    </P>
                    <FTNT>
                        <P>
                            <SU>166</SU>
                             Derrick Tin, et al., “Cyberthreats: A primer for health care professionals,” The American Journal of Emergency Medicine, p. 182-183 (Apr. 2023), 
                            <E T="03">https://doi.org/10.1016/j.ajem.2023.04.001.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>167</SU>
                             
                            <E T="03">See</E>
                             Public Law 104-191, 110 Stat. 2021 (Aug. 21, 1996) (codified at 42 U.S.C. 1320d note); Sec. 4101 of ARRA, Public Law 111-5, 123 Stat. 467 (Feb. 17, 2009), amending sec. 1848 of the SSA (codified at 42 U.S.C. 1395w-4).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>168</SU>
                             JaWanna Henry, et al., “ONC Data Brief: Adoption of Electronic Health Record Systems among U.S. Non-Federal Acute Care Hospitals: 2008-2015,” The Office of the National Coordinator for Health Information Technology, U.S. Department of Health and Human Services, p. 1 (May 2016), 
                            <E T="03">https://www.healthit.gov/sites/default/files/briefs/2015_hospital_adoption_db_v17.pdf;</E>
                             A Basic EHR collects information on patient demographics, problem lists, medication lists, and discharge summaries. It also includes computerized provider order entry for medications and enables clinicians to view certain reports. 
                            <E T="03">Id.</E>
                             at Appendix.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>169</SU>
                             “ONC Data Brief: Adoption of Electronic Health Record Systems among U.S. Non-Federal Acute Care Hospitals: 2008-2015,” 
                            <E T="03">supra</E>
                             note 168, p. 1; When used here, “certified EHR Technology” means EHR technology that meets the technological capability, functionality, and security requirements adopted by the Department as certification criteria at 45 CFR part 170.; 
                            <E T="03">see also</E>
                             “Certified EHR Technology,” The Office of the National Coordinator for Health Information Technology, U.S. Department of Health and Human Services (Sept. 6, 2013), 
                            <E T="03">https://www.cms.gov/medicare/regulations-guidance/promoting-interoperability-programs/certified-ehr-technology</E>
                             (“In order to efficiently capture and share patient data, health care providers need certified electronic health record (EHR) technology (CEHRT) that stores data in a structured format. Structured data allows health care providers to easily retrieve and transfer patient information and use the EHR in ways that can aid patient care.”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>170</SU>
                             
                            <E T="03">See</E>
                             sec. 4003(b) and 4004(b)(2) of Public Law 114-255, 130 Stat. 1165 (Dec. 13, 2016) (codified at 42 U.S.C. 300jj-11(c) and 42 U.S.C. 300jj-52).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>171</SU>
                             Dustin Charles, et al., “ONC Data Brief: Interoperability among U.S. Non-federal Acute Care Hospitals, 2014,” The Office of the National Coordinator for Health Information Technology, U.S. Department of Health and Human Services, p. 1 (Aug. 2015), 
                            <E T="03">https://www.healthit.gov/sites/default/files/briefs/onc_databrief25_interoperabilityv16final_081115.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>172</SU>
                             Meghan Hufstader Gabriel, et al., “ONC Data Brief: Interoperable Exchange of Patient Health Information Among U.S. Hospitals: 2023,” The Office of the National Coordinator for Health Information Technology, U.S. Department of Health and Human Services, p. 1 (May 2024), 
                            <E T="03">https://www.healthit.gov/sites/default/files/2024-05/Interoperable-Exchange-of-Patient-Health-Information-Among-U.S.-Hospitals-2023.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>173</SU>
                             Wesley Barker, et al., “ONC Data Brief: Hospital Capabilities to Enable Patient Electronic Access to Health Information, 2021,” The Office of the National Coordinator for Health Information Technology, U.S. Department of Health and Human Services, p. 2 and 5 (Oct. 2022) (estimates based on non-Federal acute care hospitals and applications configured to meet the application programming interface (API) specifications in the hospital's EHR), 
                            <E T="03">https://www.healthit.gov/sites/default/files/2022-12/hospital_capabilities_to_enable_patient_access_ONC_DB2021-Updated.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>174</SU>
                             Catherine Strawley, et al., “ONC Data Brief: Hospital Use of APIs to Enable Data Sharing Between EHRs and Apps,” The Office of the National Coordinator for Health Information Technology, U.S. Department of Health and Human Services, p. 2 (Sept. 2023) (estimates based on non-Federal acute care hospitals using standards-based APIs to enable patient access), 
                            <E T="03">https://www.healthit.gov/sites/default/files/2023-09/DB68-Hospital%20Use%20of%20APIs%20to%20Enable%20Data%20Sharing_508.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        Not only is PHI increasingly maintained and transmitted electronically, but treatment is also increasingly provided electronically. The coronavirus disease 2019 (COVID-19) pandemic led to a dramatic increase in the use of telemedicine.
                        <SU>175</SU>
                        <FTREF/>
                         According 
                        <PRTPAGE P="911"/>
                        to ONC data, only 15 percent of office-based physicians used any form of telemedicine in 2018-19. In 2021, telemedicine usage increased to 87 percent.
                        <SU>176</SU>
                        <FTREF/>
                         The electronic content generated or transmitted during a telemedicine visit constitutes ePHI, so the increase in telemedicine further increases the amount of PHI that is also ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>175</SU>
                             
                            <E T="03">See</E>
                             “Determination That A Public Health Emergency Exists Nationwide as the Result of the 2019 Novel Coronavirus,” Administration for Strategic Preparedness &amp; Response, U.S. Department of Health and Human Services (Jan. 31, 2020), 
                            <E T="03">https://aspr.hhs.gov/legal/PHE/Pages/2019-nCoV.aspx;</E>
                             “Renewal of Determination that a Public Health Emergency Exists As a Result of the Continued Consequences of the Coronavirus Disease 2019 (COVID-19) Pandemic,” Administration for Strategic Preparedness &amp; Response, U.S. Department of Health and Human Services (Feb. 9, 2023), 
                            <E T="03">https://aspr.hhs.gov/legal/PHE/Pages/COVID19-9Feb2023.aspx;</E>
                             “Notification of Enforcement Discretion for Telehealth Remote 
                            <PRTPAGE/>
                            Communications During the COVID-19 Nationwide Public Health Emergency,” Office for Civil Rights, U.S. Department of Health and Human Services (Jan. 20, 2021), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/special-topics/emergency-preparedness/notification-enforcement-discretion-telehealth/index.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>176</SU>
                             Yuriy Pylypchuk, et al., “ONC Data Brief: Use of Telemedicine among Office-Based Physicians, 2021,” The Office of the National Coordinator for Health Information Technology, U.S. Department of Health and Human Services, p. 1 (Mar. 2023), 
                            <E T="03">https://www.healthit.gov/sites/default/files/2023-04/DB65_TelemedicinePhysicians_508.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        It is not only the ePHI maintained in EHRs and other electronic recordkeeping systems that faces security risks. Medical equipment and devices are increasingly connected through one or more networks, which means that any issues affecting the network likely will affect the medical equipment and devices.
                        <SU>177</SU>
                        <FTREF/>
                         And some medical equipment and devices rely on off-the-shelf operating systems, such as Windows, Linux, and similar third-party software; 
                        <SU>178</SU>
                        <FTREF/>
                         thus, the medical equipment and devices can experience the same vulnerabilities as personal computing devices. Generally, the U.S. Food &amp; Drug Administration (FDA) does not need to review software patches or configuration updates for off-the-shelf software before a device manufacturer puts them in place because the FDA views most patches and configuration updates as design changes that can be made without prior discussion.
                        <SU>179</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>177</SU>
                             Nduma N. Basil, “Health Records Database and Inherent Security Concerns: A Review of the Literature,” Cureus, p. 3 (Oct. 11, 2022) (“The increase in networked medical equipment and devices implies that, if there is a security breach in the form of hacking, then traffic on the network can slow down and interfere with the delivery of healthcare services.”), 
                            <E T="03">https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9647912/.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>178</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>179</SU>
                             “Guidance Document: Information for Healthcare Organizations about FDA's `Guidance for Industry: Cybersecurity for Networked Medical Devices Containing Off-The-Shelf (OTS) Software,' ” U.S. Food &amp; Drug Administration, U.S. Department of Health and Human Services (Feb. 2005), 
                            <E T="03">https://www.fda.gov/regulatory-information/search-fda-guidance-documents/information-healthcare-organizations-about-fdas-guidance-industry-cybersecurity-networked-medical.</E>
                        </P>
                    </FTNT>
                    <P>
                        Cybercriminals may use—or target—technology assets, such as software or medical devices used for treating individuals. For example, in 2021, a cyberattack on cloud-based systems supplied by a particular company compromised the ePHI of more than 200,000 individuals and affected the software for linear accelerators used in radiotherapy, leading to disruptions to cancer treatment.
                        <SU>180</SU>
                        <FTREF/>
                         Thus, to protect technology assets used for treatment, the information systems that create, receive, maintain, and transmit ePHI also must be protected. As another example, in 2013, the Mayo Clinic 
                        <SU>181</SU>
                        <FTREF/>
                         hired a group of ethical hackers 
                        <SU>182</SU>
                        <FTREF/>
                         to identify vulnerabilities in 40 different medical devices.
                        <SU>183</SU>
                        <FTREF/>
                         The hackers were able to gain access to all of the devices, meaning that the devices could all be vulnerable to a cyberattack.
                        <SU>184</SU>
                        <FTREF/>
                         Such attacks may create an opening for a subsequent attack on the device itself or on the regulated entity's information systems that create, receive, maintain, or transmit ePHI, compromising those information systems and the ePHI itself.
                        <SU>185</SU>
                        <FTREF/>
                         It also may lead, intentionally or not, to a loss of device integrity, which could result in the corruption of the device's functionality or the ePHI on the device.
                        <SU>186</SU>
                        <FTREF/>
                         A cyberattack on a medical device may also reduce the ability of the authorized person to use the device (
                        <E T="03">e.g.,</E>
                         a denial of service attack, which is a type of cyberattack that overloads the device by flooding the network with traffic).
                        <SU>187</SU>
                        <FTREF/>
                         Depending on the device and its use, the result of cyberattacks on a medical device could range from little or no effect to serious injury or death.
                        <SU>188</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>180</SU>
                             Elizabeth Gourd, “Increase in health-care cyberattacks affecting patients with cancer,” The Lancet, p. 1215 (Sept. 2021), 
                            <E T="03">https://doi.org/10.1016/S1470-2045(21)00451-4.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>181</SU>
                             
                            <E T="03">See</E>
                             Mayo Clinic, 
                            <E T="03">https://www.mayoclinic.org/.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>182</SU>
                             An “ethical hacker” is a cybersecurity researcher who “use[s] penetration testing techniques to test an organization's cybersecurity and information technology (IT) security.” 
                            <E T="03">See</E>
                             Ed Tittel, “How to Become a White Hat Hacker,” Business News Daily (June 17, 2024), 
                            <E T="03">https://www.businessnewsdaily.com/10713-white-hat-hacker-career.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>183</SU>
                             
                            <E T="03">See</E>
                             Foued Badrouchi, et al., “Cybersecurity Vulnerabilities in Biomedical Devices: A Hierarchical Layered Framework,” Internet of Things Use Cases for the Healthcare Industry, p. 157-58 (2020); 
                            <E T="03">see also</E>
                             Monte Reel, et al., “It's Way Too Easy to Hack the Hospital,” Bloomberg Businessweek (Nov. 2015), 
                            <E T="03">https://www.bloomberg.com/features/2015-hospital-hack/.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>184</SU>
                             
                            <E T="03">See</E>
                             “Cybersecurity Vulnerabilities in Biomedical Devices: A Hierarchical Layered Framework,” 
                            <E T="03">supra</E>
                             note 183, p. 157-58.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>185</SU>
                             
                            <E T="03">See also</E>
                             “It's Way Too Easy to Hack the Hospital,” 
                            <E T="03">supra</E>
                             note 183; Nicole M. Thomasian, et al., “Cybersecurity in the internet of Medical Things,” Health Policy and Technology (Sept. 2021), 
                            <E T="03">https://doi.org/10.1016/j.hlpt.2021.100549.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>186</SU>
                             “Cybersecurity in the internet of Medical Things,” 
                            <E T="03">supra</E>
                             note 185.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>187</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>188</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        According to researchers at Brown University, medical devices are a prime target for cybercriminals. In fact, they believe, “More than just technically feasible, the widespread takedown of medical devices is an imminent threat.” 
                        <SU>189</SU>
                        <FTREF/>
                         A 2023 Government Accountability Office report on medical device cybersecurity described the importance of “robust cybersecurity controls to ensure medical device safety and effectiveness” because of “the increasing integration of wireless, internet- and network-connected capabilities, and the electronic exchange of health information.” 
                        <SU>190</SU>
                        <FTREF/>
                         The FDA has also acknowledged, “As electronic medical devices become increasingly connected to each other and to other technologies, the ability of connected systems to safely, securely and effectively exchange and use the information becomes critical. [. . .] Cybersecurity concerns rise along with the increasing medical device interoperability.” 
                        <SU>191</SU>
                        <FTREF/>
                         Accordingly, in 2023, the FDA issued updated guidance for industry and FDA staff on requirements for cybersecurity in medical devices.
                        <SU>192</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>189</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>190</SU>
                             Report to Congressional Committees, “Medical Device Cybersecurity: Agencies Need to Update Agreement to Ensure Effective Coordination,” U.S. Government Accountability Office, p. 1 (Dec. 2023), 
                            <E T="03">https://www.gao.gov/assets/d24106683.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>191</SU>
                             “Medical Device Interoperability,” U.S. Food &amp; Drug Administration, U.S. Department of Health and Human Services, 
                            <E T="03">https://www.fda.gov/medical-devices/digital-health-center-excellence/medical-device-interoperability.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>192</SU>
                             Guidance for Industry and Food &amp; Drug Administration Staff, “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions,” U.S. Food &amp; Drug Administration, U.S. Department of Health and Human Services (Sept. 27, 2023), 
                            <E T="03">https://www.fda.gov/media/119933/download.</E>
                        </P>
                    </FTNT>
                    <P>
                        And then there are digital health applications. When an application is deployed by a covered entity, an application developer may be a business associate and subject to the Security Rule. An application developer may also meet the HIPAA Rules' definition of “health care provider” 
                        <SU>193</SU>
                        <FTREF/>
                         and be a covered entity.
                        <SU>194</SU>
                        <FTREF/>
                         But also, individuals are increasingly interested in accessing their ePHI using applications and transmitting information collected by health and wellness applications to 
                        <PRTPAGE P="912"/>
                        their health care providers.
                        <SU>195</SU>
                        <FTREF/>
                         Such applications may empower individuals to better manage their health and participate in their health care and provide health care providers and researchers with a more holistic view of the individual's health at a particular point in time and over an extended period of time.
                        <SU>196</SU>
                        <FTREF/>
                         This technology, while valuable for understanding an individual's overall health, introduces another potential vulnerability to the security of ePHI and the information systems that create, receive, maintain, or transmit it.
                    </P>
                    <FTNT>
                        <P>
                            <SU>193</SU>
                             45 CFR 160.103 (definition of “Health care provider”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>194</SU>
                             Where an application developer meets the HIPAA Rules' definition of health care provider and engages in standard electronic transactions, such as billing an insurance company for its services, it is a covered entity for the purposes of the HIPAA Rules, including the Security Rule. Where an application developer is not regulated under the HIPAA Rules, other Federal laws may apply to the application developer or the application, such as the FTC Act. 
                            <E T="03">See, e.g.,</E>
                             FTC Act (codified at 15 U.S.C. 41-58).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>195</SU>
                             
                            <E T="03">See, e.g.,</E>
                             Kea Turner, et al., “Sharing patient-generated data with healthcare providers: findings from a 2019 national survey,” Journal of the American Medical Informatics Association, p. 371-376 (Nov. 12, 2020), 
                            <E T="03">https://doi.org/10.1093/jamia/ocaa272;</E>
                             Accenture Federal Services, “Conceptualizing a Data Infrastructure for the Capture, Use, and Sharing of Patient-Generated Health Data in Care Delivery and Research through 2024,” The Office of the National Coordinator for Health Information Technology, U.S. Department of Health and Human Services, p. 5 (Jan. 2018), 
                            <E T="03">https://www.healthit.gov/sites/default/files/onc_pghd_final_white_paper.pdf; see also</E>
                             Jolaade Kalinowski, et al., “Smart device ownership and use of social media, wearable trackers, and health apps among Black women with hypertension in the United States,” JMIR Cardio (pre-print), 
                            <E T="03">https://preprints.jmir.org/preprint/59243.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>196</SU>
                             
                            <E T="03">See</E>
                             “Conceptualizing a Data Infrastructure for the Capture, Use, and Sharing of Patient-Generated Health Data in Care Delivery and Research through 2024,” 
                            <E T="03">supra</E>
                             note 195, p. 1; Asos Mahmood, et al., “mHealth Apps Use and Their Associations With Healthcare Decision-Making and Health Communication Among Informal Caregivers: Evidence From the National Cancer Institute's Health Information National Trends Survey,” American Journal of Health Promotion, p. 40-52 (Jan. 2024), 
                            <E T="03">https://journals-sagepub-com.hhsnih.idm.oclc.org/doi/10.1177/08901171231202861.</E>
                        </P>
                    </FTNT>
                    <P>
                        EHRs, networked medical devices, and applications are only the beginning. Artificial intelligence (AI) in health care, particularly for diagnosis and treatment, is in the nascent stages of development, but many are eager to test its promise.
                        <SU>197</SU>
                        <FTREF/>
                         After all, many experts believe that AI promises opportunities to improve patient care, outcomes, and population health, as well as to reduce costs.
                        <SU>198</SU>
                        <FTREF/>
                         The use of AI in health care is increasing and is expected to continue to increase.
                        <SU>199</SU>
                        <FTREF/>
                         A 2023 Healthcare Information and Management Systems Society (HIMSS) survey of health care cybersecurity professionals reported that approximately 50 percent of respondents' organizations permitted the use of generative AI technology.
                        <SU>200</SU>
                        <FTREF/>
                         And other new technologies are expected shortly, as discussed below. For example, according to reports, quantum computing may be available in the near future, which may have ramifications for data privacy and security.
                        <SU>201</SU>
                        <FTREF/>
                         We also know that researchers are exploring methods for storing ePHI in biological material (
                        <E T="03">e.g.,</E>
                         DNA).
                        <SU>202</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>197</SU>
                             
                            <E T="03">See</E>
                             88 FR 75191 (Nov. 1, 2023); Ritu Agarwal, et al., “Augmenting physicians with artificial intelligence to transform healthcare: Challenges and opportunities,” Journal of Economics &amp; Management Strategy, p. 360-374 (Mar. 2024), 
                            <E T="03">https://onlinelibrary-wiley-com.hhsnih.idm.oclc.org/doi/10.1111/jems.12555;</E>
                             Becca Beets, et al., “Surveying Public Perceptions of Artificial Intelligence in Health Care in the United States: Systematic Review,” Journal of Medical internet Research (2023), 
                            <E T="03">https://doi.org/10.2196/40337.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>198</SU>
                             Michael E. Matheny, et al., “Artificial Intelligence in Health Care: A Report from the National Academy of Medicine,” Journal of the American Medical Association, p. 509-10 (2020), 
                            <E T="03">https://jamanetwork-com.hhsnih.idm.oclc.org/journals/jama/fullarticle/2757958.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>199</SU>
                             “2023 HIMSS Healthcare Cybersecurity Survey,” Healthcare Information and Management Systems Society, p. 19 (Mar. 1, 2024), 
                            <E T="03">https://www.himss.org/sites/hde/files/media/file/2024/03/01/2023-himss-cybersecurity-survey-x.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>200</SU>
                             
                            <E T="03">Id.</E>
                             at 16; Generative AI is a type of software that “uses statistical models that generalize the patterns and structures of existing data to either reorganize existing data or create new content.” “Risk In Focus: Generative A.I. And The 2024 Election Cycle,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security, 
                            <E T="03">https://www.cisa.gov/sites/default/files/2024-05/Consolidated_Risk_in_Focus_Gen_AI_ElectionsV2_508c.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>201</SU>
                             “2023 HIMSS Healthcare Cybersecurity Survey,” 
                            <E T="03">supra</E>
                             note 199, p. 22.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>202</SU>
                             
                            <E T="03">See</E>
                             Lizzie Roehrs, “CSL Professor explores DNA as data storage,” University of Illinois Urbana-Champaign The Grainger College of Engineering Coordinated Science Laboratory (Aug. 25, 2020), 
                            <E T="03">https://csl.illinois.edu/news-and-media/csl-professor-explores-dna-data-storage;</E>
                             Cheng Kai Lim, et al., “A biological camera that captures and stores images directly into DNA,” nature communications (July 3, 2023), 
                            <E T="03">https://www.nature.com/articles/s41467-023-38876-w;</E>
                             Devasier Bennet, et al., “Current and emerging opportunities in biological medium-based computing and digital data storage,” Nano Select, p. 883 (May 2022), 
                            <E T="03">https://doi-org.hhsnih.idm.oclc.org/10.1002/nano.202100275.</E>
                        </P>
                    </FTNT>
                    <P>
                        While the promise of these new technologies is exciting, they come with increased risks and vulnerabilities to ePHI and the information systems that create, receive, maintain, or transmit it. As noted by Executive Order (E.O.) 14110, “[AI] must be safe and secure. Meeting this goal requires [. . .] addressing AI systems' most pressing security risks—including with respect to biotechnology, cybersecurity, critical infrastructure, and other national security dangers—while navigating AI's opacity and complexity.” 
                        <SU>203</SU>
                        <FTREF/>
                         For these reasons, the E.O. required the Secretary of HHS, in consultation with the Secretary of Defense and the Secretary of Veterans Affairs, to establish an HHS AI Task Force to develop a strategic plan that includes policies and frameworks on responsible deployment and use of AI and AI-enabled technologies in the health and human services sector, including the incorporation of safety, privacy, and security standards into the software-development lifecycle for the protection of personally identifiable information, such as measures to address AI-enhanced cybersecurity threats in the health and human services sector.
                        <SU>204</SU>
                        <FTREF/>
                         The Department has taken a number of actions to address the use of AI in health care, including establishing an AI Council, appointing a Chief AI Officer,
                        <SU>205</SU>
                        <FTREF/>
                         and taking steps to regulate the use of AI in health care.
                        <SU>206</SU>
                        <FTREF/>
                         Accordingly, regulated entities must be prepared to identify, mitigate, and remediate such risks and vulnerabilities.
                    </P>
                    <FTNT>
                        <P>
                            <SU>203</SU>
                             88 FR 75191 (Nov. 1, 2023).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>204</SU>
                             
                            <E T="03">Id.</E>
                             at 75214.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>205</SU>
                             
                            <E T="03">See</E>
                             “HHS Artificial Intelligence (AI) Strategy: AI Council &amp; AI Community of Practice,” U.S. Department of Health and Human Services (June 6, 2024), 
                            <E T="03">https://www.hhs.gov/programs/topic-sites/ai/strategy/index.html;</E>
                             “About the HHS Office of the Chief Artificial Intelligence Officer (OCAIO),” U.S. Department of Health and Human Services (June 6, 2024), 
                            <E T="03">https://www.hhs.gov/programs/topic-sites/ai/ocaio/index.html; see also</E>
                             “Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence,” M-24-10, Office of Management and Budget, Executive Office of the President (Mar. 28, 2024), 
                            <E T="03">https://www.whitehouse.gov/wp-content/uploads/2024/03/M-24-10-Advancing-Governance-Innovation-and-Risk-Management-for-Agency-Use-of-Artificial-Intelligence.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>206</SU>
                             
                            <E T="03">See, e.g.,</E>
                             89 FR 37522, 37642 (May 6, 2024) and 89 FR 1192, 1244 (Jan. 9, 2024).
                        </P>
                    </FTNT>
                    <P>
                        While the health care industry has generally shifted from paper record-keeping and non-interoperable electronic devices to an interconnected electronic health care system, it has led to an increasing vulnerability to breaches of unsecured PHI resulting from unauthorized uses and disclosures and cyberattacks. According to an article published by the American Hospital Association Center for Health Innovation, “Health care organizations are particularly vulnerable and targeted by cyberattacks because they possess so much information of high monetary and intelligence value to cyber thieves and nation-state actors.” 
                        <SU>207</SU>
                        <FTREF/>
                         In fact, “[. . .] on the dark web, PHI is deemed more 
                        <PRTPAGE P="913"/>
                        valuable than credit card data, enabling cybercriminals to extract as much as [$1,000] per stolen medical record.” 
                        <SU>208</SU>
                        <FTREF/>
                         Before this shift to an interconnected electronic system, lost or misplaced paper records or even a laptop could lead to a breach of unsecured PHI affecting hundreds or thousands of individuals.
                        <SU>209</SU>
                        <FTREF/>
                         While a breach of that size remains significant, unauthorized access to a single workstation today could lead to a breach that affects millions of individuals because of the increase in interconnectivity.
                        <SU>210</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>207</SU>
                             John Riggi, “The importance of cybersecurity in protecting patient safety,” American Hospital Association Center for Health Innovation, 
                            <E T="03">https://www.aha.org/center/cybersecurity-and-risk-advisory-services/importance-cybersecurity-protecting-patient-safety</E>
                            ; In 2016, PHI was valued at 50 times the worth of financial information on the black market. Diane Doebele Koch, “Is the HIPAA Security Rule Enough to Protect Electronic Personal Health Information (PHI) in the Cyber Age?” Journal of Health Care Finance, p. 22 (Spring 2016) (citing Beth Kutscher, “Healthcare underspends on Cybersecurity as attacks accelerate,” Modern Healthcare (Mar. 3, 2016), 
                            <E T="03">https://www.modernhealthcare.com/article/20160303/NEWS/160309922/healthcare-underspends-on-cybersecurity-as-attacks-accelerate</E>
                            .); “New Dangers in the New World: Cyber Attacks in the Healthcare Industry,” 
                            <E T="03">supra</E>
                             note 135, p. 3 (“[. . .] stolen medical data sells for 10-20 times more than credit card data.”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>208</SU>
                             Gilbert Munoz-Cornejo, et al., “Analyzing the urban-rural divide: the role of location, time, and breach characteristics in U.S. hospital security incidents, 2012-2021,” Discover Health Systems (June 17, 2024), 
                            <E T="03">https://link.springer.com/article/10.1007/s44250-024-00105-6#:~:text=Specifically%2C%20our%20study%20shows%20that,trend%20of%20breaches%20over%20time.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>209</SU>
                             Lynne Coventry, et al., “Cybersecurity in healthcare: A narrative review of trends, threats and ways forward,” Maturitas, p. 46 (July 2018), 
                            <E T="03">https://www.maturitas.org/article/S0378-5122(18)30165-8/abstract.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>210</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Between 2018 and 2023, the number of breaches of unsecured PHI reported to the Department grew at an alarming rate (100 percent increase), as did the number of individuals affected by such breaches (950 percent increase).
                        <SU>211</SU>
                        <FTREF/>
                         The reports reflect rampant escalation of cyberattacks using hacking (260 percent increase) and ransomware (264 percent increase).
                        <SU>212</SU>
                        <FTREF/>
                         Based on reports made to OCR, in 2022, approximately three-fourths of the breaches of unsecured PHI affecting 500 or more individuals were the result of hacking of electronic equipment or a network server.
                        <SU>213</SU>
                        <FTREF/>
                         In 2023, over 160 million individuals were affected by breaches involving the PHI of 500 or more individuals—a new record. We anticipate that 2024 will surpass that record, particularly in light of the estimate provided by a large covered entity regarding the number of individuals affected by a breach of its subsidiary.
                        <SU>214</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>211</SU>
                             
                            <E T="03">See</E>
                             “Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information,” 
                            <E T="03">supra</E>
                             note 10.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>212</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>213</SU>
                             “Annual Report to Congress on Breaches of Unsecured Protected Health Information: For Calendar Year 2022,” Office for Civil Rights, U.S. Department of Health and Human Services, p. 8-9 (2022), 
                            <E T="03">https://www.hhs.gov/sites/default/files/breach-report-to-congress-2022.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>214</SU>
                             Change Healthcare is a health care clearinghouse and a subsidiary of UnitedHealth Group, 
                            <E T="03">https://www.changehealthcare.com/.</E>
                             On the morning of Feb. 21, 2024, Optum (another subsidiary of UnitedHealth Group) reported that it was “experiencing enterprise-wide connectivity issues.” By that afternoon, the announcement changed to a “network interruption related to a cyber security issue” and explained that “[o]nce [Change Healthcare] became aware of the outside threat, in the interest of protecting our partners and patients, we took immediate action to disconnect our systems to prevent further impact.” 
                            <E T="03">See</E>
                             “Optum Solution Status,” Optum, Inc., UnitedHealth Group, 
                            <E T="03">https://solution-status.optum.com/incidents/hqpjz25fn3n7</E>
                             (last accessed on July 16, 2024). On Mar. 13, 2024, the Department announced that it would be initiating an investigation into the incident. 
                            <E T="03">See</E>
                             Letter from OCR Director Melanie Fontes Rainer to Colleagues (Mar. 13, 2024), 
                            <E T="03">https://www.hhs.gov/sites/default/files/cyberattack-change-healthcare.pdf.</E>
                             Andrew Witty, UnitedHealth Group Chief Executive Officer, in his testimony to Congress, estimated that the breach of Change Healthcare may involve the PHI of one-third of Americans. “Hacking America's Health Care: Assessing the Change Healthcare Cyber Attack and What's Next,” Subcommittee on Oversight and Investigations of the Committee on Energy and Commerce, Hearing Before the Committee on Finance (May 1, 2024), 
                            <E T="03">https://www.finance.senate.gov/hearings/hacking-americas-health-care-assessing-the-change-healthcare-cyber-attack-and-whats-next.</E>
                             Change Healthcare filed its breach report with the Department on July 19, 2024. “Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information,” 
                            <E T="03">supra</E>
                             note 10. Change Healthcare's breach report currently identifies 100 million individuals as the “approximate number of individuals affected.” 
                            <E T="03">https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf.</E>
                             However, Change Healthcare is still determining the number of individuals affected. The posting on the HHS Breach Portal will be amended if Change Healthcare updates the total number of individuals affected by this breach. “Change Healthcare Cybersecurity Incident Frequently Asked Questions,” Office for Civil Rights, U.S. Department of Health and Human Services, 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/special-topics/change-healthcare-cybersecurity-incident-frequently-asked-questions/index.html.</E>
                        </P>
                    </FTNT>
                    <P>
                        In 2023, the Federal Bureau of Investigation's internet Crime Complaint Center received almost 250 reports of ransomware affecting the Healthcare and Public Health sector, the most of any of the 16 identified infrastructure sectors.
                        <SU>215</SU>
                        <FTREF/>
                         The Healthcare and Public Health sector has been the most targeted critical infrastructure sector since at least as far back as 2015.
                        <SU>216</SU>
                        <FTREF/>
                         Between 2015 and 2019, cyberattacks on health care organizations increased by 125 percent.
                        <SU>217</SU>
                        <FTREF/>
                         And between 2022 and 2023, ransomware attacks against the U.S. health care sector increased 128 percent.
                        <SU>218</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>215</SU>
                             “internet Crime Report,” internet Crime Complaint Center, Federal Bureau of Investigation, p. 13 (2023), 
                            <E T="03">https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>216</SU>
                             “Report on Improving Cybersecurity In The Health Care Industry,” 
                            <E T="03">supra</E>
                             note 117, p. 16.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>217</SU>
                             Chon Abraham, et al., “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” 
                            <E T="03">supra</E>
                             note 116, p. 539-548, 540.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>218</SU>
                             “Ransomware Attacks Surge in 2023; Attacks on Healthcare Sector Nearly Double,” The Cyber Threat Intelligence Integration Center, Office of the Director of National Intelligence (Feb. 28, 2024), 
                            <E T="03">https://www.dni.gov/files/CTIIC/documents/products/Ransomware_Attacks_Surge_in_2023.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        Many people, including regulated entities, inaccurately believe that only large regulated entities that maintain electronic records about millions of individuals are likely to face a cyberattack, and thus that it is less important for smaller regulated entities to invest resources in cybersecurity.
                        <SU>219</SU>
                        <FTREF/>
                         In fact, smaller regulated entities may also be the target of, or adversely affected by, cybercrime, partly because of the interconnectedness of health care and partly because they are less likely to have invested in cybersecurity, making them easier targets.
                        <SU>220</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>219</SU>
                             “Report on Improving Cybersecurity In The Health Care Industry,” 
                            <E T="03">supra</E>
                             note 117, p. 14.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>220</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        As explained in a recent national security memorandum, cybercriminals are targeting critical infrastructure (
                        <E T="03">i.e.,</E>
                         the physical and virtual assets and systems so vital to the Nation that their incapacity or destruction would have a debilitating impact on national security, national economic security, or national public health or safety), and their activities may be tolerated or enabled by other countries.
                        <SU>221</SU>
                        <FTREF/>
                         Thus, it is essential that the Department and regulated entities take steps to safeguard health care infrastructure and ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>221</SU>
                             Presidential Memorandum on National Security Memorandum on Critical Infrastructure Security and Resilience 
                            <E T="03">supra</E>
                             note 11.
                        </P>
                    </FTNT>
                    <P>
                        External actors are not the only, or even the greatest, threat to the security of ePHI. According to a recent study, insiders were the second leading cause of breaches in the health care sector in 2023, exceeded only by “miscellaneous errors,” such as misdelivery.
                        <SU>222</SU>
                        <FTREF/>
                         For example, a recent settlement resolved an OCR investigation involving the theft and sale of the ePHI of more than 12,000 patients by an employee of a large health care system.
                        <SU>223</SU>
                        <FTREF/>
                         In another example, security guards at a large health care provider were alleged to have used their login credentials to inappropriately access ePHI.
                        <SU>224</SU>
                        <FTREF/>
                         Thus, it is critical that regulated entities improve their cybersecurity posture to protect not only against external threats but also 
                        <PRTPAGE P="914"/>
                        internal ones, and both intentional and accidental breaches.
                    </P>
                    <FTNT>
                        <P>
                            <SU>222</SU>
                             “2024 Data Breach Investigations Report: Healthcare Snapshot,” Verizon Business, p. 12 (May 1, 2024) (The report describes misdelivery as sending information to the wrong recipient, whether by electronic or physical means), 
                            <E T="03">https://www.verizon.com/business/resources/reports/dbir/2024/industries-intro/healthcare-data-breaches/.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>223</SU>
                             Press release, “HHS' Office for Civil Rights Settles Malicious Insider Cybersecurity Investigation for $4.75 Million,” Office for Civil Rights, U.S. Department of Health and Human Services (Feb. 6, 2024), 
                            <E T="03">https://www.hhs.gov/about/news/2024/02/06/hhs-office-civil-rights-settles-malicious-insider-cybersecurity-investigation.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>224</SU>
                             Press release, “Snooping in Medical Records by Hospital Security Guards Leads to $240,000 HIPAA Settlement,” Office for Civil Rights, U.S. Department of Health and Human Services (June 15, 2023), 
                            <E T="03">https://www.hhs.gov/about/news/2023/06/15/snooping-medical-records-by-hospital-security-guards-leads-240-000-hipaa-settlement.html.</E>
                        </P>
                    </FTNT>
                    <P>
                        Emergencies or other occurrences can affect the security of ePHI without an intentional act. For example, in 2024, CrowdStrike released a defective update for its software on computers running Microsoft Windows.
                        <SU>225</SU>
                        <FTREF/>
                         This update affected the ability of regulated entities to access the ePHI of millions of individuals for varying periods of time. During this time, ePHI was unavailable, meaning that one of the key prongs of the security triad of confidentiality, integrity, and availability was affected.
                        <SU>226</SU>
                        <FTREF/>
                         Because of the increased digitization of PHI, it is, for example, essential that covered health care providers engage in thoughtful contingency planning that considers how they will proceed in the event that they are unable to access ePHI in their EHRs. Additionally, threat actors will often seek to take advantage of such incidents. As reported by a large subcontractor of a business associate, less than a week after the outage, the company “observed threat actors leveraging the event to distribute” ransomware.
                        <SU>227</SU>
                        <FTREF/>
                         The environment in which health care is delivered, the way in which it is delivered, and the manner in which related information is collected all mean that regulated entities must consider a different approach to operational continuity and resiliency in the face of such challenges. Additionally, they must be wary of the potential for bad actors to attempt to take advantage of such events.
                    </P>
                    <FTNT>
                        <P>
                            <SU>225</SU>
                             “Remediation and Guidance Hub: Falcon Content Update for Windows Hosts,” CrowdStrike, 
                            <E T="03">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>226</SU>
                             
                            <E T="03">See</E>
                             “Data Integrity: Detecting and Responding to Ransomware and Other Destructive Events,” NIST Special Publication 1800-26A, National Institute of Standards and Technology, U.S. Department of Commerce, p. 1 (Dec. 2020), 
                            <E T="03">https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1800-26.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>227</SU>
                             “Likely eCrime Actor Uses Filenames Capitalizing on July 19, 2024, Falcon Sensor Content Issues in Operation Targeting LATAM-Based CrowdStrike Customers,” CrowdStrike Blog (July 20, 2024), 
                            <E T="03">https://www.crowdstrike.com/blog/likely-ecrime-actor-capitalizing-on-falcon-sensor-issues/.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD2">C. Regulated Entities' Compliance With the Requirements of the Security Rule Is Inconsistent</HD>
                    <P>
                        Despite the proliferation of cybersecurity standards, guidelines, best practices, methodologies, procedures, and processes and the documented increase in unauthorized uses and disclosures of ePHI, many regulated entities have been slow to strengthen their security measures to protect ePHI and their information systems that create, receive, maintain, or transmit it in this new environment.
                        <SU>228</SU>
                        <FTREF/>
                         Among the reasons for this are the rapid pace of EHR adoption and digitization of health care, increased connectivity and use of cloud-based infrastructures, limited competition and a stable customer base, limited operating margins, and a failure to invest in cybersecurity infrastructure.
                        <SU>229</SU>
                        <FTREF/>
                         For example, regulated entities continue to rely on legacy systems and software that are unsupported by manufacturers, which means that the manufacturers no longer provide security patches or other updates to address security threats and vulnerabilities.
                        <SU>230</SU>
                        <FTREF/>
                         In a 2021 survey of health care cybersecurity professionals, 73 percent reported having legacy operating systems.
                        <SU>231</SU>
                        <FTREF/>
                         This apparent lack of urgency in adopting new, supported operating systems has serious implications for the confidentiality, integrity, and availability of ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>228</SU>
                             Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, p. 2 (explaining that NCVHS conducted an inquiry into whether compliance with the Security Rule had improved since the Department released the results of its 2016-2017 audit of selected provisions of the Security Rule and found that “not much had changed”); “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” 
                            <E T="03">supra</E>
                             note 116, p. 540 (“There is enough evidence to suggest that U.S. healthcare organizations lack a deliberate, organized, and comprehensive cyber-resilience strategy.”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>229</SU>
                             
                            <E T="03">See</E>
                             Susan Kiser, et al., “Ransomware: Healthcare Industry at Risk,” Journal of Business and Accounting, p. 65-66 (Fall 2021); Meghan Hufstader Gabriel, “Data Breach Locations, Types, and Associated Characteristics Among US Hospitals,” American Journal of Managed Care, p. 78 (Feb. 2018); “Is the HIPAA Security Rule Enough to Protect Electronic Personal Health Information (PHI) in the Cyber Age?” 
                            <E T="03">supra</E>
                             note 207, p. 20-23.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>230</SU>
                             Chris Hayhurst, “On Guard: Staying Vigilant Against Medical Device Vulnerabilities,” Biomedical Instrumentation &amp; Technology, Volume 54, Issue 3, p. 169 (May/June 2020); “Report on Improving Cybersecurity In The Health Care Industry,” 
                            <E T="03">supra</E>
                             note 117, p. 2.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>231</SU>
                             “2021 HIMSS Healthcare Cybersecurity Survey,” Healthcare Information and Management Systems Society, p. 18 (Jan. 28, 2022), 
                            <E T="03">https://www.himss.org/sites/hde/files/media/file/2022/01/28/2021_himss_cybersecurity_survey.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        In addition, many regulated entities fail to invest adequate resources in cybersecurity. Far too many regulated entities do not view cybersecurity as a necessary component of their operations that allows them to fulfill their health care missions. Anecdotal evidence suggests that senior management often lacks awareness of cybersecurity, including both threats and methods for protecting against such threats.
                        <SU>232</SU>
                        <FTREF/>
                         “A lack of maturity and effectiveness of the [information technology] function is evident when healthcare organizations fail to maintain a current inventory of sensitive and valuable data and where those reside.” 
                        <SU>233</SU>
                        <FTREF/>
                         While maintaining an accurate and thorough inventory of technology assets is not currently an explicit requirement of the Security Rule, it is clearly a fundamental component of conducting a risk analysis and many of the other existing requirements.
                        <SU>234</SU>
                        <FTREF/>
                         And yet, based on the Department's experience, many regulated entities are not maintaining such an inventory. At least in part because of senior management's lack of cybersecurity awareness, many fail to invest or fail to invest appropriately in cybersecurity infrastructure.
                        <SU>235</SU>
                        <FTREF/>
                         Given the vulnerability of ePHI and the information systems of regulated entities and the potential effects of cyberattacks on patient safety and the delivery of health care, it is important that regulated entities prioritize such investments.
                        <SU>236</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>232</SU>
                             “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” 
                            <E T="03">supra</E>
                             note 116, p. 543.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>233</SU>
                             
                            <E T="03">Id.</E>
                             at 542.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>234</SU>
                             
                            <E T="03">See</E>
                             68 FR 8334, 8352 (Feb. 20, 2003). In the preamble to the 2003 Security Rule, the Department explained that it had determined that an inventory requirement was unnecessary because it is redundant of other requirements. We assumed that covered entities (and later all regulated entities) would have performed this activity by virtue of having implemented the security measures required under the security management process standard.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>235</SU>
                             “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” 
                            <E T="03">supra</E>
                             note 116, p. 542-543.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>236</SU>
                             Eric C. Reese, “Healthcare's cybersecurity stakes reach alarming levels,” Health Facilities Management Magazine, Volume 76, Issue 8, p. 22 (Nov. 2022).
                        </P>
                    </FTNT>
                    <P>
                        The security of ePHI also is at risk because, despite our explanation of the Security Rule's structure in 2003,
                        <SU>237</SU>
                        <FTREF/>
                         regulated entities are not fully complying with the standards and implementation specifications. From 2016 to 2017, the Department conducted audits of 166 covered entities and 41 business associates regarding compliance with selected provisions of the HIPAA Rules, including the required implementation specifications for risk analysis 
                        <SU>238</SU>
                        <FTREF/>
                         and risk management.
                        <SU>239</SU>
                        <FTREF/>
                         The Department found that most regulated entities failed to implement the Security Rule requirements for risk analysis and risk management, requirements that are fundamental to protecting the confidentiality, integrity, and availability of ePHI.
                        <SU>240</SU>
                        <FTREF/>
                         While most of the audited business associates reported not having experienced any breaches of unsecured PHI, we found that those that 
                        <PRTPAGE P="915"/>
                        had experienced a breach generally engaged in minimal or negligible efforts to address the risk analysis and risk management requirements.
                        <SU>241</SU>
                        <FTREF/>
                         According to the report, at that time only 14 percent of covered entities and 17 percent of business associates were “substantially fulfilling their regulatory responsibilities to safeguard ePHI they [held] through risk analysis activities,” 
                        <SU>242</SU>
                        <FTREF/>
                         while 94 percent of covered entities and 88 percent of business associates “failed to implement appropriate risk management activities sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.” 
                        <SU>243</SU>
                        <FTREF/>
                         The report specifically noted that the audit results were consistent with the findings of OCR's compliance reviews and complaint investigations.
                        <SU>244</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>237</SU>
                             68 FR 8334, 8343 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>238</SU>
                             45 CFR 164.308(a)(1)(ii)(A).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>239</SU>
                             45 CFR 164.308(a)(1)(ii)(B); “2016-2017 HIPAA Audits Industry Report,” 
                            <E T="03">supra</E>
                             note 121, p. 4.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>240</SU>
                             “2016-2017 HIPAA Audits Industry Report,” 
                            <E T="03">supra</E>
                             note 121, p. 4.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>241</SU>
                             
                            <E T="03">Id.</E>
                             at 11.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>242</SU>
                             
                            <E T="03">Id.</E>
                             at 27.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>243</SU>
                             
                            <E T="03">Id.</E>
                             at 30.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>244</SU>
                             
                            <E T="03">Id.</E>
                             at 27 and 30.
                        </P>
                    </FTNT>
                    <P>
                        Recent enforcement actions provide evidence that the results of the 2016-2017 audits were not isolated cases. In 2023, OCR entered into seven resolution agreements with regulated entities after investigations indicated that they had potentially violated the Security Rule, constituting almost half of the total resolution agreements OCR entered into that year.
                        <SU>245</SU>
                        <FTREF/>
                         In each case, OCR's investigation found evidence of multiple potential violations. For example, in one case, a regulated entity did not detect an intrusion into its network until 20 months later when its files were encrypted with ransomware.
                        <SU>246</SU>
                        <FTREF/>
                         OCR's investigation found evidence of potential failures of the regulated entity to conduct a risk analysis or to sufficiently monitor information system activity. OCR also found evidence that the regulated entity may not have had policies and procedures in place to implement the requirements of the Security Rule to protect the confidentiality, integrity, and availability of ePHI.
                        <SU>247</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>245</SU>
                             
                            <E T="03">See</E>
                             “OCR News Releases &amp; Bulletins,” Office for Civil Rights, U.S. Department of Health and Human Services, 
                            <E T="03">https://www.hhs.gov/ocr/newsroom/index.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>246</SU>
                             
                            <E T="03">See</E>
                             Resolution Agreement, “Doctors' Management Services, Inc.,” Office for Civil Rights, U.S. Department of Health and Human Services (Oct. 31, 2023), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/dms-ra-cap/index.html;</E>
                             Press Release, “HHS' Office for Civil Rights Settles Ransomware Cyber-Attack Investigation,” Office for Civil Rights, U.S. Department of Health and Human Services (Oct. 31, 2023), 
                            <E T="03">https://www.hhs.gov/about/news/2023/10/31/hhs-office-civil-rights-settles-ransomware-cyber-attack-investigation.html; see also</E>
                             “Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information,” 
                            <E T="03">supra</E>
                             note 10.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>247</SU>
                             “HHS' Office for Civil Rights Settles Ransomware Cyber-Attack Investigation,” 
                            <E T="03">supra</E>
                             note 246.
                        </P>
                    </FTNT>
                    <P>
                        As another example, an OCR investigation of a large health care system found indications of multiple potential violations of the Security Rule, including failures by the regulated entity to conduct a risk analysis, monitor and safeguard its electronic information systems, and implement policies and procedures to record and examine activity in its electronic information systems containing ePHI.
                        <SU>248</SU>
                        <FTREF/>
                         The regulated entity was not only unable to prevent the cyberattack, but it was unaware the attack had occurred until two years later. This is despite the long-standing requirements of the Security Rule and the obligations imposed on regulated entities for risk analysis and risk management.
                    </P>
                    <FTNT>
                        <P>
                            <SU>248</SU>
                             
                            <E T="03">See</E>
                             Resolution Agreement, “Montefiore Medical Center,” Office for Civil Rights, U.S. Department of Health and Human Services (Nov. 17, 2023), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/montiefore/index.html;</E>
                             “HHS' Office for Civil Rights Settles Malicious Insider Cybersecurity Investigation for $4.75 Million,” 
                            <E T="03">supra</E>
                             note 223.
                        </P>
                    </FTNT>
                    <P>
                        Despite the long-standing nature of the Security Rule and the proliferation of guidance documents from NIST, the Department, CISA, FTC, and others, regulated entities continue to fail to implement reasonable and appropriate security measures as required by the Security Rule.
                        <SU>249</SU>
                        <FTREF/>
                         For example, the Security Rule and NIST guidance have addressed encryption for data in transit and at rest for many years.
                        <SU>250</SU>
                        <FTREF/>
                         And yet, in the 2021 survey of health care cybersecurity professionals, only half of the respondents reported having implemented encryption for data in transit across the enterprise.
                        <SU>251</SU>
                        <FTREF/>
                         Similarly, according to its CEO, a large covered entity failed to deploy multi-factor authentication (MFA) throughout its enterprise and experienced a significant breach.
                        <SU>252</SU>
                        <FTREF/>
                         If this is accurate, it would run counter to long-standing provisions in both the Security Rule and NIST guidance; the Security Rule has required the implementation of appropriate access controls since 2003 and NIST recommends similar controls.
                        <SU>253</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>249</SU>
                             “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” 
                            <E T="03">supra</E>
                             note 116, p. 541; “Start with Security: A Guide for Business,” 
                            <E T="03">supra</E>
                             note 17.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>250</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.312(a)(1) and (e)(1); PR.DS-1 and 2, “Framework for Improving Critical Infrastructure Cybersecurity,” Cybersecurity Framework (CSF) Version 1.1, National Institute of Standards and Technology, U.S. Department of Commerce (Apr. 16, 2018), 
                            <E T="03">https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf;</E>
                             PR.DS-01 and 02, “The NIST Cybersecurity Framework (CSF) 2.0,” 
                            <E T="03">supra</E>
                             note 15.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>251</SU>
                             “2021 HIMSS Healthcare Cybersecurity Survey,” 
                            <E T="03">supra</E>
                             note 231, p. 23.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>252</SU>
                             
                            <E T="03">See</E>
                             “Hacking America's Health Care: Assessing the Change Healthcare Cyber Attack and What's Next,” 
                            <E T="03">supra</E>
                             note 214 (According to CEO Andrew Witty, intruders used compromised credentials to remotely access an application used to enable remote access to desktops, which did not have MFA.). The Department's investigation into the Change Healthcare breach is ongoing, and no conclusion has been reached with respect to its cause or whether Change Healthcare was in violation of the Security Rule.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>253</SU>
                             45 CFR 164.308(a)(4)(ii)(B) and 164.312(a)(1); “The NIST Cybersecurity Framework (CSF) 2.0,” 
                            <E T="03">supra</E>
                             note 15; “Framework for Improving Critical Infrastructure Cybersecurity,” 
                            <E T="03">supra</E>
                             note 250.
                        </P>
                    </FTNT>
                    <P>
                        As another example, based on OCR's investigation experience, some regulated entities are not developing and implementing compliant response plans for security incidents, including those that are breaches of unsecured ePHI under the Breach Notification Rule. Section 164.308(a)(6)(i) establishes the standard that requires regulated entities to implement policies and procedures to address security incidents, while 45 CFR 164.308(a)(6)(ii) includes the implementation specifications for that standard. This requirement, included in the 2003 Final Rule, aligns with the NIST Cybersecurity Framework version 2.0 requirement for incident management.
                        <SU>254</SU>
                        <FTREF/>
                         Similarly, NIST Cybersecurity Framework version 1.1 recommended the execution and maintenance of response processes and procedures to ensure response to detected cybersecurity incidents.
                        <SU>255</SU>
                        <FTREF/>
                         And yet, when OCR investigates the circumstances surrounding breach reports, OCR continues to find evidence that regulated entities have not implemented policies and procedures to detect and respond to security incidents, leading to significant time lapses between a “successful” security incident 
                        <SU>256</SU>
                        <FTREF/>
                         and discovery of, and response to, the security incident.
                        <SU>257</SU>
                        <FTREF/>
                         Thus, based on the OCR's experience investigating and enforcing the Security Rule, the Department believes that many regulated entities would benefit from additional instruction in regulatory text regarding their compliance obligations to determine how to select security 
                        <PRTPAGE P="916"/>
                        measures that are reasonable and appropriate for their circumstances.
                    </P>
                    <FTNT>
                        <P>
                            <SU>254</SU>
                             RS.MA, “The NIST Cybersecurity Framework (CSF) 2.0,” 
                            <E T="03">supra</E>
                             note 15.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>255</SU>
                             PR.IP-9, “Framework for Improving Critical Infrastructure Cybersecurity,” 
                            <E T="03">supra</E>
                             note 250.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>256</SU>
                             45 CFR 164.304 (definition of “Security incident”). The definition of security incident includes both attempted and successful incidents. A successful incident is one in which a threat actor is able to, without authorization, access, use, disclose, modify, or destroy information or interfere with system operations in an information system.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>257</SU>
                             
                            <E T="03">See, e.g.,</E>
                             “Montefiore Medical Center,” 
                            <E T="03">supra</E>
                             note 248.
                        </P>
                    </FTNT>
                    <P>
                        We are also concerned that recent caselaw has not accurately set forth the steps regulated entities must take to adequately protect the confidentiality, integrity, and availability of ePHI, as required by the statute. Specifically, in the 
                        <E T="03">University of Texas M.D. Anderson Cancer Center</E>
                         v. 
                        <E T="03">HHS</E>
                         (“
                        <E T="03">M.D. Anderson</E>
                        ”), the U.S. Court of Appeals for the Fifth Circuit held, among other things, that the Security Rule does not say anything about how effective a mechanism for encryption must be, nor does it require that an encryption mechanism provide “bulletproof protection” of all systems containing ePHI.
                        <SU>258</SU>
                        <FTREF/>
                         Thus, under the court's interpretation, a regulated entity can meet its obligations under the Security Rule concerning encryption and decryption of ePHI by implementing a mechanism to do so, without regard for the effectiveness of the implementation.
                        <SU>259</SU>
                        <FTREF/>
                         Additionally, the court noted that the requirement for “a mechanism” does not “prohibit a [regulated] entity from creating `a mechanism' by directing employees to sign an [agreement] that requires the encryption of portable devices.” 
                        <SU>260</SU>
                        <FTREF/>
                         While the Department disagrees with the court's interpretation that merely requiring employees to sign an agreement to encrypt portable devices is sufficient to comply with its Security Rule obligations to implement a mechanism to encrypt and decrypt ePHI, the Department believes that additional clarity is warranted to ensure that regulated entities understand their obligation to have encryption mechanisms in place and deployed throughout the regulated entity's enterprise to ensure the confidentiality, integrity, and availability of ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>258</SU>
                             
                            <E T="03">University of Texas M.D. Anderson Cancer Center</E>
                             v. 
                            <E T="03">U.S. Department of Health and Human Services,</E>
                             985 F.3d 472, 478 (5th Cir. 2021).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>259</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>260</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>Several technical safeguards currently require regulated entities to implement a “mechanism” as part of complying with the associated standard. Given that written policies and procedures alone are insufficient to protect ePHI, and the misinterpretation of what it means to implement a mechanism also could lead to inadequate protection of ePHI, the Department believes that the Security Rule must be revised, consistent with its statutory mandate, as discussed in greater detail above.</P>
                    <HD SOURCE="HD2">D. It Is Reasonable and Appropriate To Strengthen the Security Rule To Address the Changes in the Health Care Environment and Clarify the Compliance Obligations of Regulated Entities</HD>
                    <HD SOURCE="HD3">1. Congress and the Department Anticipated That Security Standards Safeguards Would Evolve To Address Changes in the Health Care Environment</HD>
                    <P>
                        By requiring that regulated entities maintain reasonable and appropriate safeguards to protect against reasonably anticipated threats or hazards or unauthorized uses or disclosures of ePHI, Congress clearly anticipated that the administrative, physical, and technical safeguards implemented to protect the security of ePHI would need to change in response to changes in the environment in which health care is provided.
                        <SU>261</SU>
                        <FTREF/>
                         As the health care environment and the operations of regulated entities evolve, so must the protections for ePHI and the information systems used to create, receive, maintain, or transmit it. For example, regulated entities must be expected to adopt safeguards that address new risks to the security of ePHI, such as those posed by maintaining ePHI in the cloud; the connection of medical devices and other technology to networks; and the connection of information systems used to create, receive, maintain, or transmit ePHI to the same networks as those do not perform such activities. After all, it is reasonable to anticipate that there will be new threats or hazards to ePHI or efforts by unauthorized persons to use or disclose such ePHI in an increasingly connected environment.
                    </P>
                    <FTNT>
                        <P>
                            <SU>261</SU>
                             Sec. 1173(d)(2)(B) of Pub. L. 104-191, 110 Stat. 2026 (Aug. 21, 1996) (codified at 42 U.S.C. 1320d-2).
                        </P>
                    </FTNT>
                    <P>
                        By design, the Security Rule sets a national floor for the security measures that regulated entities are required to implement to protect the confidentiality, integrity, and availability of ePHI. In 2003, the Department opted to frame the standards in terms that were as generic as possible and in a manner that enabled the standards to be met through various approaches or technologies to ensure that regulated entities had the flexibility to determine how best to protect the confidentiality, integrity, and availability of ePHI based on their specific circumstances.
                        <SU>262</SU>
                        <FTREF/>
                         When we extended the Security Rule in 2013 to directly apply to business associates in accordance with the HITECH Act,
                        <SU>263</SU>
                        <FTREF/>
                         the Department acknowledged that some business associates might not have engaged in the formal administrative safeguards required by the Security Rule, and we made it clear that business associates would be expected to do so going forward.
                        <SU>264</SU>
                        <FTREF/>
                         Despite the changes in the health care environment between 2003 and 2013, the Department made minimal changes to the Security Rule at that time because we believed that the compliance obligations of regulated entities were clear and well-understood. In fact, when a commenter recommended that the Department remove the “addressable” designation from the Security Rule because it leads to ambiguity in the rule's application, we declined to do so at that time because we were concerned that it would reduce the rule's scalability and flexibility.
                        <SU>265</SU>
                        <FTREF/>
                         However, as we noted in 2003, the rule's flexibility of approach is primarily provided for in paragraph (b)(2) of 45 CFR 164.306 and in the standards themselves.
                        <SU>266</SU>
                        <FTREF/>
                         The addressability feature merely provided an added level of flexibility 
                        <SU>267</SU>
                        <FTREF/>
                         in a way that the Department now believes is inadequate to ensure that regulated entities implement reasonable and appropriate security safeguards.
                    </P>
                    <FTNT>
                        <P>
                            <SU>262</SU>
                             68 FR 8334, 8336 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>263</SU>
                             42 U.S.C. 17931(a); 78 FR 5566 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>264</SU>
                             78 FR 5566 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>265</SU>
                             
                            <E T="03">Id.</E>
                             at 5591.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>266</SU>
                             
                            <E T="03">See</E>
                             68 FR 8334, 8341 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>267</SU>
                             
                            <E T="03">Id.</E>
                             at 8344.
                        </P>
                    </FTNT>
                    <P>
                        Changes to the health care environment and the operations of regulated entities have increased the importance of implementing strong security measures to protect ePHI and the information systems that create, receive, maintain, or transmit it. While we recognize the burdens posed by such implementation on regulated entities, there is also a clearly documented increase in the number of breaches of unsecured PHI and instances of cybercriminals accessing ePHI without authorization at regulated entities. The changes to the health care environment, including the increase in breaches and cyberattacks, and operations of regulated entities have made it increasingly likely that unauthorized persons will seek to obtain ePHI and disrupt the U.S. health care system. Additionally, the clearly documented failure of regulated entities to fully implement the policies and procedures required by the Security Rule and apply the required security measures throughout their operations has caused the Department to question whether the existing Security Rule should be revised to clarify and strengthen the obligations of regulated entities and revisit our 
                        <PRTPAGE P="917"/>
                        decision from 2013.
                        <SU>268</SU>
                        <FTREF/>
                         In many cases involving a breach of ePHI that OCR has investigated, a breach may not have occurred, or would have been less widespread and disruptive, had the regulated entities fully implemented the provisions of the Security Rule.
                        <SU>269</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>268</SU>
                             
                            <E T="03">See</E>
                             “2016-2017 HIPAA Audits Industry Report,” 
                            <E T="03">supra</E>
                             note 121, p. 4 (“[M]ost covered entities failed to meet the requirements for other selected provisions in the audit, such as adequately safeguarding protected health information (PHI) [. . .] OCR also found that most covered entities and business associates failed to implement the HIPAA Security Rule requirements for risk analysis and risk management.”); “Enforcement Highlights,” Office for Civil Rights, U.S. Department of Health and Human Services, 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/data/enforcement-highlights/index.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>269</SU>
                             
                            <E T="03">See, e.g.,</E>
                             “Montefiore Medical Center,” 
                            <E T="03">supra</E>
                             note 248; “Doctors' Management Services, Inc.,” 
                            <E T="03">supra</E>
                             note 246.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">2. NCVHS Believes That the Security Standards Evolve To Address Changes in the Health Care Environment</HD>
                    <P>
                        The Department is not alone in believing that the Security Rule should be strengthened to address concerns about whether -regulated entities are sufficiently protecting the confidentiality, integrity, and availability of ePHI. An inquiry conducted by NCVHS between July 2021 and September 2023 reached the same conclusion.
                        <SU>270</SU>
                        <FTREF/>
                         During this inquiry, NCVHS listened to the testimony of cybersecurity experts and Department officials. The experts and Department officials “consistently voiced their concerns about the major increase in incidents and, in particular, the widespread lack of robust risk analysis on the part of covered entities and business associates that would lead to prior planning for, and mitigation of, a range of cybersecurity threats.” 
                        <SU>271</SU>
                        <FTREF/>
                         In response to this inquiry and consistent with their statutory mandate,
                        <SU>272</SU>
                        <FTREF/>
                         NCVHS transmitted two letters to the Secretary with recommendations for improving cybersecurity practices in the health care industry, including recommendations for modifying the Security Rule.
                        <SU>273</SU>
                        <FTREF/>
                         As part of the explanation for its concerns, NCVHS cited a 2021 survey of acute and ambulatory care organizations that found only 32 percent of those organizations had a comprehensive security program, while only 26 percent of the long-term and post-acute care facilities met the minimum security requirements.
                        <SU>274</SU>
                        <FTREF/>
                         Specifically, NCVHS made the following recommendations for improvements to the Security Rule:
                    </P>
                    <FTNT>
                        <P>
                            <SU>270</SU>
                             Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, p. 2 (detailing the inquiry undertaken by NCVHS into the scope and breadth of security risks and how to best address those challenges).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>271</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>272</SU>
                             
                            <E T="03">See</E>
                             42 U.S.C. 1320d-1(f).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>273</SU>
                             
                            <E T="03">See</E>
                             Letter from NCVHS Chair Jacki Monson (2022), 
                            <E T="03">supra note 123;</E>
                             Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>274</SU>
                             
                            <E T="03">See</E>
                             Letter from NCVHS Chair Jacki Monson (2022), 
                            <E T="03">supra</E>
                             note 123, p. 4 (citing a survey performed by a College of Healthcare Information Management Executives (CHIME) as explained at Jill McKeon, “32% of Healthcare Organizations Have a Comprehensive Security Program,” Health IT Security (Nov. 22, 2021), 
                            <E T="03">https://healthitsecurity.com/news/32-of-healthcare-organizations-have-a-comprehensive-securityprogram</E>
                            ).
                        </P>
                    </FTNT>
                    <P>
                        • Eliminate from the addressable implementation specifications the choice not to implement a specification or alternative, and instead require regulated entities to implement the specification or adopt a documented reasonable alternative.
                        <SU>275</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>275</SU>
                             
                            <E T="03">See</E>
                             Letter from NCVHS Chair Jacki Monson (2022), 
                            <E T="03">supra</E>
                             note 123, p. 4; 
                            <E T="03">see also</E>
                             Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, Appendix p. 1.
                        </P>
                    </FTNT>
                    <P>
                        • Include specific minimum cybersecurity hygiene requirements that are reflective of modern industry best practices, including designation of a qualified information security official, elimination of default passwords, adoption of MFA, institution of offline backups, installation of critical patches within a reasonable time, and transparency of impact and vulnerability disclosures.
                        <SU>276</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>276</SU>
                             
                            <E T="03">See</E>
                             Letter from NCVHS Chair Jacki Monson (2022), 
                            <E T="03">supra</E>
                             note 123, p. 5-10; 
                            <E T="03">see also</E>
                             Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, Appendix p. 2.
                        </P>
                    </FTNT>
                    <P>
                        • Require that regulated entities implement a security program and that they implement standard minimum security controls.
                        <SU>277</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>277</SU>
                             Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, Appendix p. 1-4.
                        </P>
                    </FTNT>
                    <P>
                        • Require that regulated entities adopt a risk-based approach in their security program.
                        <SU>278</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>278</SU>
                             
                            <E T="03">Id.</E>
                             at Appendix p. 4-5.
                        </P>
                    </FTNT>
                    <P>
                        • Require that regulated entities perform a risk analysis in a manner that conforms with guidance from NIST and CISA.
                        <SU>279</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>279</SU>
                             
                            <E T="03">Id.</E>
                             at Appendix p. 4-6.
                        </P>
                    </FTNT>
                    <P>
                        • Define compensating controls more specifically and provide a wider range of examples that apply to a greater variety of types of entities.
                        <SU>280</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>280</SU>
                             
                            <E T="03">Id.</E>
                             at Appendix p. 6-7.
                        </P>
                    </FTNT>
                    <P>
                        • Reinforce the need for regulated entities to account for AI systems and data within their risk analysis for all and any new technology.
                        <SU>281</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>281</SU>
                             
                            <E T="03">Id.</E>
                             at Appendix p. 7-8.
                        </P>
                    </FTNT>
                    <P>
                        • Establish a consistent floor for cyber incident reporting and harmonize such requirements with incident reporting provisions applicable to health care critical infrastructure actors and health care Federal contractors.
                        <SU>282</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>282</SU>
                             
                            <E T="03">Id.</E>
                             at 9-10.
                        </P>
                    </FTNT>
                    <P>
                        The Department, in drafting this NPRM, relied on the recommendations of NCVHS, OCR's enforcement experience, news reports, and our assessment of the environment. Consistent with NCVHS' recommendation to revisit the Security Rule's classification of some implementation specifications as “addressable,” the Department also believes that it is appropriate to revisit our decision regarding the amount of flexibility regulated entities have in determining reasonable and appropriate safeguards, as described above. Based on OCR's experience in investigations and audits, we believe that regulated entities would benefit from greater specificity in the Security Rule. The Department has provided extensive guidance on questions to consider when adopting and implementing security measures and ways to comply with the Security Rule,
                        <SU>283</SU>
                        <FTREF/>
                         as directed by the HITECH Act. And yet, despite this proliferation of guidance, regulated entities continue not to comply. For example, despite the explanation in 45 CFR 164.306(d) about addressable implementation specifications and the notable changes in the environment in which health care is provided, we are concerned that some regulated entities proceed as if compliance with an addressable implementation specification is optional—and that where there is an addressable implementation specification, that compliance with the relevant standard is also optional. That interpretation is incorrect and weakens the cybersecurity posture of regulated entities. We believe that compliance with the implementation specifications currently designated as addressable is not—and should not be—optional, particularly in light of the shift to an interconnected and cloud-based environment and a significant increase in the number of breaches of unsecured PHI from both internal and external actors, regardless of the regulated entity's specific circumstances. Thus, we believe that it is necessary to strengthen the Security Rule to reflect the changes in the health care environment and the evolution of 
                        <PRTPAGE P="918"/>
                        technology and to underscore that compliance with all of our proposals, if finalized, is required.
                    </P>
                    <FTNT>
                        <P>
                            <SU>283</SU>
                             The Department has issued, among other things, a video presentation on trends in real world cyberattacks, a cybersecurity checklist and infographic, guidance on ransomware, a crosswalk with the NIST CSF, and an ongoing series of newsletters on various topics pertaining to cybersecurity. 
                            <E T="03">See</E>
                             “Cyber Security Guidance Material,” Office for Civil Rights, U.S. Department of Health and Human Services, 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity/index.html.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">3. A Strengthened Security Rule Would Continue To Be Flexible and Scalable While Providing Regulated Entities With Greater Clarity</HD>
                    <P>
                        The Security Rule's fundamental flexibility and scalability generally would remain should the proposals in this NPRM be adopted. However, we are proposing to reduce that flexibility to better strengthen protections and address the changed nature of the environment in which health care is provided. The Department is also proposing in this NPRM to strengthen the Security Rule by providing greater clarity regarding the nature of its flexibility and scalability and the Department's expectations, as requested by regulated entities and other stakeholders. In fact, in response to a request for information published in 2022,
                        <SU>284</SU>
                        <FTREF/>
                         several commenters urged the Department to propose regulations that establish a single set of clear standards for regulated entities, raise the floor for security requirements and expectations, and encourage regulated entities to safeguard ePHI while maintaining flexibility and scalability. Commenters also encouraged the Department to rely on commonly available, non-proprietary frameworks that allow regulated entities to adopt critical security measures. We believe that our proposals are consistent with those recommendations.
                    </P>
                    <FTNT>
                        <P>
                            <SU>284</SU>
                             
                            <E T="03">See</E>
                             87 FR 19833 (Apr. 6, 2022).
                        </P>
                    </FTNT>
                    <P>
                        Under the proposal, regulated entities would retain the ability to determine the security measures that are reasonable and appropriate to fulfill the required standards and implementation specifications, taking into consideration the factors listed at proposed 45 CFR 164.306(b)(2). In fact, the NPRM, if adopted as proposed, would add to the rule's flexibility and scalability by adding a new factor for regulated entities to consider when determining the reasonable and appropriate security measures.
                        <SU>285</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>285</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.306(b)(2)(v).
                        </P>
                    </FTNT>
                    <P>
                        Additionally, if modifications are adopted as proposed, the Security Rule would remain flexible and scalable by retaining broad standards with which regulated entities could comply in a variety of ways. In 2003, the 13 implementation specifications that the Security Rule requires were considered so basic that no covered entity could effectively protect ePHI without implementing them.
                        <SU>286</SU>
                        <FTREF/>
                         While the Department agrees that these implementation specifications remain essential, we no longer believe that they are sufficient to address the risks to ePHI today. Rather, regulated entities must do more to ensure the confidentiality, integrity, and availability of ePHI today because of the changes in the environment in which health care is provided, how ePHI is maintained, the level of connectivity between information systems, and the technological sophistication of bad actors.
                    </P>
                    <FTNT>
                        <P>
                            <SU>286</SU>
                             68 FR 8334, 8336 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <P>
                        We acknowledged in 2003 and again acknowledge here that “there is no such thing as a totally secure system that carries no risks to security.” 
                        <SU>287</SU>
                        <FTREF/>
                         We posited at that time that Congress intended to set an “exceptionally high goal for the security of [ePHI],” while also recognizing that securing ePHI did not require that covered entities do so without regard for the cost.
                        <SU>288</SU>
                        <FTREF/>
                         However, we also made clear that a covered entity is required to implement adequate security measures and that cost was but one factor for a covered entity to consider when determining what constituted appropriate security measures.
                        <SU>289</SU>
                        <FTREF/>
                         As we noted, “Cost is not meant to free covered entities from this responsibility.” 
                        <SU>290</SU>
                        <FTREF/>
                         In the 2013 Omnibus Rule, we further explained that “[regulated entities] have the flexibility to choose security measures appropriate for their size, resources, and the nature of the security risks they face, enabling them to reasonably implement any given Security Rule standard. [. . .] Thus, the costs of implementing for [. . .] business associates will be proportional to their size and resources.” 
                        <SU>291</SU>
                        <FTREF/>
                         We continue to believe that this is the case. Additionally, as discussed above, there is a significant cost associated with breaches and unauthorized access—financial, reputational (for both the individual and the regulated entity), and more. Thus, we believe that the standards and implementation specifications that we propose in this NPRM are the minimum that regulated entities should be doing to protect the security of ePHI and lower the costs associated with breaches and other incidents.
                    </P>
                    <FTNT>
                        <P>
                            <SU>287</SU>
                             
                            <E T="03">Id.</E>
                             at 8346.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>288</SU>
                             
                            <E T="03">Id.</E>
                             At that time, the Security Rule applied directly only to covered entities. As discussed above, Congress later extended the application of the Security Rule directly to business associates.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>289</SU>
                             68 FR 8334, 8343 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>290</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>291</SU>
                             78 FR 5566, 5589 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">4. Small and Rural Health Care Providers Must Implement Strong Security Measures To Provide Efficient and Effective Health Care</HD>
                    <P>
                        The statute requires that we consider the “needs and capabilities of small health care providers and rural health care providers (as such providers are defined by the Secretary).” 
                        <SU>292</SU>
                        <FTREF/>
                         We recognize that small and rural health care providers may have needs and capabilities that differ from those of other regulated entities. For example, small health care providers and rural health care providers are often located at a greater distance from other health care providers.
                        <SU>293</SU>
                        <FTREF/>
                         It may be more challenging for them to attract and retain clinicians and administrative support staff.
                        <SU>294</SU>
                        <FTREF/>
                         They also face difficulty attracting and retaining security experts and must make difficult decisions regarding investments in competing priorities.
                        <SU>295</SU>
                        <FTREF/>
                         Often, preparation for security incidents or other occurrences that adversely affect the confidentiality, integrity, or availability of ePHI is neglected in favor of other priorities, putting small and rural health care providers at greater risk for such an occurrence.
                        <SU>296</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>292</SU>
                             42 U.S.C. 1320d-2(d)(1)(A)(v).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>293</SU>
                             
                            <E T="03">See</E>
                             “Why Health Care is Harder to Access in Rural America,” U.S. Government Accountability Office (May 16, 2023) (When local hospitals close in rural areas, residents have to travel more than 20 miles further to receive common health care and 40 miles further to receive less common health care, such as substance use disorder treatment. Such rural areas generally have fewer health care providers overall.), 
                            <E T="03">https://www.gao.gov/blog/why-health-care-harder-access-rural-america.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>294</SU>
                             
                            <E T="03">See</E>
                             “A National Staffing Emergency in Rural Health Care,” American Hospital Association (Dec. 19, 2023), 
                            <E T="03">https://www.aha.org/advancing-health-podcast/2023-12-20-national-staffing-emergency-rural-health-care.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>295</SU>
                             
                            <E T="03">See</E>
                             Debi Primeau, “How Small Organizations Handle HIPAA Compliance,” Journal of the American Health Information Management Association, Volume 88, Issue 4, p. 18-21, 19 (Apr. 2017); Kat Jercich, “Rural hospitals are more vulnerable to cyberattacks—here's how they can protect themselves,” Healthcare IT News (Sept. 8, 2021); 
                            <E T="03">see also</E>
                             Tami Lichtenberg, “Recovering from a Cybersecurity Attack and Protecting the Future in Small, Rural Health Organizations” (Oct. 4, 2023), 
                            <E T="03">https://www.ruralhealthinfo.org/rural-monitor/cybersecurity-attacks.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>296</SU>
                             
                            <E T="03">See</E>
                             “How Small Organizations Handle HIPAA Compliance,” 
                            <E T="03">supra</E>
                             note 295, p. 19; “Rural hospitals are more vulnerable to cyberattacks—here's how they can protect themselves,” 
                            <E T="03">supra</E>
                             note 295.
                        </P>
                    </FTNT>
                    <P>
                        We continue to believe that it is just as important for small and rural health care providers to implement strong security measures as it is for larger health care providers and other categories of regulated entities. According to experts, “Cybercriminals go after small businesses, especially those in the healthcare industry, 
                        <PRTPAGE P="919"/>
                        because they are easy targets.” 
                        <SU>297</SU>
                        <FTREF/>
                         In 2017, 93 percent of small rural and critical access hospitals and 86 percent of physician offices relied on health IT to inform their clinical practice.
                        <SU>298</SU>
                        <FTREF/>
                         And yet, small health care providers are less likely than a larger organization to even have a designated security or compliance officer.
                        <SU>299</SU>
                        <FTREF/>
                         Smaller practices and rural and community facilities also may be more likely to rely on older technologies that are no longer supported by security patches and updates, including medical devices such as insulin pumps and pacemakers in which inaccuracies or errors could affect patient safety.
                        <SU>300</SU>
                        <FTREF/>
                         Thus, small health care providers “are at the greatest risk of a breach. [. . .] Smaller, rural practice settings are especially high-risk target areas for a breach.” 
                        <SU>301</SU>
                        <FTREF/>
                         According to an expert who speaks to and works with health care providers on IT services and cybersecurity, small health care providers are “more susceptible because they do not have a lot of the tools and security measures necessary to protect themselves.” 
                        <SU>302</SU>
                        <FTREF/>
                         For example, a critical access hospital in Colorado recovered from a cyberattack in 2019, but it required “an incredible amount of staff time, many months of recovery efforts, and an enormous financial outlay to restore systems and prevent another attack.” 
                        <SU>303</SU>
                        <FTREF/>
                         In fact, the hospital estimates that “it took a full year of a staff person's time to complete the recovery and protect the organization for the future.” 
                        <SU>304</SU>
                        <FTREF/>
                         These costs do not include the multiple ransoms paid to the attackers after the first set of keys did not unlock all of the data.
                        <SU>305</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>297</SU>
                             “Too Small to Be Attacked by Cybercriminals? Not So Fast,” Same-Day Surgery, Volume 43, Issue 7 (July 2019), 
                            <E T="03">https://www.reliasmedia.com/articles/144561-too-small-to-be-attacked-by-cybercriminals-not-so-fast.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>298</SU>
                             “Percent of Hospitals, By Type, that Possess Certified Health IT,” Health IT Quick-Stat #52 (Sept. 2018), 
                            <E T="03">https://www.healthit.gov/data/quickstats/percent-hospitals-type-possess-certified-health-it;</E>
                             “Office-based Physician Electronic Health Record Adoption,” Health IT Quick-Stat #50, 
                            <E T="03">https://www.healthit.gov/data/quickstats/office-based-physician-electronic-health-record-adoption.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>299</SU>
                             “How Small Organizations Handle HIPAA Compliance,” 
                            <E T="03">supra</E>
                             note 295, p. 19.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>300</SU>
                             
                            <E T="03">See id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>301</SU>
                             
                            <E T="03">Id.; see also</E>
                             “Recovering from a Cybersecurity Attack and Protecting the Future in Small, Rural Health Organizations,” 
                            <E T="03">supra</E>
                             note 295.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>302</SU>
                             “Too Small to Be Attacked by Cybercriminals? Not So Fast,” 
                            <E T="03">supra</E>
                             note 297.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>303</SU>
                             “Recovering from a Cybersecurity Attack and Protecting the Future in Small, Rural Health Organizations,” 
                            <E T="03">supra</E>
                             note 295.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>304</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>305</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Patients and communities have a critical need for health care providers, including rural hospitals and other rural health care providers, to be resilient and remain operational, which depends in part on the cybersecurity of their electronic information systems. For rural health care providers, especially hospitals, a breach can significantly affect an entire community.
                        <SU>306</SU>
                        <FTREF/>
                         Rural health care providers often are separated by significant distances, which can have real consequences for someone experiencing a medical emergency.
                        <SU>307</SU>
                        <FTREF/>
                         A recent study comparing hospital characteristics and operations of rural and urban hospitals that experienced ransomware attacks between 2016 and 2021 found that rural hospitals experienced large declines in inpatient admissions and Medicare revenue, similar to those experienced by urban hospitals.
                        <SU>308</SU>
                        <FTREF/>
                         The study also found that the decline in volume and revenue of hospital outpatient and emergency room visits was more pronounced among rural facilities.
                        <SU>309</SU>
                        <FTREF/>
                         In fact, in June 2023, a hospital in rural Illinois announced that it would close, in part because a 2021 cyberattack prevented it from submitting claims to health plans for months.
                        <SU>310</SU>
                        <FTREF/>
                         According to a local elected official, the hospital's closure would require some residents to travel approximately 30 minutes for the nearest emergency room and obstetrics services.
                        <SU>311</SU>
                        <FTREF/>
                         Thus, implementing security measures to maintain facility operations is critical to minimize or avoid disruptions to patient care and patient safety activities in such facilities. Consistent with these examples, the Department believes that small and rural health care providers are also viewed as potential targets by cybercriminals, and such providers need to implement strong cybersecurity measures to secure the ePHI in their possession. In fact, in June 2024, the Administration announced a collaboration with the private sector to provide additional cybersecurity resources for rural health care providers in recognition of the importance of protecting the security of ePHI created, received, maintained, or transmitted by such entities.
                        <SU>312</SU>
                        <FTREF/>
                         We believe this collaboration will provide small and rural health care providers with additional support, particularly when coupled with other resources described in greater detail below.
                        <SU>313</SU>
                        <FTREF/>
                         Thus, we believe that small and rural health care providers have both the need to comply with the proposals in this NPRM and the capability of doing so. Additionally, we believe that the NPRM would continue to provide all regulated entities, including small and rural health care providers, the ability to take into account their circumstances when determining which security measures are reasonable and appropriate.
                        <SU>314</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>306</SU>
                             
                            <E T="03">See, e.g.,</E>
                             “Fact Sheet: Biden-Harris Administration Bolsters Protections for Americans' Access to Healthcare Through Strengthening Cybersecurity,” The White House (June 10, 2024), 
                            <E T="03">https://www.whitehouse.gov/briefing-room/statements-releases/2024/06/10/fact-sheet-biden-harris-administration-bolsters-protections-for-americans-access-to-healthcare-through-strengthening-cybersecurity/;</E>
                             “How Do Ransomware Attacks Impact Rural Hospitals?,” National Institute for Health Care Management Foundation, p. 1 (2024), 
                            <E T="03">https://nihcm.org/assets/articles/FINAL-NIHCM-RI-Hannah-Neprash_2024-08-01-132728_ushq.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>307</SU>
                             “How Do Ransomware Attacks Impact Rural Hospitals?” 
                            <E T="03">supra</E>
                             note 306, p. 2.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>308</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>309</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>310</SU>
                             Kevin Collier, “An Illinois hospital is the first health care facility to link its closing to a ransomware attack,” NBC News (June 12, 2023), 
                            <E T="03">https://www.nbcnews.com/tech/security/illinois-hospital-links-closure-ransomware-attack-rcna85983.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>311</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>312</SU>
                             “Fact Sheet: Biden-Harris Administration Bolsters Protections for Americans' Access to Healthcare Through Strengthening Cybersecurity,” 
                            <E T="03">supra</E>
                             note 306.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>313</SU>
                             
                            <E T="03">See, e.g.,</E>
                             “Free Cybersecurity Services and Tools,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security, 
                            <E T="03">https://www.cisa.gov/resources-tools/resources/free-cybersecurity-services-and-tools;</E>
                             “Cyber Hygiene Services,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security, 
                            <E T="03">https://www.cisa.gov/cyber-hygiene-services;</E>
                             “Cybersecurity Resources for High-Risk Communities,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security, 
                            <E T="03">https://www.cisa.gov/audiences/high-risk-communities/cybersecurity-resources-high-risk-communities.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>314</SU>
                             
                            <E T="03">See, e.g.,</E>
                             45 CFR 164.306.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">5. A Strengthened Security Rule Is Critical to an Efficient and Effective Health Care System</HD>
                    <P>
                        While the Security Rule generally continues to accomplish a primary goal of HIPAA,
                        <SU>315</SU>
                        <FTREF/>
                         the Department believes that it is essential to propose modifications to strengthen its protections for the confidentiality, integrity, and availability of ePHI to address the changing health care environment. We also believe it is important to clarify the obligations of regulated entities and emphasize the importance of protecting the confidentiality, integrity, and availability of ePHI. We believe that the proposed revisions would require regulated entities to consider and potentially modify their safeguards more regularly, which would better enable them to quickly respond to changes in the environment and be consistent with cybersecurity best practices. While we do not expect that compliance with the Security Rule will 
                        <PRTPAGE P="920"/>
                        prevent all breaches or interruptions in the confidentiality, integrity, or availability of ePHI, we believe that it will prevent many and enable regulated entities to identify, mitigate, and remediate the damage more quickly if there is a breach or other security incident, thereby reducing harm to individuals and the overall costs of such occurrences to regulated entities and to the U.S. health care system. As such, the proposed modifications would support a primary goal of HIPAA's Administrative Simplification provisions: improving the efficiency and effectiveness of the U.S. health care system by encouraging the development of health information systems through the establishment of uniform standards and requirements for electronic transmission of ePHI, including those for security.
                        <SU>316</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>315</SU>
                             
                            <E T="03">See</E>
                             sec. 261 of Pub. L. 104-191, 110 Stat. 2021 (Aug. 21, 1996), as amended by sec. 1104(a) of Pub. L. 111-148, 124 Stat. 146 (Mar. 23, 2010) (codified at 42 U.S.C. 1320d note).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>316</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD2">E. The Secretary Must Develop Standards for the Security of ePHI Because None Have Been Developed by an ANSI-Accredited Standard Setting Organization</HD>
                    <P>
                        HIPAA requires the Secretary to adopt standards that have been developed, adopted, or modified by a standard setting organization accredited by ANSI, except in certain circumstances.
                        <SU>317</SU>
                        <FTREF/>
                         For example, HIPAA permits the Secretary to develop standards where no relevant standards have been developed, adopted, or modified by an ANSI-accredited standard setting organization. In developing, adopting, or modifying a standard, the Secretary is required to consult with standard setting organizations, NCVHS, and with the appropriate Federal and State agencies.
                        <SU>318</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>317</SU>
                             42 U.S.C. 1320d-1(c)(1) and (2).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>318</SU>
                             42 U.S.C. 1320d-1(c)(2)(B).
                        </P>
                    </FTNT>
                    <P>
                        The statutory definition of the term “standard” applies only to standards for electronic transactions and data elements for such transactions that are appropriate for: (1) the financial and administrative transactions described in the statute; and (2) other financial and administrative transactions consistent with the goals of improving the operation of the health care system and reducing administrative costs, as determined appropriate by the Secretary.
                        <SU>319</SU>
                        <FTREF/>
                         Under HIPAA, security is not considered a financial or administrative transaction, or a data element of such transaction.
                        <SU>320</SU>
                        <FTREF/>
                         In the “Health Insurance Reform: Standards for Electronic Transactions” final rule in 2000, we explicitly adopted a broader definition of “standard” because we recognized that the statutory definition only applied to standards for financial and administrative transactions, despite the statute's requirement that the Secretary adopt standards addressing other matters, including privacy and security.
                        <SU>321</SU>
                        <FTREF/>
                         At that time, we explained that we adopted a broader definition of standard to accommodate the varying functions of the specific standards proposed in other HIPAA regulations.
                        <SU>322</SU>
                        <FTREF/>
                         For the same reason, we believe that it is appropriate to continue to rely on the regulatory definition of standard.
                        <SU>323</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>319</SU>
                             
                            <E T="03">See</E>
                             42 U.S.C. 1320d(7) (definition of “Standard”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>320</SU>
                             
                            <E T="03">See</E>
                             42 U.S.C. 1320d-2(a)(1).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>321</SU>
                             65 FR 50312, 50320 (Aug. 17, 2000); 
                            <E T="03">see also</E>
                             42 U.S.C. 1320d-2(b), (c), and (d); sec. 264(c) of HIPAA.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>322</SU>
                             65 FR 50312, 50320 (Aug. 17, 2000).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>323</SU>
                             45 CFR 160.103 (definition of “Standard”).
                        </P>
                    </FTNT>
                    <P>
                        As discussed above, in both 1998 and 2003, the Department determined that no comprehensive, scalable, and technology-neutral set of standards exists, and accordingly, we proposed and adopted a new standard.
                        <SU>324</SU>
                        <FTREF/>
                         In 2013, we made only minor modifications to the standards when we complied with explicit directions from Congress to apply the requirements of the Security Rule to business associates, so we did not need to consider whether an ANSI-accredited standard setting organization had adopted a comprehensive set of standards on the security for ePHI that was flexible, scalable, and technology-neutral.
                        <SU>325</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>324</SU>
                             63 FR 43242, 43249 (Aug. 12, 1998); 68 FR 8334, 8341 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>325</SU>
                             78 FR 5566, 5589-91, 5693-95 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <P>
                        However, because we believe it is appropriate for us to consider modifying the Security Rule at this time for the reasons discussed above, we must again consider whether an ANSI-accredited standards setting organization has developed, adopted, or modified a standard relating to the security of ePHI. The Department continues to believe that any standard must be comprehensive, rather than piecemeal, as recommended by the ANSI Healthcare Informatics Standards Board.
                        <SU>326</SU>
                        <FTREF/>
                         We also continue to agree with the recommendation that the standards should be technology-neutral because security technology continues to evolve to keep pace with the evolution of technology more broadly. Additionally, the Security Rule must remain flexible and scalable to allow for consideration of the wide variety of regulated entities, enabling such entities to determine the reasonable and appropriate security measures for their circumstances by taking into account the factors specified by HIPAA.
                        <SU>327</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>326</SU>
                             63 FR 43249 (Aug. 12, 1998); 68 FR 8341 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>327</SU>
                             42 U.S.C. 1320d-2(d)(1)(A).
                        </P>
                    </FTNT>
                    <P>
                        We are not aware of any standard setting organizations that are accredited by ANSI that have issued standards for the security of ePHI, let alone standards that are sufficiently comprehensive, flexible, scalable, and technology-neutral to enable regulated entities to take into account the HIPAA factors. For example, NIST has issued numerous publications addressing health care cybersecurity that are considered by NIST to be guidance, rather than standards. In fact, NIST is ANSI-accredited for only one standard.
                        <SU>328</SU>
                        <FTREF/>
                         And with the exception of publications that analyze the Security Rule, NIST's guidance does not specifically address the security of ePHI. CISA has issued cross-sector CPGs, but it is not ANSI-accredited. There may be other organizations that have set standards for the transmission of particular information, such as the secure transmission of images, but adopting such individual standards would not meet the Department's criteria. In this case, adoption of such standard would be far too granular and require the Department to revise the Security Rule at the same interval as the particular standard, which may be irregular. Additionally, given that the Department is limited to modifying each standard or implementation specification no more frequently than once every 12 months, this approach would be inefficient and could lead to a requirement that the Department update the Security Rule more than once a year, depending on when such individual standards or implementation specifications are revised. Even modifying the standards annually would require a significant investment of Department resources, not to mention the investment required of regulated entities to comply with an ever-changing set of requirements.
                    </P>
                    <FTNT>
                        <P>
                            <SU>328</SU>
                             “ANSI/NIST-ITL Standard,” National Institute of Standards and Technology, U.S. Department of Commerce (Feb. 3, 2023), 
                            <E T="03">https://www.nist.gov/programs-projects/ansinist-itl-standard.</E>
                        </P>
                    </FTNT>
                    <P>
                        Additionally, in 2021, Congress amended the HITECH Act to require the Secretary to consider whether a regulated entity has adequately demonstrated that it had in place recognized security practices for a certain period of time.
                        <SU>329</SU>
                        <FTREF/>
                         Congress defined “recognized security practices” to include certain NIST publications; the approaches promulgated under 
                        <PRTPAGE P="921"/>
                        section 405(d) of the Cybersecurity Act of 2015; “and other programs and processes that address cybersecurity and that are developed, recognized, or promulgated through regulations under other statutory authorities.” 
                        <SU>330</SU>
                        <FTREF/>
                         However, the HITECH Act amendment did not require the Secretary to accept a regulated entity's implementation of recognized security practices as an alternative to compliance with the Security Rule, nor did it provide that such implementation was sufficient to meet the security objectives of HIPAA or the HITECH Act. Accordingly, it is appropriate for the Department to develop and adopt its own standards to meet the statutory objective of ensuring the security of ePHI. The standards and implementation specifications proposed herein take into consideration not only those promulgated by NIST, but also guidelines, best practices, methodologies, processes, and procedures published by CISA, the HHS 405(d) program, CMS, State governments, and others. The proposals also enable regulated entities to adopt security measures that ensure the confidentiality, integrity, and availability of ePHI; protect against any reasonably anticipated threats or hazards to the security or integrity of ePHI and unauthorized uses or disclosures of such ePHI; ensure compliance with the Security Rule by the workforce members of regulated entities, while also taking into account the technical capabilities of record systems used to maintain ePHI; the costs of such measures; the need for training users who have access to ePHI; the value of audit trails in computerized record systems; and the needs and capabilities of small and rural health care providers.
                    </P>
                    <FTNT>
                        <P>
                            <SU>329</SU>
                             
                            <E T="03">See</E>
                             section 13412(a) of the HITECH Act, as amended by section 1 of Public Law 116-321, 134 Stat. 5072 (Jan. 5, 2021) (codified at 42 U.S.C. 17941(a)(1)).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>330</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        The Department has consulted with and relied on the recommendations of NCVHS in the formulation of this proposed rule 
                        <SU>331</SU>
                        <FTREF/>
                         and intends to continue to engage in these consultations before finalizing the rule.
                        <SU>332</SU>
                        <FTREF/>
                         We also expect to consult with the National Uniform Billing Committee, the National Uniform Claim Committee, the Workgroup for Electronic Data Interchange, and the American Dental Association before finalizing this rule, as required by section 1172(c)(3)(A)(ii) of HIPAA.
                        <SU>333</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>331</SU>
                             
                            <E T="03">See</E>
                             Letter from NCVHS Chair Jacki Monson (2022), 
                            <E T="03">supra</E>
                             note 123; Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>332</SU>
                             42 U.S.C. 1320d-1(f).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>333</SU>
                             42 U.S.C. 1320d-1(c)(3)(A)(ii).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD1">IV. Section-by-Section Description of the Proposed Amendments to the Security Rule</HD>
                    <P>This section contains a description of the proposed amendments to the Security Rule and the Department's rationale for its proposals. As part of this rationale, we often include a discussion of best practices contained in previously published guidance documents issued by the Department, NIST, and other Federal agencies. We request comment on previously published guidance documents that are not discussed herein that were issued by the Department or other Federal agencies and contain best practices but may be relevant or applicable to regulated entities, including the names of and citations for such guidance documents. We do not propose to adopt referenced best practices as the standard or implementation specifications unless otherwise specified in the proposed regulatory text. Rather, we include such discussion to provide regulated entities with context for the aforementioned proposals. We recognize that regulated entities are of varying types and sizes and may be concerned that requiring the adoption of such best practices might not be appropriate for all. However, we request comment on whether we should require implementation of certain aspects of a particular guidance document. If so, please explain which aspect(s) we should require, the rationale, and information about the burden of implementing such aspect(s).</P>
                    <HD SOURCE="HD2">A. Section 160.103—Definitions</HD>
                    <HD SOURCE="HD3">1. Current Provision</HD>
                    <P>
                        Electronic media are used by many health care organizations to process, transmit, and maintain ePHI. As defined by the Security Rule, the term “electronic media” 
                        <SU>334</SU>
                        <FTREF/>
                         encompasses both (1) electronic storage material on which data is or may be electronically recorded; and (2) transmission media used to exchange information already in electronic storage media. It specifically excludes certain transmissions, such as those of paper, via facsimile (“fax”), and voice, via telephone, from being considered transmissions via electronic media if the information being exchanged did not exist in electronic form immediately before the transmission.
                    </P>
                    <FTNT>
                        <P>
                            <SU>334</SU>
                             45 CFR 160.103 (definition of “Electronic media”).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">2. Issues To Address</HD>
                    <P>
                        The Department revised the definition of “electronic media” in 2013 by replacing the term “electronic storage media” with “electronic storage material” in recognition that there may be storage material other than “media” that houses electronic data in the future.
                        <SU>335</SU>
                        <FTREF/>
                         At that time, the Department said that a fax machine accepting a hardcopy document for transmission is not a covered transmission even though the document may have originated from printing from an electronic file.
                        <SU>336</SU>
                        <FTREF/>
                         In response to commenter concerns, we also clarified that ePHI maintained, intentionally or otherwise, in a photocopier, fax machine, or other device is subject to the Security Rule and reminded regulated entities that they should be aware of the capabilities of such devices with respect to their ability to maintain ePHI.
                        <SU>337</SU>
                        <FTREF/>
                         Additionally, a regulated entity should consider the appropriateness of implementing security measures that account for such capabilities.
                        <SU>338</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>335</SU>
                             78 FR 5566 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>336</SU>
                             
                            <E T="03">Id.</E>
                             at 5576.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>337</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>338</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Since 2013, the role technology plays in the storage and transmission of information has changed, as have the types of media used to store and transmit such information. For example, traditional landlines 
                        <SU>339</SU>
                        <FTREF/>
                         are rapidly being replaced with electronic communication technologies, such as Voice over internet Protocol (VoIP),
                        <SU>340</SU>
                        <FTREF/>
                         and mobile technologies that use electronic media, such as the internet, intra- and extranets, cellular, and Wi-Fi.
                        <SU>341</SU>
                        <FTREF/>
                         Some current electronic technologies that regulated entities use for remote communications may include communication applications on a smartphone or another computing device, VoIP technologies, technologies that electronically record or transcribe a telehealth session, and messaging services that electronically store audio messages. The definition of electronic media does not account for these changes because it excepts 
                        <PRTPAGE P="922"/>
                        transmissions via fax, and of voice, via telephone, from transmissions via electronic media, nor does the definition take into consideration new and emerging technologies. Accordingly, the Department believes that it is appropriate to reconsider this definition.
                    </P>
                    <FTNT>
                        <P>
                            <SU>339</SU>
                             A standard telephone line, often described as a traditional landline, uses circuit-switched voice communication service technologies through the Public Switched Telephone Network. The information transmitted through such traditional telephones is not electronic.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>340</SU>
                             VoIP technologies convert audio into a digital signal that is then transmitted over the internet. 
                            <E T="03">See</E>
                             Voice Over internet Protocol (VoIP), Federal Communications Commission, 
                            <E T="03">https://www.fcc.gov/general/voice-over-internet-protocol-voip.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>341</SU>
                             A 2022 report by the Federal Communications Commission stated that the “number of fixed retail switched-access lines declined over the past three years at a compound annual rate of 12.3%, while interconnected VoIP subscriptions increased at a compound annual growth rate of 0.7%.” 
                            <E T="03">See</E>
                             “2022 COMMUNICATIONS MARKETPLACE REPORT,” Federal Communications Commission, p. 122 (Dec. 30, 2022), 
                            <E T="03">https://docs.fcc.gov/public/attachments/FCC-22-103A1.pdf.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">3. Proposals</HD>
                    <P>The Department proposes to modify the definition of “electronic media” as follows. First, the Department proposes to revise paragraph (1) of the definition to clarify that electronic media includes not only media on which data may be recorded, but also media on which data may be maintained or processed.</P>
                    <P>
                        Generally, data is either at rest, in transit, or in process (
                        <E T="03">e.g.,</E>
                         being worked on, in use, being modified in memory, or being updated).
                        <SU>342</SU>
                        <FTREF/>
                         After the data is no longer in use, it is either maintained or transmitted. It is especially important for entities to protect data in process because generally, data must be unencrypted to be processed, making this a time when it is particularly vulnerable to a breach or other security incident.
                        <SU>343</SU>
                        <FTREF/>
                         To that end, the Department's proposal would clarify that the definition includes electronic media that is used to record, maintain, or process data.
                    </P>
                    <FTNT>
                        <P>
                            <SU>342</SU>
                             
                            <E T="03">See</E>
                             “NIST Privacy Framework: A Tool for Improving Privacy Through Enterprise Risk Management, Version 1.0,” National Institute of Standards and Technology, U.S. Department of Commerce, p. 29 (Jan. 16, 2020) (see definition of “data processing”), 
                            <E T="03">https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.01162020.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>343</SU>
                             
                            <E T="03">See</E>
                             Maithilee Joshi, et al., “Delegated Authorization Framework for EHR Services Using Attribute-Based Encryption,” IEEE Transactions on Services Computing, Volume 14, No. 6, p. 1 (2021) (discussing that health care providers are increasingly using Cloud-based EHR services to manage ePHI, which increases the possibility of attacks on ePHI), 
                            <E T="03">https://ebiquity.umbc.edu/get/a/publication/1126.pdf; see also</E>
                             “Security Standards: Technical Safeguards,” HIPAA Security Series, Office for Civil Rights, U.S. Department of Health and Human Services, (May 2005, revised Mar. 2007) (The goal of encryption is to protect ePHI from being accessed and viewed by unauthorized users.), 
                            <E T="03">https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/administrative/securityrule/techsafeguards.pdf?language=es.</E>
                        </P>
                    </FTNT>
                    <P>The Department also proposes to revise paragraph (1) to clarify and update terminology used in a non-exhaustive list of examples of electronic storage material. Additionally, to ensure that the definition includes future technology, the Department proposes to add to the list of examples “any other form of digital memory or storage” on which data may be recorded, maintained, or processed.</P>
                    <P>
                        As discussed above, traditional landlines and fax machines are rapidly being replaced with electronic communication technologies and mobile technologies that use electronic media. The Security Rule applies when a regulated entity uses such electronic communication technologies. Therefore, regulated entities using telephone systems and fax equipment that transmit ePHI need to apply the Security Rule safeguards to those technologies.
                        <SU>344</SU>
                        <FTREF/>
                         Accordingly, in paragraph (2), we propose to revise the description of “transmission media” to recognize that data is transmitted almost exclusively in electronic form today. The limited exception to this would be data that is handwritten on paper and hand-delivered or mailed, such that the data is never on electronic storage material. Additionally, the Department proposes to include public networks in the examples of transmission media and to remove the sentence that describes transmissions that are not considered transmissions via electronic media. By making these changes, we would reflect technology's evolution since 2013.
                    </P>
                    <FTNT>
                        <P>
                            <SU>344</SU>
                             The Department previously acknowledged that information transmitted by a telephone voice response system in response to a telephone request, and some voice technology digitally produced from an information system and transmitted by telephone are both covered by this definition. See 68 FR 8334, 8342 (Feb. 20, 2003); 75 FR 40868, 40874 (July 14, 2010); and 78 FR 5566, 5575 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <P>
                        We also propose to make a technical correction to paragraph (2) of the definition, consistent with a revision made in the 2013 Omnibus Rule to paragraph (1).
                        <SU>345</SU>
                        <FTREF/>
                         Specifically, the Department proposes to replace the term “electronic storage media” with “electronic storage material” in paragraph (2) to clarify the connection between definitions of electronic storage material and transmission media. We neglected to make this change in 2013 when we replaced “electronic storage media” with “electronic storage material” in paragraph (1), which means that paragraph (2) relies on a term that is no longer defined. This technical correction we propose is consistent with how the Department has interpreted the definition of transmission media and the connection between it and electronic storage material since the change was made in 2013.
                    </P>
                    <FTNT>
                        <P>
                            <SU>345</SU>
                             78 FR 5566, 5575-5576 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">4. Request for Comment</HD>
                    <P>The Department requests comment on the foregoing proposals, including any benefits, drawbacks, or unintended consequences. We also request comment on the following considerations in particular:</P>
                    <P>a. Whether the proposed modifications accurately capture current use of electronic media.</P>
                    <P>b. Whether the proposed modifications allow for future technological innovation.</P>
                    <P>c. Whether there are other types of electronic storage material that the Department should include in the non-exhaustive list of examples.</P>
                    <P>d. Whether there are other types of transmission media that the Department should include in the non-exhaustive list of examples.</P>
                    <HD SOURCE="HD2">B. Section 164.304—Definitions</HD>
                    <P>Section 164.304 includes definitions for key regulatory terms in the Security Rule. The Department proposes to add ten new defined terms and to modify the definitions of fifteen existing terms. The proposed new regulatory terms would be: Deploy, Implement, Electronic information system, Multi-factor authentication, Relevant electronic information system, Risk, Technical controls, Technology asset, Threat, and Vulnerability. The definitions we propose to modify are for the following terms: Access, Administrative safeguards, Authentication, Availability, Confidentiality, Information system, Malicious software, Password, Physical safeguards, Security or Security measures, Security incident, Technical safeguards, User, and Workstation. Generally, the Department is proposing to add or modify regulatory terms that would either clarify how regulated entities should apply the standards and implementation specifications or modernize the rule to better account for changes in the environment in which health care is provided.</P>
                    <HD SOURCE="HD3">1. Clarifying the Definition of “Access”</HD>
                    <HD SOURCE="HD3">a. Current Provision and Issues To Address</HD>
                    <P>
                        The Security Rule defines the term “access” as the ability or means necessary to perform a set of activities describing how a user may interact with a system resource.
                        <SU>346</SU>
                        <FTREF/>
                         These activities are reading, writing, modifying, communicating data/information, or otherwise using any component of an information system. The definition applies only to the Security Rule, not to the Breach Notification Rule or the Privacy Rule.
                    </P>
                    <FTNT>
                        <P>
                            <SU>346</SU>
                             45 CFR 164.304 (definition of “Access”).
                        </P>
                    </FTNT>
                    <P>
                        The term “access” defines the scope of some key regulatory provisions in the Security Rule. For example, whether a person meets the definition of a “user” is determined based on whether their access to information or a component of the regulated entity's information system is authorized.
                        <SU>347</SU>
                        <FTREF/>
                         The definition 
                        <PRTPAGE P="923"/>
                        of the term “security incident” requires consideration of whether a person attempted to access or accessed information without authorization.
                        <SU>348</SU>
                        <FTREF/>
                         To determine whether a regulated entity complied with the administrative safeguard standard for workforce security, the Department must consider to what extent a regulated entity established policies and procedures for ensuring that workforce members have appropriate access to ePHI.
                        <SU>349</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>347</SU>
                             45 CFR 164.304 (definition of “User”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>348</SU>
                             45 CFR 164.304 (definition of “Security incident”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>349</SU>
                             45 CFR 164.308(a)(3)(i); proposed 45 CFR 164.308(a)(9)(i).
                        </P>
                    </FTNT>
                    <P>The current definition is expansive but not fully representative of how users could interact with information today. As discussed above, users create, receive, maintain, and transmit information in more ways now than they did ten years ago. Thus, the Department believes that it is critical for the Department to consider modifying the definition of this term to adequately reflect the current electronic environment.</P>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>The Department proposes to expand the list of activities that should be considered under the term by adding the activities of “deleting” and “transmitting.” The Department also proposes to replace “system resource” with “component of an information system” to rely on an already defined term, “information system.” The proposed modification would clarify that the term includes any and all components of an information system and an information system as a whole. Additionally, the Department believes that a component of an information system better describes how the term access applies today because it is inclusive of hardware, software, and people, as opposed to only the inherent capabilities that contribute to performance, such as system memory and hard disk space.</P>
                    <HD SOURCE="HD3">2. Clarifying the Definition of “Administrative Safeguards”</HD>
                    <HD SOURCE="HD3">a. Current Provision and Issues To Address</HD>
                    <P>
                        Administrative safeguards are administrative actions, policies, and procedures to manage the selection, development, implementation, and maintenance (including reviewing and modifying) of security measures to protect ePHI.
                        <SU>350</SU>
                        <FTREF/>
                         Administrative safeguards also manage the conduct of the regulated entity's workforce in relation to the protection of ePHI. Under the Security Rule, there are minor inconsistencies in language between the definitions of the types of safeguards, which might lead to uncertainty about how to interpret the terms and lead to unintended consequences. For example, the definitions of “administrative safeguards” and “physical safeguards” use “are,” while the definition of technical safeguards uses “means.” 
                        <SU>351</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>350</SU>
                             45 CFR 164.304 (definition of “Administrative safeguards”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>351</SU>
                             45 CFR 164.304 (definitions of “Administrative safeguards,” “Physical safeguards,” and “Technical safeguards”).
                        </P>
                    </FTNT>
                    <P>In addition, the existing definition of “administrative safeguards” does not expressly relate the administrative actions to the policies and procedures addressing the activities covered by the definition, nor does it make clear that the policies and procedures are in addition to the administrative actions. The same is true for the definitions of physical and technical safeguards. Further, the definition of “administrative safeguards” does not expressly mention managing updates and modifications to safeguards.</P>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>To address the minor inconsistencies between the definitions of the safeguards and to ensure that each safeguard is afforded an equal weight of importance, the Department proposes similar but minor changes across the definitions. The Department proposes to add the word “related” to the definition here, and below to add the words “and related” when necessary, to more clearly connect the components that make up safeguards. In the case of administrative safeguards, the Department's proposal relates administrative actions to administrative policies and procedures. The Department believes that this change would reduce confusion and improve clarity about compliance obligations. We are proposing a similar change to the definitions of physical safeguards and technical safeguards below. Additionally, we are proposing to clarify that maintenance includes updating and modifying with respect to administrative safeguards.</P>
                    <HD SOURCE="HD3">3. Clarifying the Definition of “Authentication”</HD>
                    <HD SOURCE="HD3">a. Current Provision and Issues To Address</HD>
                    <P>
                        The Security Rule defines authentication as corroboration that a person is the one claimed. By limiting the definition of authentication to persons, the current definition neglects to acknowledge the importance to the security of ePHI of authenticating technology assets that are components of a regulated entity's electronic information systems that create, receive, maintain, or transmit ePHI or that otherwise affect the confidentiality, integrity, or availability of ePHI, or that the regulated entity intends to connect to such electronic information systems.
                        <SU>352</SU>
                        <FTREF/>
                         Absent such authentication, a bad actor could add technology assets (
                        <E T="03">e.g.,</E>
                         software) to a regulated entity's electronic information systems that enable the bad actor to compromise the security of ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>352</SU>
                             
                            <E T="03">See also</E>
                             Special Publication 800-82r3, Guide to Operational Technology Security, National Institute of Standards and Technology, section 6.2.1, p. 97, Identity Management and Access Control (PR.AC) (discussing the need of organizations to apply authentication controls for users, devices, and processes within the technology environment) (September 2023).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>To modernize the definition of authentication to reflect best practices in cybersecurity today, the Department proposes to clarify the definition to mean corroboration that either a person or technology asset is the one they are claiming to be. The modified definition would also improve readability with minor changes in wording. The Department believes as proposed, the revised definition would more accurately reflect the role played by technology assets in electronic information systems today. For example, a covered health care provider permits individuals to access their own PHI using an application that connects to the software that runs the covered health care provider's patient portal. Not only must the individual be authenticated as a user, but the application must be authenticated such that the covered entity's software can verify that the application is what it claims to be. In another example, a portable technology asset for retrieving and storing PHI in the cloud must be authenticated before retrieving data from cloud storage.</P>
                    <HD SOURCE="HD3">4. Clarifying the Definition of “Availability”</HD>
                    <HD SOURCE="HD3">a. Current Provision and Issues To Address</HD>
                    <P>
                        “Availability” is defined in the Security Rule as the property that data or information is accessible and usable upon demand by an authorized person. Although not intended, the current definition could be read to limit the scope of availability only to authorized persons. And yet, it is equally important to ensure that authorized technology assets, such as connected medical devices, software, and workstations, 
                        <PRTPAGE P="924"/>
                        have access on demand to ePHI to carry out their functions.
                    </P>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>Given the increased connectivity of the health care environment, the Department proposes to clarify the definition of availability by specifying that availability means the property that data or information is accessible and usable upon demand by not only an authorized person, but also an authorized technology asset. In so doing, the Department is not changing the meaning of availability, but rather clarifying its scope.</P>
                    <HD SOURCE="HD3">5. Clarifying the Definition of “Confidentiality”</HD>
                    <HD SOURCE="HD3">a. Current Provision and Issues To Address</HD>
                    <P>Similar to the definition of availability, the definition of the term “confidentiality” could be read as limited to the property that data or information is not made available or disclosed to unauthorized persons or processes. Read that way, the definition does not reflect today's health care environment in which data and information may be accessed through any component of an interconnected electronic information system.</P>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>The Department proposes to clarify the definition of confidentiality to specify that it means the property that data or information is not made available or disclosed to unauthorized persons, technology assets, or processes.</P>
                    <HD SOURCE="HD3">6. Adding Definitions of “Deploy” and “Implement”</HD>
                    <HD SOURCE="HD3">a. Issues To Address</HD>
                    <P>
                        The Security Rule directs regulated entities to implement technical policies and procedures and assumes that such implementation requires the installation and configuration of technical safeguards.
                        <SU>353</SU>
                        <FTREF/>
                         OCR is concerned, based on its investigations and compliance reviews, that some regulated entities may interpret the regulatory requirement to implement technical policies and procedures to mean that a regulated entity is only required to establish written policies and procedures about technical requirements, but need not then apply effective, automated technical policies and procedures to all ePHI throughout the regulated entity's enterprise. For example, in 
                        <E T="03">M.D. Anderson,</E>
                         the court stated that the encryption requirement at 45 CFR 164.312(a)(2)(iv) requiring a regulated entity to implement a mechanism to encrypt ePHI does not “require a covered entity to warrant that its mechanism provides bulletproof protection of `all systems containing ePHI.' Nor does it require covered entities to warrant that all ePHI is always and everywhere `inaccessible to unauthorized users.' ” 
                        <SU>354</SU>
                        <FTREF/>
                         Further, the court added that the requirement does not “say anything about how effective a mechanism must be, how universally it must be enforced, or how impervious to human error or hacker malfeasance it must be.” 
                        <SU>355</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>353</SU>
                             While the Department also regulates “adoption and meaningful use of certified EHR technology,” such as the actions of the end-user with respect to having and meaningfully using certified health IT to meet certain requirements, such as those requirements for the Promoting Interoperability performance category of the Merit-based Incentive Payment System (MIPS) (sections 1848(q)(2)(B)(iv) and 1848(o)(2) of the SSA), the definitions proposed in this NPRM would apply only to regulated entities' compliance with the Security Rule.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>354</SU>
                             
                            <E T="03">University of Texas M.D. Anderson Cancer Center, supra</E>
                             note 258, p. 478.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>355</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>Therefore, the Department believes it is necessary to add definitions that distinguish between implementation of the administrative and technical safeguards by separately describing how regulated entities can comply with requirements to implement technical safeguards and install technical solutions.</P>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>The Department proposes to define the term “deploy” to identify a specific type of “implementation.” We believe that the new term and definition would help to better describe the compliance obligations for implementation specifications related to the use of technology for securing the confidentiality, integrity, or availability of ePHI. As proposed, the definition would require a regulated entity to ensure that technology is in place, configured for use, and actually in use and operational throughout the regulated entity. The Department's proposed use of the term helps illustrate its purpose and utility in clarifying that policies and procedures, while necessary, are insufficient to meet requirements for technical safeguards.</P>
                    <P>
                        For example, the Department is proposing to create a new requirement for regulated entities to verify that business associates have deployed technical safeguards—that is, the technology is configured and operational, not only addressed in policies and procedures.
                        <SU>356</SU>
                        <FTREF/>
                         In another example, the Department is proposing new implementation specifications under the access control standard that would require a regulated entity to deploy technical controls for relevant electronic information systems so that the system is configured and applied to limit access to only users and technology assets that have been granted access rights.
                        <SU>357</SU>
                        <FTREF/>
                         In the automatic logoff implementation specification for that same standard, the Department is proposing to replace the requirement to implement electronic procedures for terminating an electronic session with a requirement to deploy technical controls that terminate an electronic session after a period of inactivity.
                        <SU>358</SU>
                        <FTREF/>
                         In each case, the technical controls must not only be configured for use, but they also must be applied to and in effect in all ePHI and relevant electronic information systems.
                    </P>
                    <FTNT>
                        <P>
                            <SU>356</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(b)(1)(i) and (ii) and (b)(2)(ii).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>357</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.312(a)(1).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>358</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.312(a)(2)(iv).
                        </P>
                    </FTNT>
                    <P>
                        The Department proposes to define the term “implement” to clarify that a safeguard must be put into place and be in effect throughout the enterprise, as opposed to only some components of a regulated entity's relevant information systems (
                        <E T="03">e.g.,</E>
                         some laptops or servers) or applied to a subset of ePHI. The Department also proposes the term to further clarify what it means to configure and put technology, technical controls, and related policies and procedures into effect and be in use, operational, and function as expected throughout the regulated entity's enterprise (
                        <E T="03">i.e.,</E>
                         deploy) as compared to putting into place and making effective administrative or physical safeguards. Further, the Department proposes to expressly clarify that implement also means that a safeguard must function as expected. Under this proposal, if adopted, we would not consider a safeguard to be implemented if it is not functioning in the manner in which it is expected.
                    </P>
                    <P>For example, a regulated entity's administrative policy requiring it to take action to prevent infections from malicious software is not implemented until it is applied throughout the enterprise, meaning that the entity has ensured that anti-malware protections have been put into place on all relevant electronic information systems that create, receive, maintain, or transmit ePHI or that otherwise affect the confidentiality, integrity, or availability of ePHI throughout the enterprise.</P>
                    <P>
                        Similarly, to operationalize such a policy, the regulated entity must deploy technology assets and/or technical controls to block such software according to its technical policies and 
                        <PRTPAGE P="925"/>
                        procedures. In this regard, the proposed term “deploy” clarifies that the technology assets or technical control must be put into place, configured, and actually work (
                        <E T="03">i.e.,</E>
                         function in the manner expected of the technology or technical control) throughout a regulated entity, in addition to the relevant policy and procedures being applied across a regulated entity. To implement a policy and procedure is separate from the implementation of a technology asset or technical control but in both cases, the underlying requirement is application across the enterprise.
                    </P>
                    <HD SOURCE="HD3">7. Adding a Definition of “Electronic Information System”</HD>
                    <HD SOURCE="HD3">a. Issues To Address</HD>
                    <P>
                        The current Security Rule includes explicit requirements for regulated entities to protect electronic information systems by implementing policies and procedures to limit physical access to such systems 
                        <SU>359</SU>
                        <FTREF/>
                         and by implementing technical policies and procedures for electronic information systems that maintain ePHI to allow access to only persons or technology assets that have been granted access rights pursuant to 45 CFR 164.308(a)(4).
                        <SU>360</SU>
                        <FTREF/>
                         Further, the physical measures, policies, and procedures that meet the definition of physical safeguards are specifically limited to those that protect regulated entities' electronic information systems and related buildings and equipment.
                        <SU>361</SU>
                        <FTREF/>
                         And yet, the Security Rule does not explicitly define this term. Instead, it assumes that the definition is easily understood to be a subset of information system, a broad term that is not limited by the boundaries of the Security Rule. The Department believes that regulated entities would benefit from additional clarity regarding the definition of this term, given its foundational nature.
                    </P>
                    <FTNT>
                        <P>
                            <SU>359</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.310(a)(1).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>360</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.312(a)(1).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>361</SU>
                             45 CFR 164.304 (definition of “Physical safeguards”).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>The Department proposes to add a definition of “electronic information system” to better distinguish the concept from the broader category of an information system. Accordingly, the Department would limit the definition to an interconnected set of electronic information resources under the same direct management control that shares common functionality. Under this proposal, an electronic information system generally would include technology assets, such as hardware, software, electronic media, data, and information.</P>
                    <HD SOURCE="HD3">8. Modifying the Definition of “Information System”</HD>
                    <HD SOURCE="HD3">a. Current Provision and Issues To Address</HD>
                    <P>As discussed above, the Department seeks to clarify the scope of an information system, as compared to an electronic information system. We believe that it would be beneficial to align the common elements of these terms and clarify the relationship between them, given their importance to compliance with requirements of the Security Rule. Additionally, the changes in the environment, such as the shift to cloud-based computing, may raise questions regarding the Department's interpretation of “direct management control.”</P>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>Accordingly, the Department proposes to modify the definition of “information system,” to clarify that an information system “generally”, not just “normally,” includes hardware, software, data, communications, and people. The Department believes this proposed modification, combined with the existing broad reference to “resources,” more accurately reflects the typical components of an information system and the full extent of resources that are addressed by the Security Rule. We also propose to remove “applications” from the list of technology assets that are generally included in an information system because applications are a type of software, making the inclusion of applications redundant. This proposed modification would not alter our interpretation that an information system includes applications.</P>
                    <P>We use this opportunity to affirm that a technology asset may be included as part of the information systems of multiple regulated entities where such regulated entities all have direct management control over the technology asset. For example, both a health care provider and a cloud-based EHR vendor have direct management control over the ePHI in the cloud-based EHR. Accordingly, such ePHI generally is part of both the information system of the health care provider and of the cloud-based EHR vendor. Additionally, the EHR that is used to create, receive, maintain, or transmit ePHI, regardless of whether it is accessed using software installed on the health care provider's workstation(s) or an internet browser, generally is also part of the information system of both entities because both the health care provider and the vendor have direct management control over the EHR.</P>
                    <HD SOURCE="HD3">9. Modifying the Definition of “Malicious software”</HD>
                    <HD SOURCE="HD3">a. Current Provision and Issues To Address</HD>
                    <P>Persons seeking unauthorized access to data and information are increasingly sophisticated. Their methods of attempting to gain such access can take many forms and result in a wide array of harms, as discussed above. One of the methods they use is through the introduction of malicious software (also referred to as malware) into an electronic information system. As the sophistication of bad actors has increased, so has the variety of types of malicious software that they use to access electronic information systems. The Security Rule defines malicious software but limits it to software designed to damage or disrupt a system. The regulatory text provides only one example of malicious software in regulatory text—a virus.</P>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>
                        The Department proposes to replace the current definition of malicious software with one that would be consistent with how cybersecurity experts define the term today.
                        <SU>362</SU>
                        <FTREF/>
                         Specifically, we propose to define it to mean software or firmware intended to perform an unauthorized action or activity that will have adverse impact on an electronic information system and/or the confidentiality, integrity, or availability of electronic protected health information. This proposal would therefore clarify that malicious software could include either software or firmware and that the negative effects of the malicious software may not be limited to damaging or disrupting a system. Rather, effects of the software could be intended to have any type of adverse impact on an electronic information system and/or the confidentiality, integrity, or availability of ePHI. The Department also proposes to include in regulatory text a non-exhaustive list of examples, such as viruses, worms, Trojan horses, spyware, and some forms of adware, to assist regulated entities in understanding what constitutes malicious software.
                    </P>
                    <FTNT>
                        <P>
                            <SU>362</SU>
                             
                            <E T="03">See</E>
                             NIST definition of “malware,” Glossary, Computer Security Resource Center, National Institute for Standards and Technology, U.S. Department of Commerce, 
                            <E T="03">https://csrc.nist.gov/glossary/term/malware.</E>
                        </P>
                    </FTNT>
                    <PRTPAGE P="926"/>
                    <HD SOURCE="HD3">10. Adding a Definition of “Multi-Factor Authentication” (MFA)</HD>
                    <HD SOURCE="HD3">a. Issues To Address</HD>
                    <P>The Security Rule includes several technical safeguard provisions that require regulated entities to identify and authenticate persons accessing information and systems to protect ePHI. Section 164.312(a)(2)(1) includes the standard that requires a regulated entity to implement technical policies and procedures that limit access to ePHI to only those persons or software programs that have been granted access rights, while 45 CFR 164.312(d)(2), the standard for person or entity authentication, requires a regulated entity to implement procedures to verify that a person seeking access to ePHI is the one claimed.</P>
                    <P>
                        Historically, regulated entities relied on combinations of usernames and passwords to identify users and authenticate users to the system. We recognize that such combinations are insufficient to secure sensitive information and that more sophisticated mechanisms for doing so have been developed. As a best practice for managing cyber threats, most cybersecurity frameworks, including those discussed above, recommend that organizations adopt solutions that rely on multiple factors to identify and authenticate users. For example, the HHS 405(d) Program's “Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients” 
                        <SU>363</SU>
                        <FTREF/>
                         recommends a layered approach to cyber defense (
                        <E T="03">i.e.,</E>
                         if a first layer is breached, a second exists to prevent a complete breach).
                        <SU>364</SU>
                        <FTREF/>
                         It further provides that MFA as a source of identity and access security control is an important means to control access to infrastructure and conduct proper change management control.
                        <SU>365</SU>
                        <FTREF/>
                         The Department's CPGs 
                        <SU>366</SU>
                        <FTREF/>
                         identify MFA as an essential goal and a critical, additional layer of security for the protection of assets and accounts that are directly accessible from the internet.
                        <SU>367</SU>
                        <FTREF/>
                         The Department has also explained in guidance that weak authentication processes leave organizations vulnerable to intrusion, while effective authentication ensures that only authorized entities may access information systems and data.
                        <SU>368</SU>
                        <FTREF/>
                         Additionally, CISA has issued recommendations for implementing MFA, specifically MFA solutions that are phishing resistant to protect against disclosures of authentication data to a bad actor.
                        <SU>369</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>363</SU>
                             “Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients,” 
                            <E T="03">supra</E>
                             note 16.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>364</SU>
                             
                            <E T="03">Id.</E>
                             at 15.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>365</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>366</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>367</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>368</SU>
                             
                            <E T="03">See</E>
                             “HIPAA and Cybersecurity Authentication,” Cybersecurity Newsletter, Office for Civil Rights, U.S. Department of Health and Human Services (June 2023), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity-newsletter-june-2023/index.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>369</SU>
                             
                            <E T="03">Id.</E>
                             (citing “Implementing Phishing-Resistant MFA,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security (Oct. 2022), 
                            <E T="03">https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf</E>
                            ); NIST also has issued draft defined characteristics for phishing-resistant authenticators. 
                            <E T="03">See</E>
                             David Temoshok, et al., “Digital Identity Guidelines,” NIST Special Publication 800-63-4 2pd (Second Public Draft), National Institute of Standards and Technology, U.S. Department of Commerce, p. 36 (Aug. 21, 2024), 
                            <E T="03">https://csrc.nist.gov/pubs/sp/800/63/4/2pd.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>
                        The Department proposes to define the term “Multi-factor authentication” to provide regulated entities with a specific level of authentication for accessing relevant electronic information systems.
                        <SU>370</SU>
                        <FTREF/>
                         Regulated entities would be required to apply this proposed definition when implementing the proposed rule's specific requirements for authenticating users' identities through verification of at least two of three categories of factors of information about the user. The proposed categories would be:
                    </P>
                    <FTNT>
                        <P>
                            <SU>370</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.312(f)(2)(ii).
                        </P>
                    </FTNT>
                    <P>• Information known by the user, including but not limited to a password or personal identification number (PIN).</P>
                    <P>• Item possessed by the user, including but not limited to a token or a smart identification card.</P>
                    <P>• Personal characteristic of the user, including but not limited to fingerprint, facial recognition, gait, typing cadence, or other biometric or behavioral characteristics.</P>
                    <P>
                        MFA relies on the user presenting at least two factors. Authentication that relies on multiple instances of the same factor, such as requiring a password and PIN, is not MFA because both factors are “something you know.” 
                        <SU>371</SU>
                        <FTREF/>
                         For example, where MFA is deployed, users could seek access by entering a password. However, without the entry of at least a second factor such as a token 
                        <SU>372</SU>
                        <FTREF/>
                         or smart identification card, the user is not granted access and the password is useless by itself. Cybercriminals seeking access to MFA-protected information systems require significantly more resources to launch the attack because there are multiple data points required to succeed.
                        <SU>373</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>371</SU>
                             
                            <E T="03">See</E>
                             “HIPAA and Cybersecurity Authentication,” 
                            <E T="03">supra</E>
                             note 368 (citing David Temoshok, et al., “Digital Identity Guidelines,” NIST Special Publication 800-63-4 (Initial Public Draft), National Institute of Standards and Technology, U.S. Department of Commerce, p. 17 (Dec. 2022), 
                            <E T="03">https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63-4.ipd.pdf</E>
                            ).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>372</SU>
                             NIST defines “token” as “a portable, user-controlled, physical device (
                            <E T="03">e.g.,</E>
                             smart card or memory stick) used to store cryptographic information and possibly also perform cryptographic functions.” 
                            <E T="03">See</E>
                             NIST definition of “token,” Glossary, Computer Security Resource Center, National Institute of Standards and Technology, U.S. Department of Commerce (citing Elaine Barker, et al., “Recommendation for Key Management: Part 2—Best Practices for Key Management Organizations,” NIST Special Publication 800-57, Part 2, Revision 1, National Institute of Standards and Technology, U.S. Department of Commerce (May 2019)), 
                            <E T="03">https://csrc.nist.gov/glossary/term/token#:~:text=NIST%20SP%20800%2D63%2D3%20under%20Token,possibly%20also%20perform%20cryptographic%20functions.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>373</SU>
                             Letter from NCVHS Chair Jacki Monson (2022), 
                            <E T="03">supra</E>
                             note 123, p. 7.
                        </P>
                    </FTNT>
                    <P>
                        The Department proposes that the personal characteristics that could be used as factors would include both physical characteristics, such as fingerprints or facial identifiers, and behavioral characteristics, such as a user's gait or typing cadence.
                        <SU>374</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>374</SU>
                             
                            <E T="03">See</E>
                             “Digital Identity Guidelines: Authentication and Lifecycle Management”, NIST Special Publication 800-63B, National Institute of Standard and Technology, section 5.3.3, Use of Biometrics, (Oct. 16, 2023), 
                            <E T="03">https://pages.nist.gov/800-63-3/sp800-63b.html#sec5.</E>
                             We recognize that some of the example characteristics may not satisfy today's standards; however, the Department anticipates that they may in the future and proposes that they be included as examples such that regulated entities will be permitted to use them when the relevant standards are updated to allow for such use.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">11. Clarifying the Definition of “Password”</HD>
                    <HD SOURCE="HD3">a. Current Provision and Issues To Address</HD>
                    <P>
                        The Security Rule currently defines “password” as confidential authentication information composed of a string of characters.
                        <SU>375</SU>
                        <FTREF/>
                         The definition provides no further regulatory instruction on what constitutes a “character” for purpose of compliance.
                    </P>
                    <FTNT>
                        <P>
                            <SU>375</SU>
                             45 CFR 164.304 (definition of “Password”).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>
                        The Department proposes to add examples to the definition to further clarify what constitutes a character, and adds “such as letters, numbers, spaces, and other symbols” to the existing definition. The Department believes that regulatory examples would provide necessary context for regulated entities that deploy safeguards involving passwords.
                        <PRTPAGE P="927"/>
                    </P>
                    <HD SOURCE="HD3">12. Clarifying the Definition of “Physical Safeguards”</HD>
                    <HD SOURCE="HD3">a. Current Provision and Issues To Address</HD>
                    <P>“Physical safeguards” encompass the physical measures, policies, and procedures that protect a regulated entity's electronic information systems and related buildings and equipment from natural and environmental hazards, and unauthorized intrusion. As discussed within the definition of administrative safeguards, the Department believes that it is necessary to reduce minor inconsistences in language between the definitions of the types of safeguards. Additionally, the definition of physical safeguards relies on an undefined term (“buildings”), despite the existence of a defined term (“facilities”) that has an equivalent meaning.</P>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>
                        The Department proposes to clarify that the policies and procedures referred to in the definition are those that specifically are related to physical measures, and to replace “buildings” with “facilities” because facility is a defined term under the Security Rule and has an equivalent meaning.
                        <SU>376</SU>
                        <FTREF/>
                         The Department intends and has always intended the physical safeguards to apply to any location where a regulated entity might possess ePHI, including the physical premises and interior and exterior of a building, and any location that might affect the confidentiality, integrity, or availability of ePHI. Additionally, given the mobility of technology today, including workstations that may access ePHI, we believe it would be more appropriate to use the term facility to make clear that the physical safeguards are to apply throughout the premises of the regulated entity. For the same reasons discussed above, we also propose to clarify that the physical safeguards serve to protect relevant electronic information systems, as we propose to define the term elsewhere in this NPRM, rather than all electronic information systems. Further, the Department proposes to better standardize the administrative, physical, and technical safeguard requirements by using defined terms where they exist.
                    </P>
                    <FTNT>
                        <P>
                            <SU>376</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.304 (definition of “Facility”).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">13. Adding a Definition of “Relevant Electronic Information System”</HD>
                    <HD SOURCE="HD3">a. Issues To Address</HD>
                    <P>
                        The Security Rule requires a regulated entity to ensure the confidentiality, integrity, and availability of all of the ePHI it creates, receives, maintains, or transmits.
                        <SU>377</SU>
                        <FTREF/>
                         To protect the ePHI as required, a regulated entity must also protect the electronic information systems that create, receive, maintain, or transmit ePHI and the electronic information systems that otherwise affect the confidentiality, integrity, or availability of ePHI. The Department believes that regulated entities are not consistently protecting ePHI in a manner that is consistent with their Security Rule obligations and believes that it is necessary to clarify the scope of those obligations. We believe that creating a new defined term for the electronic information systems to which the Security Rule requirements apply will help achieve this goal by ensuring that regulated entities fully understand how their technology assets and the architecture of their electronic information systems affect the confidentiality, integrity, and availability of ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>377</SU>
                             45 CFR 164.306.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>The Department proposes to add and define the term “relevant electronic information system” to mean an electronic information system that creates, receives, maintains, or transmits ePHI or that otherwise affects the confidentiality, integrity, or availability of ePHI. We believe that distinguishing between a relevant electronic information system and an electronic information system, as proposed, would further clarify the scope of regulated entities' compliance obligations, including the obligation of regulated entities to understand the relationship between their various electronic information systems and the confidentiality, integrity, and availability of ePHI.</P>
                    <P>
                        The Department believes it is important to clarify that the requirements of the Security Rule do not only apply to electronic information systems that create, receive, maintain, or transmit ePHI. After all, cybercriminals may be able to access ePHI by leveraging vulnerabilities in some electronic information systems that do not themselves create, receive, maintain, or transmit ePHI where such information systems are connected to or otherwise affect electronic information systems that do create, receive, maintain, or transmit ePHI. For example, while a payment processing system used in a covered entity's food and beverage outlets or gift shops may not create, receive, maintain, or transmit ePHI, it may affect the confidentiality, integrity, or availability of ePHI in certain circumstances, such as where such systems are connected to the same network as servers that contain ePHI.
                        <SU>378</SU>
                        <FTREF/>
                         Accordingly, we would interpret an electronic information system as otherwise affecting the confidentiality, integrity, or availability of ePHI if it is insufficiently segregated physically and electronically from an electronic information system that creates, receives, maintains, or transmits ePHI or one that otherwise affects the confidentiality, integrity, or availability of ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>378</SU>
                             
                            <E T="03">See, e.g.,</E>
                             Steve Alder, “$8.9 Million Banner Health Data Breach Settlement Gets Final Approval,” The HIPAA Journal (Apr. 27, 2020), 
                            <E T="03">https://www.hipaajournal.com/8-9-million-banner-health-data-breach-settlement-gets-final-approval/</E>
                            (describing a settlement to cover claims stemming from an attack on a health system's payment processing system used in the food and beverage outlets of its hospitals).
                        </P>
                    </FTNT>
                    <P>
                        An electronic information system would also fit the category of “otherwise affecting” if it contains information that relates to an electronic information system that creates, receives, maintains, or transmits ePHI or to another electronic information system that otherwise affects the confidentiality, integrity, or availability of ePHI. For example, a compromised electronic information system used to provide administrative functions, such as user authentication or management of storage area network infrastructure, that does not contain ePHI may allow unauthorized access to ePHI (affecting the confidentiality of ePHI) or disruption of storage configuration data (affecting the integrity and availability of ePHI). An electronic information system that is not connected to a covered health care provider's EHR but that maintains user IDs and passwords for the EHR also may not create, receive, maintain, or transmit ePHI; however, the confidentiality, integrity, or availability of the ePHI in the EHR would be affected if an unauthorized person gained access to that electronic information system. And the same is true for an electronic information system that contains the decryption keys for a regulated entity's encryption algorithms. Thus, it is important that administrative, physical, and technical safeguards be implemented not only for electronic information systems that create, receive, maintain, or transmit ePHI, but also for electronic information systems that otherwise affect the confidentiality, integrity, or availability of ePHI.
                        <PRTPAGE P="928"/>
                    </P>
                    <HD SOURCE="HD3">14. Adding a Definition of “Risk”</HD>
                    <HD SOURCE="HD3">a. Issues To Address</HD>
                    <P>
                        The Security Rule does not currently include a definition for the term “risk.” The Department considered defining it when it first promulgated the final rule in 2003, but declined to do so because it determined that the term was commonly understood.
                        <SU>379</SU>
                        <FTREF/>
                         However, the Department now believes that the lack of a definition may affect the clarity of some key requirements for regulated entities. Such requirements include conducting a risk analysis to assess the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the regulated entity 
                        <SU>380</SU>
                        <FTREF/>
                         and implementing security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with the general rules at 45 CFR 164.306(a).
                        <SU>381</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>379</SU>
                             63 FR 8334, 8340 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>380</SU>
                             45 CFR 164.308(a)(1)(i)(A).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>381</SU>
                             45 CFR 164.308(a)(1)(i)(B). Section 164.306(a) requires regulated entities to comply with four general requirements to protect ePHI.
                        </P>
                    </FTNT>
                    <P>
                        One of the ways NIST defines the term is as “a measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.” 
                        <SU>382</SU>
                        <FTREF/>
                         This and other NIST definitions serve as helpful references for the Department when considering how to define the term within the rule.
                    </P>
                    <FTNT>
                        <P>
                            <SU>382</SU>
                             
                            <E T="03">See</E>
                             NIST definition of “risk,” Glossary, Computer Security Resource Center, National Institute of Standards and Technology, U.S. Department of Commerce (citing William Newhouse, et al., “Multifactor Authentication for E-Commerce,” NIST Special Publication 1800-17, National Institute of Standards and Technology, U.S. Department of Commerce (July 2019)), 
                            <E T="03">https://csrc.nist.gov/glossary/term/risk.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>
                        The Department proposes to define “risk” as the extent to which the confidentiality, integrity, or availability of ePHI is threatened by a potential circumstance or event. The Department believes that defining the term would clarify several existing and proposed provisions of the Security Rule, such as the factors regulated entities must consider when determining the security measures they will implement 
                        <SU>383</SU>
                        <FTREF/>
                         and the importance and purpose of conducting the required risk analysis.
                        <SU>384</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>383</SU>
                             45 CFR 164.304(b)(2)(iv).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>384</SU>
                             45 CFR 164.308(a)(1)(ii)(A); proposed 45 CFR 164.308(a)(2)(i).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">15. Clarifying the Definitions of “Security or Security Measures” and “Security Incident”</HD>
                    <HD SOURCE="HD3">a. Current Provision and Issues To Address</HD>
                    <P>
                        The Security Rule defines “security or security measures” as encompassing all of the administrative, physical, and technical safeguards in an information system.
                        <SU>385</SU>
                        <FTREF/>
                         The definition implies that the safeguards must be part of the information system, as opposed to something that may be applied or done to a system to protect the confidentiality, integrity, and availability of ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>385</SU>
                             45 CFR 164.304 (definition of “Security or Security measures”).
                        </P>
                    </FTNT>
                    <P>The rule also defines “security incident” as the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. The existing definition does not make clear that a security incident may result from two types of behaviors—those related to attempted or successful but unauthorized access, use, disclosure, modification, or destruction of information in an information system, and those that are related to the attempted or successful unauthorized interference with system operations in an information system. In other words, a security incident may directly touch upon information in a system or interfere with the operations of the system itself. The Department believes that it is necessary to clearly convey the distinct types of incidents to regulated entities to ensure that regulated entities implement and deploy safeguards that address both concerns.</P>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>
                        The Department proposes to modify the definition of “security or security measures” to clarify that security or security measures may not only exist in information systems but may also be applied to information systems.
                        <SU>386</SU>
                        <FTREF/>
                         This clarification would better reflect the multi-layered approach to cybersecurity recommended by experts to address the concerns facing regulated entities today. For example, a regulated entity may determine that it is necessary to apply access controls and encryption mechanisms through an external mechanism, such as added firewall technology,
                        <SU>387</SU>
                        <FTREF/>
                         that is applied to the system, rather than technical controls that are embedded within the system or components of the system. The Department believes that the proposed definition would provide a more complete instruction.
                    </P>
                    <FTNT>
                        <P>
                            <SU>386</SU>
                             45 CFR 164.304 (definition of “Security or Security measures”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>387</SU>
                             
                            <E T="03">See</E>
                             NIST definition of “firewall,” Glossary, Computer Security Resource Center, National Institute of Standards and Technology, U.S. Department of Commerce, 
                            <E T="03">https://csrc.nist.gov/glossary/term/firewall.</E>
                        </P>
                    </FTNT>
                    <P>The Department proposes to reorganize the definition of “security incident” into two numbered paragraphs to delineate the two separate categories of security incidents. We also propose to clarify that in both instances, the definition applies when the described action affects an information system and regardless of whether an attempt to affect the information in the system or interfere with system operations is successful or not.</P>
                    <HD SOURCE="HD3">16. Adding Definitions of “Technical Controls”</HD>
                    <HD SOURCE="HD3">a. Issues To Address</HD>
                    <P>
                        Throughout the technical safeguards provisions in 45 CFR 164.312, the Department directs regulated entities to implement technical policies and procedures. The court in 
                        <E T="03">M.D. Anderson</E>
                         interpreted technical policies and procedures as written policies and procedures on technical matters.
                        <SU>388</SU>
                        <FTREF/>
                         This interpretation does not reflect the Department's intent for technical safeguards to include policies and procedures that rely on technology or technological solutions for implementation.
                        <SU>389</SU>
                        <FTREF/>
                         We believe that the court's interpretation could have significant consequences for the confidentiality, integrity, and availability of ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>388</SU>
                             
                            <E T="03">See generally University of Texas M.D. Anderson Cancer Center, supra</E>
                             note 258, p. 478.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>389</SU>
                             For example, in the 2003 Final Rule, we explained that in developing technical safeguards, the Department proposed technical security services requirements and specific technical security mechanisms with implementation specifications without carving out or limiting these items to policies and procedures about the requirements. 
                            <E T="03">See</E>
                             68 FR 8334, 8354 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>
                        The Department proposes to add and define the term “technical controls” to help regulated entities better understand what we mean by technical safeguards for purposes of complying with the Security Rule. We propose to define technical controls as technical mechanisms contained in the hardware, software, or firmware components of an electronic information system that are primarily implemented and executed by the electronic information system to protect it and the data within the electronic information system. The Department believes that adding this term would better convey the expectation that a regulated entity is 
                        <PRTPAGE P="929"/>
                        required to deploy technical safeguards across its enterprise by, among other things, configuring and using technical mechanisms in the hardware, software, and firmware components of its relevant electronic information systems to protect ePHI and electronic information systems that create, receive, maintain, or transmit ePHI or that otherwise affect the confidentiality, availability, or integrity of ePHI.
                    </P>
                    <HD SOURCE="HD3">17. Modifying the Definition of “Technical Safeguards”</HD>
                    <HD SOURCE="HD3">a. Current Provision and Issues To Address</HD>
                    <P>
                        The current definition of “technical safeguards” includes the technology and policy and procedures for its use that protect ePHI and control access to it.
                        <SU>390</SU>
                        <FTREF/>
                         As discussed above, the Department believes that there is an immediate need to modernize and update the definition to better reflect the role technology plays in protecting ePHI and the technical components of information systems, versus the role of policies and procedures. This would complement our effort to clarify the relationship between technology and the implementation of technical policies and procedures.
                    </P>
                    <FTNT>
                        <P>
                            <SU>390</SU>
                             45 CFR 164.304 (definition of “Technical safeguards”).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>The Department proposes to modify the definition of “technical safeguards” to expressly include “technical controls.” We also propose to add language that would clarify that the technology, technical controls, and related policies and procedures in this category govern the use of the technology to protect and control access to ePHI. The proposed changes also would improve the consistency of language across the safeguard provisions and rule.</P>
                    <HD SOURCE="HD3">18. Adding a Definition of “Technology Asset”</HD>
                    <HD SOURCE="HD3">a. Issues To Address</HD>
                    <P>Throughout the Security Rule, standards and implementation specifications list the components of electronic information systems to which its requirements apply. Based on the Department's enforcement experience, we believe that it would be beneficial to more clearly distinguish between the requirements that apply to all components of an electronic information system and those that only apply to certain components. Additionally, we believe it would be beneficial to distinguish between requirements that apply specifically to each particular component of an electronic information system and those that apply to the electronic information system as a whole.</P>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>The Department proposes to define the term “technology asset” to mean the components of an electronic information system, including but not limited to hardware, software, electronic media, information, and data. In so doing, we would clarify which Security Rule requirements apply to all of the components of electronic information systems as opposed to those that apply only to certain components, and which requirements apply to each particular components and which apply to the entire electronic information system.</P>
                    <P>For example, understanding the risks and vulnerabilities to a regulated entity's ePHI requires a thorough understanding of the components of its electronic information systems, the electronic information systems themselves, how they are connected, and how ePHI moves through those systems. Thus, by requiring a regulated entity to conduct an inventory of its technology assets and to create a network map of its electronic information systems, we clarify that a regulated entity is obligated to consider not only its electronic information systems as a whole, but also the components within those electronic information systems and their functions.</P>
                    <HD SOURCE="HD3">19. Adding a Definition of “Threat”</HD>
                    <HD SOURCE="HD3">a. Issues To Address</HD>
                    <P>
                        Addressing threats to the confidentiality, integrity, and availability of ePHI is a key function of the Security Rule, but the rule does not define “threat.” The concept of threat also underlies the Department's proposed definition of “risk” defined above and forms the basis of a key proposed implementation specification associated with the standard for risk analysis.
                        <SU>391</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>391</SU>
                             Proposed 45 CFR164.308(a)(2)(ii)(A)(
                            <E T="03">2</E>
                            ).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>
                        The Department proposes to define the term “threat” to mean any circumstance or event with the potential to adversely affect the confidentiality, integrity, or availability of ePHI. This proposal is similar to NIST's varying definitions of threat, edited to apply specifically to health care and the type of information addressed by the Security Rule.
                        <SU>392</SU>
                        <FTREF/>
                         Under this proposal, we would construe the term to apply broadly to include threats caused by, or existing because of, a variety of circumstances that specifically could affect the security of ePHI. Hackers, malicious insiders, and malicious software are examples of threat sources.
                    </P>
                    <FTNT>
                        <P>
                            <SU>392</SU>
                             
                            <E T="03">See</E>
                             NIST definition of “threat,” Glossary, Computer Security Resource Center, National Institute of Standards and Technology, U.S. Department of Commerce, 
                            <E T="03">https://csrc.nist.gov/glossary/term/threat.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">20. Clarifying the Definition of “User”</HD>
                    <HD SOURCE="HD3">a. Current Provision and Issues To Address</HD>
                    <P>
                        The Department first defined the term “person” in the HIPAA Rules as part of the 2003 “Civil Money Penalties: Procedures for Investigations, Imposition of Penalties, and Hearings” interim final rule to distinguish a “natural person” who could testify in the context of administrative proceedings from an “entity” (defined therein as a “legal person”) on whose behalf a person would testify.
                        <SU>393</SU>
                        <FTREF/>
                         Although they were both published in 2003, the interim final rule was published two months after the Security Rule. Thus, when the Security Rule was published in 2003, it was necessary to specify that the term “user” included both natural persons and entities, but we believe that this is no longer the case because the current definition of “person” includes natural persons as well as entities.
                        <SU>394</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>393</SU>
                             
                            <E T="03">See</E>
                             45 CFR 160.502 of the 2003 interim final rule, 68 FR 18895, 18898 (Apr. 17, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>394</SU>
                             45 CFR 160.103 (definition of “Person”).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>
                        The Department proposes to clarify the definition of “User” by removing the reference to an entity.
                        <SU>395</SU>
                        <FTREF/>
                         Because the definition of “person” includes an entity, including entity in the definition of “user” is redundant and could cause confusion. We believe that this is a technical correction because it would not change how the Department has interpreted the term.
                    </P>
                    <FTNT>
                        <P>
                            <SU>395</SU>
                             45 CFR 164.304 (definition of “User”).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">21. Adding a Definition of “Vulnerability”</HD>
                    <HD SOURCE="HD3">a. Issues To Address</HD>
                    <P>The term “vulnerability” is currently not defined in the Security Rule.</P>
                    <P>
                        The Department previously explained that although some cyberattacks may be sophisticated and exploit previously unknown vulnerabilities (
                        <E T="03">i.e.,</E>
                         zero-day attacks), most can be prevented or mitigated by addressing known vulnerabilities.
                        <SU>396</SU>
                        <FTREF/>
                         For example, 
                        <PRTPAGE P="930"/>
                        exploitable vulnerabilities exist across many components of IT infrastructures including, but not limited to, servers, desktops, mobile device operating systems, web software, and firewalls.
                        <SU>397</SU>
                        <FTREF/>
                         To mitigate against intrusions and hacking threats, the Department has recommended that regulated entities install vendor patches, make software updates, and monitor sources of cybersecurity alerts describing new vulnerabilities, such as the NIST National Vulnerability Database 
                        <SU>398</SU>
                        <FTREF/>
                         and CISA's Known Exploited Vulnerabilities Catalog.
                        <SU>399</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>396</SU>
                             
                            <E T="03">See</E>
                             “Defending Against Common Cyber-Attacks,” Cybersecurity Newsletter, Office for Civil Rights, U.S. Department of Health and Human 
                            <PRTPAGE/>
                            Services (Mar. 2022), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity-newsletter-first-quarter-2022/index.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>397</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>398</SU>
                             
                            <E T="03">Id.;</E>
                             The National Vulnerability Database is the U.S. government repository of standards-based vulnerability management data. 
                            <E T="03">See</E>
                             “National Vulnerability Database,” National Institute of Standards and Technology, U.S. Department of Commerce, 
                            <E T="03">https://nvd.nist.gov.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>399</SU>
                             “Known Exploited Vulnerabilities Catalog,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security, 
                            <E T="03">https://www.cisa.gov/known-exploited-vulnerabilities-catalog.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>
                        The Department proposes to define vulnerability by adopting substantially the same definition as NIST (a “weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source”) 
                        <SU>400</SU>
                        <FTREF/>
                         with minor changes to clarify how it applies to regulated entities and ePHI. The definition, if adopted as proposed, would then form the basis for understanding key assessment and mitigation strategies proposed in this NPRM, such as risk analyses,
                        <SU>401</SU>
                        <FTREF/>
                         patch management,
                        <SU>402</SU>
                        <FTREF/>
                         and vulnerability management and scans.
                        <SU>403</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>400</SU>
                             
                            <E T="03">See</E>
                             NIST definition of “vulnerability,” Glossary, Computer Security Resource Center, National Institute of Standards and Technology, U.S. Department of Commerce, 
                            <E T="03">https://csrc.nist.gov/glossary/term/vulnerability.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>401</SU>
                             Proposed 45 CFR 164.308(a)(2)(ii)(A)(
                            <E T="03">7</E>
                            ).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>402</SU>
                             Proposed 45 CFR 164.308(a)(4)(i).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>403</SU>
                             Proposed 45 CFR 164.312(h)(1).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">22. Clarifying the Definition of “Workstation”</HD>
                    <HD SOURCE="HD3">a. Current Provision and Issues To Address</HD>
                    <P>
                        The Department currently defines the term “workstation” to mean an electronic computing device and provides the examples of technology that dominated the health care environment in 2003 and 2013, such as a laptop, desktop computer, and other device that performs similar functions, and electronic media stored in its immediate environment.
                        <SU>404</SU>
                        <FTREF/>
                         Workstations are essential for workforce members to perform their assigned functions, such as clinicians entering an individual's health history and treatment plan or billing staff preparing claims. Workstations are one of the key entry points for users to access a regulated entity's information systems. Thus, the Security Rule contains provisions requiring that regulated entities secure not only their information systems, but also individual workstations.
                        <SU>405</SU>
                        <FTREF/>
                         However, as discussed above, the health care environment has changed. It now includes both the physical and virtual environment and is replete with mobile devices and other types of devices that may serve as multi-functional workstations. Clinicians and other workforce members often rely on smart phones, smart watches, tablets, laptops, and even personal digital assistants, among other devices. These devices have proliferated, and so has their ability to perform a wide variety of functions with increasing sophistication. The Department believes that it is necessary to update the definition to reflect the evolved nature of the landscape.
                    </P>
                    <FTNT>
                        <P>
                            <SU>404</SU>
                             45 CFR 164.304 (definition of “Workstation”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>405</SU>
                             
                            <E T="03">See, e.g.,</E>
                             45 CFR 164.310(b) and (c).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">b. Proposal</HD>
                    <P>In recognition of this changed environment, the Department proposes to modify the definition of workstation to provide additional examples of what constitutes a workstation. Specifically, we propose to add the examples of a server, virtual device, and a mobile device such as a smart phone or tablet. Virtual devices could include a virtual medical device, virtual server, or virtual desktop computer. The proposed definition also would clarify that technology properly considered as a “workstation” is not limited to the proposed regulatory examples.</P>
                    <HD SOURCE="HD3">23. Request for Comment</HD>
                    <P>The Department requests comment on all the foregoing proposed definitions, including any benefits, drawbacks, or unintended consequences. We also request comment on the following considerations in particular:</P>
                    <P>a. Whether any of the proposed definitions would be problematic for regulated entities or result in unintended adverse consequences. If so, please explain.</P>
                    <P>b. Whether the Department should consider an alternative definition for any terms the Department proposes to define in the rule. If the answer is yes, please propose such an alternative definition and a reference or supporting rationale.</P>
                    <P>c. Whether the Department should define any additional terms within the rule. If the answer is yes, please propose such additional terms and definitions, along with any reference or supporting rationale.</P>
                    <P>d. With respect to the definitions of “information system” and “electronic information system,” the extent of a covered entity's direct management control over applications in cloud computing environments, such as a cloud-based EHR system.</P>
                    <P>e. With respect to the definitions of “information system” and “electronic information system,” the extent of a business associate's direct management control over applications in cloud computing environments, where the business associate is the cloud service provider.</P>
                    <P>f. Whether defining the term “technical controls” and adding it to the definition of “technical safeguards” would more clearly explain the requirements of 45 CFR 164.312.</P>
                    <P>g. Whether defining “implement” and “deploy” as we propose would more clearly explain the differences between what is expected of regulated entities with respect to administrative and physical safeguards and technical safeguards. To the extent that the proposals would not clarify the differences, please provide alternative solutions.</P>
                    <HD SOURCE="HD2">C. Section 164.306—Security Standards: General Rules</HD>
                    <HD SOURCE="HD3">1. Current Provisions</HD>
                    <P>
                        Section 164.306 applies to regulated entities and includes the general rules for security standards. Generally, paragraph (a) codifies HIPAA statutory requirements for safeguarding ePHI.
                        <SU>406</SU>
                        <FTREF/>
                         Under these rules, regulated entities are required to do all of the following:
                    </P>
                    <FTNT>
                        <P>
                            <SU>406</SU>
                             
                            <E T="03">See</E>
                             42 U.S.C. 1320d-2(d).
                        </P>
                    </FTNT>
                    <P>
                        • Ensure the confidentiality, integrity, and availability of all ePHI the regulated entity creates, receives, maintains, or transmits.
                        <SU>407</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>407</SU>
                             
                            <E T="03">See</E>
                             42 U.S.C. 1320d-2(d)(2)(A).
                        </P>
                    </FTNT>
                    <P>
                        • Protect against reasonably anticipated threats or hazards to the security or integrity of such information.
                        <SU>408</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>408</SU>
                             See 42 U.S.C. 1320d-2(d)(2)(B)(i).
                        </P>
                    </FTNT>
                    <P>
                        • Protect against any reasonably anticipated uses or disclosures of such information not permitted by the Privacy Rule.
                        <SU>409</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>409</SU>
                             
                            <E T="03">See</E>
                             42 U.S.C. 1320d-2(d)(2)(B)(ii).
                        </P>
                    </FTNT>
                    <P>
                        • Ensure that workforce members comply with the Security Rule.
                        <SU>410</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>410</SU>
                             
                            <E T="03">See</E>
                             42 U.S.C. 1320d-2(d)(2)(C).
                        </P>
                    </FTNT>
                    <P>
                        Paragraph (b) of this section permits regulated entities to determine the most 
                        <PRTPAGE P="931"/>
                        appropriate security measures for protecting ePHI and their information systems. Accordingly, 45 CFR 164.306(b)(1) permits regulated entities to use any security measures to reasonably and appropriately implement the standards and implementation specifications of the Security Rule, while 45 CFR 164.306(b)(2) contains the factors that regulated entities are to consider when deciding which security measures to use. This paragraph furthers the aim of HIPAA's requirement for the security standards to take into account certain factors by providing for their consideration by regulated entities.
                        <SU>411</SU>
                        <FTREF/>
                         Accordingly, 45 CFR 164.306(b)(2) directs regulated entities to take these factors into account when determining the manner in which they will comply with the security standards and implementation specifications.
                    </P>
                    <FTNT>
                        <P>
                            <SU>411</SU>
                             The factors are: (1) the technical capabilities of records systems used to maintain health information; (2) the costs of security measures; (3) the need for training; (4) the value of audit trails in computerized record systems; and (5) the needs and capabilities of small and rural health care providers. 
                            <E T="03">See</E>
                             42 U.S.C. 1320d-2(d)(1)(A)(i)-(v).
                        </P>
                    </FTNT>
                    <P>Section 164.306(c) requires regulated entities to comply with the administrative, physical, and technical safeguard standards in sections 45 CFR 164.308, 164.310, and 164.312 respectively, and with standards for organizational requirements and policies, procedures, and documentation requirements in sections 45 CFR 164.314 and 164.316. This provision is followed by paragraph (d), which explains that regulated entities are required to implement a specific implementation specification if described as “required.” If the implementation specification is described as “addressable,” regulated entities are required to implement the implementation specification if it is reasonable and appropriate to do so; or, if it is not reasonable and appropriate, document why and implement an equivalent alternative measure.</P>
                    <P>Finally, the maintenance provision at 45 CFR 164.306(e) requires regulated entities to review and modify security measures implemented under the Security Rule as needed to continue providing reasonable and appropriate protection of ePHI. It also requires regulated entities to update documentation of such security measures in accordance with the requirements for documentation at 45 CFR 164.316(b)(2)(iii).</P>
                    <HD SOURCE="HD3">2. Issues To Address</HD>
                    <P>
                        We believe that we can improve consistency in language between this section and other Security Rule provisions and better align this section with statutory terms and intent. For example, we are concerned that regulated entities are misinterpreting 45 CFR 164.306(a) to apply the requirements of the Security Rule to only some ePHI, rather than all ePHI. This interpretation could lead to inadequate protection of ePHI and relevant electronic information systems.
                        <SU>412</SU>
                        <FTREF/>
                         We also believe that consistency in language facilitates clear understanding and less ambiguity about how regulated entities must apply Security Rule standards.
                    </P>
                    <FTNT>
                        <P>
                            <SU>412</SU>
                             
                            <E T="03">See University of Texas M.D. Anderson Cancer Center, supra</E>
                             note 258, p. 478.
                        </P>
                    </FTNT>
                    <P>
                        Flexibility and scalability are among the Security Rule's defining characteristics, and we intend to preserve those elements to the extent possible. However, we believe that in this era of increased reliance on technology, more sophisticated cyber capabilities, and increasing cyberattacks, it is critical for regulated entities to implement and deploy strong security measures to protect ePHI and related information systems. We are concerned that regulated entities have focused their attention primarily on the cost of security measures, rather than considering the reasonableness and appropriateness of security measures in the context of all of the listed factors, including the probability and criticality of potential risks to ePHI.
                        <SU>413</SU>
                        <FTREF/>
                         Further, the Department believes that providing additional clarity would improve the ability of regulated entities to evaluate security measures for the protection of ePHI and the ability of a security measure to facilitate a regulated entity's recovery from emergencies and to support continued operations. With these proposed modifications, the Department seeks to ensure that regulated entities' reliance on the Security Rule's flexibility and scalability does not come at the expense of adequate security. The current regulation's framework in 45 CFR 164.306(b) lacks any express factor that would require an evaluation of the effectiveness of the security measures in supporting the resiliency of the regulated entity.
                    </P>
                    <FTNT>
                        <P>
                            <SU>413</SU>
                             68 FR 8334, 8343 (Feb. 20, 2023).
                        </P>
                    </FTNT>
                    <P>
                        The Department has explained in regulation and guidance the difference between required and addressable implementation specifications. The meaning of “required” is clear. Regarding “addressable,” we previously explained that its purpose is to provide regulated entities flexibility with respect to implementation compliance.
                        <SU>414</SU>
                        <FTREF/>
                         We also previously explained that a regulated entity must assess whether a given addressable implementation specification is a reasonable and appropriate security measure to apply within its environment, and if it is, the regulated entity must implement the addressable implementation specification.
                        <SU>415</SU>
                        <FTREF/>
                         However, the Department remains concerned that regulated entities believe that flexibility overrides the need for them to protect all ePHI and do not uniformly treat addressable implementation specifications as needing to be met if they are reasonable and appropriate. OCR's enforcement experience and interaction with regulated entities causes us to believe that “addressable” is misunderstood to be optional, leading regulated entities to choose not to adopt the implementation specification, even when it would be reasonable and appropriate for them to do so.
                        <SU>416</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>414</SU>
                             
                            <E T="03">See</E>
                             “What is the difference between addressable and required implementation specifications in the Security Rule?,” Office for Civil Rights, U.S. Department of Health and Human Services, HIPAA FAQ #2020 (Dec. 28, 2022), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/faq/2020/what-is-the-difference-between-addressable-and-required-implementation-specifications/index.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>415</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.306(d)(3); “What is the difference between addressable and required implementation specifications in the Security Rule?,” 
                            <E T="03">supra</E>
                             note 414.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>416</SU>
                             The Department has consistently attempted to dispel the notion that addressable implementation specifications are optional. 
                            <E T="03">See, e.g.,</E>
                             “Security 101 for Covered Entities,” HIPAA Security Series, Centers for Medicare &amp; Medicaid Services, p. 6 (Nov. 2004, revised Mar. 2007), 
                            <E T="03">https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/administrative/securityrule/security101.pdf?language=es; “Controlling Access to ePHI: For Whose Eyes Only?,” Cybersecurity Newsletter,</E>
                             Office for Civil Rights, U.S. Department of Health and Human Services (July 14, 2021), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity-newsletter-summer-2021/index.html; and “HIPAA Security Rule Facility Access Controls—What are they and how do you implement them?,” Cybersecurity Newsletter,</E>
                             Office for Civil Rights, U.S. Department of Health and Human Services (
                            <E T="03">Aug. 2024), https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity-newsletter-august-2024/index.html.</E>
                        </P>
                    </FTNT>
                    <P>
                        In 2022, NCVHS recommended that the Department eliminate the choice to not implement a specification or alternative, and instead require that regulated entities implement the specification or adopt a documented reasonable alternative.
                        <SU>417</SU>
                        <FTREF/>
                         According to a survey referenced by NCVHS, despite private sector and government efforts to address a changing cybersecurity landscape, the majority of health care entities have failed to maintain a comprehensive security program and 
                        <PRTPAGE P="932"/>
                        continue to neglect people and process measures necessary for a comprehensive security program.
                        <SU>418</SU>
                        <FTREF/>
                         NCVHS also pointed to a continued failure of regulated entities to develop adequate incident recovery plans and to assess their vulnerability to cyberattacks grounded in social engineering.
                        <SU>419</SU>
                        <FTREF/>
                         Finally, NCVHS opined that the current structure of the Security Rule is inadequate to protect U.S. health care infrastructure because it does not require regulated entities “to adopt the basic building blocks of good security hygiene, or a documented, reasonable alternative.” 
                        <SU>420</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>417</SU>
                             Letter from NCVHS Chair Jacki Monson (2022), 
                            <E T="03">supra</E>
                             note 123, p. 2.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>418</SU>
                             
                            <E T="03">Id.</E>
                             at Appendix p. 4.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>419</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>420</SU>
                             
                            <E T="03">Id</E>
                             at 5.
                        </P>
                    </FTNT>
                    <P>
                        We share NCVHS' concerns and believe that we must squarely confront the problem of regulated entities treating addressable implementation specifications as optional. Relatedly, we also believe that we must consider modifying the Security Rule to set an acceptable minimum level of security specifications. Circumstances have changed sufficiently since 2003 such that we now believe that good cyber hygiene requires regulated entities to implement more than the implementation specifications that we originally mandated.
                        <SU>421</SU>
                        <FTREF/>
                         Indeed, we believe that it requires compliance with all of the standards and implementation specifications we are proposing, with specific, limited exceptions.
                    </P>
                    <FTNT>
                        <P>
                            <SU>421</SU>
                             
                            <E T="03">See</E>
                             68 FR 8334, 8336 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <P>We also believe that the current maintenance requirement in 45 CFR 164.306(e) would benefit from increased specificity in light of the dramatic transformation of the health IT environment discussed above. For example, providing the frequency with which regulated entities must review and update their security measures would improve the security of ePHI and regulated entities' compliance with the Security Rule. The Security Rule's maintenance requirement would be further strengthened by requiring regulated entities to test their security measures to verify their sufficiency, and by clarifying the Department's expectations regarding documentation. Regulated entities' lack of documentation about how they implement security measures makes it difficult for them to know what security measures they have in fact implemented and to demonstrate compliance with the requirements of the Security Rule. Finally, the maintenance requirement in 45 CFR 164.306(e) is not included in or designated as a Security Rule standard, although it explicitly references the overarching documentation requirements in 45 CFR 164.316(b)(2)(iii). Thus, there is overlap between the two sections that may be causing confusion regarding the obligations of regulated entities to maintain security measures.</P>
                    <HD SOURCE="HD3">3. Proposals</HD>
                    <HD SOURCE="HD3">a. Section 164.306(a)—General Requirements</HD>
                    <P>The Department proposes to expand the introductory language to the general requirements provision at 45 CFR 164.306(a) to clarify the extent to which the general requirements apply to the obligations of regulated entities with respect to ePHI that they create, receive, maintain, or transmit.</P>
                    <P>Under the proposal, the Department would clarify that the general requirements apply to “all” ePHI. Additionally, the Department proposes to move language from paragraph (a)(1) to paragraph (a) to further emphasize that regulated entities must apply the requirements of the Security Rule to protect all of the ePHI they create, receive, maintain, or transmit. We also propose to clarify that “each” regulated entity would be required to apply the obligations in paragraphs (a)(1) through (4) to all ePHI it creates, receives, maintains, or transmits. The Department believes that this proposal would stress to regulated entities that each and every covered entity and business associate would be responsible for ensuring it meets Security Rule requirements with respect to all ePHI.</P>
                    <P>The Department believes this proposed change would also help address issues raised by current interpretations of the Security Rule that suggest that its plain wording may not require regulated entities to fully implement each security measure to protect all ePHI. Thus, the Department's proposed language would clarify that a security measure must be implemented such that it protects the security of all ePHI and all information systems that affect the confidentiality, integrity, and availability of ePHI.</P>
                    <P>
                        Additionally, the Department proposes to modify the general requirements of paragraph (a)(2) to require each regulated entity to protect against any reasonably anticipated threats or hazards to the confidentiality, integrity, or availability of all ePHI, instead of to the security or integrity of ePHI. We believe that this proposal would better align this requirement with the general requirement at 45 CFR 164.306(a)(1), and confidentiality, integrity, and availability are generally considered the three basic elements of security.
                        <SU>422</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>422</SU>
                             68 FR 8334, 8341 (Feb. 20, 2003); 
                            <E T="03">see also</E>
                             Jennifer Cawthra, et al., “Data Integrity: Identifying and Protecting Assets Against Ransomware and Other Destructive Events,” NIST Special Publication 1800-25A, National Institute of Standards and Technology, U.S. Department of Commerce, p. 1 (Dec. 2020) (“The CIA triad represents the three pillars of information security: confidentiality, integrity, and availability.”), 
                            <E T="03">https://www.nccoe.nist.gov/publication/1800-25/VolA/index.html.</E>
                        </P>
                    </FTNT>
                    <P>Additionally, the Department proposes a minor change to paragraph (a)(3) to refer specifically to ePHI, rather than using a more general term. We believe that both proposals would constitute technical revisions and that neither would alter the meaning of 45 CFR 164.306(a)(2) or (3), respectively.</P>
                    <P>Finally, the Department proposes to modify paragraph (a)(4) so that each regulated entity would be required to ensure that its workforce complies not only with the Security Rule, but also all administrative, physical, and technical safeguards implemented in accordance with this subpart.</P>
                    <P>
                        These proposals would better align the language of the general requirements in paragraph (a) of 45 CFR 164.306 with the statute 
                        <SU>423</SU>
                        <FTREF/>
                         and 45 CFR 164.530(c).
                        <SU>424</SU>
                        <FTREF/>
                         These proposals are also consistent with our proposals to revise the introductory language for each of the safeguard provisions to clarify the provisions therein would be the minimum regulated entities are to implement, 
                        <E T="03">i.e.,</E>
                         that the security measures required by the Security Rule constitute a floor of protections, not a ceiling.
                    </P>
                    <FTNT>
                        <P>
                            <SU>423</SU>
                             42 U.S.C. 1320d-2(d)(2)(A) and (C).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>424</SU>
                             Section 164.530(c) includes the Privacy Rule standard and implementation specification for safeguarding PHI. It requires covered entities to have in place appropriate administrative, physical, and technical safeguards to protect the privacy of PHI. Additionally, it requires covered entities to reasonably safeguard PHI from intentional or unintentional uses or disclosures that violate the Privacy Rule, and to limit incidental uses or disclosures made pursuant to a permissible or required use or disclosure of PHI.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">b. Section 164.306(b)—Flexibility of Approach</HD>
                    <P>
                        The Department's proposals generally retain the flexible approach described in paragraph (b). As discussed above, the Security Rule carefully balances the benefits of safeguarding against risks to security and the burdens of implementing protective measures by, for example, enabling regulated entities to take into account specified factors when determining how to implement security measures in a manner that complies with the Security Rule. To acknowledge the rapid evolution of technology and increasing threats, the Department proposes to clarify 
                        <PRTPAGE P="933"/>
                        paragraph (b)(1) to provide that regulated entities are to apply reasonable and appropriate security measures to implement the standards and implementation specifications of the Security Rule. This proposal, if adopted, would replace the existing paragraph providing for regulated entities' reasonable and appropriate implementation of standards and implementation specifications, which could be misinterpreted to mean that a regulated entity may determine that implementation itself is unreasonable or inappropriate in some circumstances. That has never been the case. Thus, the proposed modification would clarify that implementation is not optional based on whether a regulated entity believes it is reasonable and appropriate; to the contrary, a regulated entity is required to implement the standards and implementation specifications and must adopt reasonable and appropriate security measures that allow the entity to achieve such implementation. The proposed clarification would comport more precisely with the statute, which requires regulated entities to maintain “reasonable and appropriate” safeguards.
                        <SU>425</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>425</SU>
                             42 U.S.C. 1320d-2(d).
                        </P>
                    </FTNT>
                    <P>
                        The Department also proposes to add a new element to the list of factors that regulated entities must take into account when deciding whether a particular security measure (
                        <E T="03">e.g.,</E>
                         a technical control) is reasonable and appropriate for implementing a standard and its associated implementation specifications: the effectiveness of the security measure in supporting the resiliency of the regulated entity. A regulated entity would be required to consider this factor, in addition to the existing factors, for example, when choosing a specific encryption solution that allows the entity to meet the proposed requirement to encrypt ePHI, which will help prevent an unauthorized user from accessing the entity's ePHI; or when developing its security incident plan or disaster recovery plan, which will help ensure that the regulated entity can recover data or reestablish data integrity after a security incident or disaster.
                    </P>
                    <P>
                        The Department proposes at 45 CFR 164.306(b)(2)(v) to require a regulated entity to take into account how effectively its application of a particular security measure to achieve compliance with a standard and its associated implementation specifications would support its resiliency in the face of an event that adversely affects the entity. According to NIST, “information system resilience” addresses how well information systems “continue to (i) operate under adverse conditions or stress, even if in a degraded or debilitated state, while maintaining essential operational capabilities; and (ii) recover to an effective operational posture in a time frame consistent with mission needs.” 
                        <SU>426</SU>
                        <FTREF/>
                         Recently, in this era of rising cybercrime, NIST described “cyber resiliency” as “the ability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises on systems that use or are enabled by cyber resources.” 
                        <SU>427</SU>
                        <FTREF/>
                         Thus, the Department proposes to require a regulated entity to consider the ability of its implementation of a particular security measure to aid it in preventing, withstanding, and recovering from an emergency or other occurrence that affects the confidentiality, integrity, or availability of ePHI, including a successful security incident.
                    </P>
                    <FTNT>
                        <P>
                            <SU>426</SU>
                             Joint Task Force, “Managing Information Security Risk: Organization, Mission, and Information System View,” NIST Special Publication 800-39, Appendix B, National Institute of Standards and Technology, U.S. Department of Commerce, p. B-5 (Mar. 2011), 
                            <E T="03">https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>427</SU>
                             Ron Ross, et al., “Developing Cyber-Resilient Systems: A Systems Security Engineering Approach,” NIST Special Publication 800-160, Volume 2, Revision 1, National Institute of Standards and Technology, U.S. Department of Commerce, p. 1 (Dec. 2021), 
                            <E T="03">https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v2r1.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        The Department proposes this new requirement to better enable regulated entities to ensure the confidentiality, integrity, and availability of all ePHI that they create, receive, maintain, or transmit. The general rules require regulated entities to not only prevent threats and hazards to the confidentiality and integrity of ePHI, but also to ensure the availability of ePHI, even during a security incident that has the potential to severely hinder the ability of a regulated entity to provide health care or to bring it to a standstill. This new factor would require a regulated entity to consider whether a particular approach to complying with a standard and the associated implementation specifications can help it recover from an emergency or other occurrence, in addition to maintaining operations throughout the event. The Department proposes this factor to complement its proposals to strengthen the standards for security incident procedures 
                        <SU>428</SU>
                        <FTREF/>
                         and contingency planning 
                        <SU>429</SU>
                        <FTREF/>
                         and proposals for new standards for patch management 
                        <SU>430</SU>
                        <FTREF/>
                         and vulnerability management,
                        <SU>431</SU>
                        <FTREF/>
                         discussed in detail below. If finalized, these proposals would help to ensure that regulated entities put in place the necessary measures to implement these standards.
                    </P>
                    <FTNT>
                        <P>
                            <SU>428</SU>
                             Proposed 45 CFR 164.308(a)(12)(i).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>429</SU>
                             Proposed 45 CFR 164.308(a)(13)(i).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>430</SU>
                             Proposed 45 CFR 164.308(a)(4)(i).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>431</SU>
                             Proposed 45 CFR 164.312(h)(1).
                        </P>
                    </FTNT>
                    <P>The factors contemplate that regulated entities will regularly evaluate the security measures they have applied to comply with the standards and implementation specifications based on the technology available and known risks and vulnerabilities at the time of the evaluation. The Department expects that when the existing factors are considered with the factor proposed in this NPRM, a regulated entity would be required to consider whether a specific technical control has become sufficiently ubiquitous such that choosing not to adopt it would be unreasonable.</P>
                    <HD SOURCE="HD3">c. Section 164.306(c)—Standards and Implementation Specifications</HD>
                    <P>
                        To address the Department's concerns regarding the apparent misunderstanding by regulated entities of “addressable,” we propose to modify 45 CFR 164.306(c) and (d) by collapsing the separate paragraphs into one paragraph (c) to address both standards and implementation specifications and to remove the distinction between “addressable” and “required” implementation specifications. Instead, proposed paragraph (c), if adopted, would require regulated entities to comply with both the standards and implementation specifications. The Department believes that eliminating the distinction would make clear to regulated entities what has always been a requirement—that the Security Rule sets a floor for cybersecurity protections and that its flexibility is in allowing them to choose the manner in which they meet the standards and implementation specifications, not whether they meet them. The proposed change also would be consistent with NCVHS' recommendation to require regulated entities to meet certain minimum cybersecurity hygiene requirements.
                        <SU>432</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>432</SU>
                             
                            <E T="03">See</E>
                             Letter from NCVHS Chair Jacki Monson (2022), 
                            <E T="03">supra</E>
                             note 123, p. 5-10.
                        </P>
                    </FTNT>
                    <P>
                        The Department acknowledges that proposing to remove the addressability distinction is a change from the approach adopted in the 2003 Final Rule. At that time, we explained that the decision to include addressable implementation specifications was made to provide additional flexibility to 
                        <PRTPAGE P="934"/>
                        covered entities.
                        <SU>433</SU>
                        <FTREF/>
                         In this rulemaking, the Department proposes to strengthen protections and address evolving cybersecurity threats. While we acknowledge that this proposal would reduce the Security Rule's flexibility, we believe that it is necessary to do so to achieve HIPAA's purpose of an efficient and effective health care system that relies on the secure electronic exchange of ePHI. Importantly, removing the distinction between required and addressable would not eliminate all of the Security Rule's flexibility and scalability. Instead, it would simply clarify for regulated entities where the floor of protection must lie, and regulated entities must implement solutions that meet that floor, taking into consideration their needs and capabilities. For example, a small or rural health care provider must implement a solution that ensures the protection of ePHI in the manner required by the Security Rule, but the specific solution that it chooses would reflect consideration of its particular circumstances, including available resources. In some cases, a small or rural health care provider might opt to implement a cloud-based EHR or other software solution that could reduce the health care provider's need to separately invest in data storage, backup systems, and IT personnel. And in other circumstances, a small or rural health care provider might choose to contract with a third party to provide IT support, rather than hiring its own workforce members to perform such functions.
                    </P>
                    <FTNT>
                        <P>
                            <SU>433</SU>
                             
                            <E T="03">See</E>
                             68 FR 8334, 8344 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <P>The Department also proposes to delete the maintenance provision at 45 CFR 164.306(e). Instead, as discussed in greater detail below, we propose to clearly delineate maintenance implementation specifications for specific standards, when applicable. We believe this approach would clarify how maintenance requirements relate to specific security measures and would remove any ambiguity about the need for regulated entities to regularly review, test, and modify measures as reasonable and appropriate. We further discuss maintenance provisions below for each safeguard.</P>
                    <HD SOURCE="HD3">4. Request for Comment</HD>
                    <P>The Department requests comment on the foregoing proposals, including any benefits, drawbacks, or unintended consequences. We also request comment on the following considerations in particular:</P>
                    <P>a. Whether removing the distinction between required and addressable implementation specifications would result in unintended negative consequences for regulated entities. If so, please explain and provide a recommendation for how the Department should clarify how regulated entities are required to implement the security measures described in the proposed rule.</P>
                    <P>b. Whether the Department should include other factors in 45 CFR 164.306(b) for regulated entities to consider when selecting the security measures that they will implement to meet the requirements of the Security Rule. If so, please explain.</P>
                    <P>c. Whether the factor proposed by the Department at proposed 45 CFR 164.306(b)(2)(v) would help regulated entities identify reasonable and appropriate security measures.</P>
                    <P>d. Whether the Department's proposals sufficiently clarify that a regulated entity is expected to modify its security measures in response to changes in the environment in which health care is provided, including, but not limited to, the adoption of new technology, the evolution of existing technology, and the emergence of new threats.</P>
                    <P>e. Whether the proposals sufficiently take into account the needs and capabilities of small health care providers and rural health care providers, as required by the statute. If not, please explain and include a recommendation for ways that the Department could better account for such needs and capabilities while adequately ensuring the confidentiality, integrity, and availability of ePHI that they create, receive, maintain, or transmit. The recommendations should also take into consideration the effect of the actions taken by small and rural health care providers on the ePHI that is created, received, maintained, or transmitted by other regulated entities with whom small and rural health care providers interact.</P>
                    <HD SOURCE="HD2">D. Section 164.308—Administrative Safeguards</HD>
                    <P>Section 164.308 of title 45 CFR contains the administrative safeguards that a regulated entity must implement, consistent with the general requirements described in 45 CFR 164.306. All of the standards and implementation specifications found in the Administrative Safeguards section refer to administrative functions, such as policies and procedures that must be in place for the management and execution of security measures.</P>
                    <HD SOURCE="HD3">1. Current Provisions</HD>
                    <HD SOURCE="HD3">a. Section 164.308(a)</HD>
                    <P>Section 164.308(a) contains most of the standards and associated implementation specifications that are categorized as administrative safeguards. The standards for administrative safeguards are as follows:</P>
                    <P>• Security management process.</P>
                    <P>• Assigned security responsibility.</P>
                    <P>• Workforce security.</P>
                    <P>• Information access management.</P>
                    <P>• Security awareness and training.</P>
                    <P>• Security incident procedures.</P>
                    <P>• Contingency plan.</P>
                    <P>• Evaluation.</P>
                    <P>The standard for security management process at 45 CFR 164.308(a)(1)(i) requires regulated entities to implement policies and procedures to prevent, detect, contain, and correct security violations. The Security Rule directs regulated entities as to how they are to comply with the standard for security management process through four implementation specifications. Section 164.308(a)(1)(ii)(A) requires regulated entities to conduct a risk analysis that accurately and thoroughly assesses potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI they hold. The implementation specification for risk management at 45 CFR 164.308(a)(1)(ii)(B) requires regulated entities to implement measures to reduce risks and vulnerabilities, such as those identified in the risk analysis, to a reasonable and appropriate level. Under 45 CFR 164.308(a)(1)(ii)(C), regulated entities are required to apply appropriate sanctions against workforce members who fail to comply with applicable security policies and procedures, while the implementation specification for information system activity review at 45 CFR 164.308(a)(1)(ii)(D) requires regulated entities to implement procedures to regularly review information system activity records.</P>
                    <P>The standard for assigned security responsibility at 45 CFR 164.308(a)(2) requires regulated entities to identify a security official who is responsible for the development and implementation of the policies and procedures that are required by this section. There are no implementation specifications associated with this standard.</P>
                    <P>
                        Section 164.308(a)(3)(i) contains the standard for workforce security and requires regulated entities to implement policies and procedures to ensure that their workforce members have appropriate access to ePHI, which includes preventing workforce members who do not have authorized access from 
                        <PRTPAGE P="935"/>
                        obtaining it. The implementation specifications associated with this standard address the need to implement certain procedures regarding workforce member access to ePHI. Section 164.308(a)(3)(ii)(A) addresses the implementation of procedures for the authorization and/or supervision of workforce members who work with ePHI or in locations where it might be accessed. The implementation specification for workforce clearance procedure at 45 CFR 164.308(a)(3)(ii)(B) addresses the implementation of procedures to determine that a workforce member's access to ePHI is appropriate, while 45 CFR 164.308(a)(3)(ii)(C) addresses the implementation of procedures for terminating a workforce member's access to ePHI when their employment or similar arrangement ends or as required by the regulated entity's workforce clearance procedures.
                    </P>
                    <P>
                        Under 45 CFR 164.308(a)(4)(i), the standard for information access management, a regulated entity is required to implement policies and procedures for authorizing access to ePHI in a manner that is consistent with the requirements of the Privacy Rule, that is, only when such access is appropriate based on the user or recipient's role (
                        <E T="03">i.e.,</E>
                         “role-based access”). This interpretation is consistent with the Privacy Rule's standard that limits most uses and disclosures of PHI to the “minimum necessary” to accomplish the purpose of the use or disclosure.
                        <SU>434</SU>
                        <FTREF/>
                         The standard for information access management has three implementation specifications: paragraph (a)(4)(ii)(A) requires a health care clearinghouse that is part of a larger organization to implement policies and procedures to protect ePHI from unauthorized access by that organization; paragraph (a)(4)(ii)(B) addresses implementation of policies and procedures for granting access to ePHI, for example, through a workstation, program, or other mechanism; and paragraph (a)(4)(ii)(C) addresses the implementation of policies and procedures that, based on the regulated entity's access authorization policies, establish, document, review, and modify a user's right of access to a workstation, program, or other process.
                    </P>
                    <FTNT>
                        <P>
                            <SU>434</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.502(b) and 164.514(d).
                        </P>
                    </FTNT>
                    <P>Section 164.308(a)(5)(i) contains the standard for security awareness and training. This standard requires a regulated entity to implement a security awareness and training program for all workforce members, including management. There are four associated implementation specifications that address the need for regulated entities to implement the following:</P>
                    <P>
                        • Periodic security updates.
                        <SU>435</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>435</SU>
                             45 CFR 164.308(a)(5)(ii)(A).
                        </P>
                    </FTNT>
                    <P>
                        • Procedures for guarding against, detecting, and reporting malicious software.
                        <SU>436</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>436</SU>
                             45 CFR 164.308(a)(5)(ii)(B).
                        </P>
                    </FTNT>
                    <P>
                        • Procedures for monitoring log-in attempts and reporting discrepancies.
                        <SU>437</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>437</SU>
                             45 CFR 164.308(a)(5)(ii)(C).
                        </P>
                    </FTNT>
                    <P>
                        • Procedures for creating, changing, and safeguarding passwords.
                        <SU>438</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>438</SU>
                             45 CFR 164.308(a)(5)(ii)(D).
                        </P>
                    </FTNT>
                    <P>The standard for security incident procedures at 45 CFR 164.308(a)(6)(i) requires a regulated entity to implement policies and procedures to address security incidents. The one implementation specification associated with this standard, 45 CFR 164.308(a)(6)(ii), requires regulated entities to identify and respond to suspected or known security incidents; to mitigate, to the extent practicable, harmful effects of security incidents that are known to the regulated entity; and to document security incidents and their outcomes.</P>
                    <P>
                        Under the standard for contingency planning at 45 CFR 164.308(a)(7)(i), a regulated entity is required to establish, and implement as needed, policies and procedures for responding to an emergency or other occurrence that damages systems that contain ePHI. The standard includes five implementation specifications at 45 CFR 164.308(a)(7)(ii). The first, paragraph (a)(7)(ii)(A), requires a regulated entity to establish and implement procedures to create and maintain exact copies of ePHI that are retrievable.
                        <SU>439</SU>
                        <FTREF/>
                         Paragraph (a)(7)(ii)(B) requires a regulated entity to establish, and implement as needed, procedures to restore any lost data.
                        <SU>440</SU>
                        <FTREF/>
                         Paragraph (a)(7)(ii)(C) requires a regulated entity to establish, and implement as needed, procedures to enable continuation of critical business processes for protecting the security of ePHI while the regulated entity is operating in emergency mode. Paragraph (a)(7)(ii)(D) addresses the implementation of procedures for periodic testing and revision of contingency plans, and paragraph (a)(7)(ii)(E) addresses the assessment of the relative criticality of specific applications and data in support of other contingency plan components.
                    </P>
                    <FTNT>
                        <P>
                            <SU>439</SU>
                             45 CFR 164.308(a)(7)(ii)(A).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>440</SU>
                             45 CFR 164.308(a)(7)(ii)(B).
                        </P>
                    </FTNT>
                    <P>The standard for evaluation at 45 CFR 164.308(a)(8) requires a regulated entity to periodically perform a technical and nontechnical evaluation that establishes the extent to which the regulated entity's security policies and procedures meet the requirements of the Security Rule. The initial evaluation is to be based upon the standards implemented under the Security Rule, while subsequent evaluations are to be conducted in response to environmental or operational changes affecting the security of ePHI.</P>
                    <HD SOURCE="HD3">b. Section 164.308(b)</HD>
                    <P>
                        Section 164.308(b) contains the administrative safeguards that apply to the relationships between regulated entities. Specifically, 45 CFR 164.308(b)(1) permits a covered entity to engage a business associate to create, receive, maintain, or transmit ePHI on the covered entity's behalf when it obtains satisfactory assurances (consistent with the organizational requirements for business associate agreements or other arrangements in 45 CFR 164.314(a)) that the business associate will appropriately safeguard the ePHI. Similarly, under 45 CFR 164.308(b)(2), a business associate may retain a subcontractor to create, receive, maintain, or transmit ePHI on its behalf if the business associate obtains satisfactory assurances through a business associate agreement or other arrangement that the subcontractor will appropriately safeguard the information. Section 164.308(b)(3) requires that the contract or other arrangement be in writing.
                        <SU>441</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>441</SU>
                             45 CFR 164.308(b)(3).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">2. Issues To Address</HD>
                    <P>
                        The Security Rule administrative standards are comprehensive, but our experience has demonstrated that they have been misunderstood by some regulated entities, especially regarding how compliance with the standards and implementation specifications must be integrated with the general requirements in 45 CFR 164.306, including the requirement in 45 CFR 164.306(e) that a regulated entity must review and modify security measures. Section 164.306 does not explicitly reference specific security measures, and we are concerned that recent caselaw has highlighted conditions that may cause regulated entities to misinterpret regulatory text that connects the maintenance provision at 45 CFR 164.306(e) with the documentation requirements in 45 CFR 164.316 and the administrative safeguards. Through OCR's educational and enforcement efforts, we also have observed inadequacies in compliance with security management processes. For example, some regulated entities have 
                        <PRTPAGE P="936"/>
                        incorrectly interpreted the standards to not require implementing administrative safeguards, such as risk analyses, for all relevant electronic information systems. Some regulated entities have not documented in writing their policies, procedures, plans, and analyses.
                        <SU>442</SU>
                        <FTREF/>
                         As discussed above, many mistakenly treated “addressable” implementation standards as optional.
                        <SU>443</SU>
                        <FTREF/>
                         Enforcement experience has shown that regulated entities generally do not perform all elements of the risk management process that are fundamental to protecting the confidentiality, integrity, and availability of ePHI and to cybersecurity more broadly.
                    </P>
                    <FTNT>
                        <P>
                            <SU>442</SU>
                             
                            <E T="03">See</E>
                             proposed revisions to 45 CFR 164.316 for a more fulsome discussion of documentation requirements.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>443</SU>
                             
                            <E T="03">See</E>
                             proposed revisions to 45 CFR 164.306(c) and (d) for a more fulsome discussion of the distinction between “required” and “addressable” implementation specifications.
                        </P>
                    </FTNT>
                    <P>
                        In addition, since the Security Rule was issued in 2003 and revised in 2013, newer, more protective security technology has become widely available to regulated entities, and best practices for securing electronic information have evolved. NIST has published numerous guides, including its recent Cybersecurity Framework 2.0, providing resources for establishing and implementing policies and practices to better manage cybersecurity risks.
                        <SU>444</SU>
                        <FTREF/>
                         OCR is drawing upon its enforcement experience, as well as best practices, guidelines, processes, and procedures for improving cybersecurity to propose changes to these standards to better protect ePHI that a regulated entity creates, receives, maintains, or transmits. We believe that these proposals would help ensure that regulated entities implement compliance activities that are consistent with recommendations made by NIST, the HHS 405(d) program, and standards setting bodies regarding cybersecurity.
                    </P>
                    <FTNT>
                        <P>
                            <SU>444</SU>
                             
                            <E T="03">See</E>
                             “The NIST Cybersecurity Framework (CSF) 2.0,” 
                            <E T="03">supra</E>
                             note 15.
                        </P>
                    </FTNT>
                    <P>
                        Because business associates are directly liable for compliance with the Security Rule, in our 2013 Security Rule revisions we did not require covered entities to implement any additional safeguards to ensure that their business associate is in fact in compliance.
                        <SU>445</SU>
                        <FTREF/>
                         However, OCR has learned through its enforcement experience that many covered entities have entrusted ePHI to business associates that are not employing appropriate safeguards. Some business associates have such market power that covered entities may believe they have no alternative to using their services, even if they have concerns about the safeguards employed by the business associate. The Department is concerned by the breaches experienced by business associates and the effects of such breaches on the confidentiality, integrity, and availability of ePHI.
                        <SU>446</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>445</SU>
                             
                            <E T="03">See</E>
                             78 FR 5566, 5572-5573 (Jan. 25, 2013) (explaining reasons for adopting proposal to apply the business associate provisions of the HIPAA Rules to subcontractors and thus, provides in the definition of “business associate” that a business associate includes a “subcontractor that creates, receives, maintains, or transmits protected health information on behalf of the business associate”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>446</SU>
                             
                            <E T="03">See, e.g.,</E>
                             OCR information about the Change Healthcare cybersecurity incident. “Change Healthcare Cybersecurity Incident Frequently Asked Questions,” U.S. Department of Health and Human Services (July 30, 2024), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/special-topics/change-healthcare-cybersecurity-incident-frequently-asked-questions/index.html.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">3. Proposals</HD>
                    <HD SOURCE="HD3">a. Section 164.308—Administrative Safeguards</HD>
                    <P>Throughout this section, the Department proposes to add explicit maintenance requirements to certain standards to address concerns that regulated entities may be misinterpreting the regulatory text that connects the maintenance provision at 45 CFR 164.306(e) with the administrative safeguards. These proposals would clarify that a regulated entity is required to maintain certain security measures, and that where a regulated entity is required to maintain a particular security measure, it is required to review and test such measure on a specified cadence, and to modify the measure as reasonable and appropriate. Testing of particular security measures, such as technical controls or policies and procedures, would include verifying that the security measures work as designed and that workforce members know how to implement them. For example, written policies and procedures can be tested through various methods including, but not limited to: simulating security events that mimic real-world attacks to assess how effectively employees follow incident response and security procedures; conducting knowledge assessments after training on policies and procedures; and reviewing system logs and access records to evaluate whether policies and procedures governing access to ePHI are being followed. We would expect a regulated entity to take the results of the required tests into consideration when determining whether it is reasonable and appropriate to modify its security measures, as well as the actions that would be expected of a regulated entity that is similarly situated based on the results of such tests.</P>
                    <P>We also propose to modify certain administrative safeguards to clarify the obligations of a regulated entity to ensure the confidentiality, integrity, and availability of ePHI by securing its relevant electronic information systems—that is, its electronic information systems that create, receive, maintain, or transmit ePHI and those that otherwise affect its confidentiality, integrity, or availability—and the technology assets in its relevant electronic information systems.</P>
                    <HD SOURCE="HD3">b. Section 164.308(a)</HD>
                    <P>The Department proposes to modify the general language at 45 CFR 164.308(a) to clarify the connection between the general rules for security standards at 45 CFR 164.306, the standards for policies and procedures and documentation requirements at 45 CFR 164.316, and the standards for the administrative safeguards under 45 CFR 164.308(a). We also propose to clarify that regulated entities would be required to implement all of the administrative safeguards of the Security Rule to protect the confidentiality, integrity, or availability of all ePHI that they create, receive, maintain, or transmit. Thus, when read together, proposed 45 CFR 164.308(a) and 164.316(a) would require that a regulated entity implement and document, in writing, its implementation of the administrative safeguards required by the Security Rule. These requirements set the baseline for administrative safeguards. Nothing in this NPRM would prevent a regulated entity from implementing additional administrative safeguards, provided that those additional safeguards do not conflict with any requirements in the Security Rule.</P>
                    <P>The proposed changes are discussed in greater detail below.</P>
                    <HD SOURCE="HD3">c. Section 164.308(a)(1)(i)—Standard: Technology Asset Inventory</HD>
                    <P>
                        We propose to modify 45 CFR 164.308(a)(1) by elevating to standard-level status the existing implementation specifications for the standard for security management process at 45 CFR 164.308(a)(1)(ii)(A) through (D), and deleting the existing standard. Doing so would highlight the importance of these elements and permit us to add implementation specifications that detail our expectations for compliance with those elements. We believe that providing more specificity in our requirements would help regulated entities better understand their compliance responsibilities for 
                        <PRTPAGE P="937"/>
                        safeguarding ePHI. These proposals are consistent with current guidance, as described below.
                    </P>
                    <P>In place of the existing standard for security management process, we propose a standard at 45 CFR 164.308(a)(1)(i) that would require a regulated entity to conduct and maintain an accurate and thorough written technology asset inventory and a network map of its electronic information systems and all technology assets that may affect the confidentiality, integrity, or availability of ePHI. The inventory forms the foundation for a fulsome and accurate risk analysis. A regulated entity must identify its information systems that create, receive, maintain, or transmit ePHI and all technology assets, as we propose to define them in 45 CFR 164.304, that may affect ePHI in such information systems in order to secure them. Regulated entities cannot understand the risks to the confidentiality, integrity, and availability of their ePHI without a complete understanding of these assets. We believe that this proposal would clarify compliance expectations and provide increased protections for the confidentiality, integrity, and availability of ePHI. Consistent with practices previously highlighted in guidance, regulated entities would be required by this proposal to conduct and maintain an accurate and thorough written inventory of technology assets.</P>
                    <P>
                        The standard would also require each regulated entity to determine the movement of ePHI through, into, and out of its information systems and to describe such movement in a network map. A regulated entity's network map would reflect where its technology assets are, for example, physically located at the regulated entity's worksite, or accessed through the cloud. As another example, a covered entity might determine that ePHI is created, received, maintained, or transmitted by one or more offshore business associates (
                        <E T="03">i.e.,</E>
                         persons that are located outside of the U.S.) for such services as claims processing, call center staffing, and technical support, activities that inherently involve ePHI. The technology assets used by the business associate to create, receive, maintain, or transmit ePHI are not a part of the covered entity's electronic information system, but do affect the confidentiality, integrity, or availability of ePHI and so would be required to be included in the network map of the covered entity.
                        <SU>447</SU>
                        <FTREF/>
                         Such assets would be considered part of the business associate's electronic information systems and therefore would need to be included in both its technology asset inventory and network map. Any technology assets used by the covered entity to create, receive, maintain, or transmit ePHI to the business associate would need to be accounted for in both its technology asset inventory and network map. Such technology assets would not be part of the business associate's technology asset inventory, but would need to be included on its network map.
                    </P>
                    <FTNT>
                        <P>
                            <SU>447</SU>
                             
                            <E T="03">See</E>
                             “Guidance on HIPAA &amp; Cloud Computing,” Office for Civil Rights, U.S. Department of Health and Human Services (“A covered entity (or business associate) that engages a [cloud service provider (CSP)] should understand the cloud computing environment or solution offered by a particular CSP so that the covered entity (or business associate) can appropriately conduct its own risk analysis and establish risk management policies, as well as enter into appropriate [business associate agreements.].”), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html.</E>
                        </P>
                    </FTNT>
                    <P>
                        This proposed standard aligns with the Department's enhanced CPG for Asset Inventory, which requires that a regulated entity identify assets to more rapidly detect and respond to potential risks and vulnerabilities,
                        <SU>448</SU>
                        <FTREF/>
                         and is consistent with NCVHS' recommendation to require regulated entities to identify where all PHI is stored and to collect data on applications and systems used by the organization to create a systems inventory.
                        <SU>449</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>448</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>449</SU>
                             
                            <E T="03">See</E>
                             Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, Appendix p. 5.
                        </P>
                    </FTNT>
                    <P>
                        In 2003, the Department elected not to require regulated entities to conduct an inventory because we believed that regulated entities would understand that such an inventory is a vital component of the risk analysis, making it redundant of other requirements of the Security Rule.
                        <SU>450</SU>
                        <FTREF/>
                         The Department and NIST have provided extensive guidance, described below, about how to conduct such inventories as part of compliance with 45 CFR 164.308. However, nearly 20 years of enforcement experience indicates that regulated entities routinely disregard this part of the process. OCR's investigations frequently find that organizations lack sufficient understanding of where all the ePHI entrusted to their care is located.
                        <SU>451</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>450</SU>
                             
                            <E T="03">See</E>
                             68 FR 8333, 8352 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>451</SU>
                             
                            <E T="03">See</E>
                             “Making a List and Checking it Twice: HIPAA and IT Asset Inventories,” Cybersecurity Newsletter, Office for Civil Rights, U.S. Department of Health and Human Services (Aug. 25, 2020), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity-newsletter-summer-2020/index.html.</E>
                        </P>
                    </FTNT>
                    <P>
                        Understanding one's environment—particularly how ePHI is created and enters an organization, how ePHI flows through an organization, and how ePHI leaves an organization—is crucial to understanding the risks ePHI is exposed to throughout an organization.
                        <SU>452</SU>
                        <FTREF/>
                         According to the NIST Cybersecurity Framework 2.0, having a comprehensive understanding of the organization's assets (
                        <E T="03">e.g.,</E>
                         data, hardware, software, systems, facilities, services, people), suppliers, and related cybersecurity risks enables a regulated entity to prioritize its efforts consistent with its risk management strategy and its mission needs.
                        <SU>453</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>452</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>453</SU>
                             
                            <E T="03">See</E>
                             “The NIST Cybersecurity Framework (CSF) 2.0,” 
                            <E T="03">supra</E>
                             note 15, p. 3.
                        </P>
                    </FTNT>
                    <P>
                        The proposed standard would be accompanied by three implementation specifications. Under the proposed implementation specification for inventory at proposed 45 CFR 164.308(a)(1)(ii)(A), the regulated entity would be required to establish a written inventory that contains the regulated entity's technology assets. Technology assets are components of an electronic information system, including but not limited to hardware, software, electronic media, information, and data. The written inventory would be required to include technology assets that create, receive, maintain, or transmit ePHI and those that do not but that may affect the confidentiality, integrity, or availability of ePHI.
                        <SU>454</SU>
                        <FTREF/>
                         It would also be required to include the identification, version, person accountable for, and location of each of the assets or information system components.
                        <SU>455</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>454</SU>
                             Proposed 45 CFR 164.308(a)(1)(ii)(A).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>455</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>The proposed implementation specification for network map at proposed 45 CFR 164.308(a)(1)(ii)(B) would require a regulated entity to develop a network map that illustrates the movement of ePHI throughout its electronic information systems, including but not limited to how ePHI enters and exits such information systems, and is accessed from outside of such information systems.</P>
                    <P>
                        Under the proposed implementation specification for maintenance at proposed 45 CFR 164.308(a)(1)(ii)(C), a regulated entity would be required to review and update the written inventory of technology assets and the network map in the following circumstances: (1) on an ongoing basis, but at least once every 12 months; and (2) when there is a change in the regulated entity's environment or operations that may affect ePHI. Such a change in the 
                        <PRTPAGE P="938"/>
                        regulated entity's environment or operations would include, but would not be limited to, the adoption of new technology assets; the upgrading, updating, or patching of technology assets; newly recognized threats to the confidentiality, integrity, or availability of ePHI; a sale, transfer, merger, or consolidation of all or part of the regulated entity with another person; a security incident that affects the confidentiality, integrity, and availability of ePHI; and relevant changes in Federal, State, Tribal, or territorial law. For example, a dissolution or bankruptcy of the regulated entity would require the regulated entity to review and update its inventory and network map. For another example, if a State implemented regulations specifying cybersecurity requirements for all hospitals, these proposed specifications would require a regulated entity in that State to review and update its inventory and network map considering implementation of the State regulations by the regulated entity or other persons whose activities may affect movement of ePHI throughout its electronic information systems.
                        <SU>456</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>456</SU>
                             
                            <E T="03">See, e.g.,</E>
                             “New York State Register,” 
                            <E T="03">supra</E>
                             note 14.
                        </P>
                    </FTNT>
                    <P>The proposed standard is consistent with the NIST Cybersecurity Framework Identify function, Asset Management (ID.AM) category, which describes inventorying hardware and software and mapping communication and data flows to create and maintain an asset inventory that can be used in a risk analysis process. For example, the Cybersecurity Framework recommends that when creating an asset inventory, organizations should include all of the following, as applicable:</P>
                    <P>
                        • Hardware assets that comprise physical elements, including electronic devices and media, that make up an organization's networks and systems. This may include mobile devices, servers, peripherals (
                        <E T="03">e.g.,</E>
                         printers, USB hubs), workstations, removable media, firewalls, and routers.
                    </P>
                    <P>• Software assets that are programs and applications that run on an organization's electronic devices. Well-known software assets include anti-malicious software tools, operating systems, databases, email, administrative and financial records systems, electronic medical/health record systems, and clinical decision support tools, including those that rely on AI. Though lesser known, there are other programs important to IT operations and security such as backup solutions, and other administrative tools that also should be included in an organization's inventory.</P>
                    <P>
                        • Data assets that include ePHI that an organization creates, receives, maintains, or transmits on its network, electronic devices, and media. How ePHI is used and flows through an organization is important to consider as an organization conducts its risk analysis.
                        <SU>457</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>457</SU>
                             “Making a List and Checking it Twice: HIPAA and IT Asset Inventories,” 
                            <E T="03">supra</E>
                             note 451.
                        </P>
                    </FTNT>
                    <P>Where multiple persons have control over a technology asset, all persons that have control should include the asset in both their technology asset inventories and on their network maps. For example, where a covered entity contracts with a cloud-based EHR vendor, both the covered entity and the EHR vendor have control over the ePHI in the EHR. Thus, the ePHI in the EHR and the EHR should be included in the technology asset inventories and network maps of both the covered entity and the cloud-based EHR vendor. Where the technology assets are controlled entirely by another person, such as the servers controlled by a cloud-based provider of data backup services, the technology assets would not be considered part of a health care provider's electronic information systems, and therefore would not have to be included in its technology asset inventory. However, the data backup provider would have to be included in the health care provider's network map.</P>
                    <P>
                        When creating or maintaining a technology asset inventory that can aid in identifying risks to ePHI, regulated entities should consider their technology assets that may not create, receive, maintain or transmit ePHI, but that may affect technology assets that do so.
                        <SU>458</SU>
                        <FTREF/>
                         Assets within an organization that do not create, receive, maintain, or transmit ePHI may still present opportunities for intruders to enter the regulated entity's electronic information systems, which could lead to risks to the confidentiality, integrity, or availability of an organization's ePHI. For example, consider a smart device that is connected to the internet (
                        <E T="03">e.g.,</E>
                         connected to the Internet of Things 
                        <SU>459</SU>
                        <FTREF/>
                         (IoT)) and provides access to facilities for maintenance personnel to control and monitor an organization's heating, ventilation, and air conditioning (HVAC). Although it may not maintain or process ePHI, such a device potentially can present serious risks to the security of ePHI in an organization's information systems. Unpatched IoT devices with known vulnerabilities, such as weak or unchanged default passwords installed on a network without firewalls, network segmentation, or other techniques that deny or impede an intruder's lateral movement, can provide an intruder with access to an organization's relevant electronic information systems. The intruder may then leverage this access to conduct reconnaissance and further penetrate an organization's network and potentially compromise ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>458</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>459</SU>
                             NIST defines the Internet of Things as “[t]he network of devices that contain the hardware, software, firmware, and actuators which allow the devices to connect, interact, and freely exchange data and information.” NIST definition of “Internet of Things,” Glossary, Computer Security Resource Center, National Institute of Standards and Technology, U.S. Department of Commerce, 
                            <E T="03">https://csrc.nist.gov/glossary/term/internet_of_things.</E>
                        </P>
                    </FTNT>
                    <P>The risks and deficiencies OCR has observed in its enforcement experience persuades us that we must consider adding an express requirement for a regulated entity to conduct an accurate and thorough written inventory of its technology assets and create a network map.</P>
                    <HD SOURCE="HD3">d. Section 164.308(a)(2)(i)—Standard: Risk Analysis</HD>
                    <P>
                        After a regulated entity conducts a written inventory of its technology assets and creates its network map, it is critical for it to identify the potential risks and vulnerabilities to its ePHI. Conducting a risk analysis is necessary to adequately protect the confidentiality, integrity, and availability of ePHI because it provides the basis for determining the manner in which the regulated entity will comply with and carry out the other standards and implementation specifications in the Security Rule.
                        <SU>460</SU>
                        <FTREF/>
                         Basic questions that a regulated entity would consider when conducting a risk analysis that is compliant with the Security Rule include: 
                        <SU>461</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>460</SU>
                             
                            <E T="03">See</E>
                             “Guidance on Risk Analysis,” Office for Civil Rights, U.S. Department of Health and Human Services (July 22, 2019), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html?language=es.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>461</SU>
                             
                            <E T="03">Id.; see also</E>
                             Jeffrey A. Marron, “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” NIST Special Publication 800-66, Revision 2, National Institute of Standards and Technology, U.S. Department of Commerce, p.28-84 (Feb. 2024), 
                            <E T="03">https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-66r2.pdf.</E>
                        </P>
                    </FTNT>
                    <P>• Have you identified all the ePHI that you create, receive, maintain, or transmit?</P>
                    <P>• What are the external sources of ePHI? For example, do vendors or consultants create, receive, maintain, or transmit ePHI?</P>
                    <P>
                        • What are the human, natural, and environmental threats to information systems that contain ePHI?
                        <PRTPAGE P="939"/>
                    </P>
                    <P>• What are the risks posed by legacy devices, including any risks that would be posed by replacing legacy devices with new ones?</P>
                    <P>
                        There are numerous methods of performing a risk analysis, and there is no single method or “best practice” that guarantees compliance with the Security Rule.
                        <SU>462</SU>
                        <FTREF/>
                         The Department has issued multiple guidance documents and tools for regulated entities to help them implement risk analyses,
                        <SU>463</SU>
                        <FTREF/>
                         and several versions of its Security Risk Assessment Tool, a desktop application that walks users through the process of conducting a risk assessment.
                        <SU>464</SU>
                        <FTREF/>
                         NIST has published numerous guides for risk assessment over the past two decades,
                        <SU>465</SU>
                        <FTREF/>
                         in addition to reference materials it has developed in collaboration with the Department, including a toolkit and a crosswalk between the Security Rule to NIST Cybersecurity Framework,
                        <SU>466</SU>
                        <FTREF/>
                         and “how to” guides on risk analysis.
                        <SU>467</SU>
                        <FTREF/>
                         In February 2024, NIST released a new guide that provides resources for implementing a Security Rule risk analysis.
                        <SU>468</SU>
                        <FTREF/>
                         Consistent with previous Department guidance, the guide describes key elements in a comprehensive risk assessment process, that include the following:
                    </P>
                    <FTNT>
                        <P>
                            <SU>462</SU>
                             
                            <E T="03">See</E>
                             “Guidance on Risk Analysis,” 
                            <E T="03">supra</E>
                             note 460.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>463</SU>
                             
                            <E T="03">See id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>464</SU>
                             
                            <E T="03">See</E>
                             “Security Risk Assessment Tool,” Office for Civil Rights and Office of the National Coordinator for Health Information Technology, U.S. Department of Health and Human Services (updated Sept. 5, 2023), 
                            <E T="03">https://www.healthit.gov/topic/privacy-security-and-hipaa/security-risk-assessment-tool.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>465</SU>
                             
                            <E T="03">See</E>
                             “HIPAA Security Rule,” National Institute of Standards and Technology, U.S. Department of Commerce (Jan. 3, 2011, updated July 21, 2022), 
                            <E T="03">https://www.nist.gov/programs-projects/security-health-information-technology/hipaa-security-rule.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>466</SU>
                             
                            <E T="03">See</E>
                             “HIPAA Security Rule Crosswalk to NIST Cybersecurity Framework,” Office for Civil Rights, U.S. Department of Health and Human Services (June 2020), 
                            <E T="03">https://www.hhs.gov/guidance/sites/default/files/hhs-guidance-documents//nist-csf-to-hipaa-security-rule-crosswalk-02-22-2016-final.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>467</SU>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>468</SU>
                             
                            <E T="03">See id.</E>
                        </P>
                    </FTNT>
                    <P>
                        • Prepare for the assessment by conducting a technology asset inventory.
                        <SU>469</SU>
                        <FTREF/>
                         Determine whether ePHI is transmitted to external third parties, such as cloud service providers or others. The regulated entity can also examine how access to ePHI is controlled and whether ePHI is encrypted at rest and in transit. The scope of a risk assessment should include both the physical boundaries of a regulated entity's location and a logical boundary that includes any devices or media that contain ePHI, including electronic networks through which ePHI is transmitted, regardless of its location.
                    </P>
                    <FTNT>
                        <P>
                            <SU>469</SU>
                             This component of the assessment would be accomplished under the NPRM, if adopted, through compliance with the proposed standard for technology asset inventory at proposed 45 CFR 164.308(a)(1)(i). Under the current Security Rule, we consider the technology asset inventory to be a component of the standard for risk analysis.
                        </P>
                    </FTNT>
                    <P>• Identify reasonably anticipated threats. The list of threat events and threat sources should include reasonably anticipated and probable human and natural incidents that can negatively affect the regulated entity's ability to protect ePHI. The information gathered for the technology asset inventory should be used to identify reasonably anticipated threats to ePHI.</P>
                    <P>
                        • Identify potential vulnerabilities and predisposing conditions. For any of the various threats identified above to result in a significant risk, each needs a vulnerability or predisposing condition that can be exploited. While it is necessary to review threats and vulnerabilities as unique elements, they are often considered at the same time. Organizations should consider a given loss scenario and evaluate both, such as what threat sources might initiate which threat events or what vulnerabilities or predisposing conditions those threat sources might exploit to cause an adverse effect. From this, the regulated entity should develop a list of vulnerabilities (
                        <E T="03">i.e.,</E>
                         flaws or weaknesses) that could be exploited by potential threat sources.
                    </P>
                    <P>
                        • Determine the likelihood that a threat would exploit a vulnerability. For each threat event/threat source identified, a regulated entity should consider: the likelihood that the threat would occur and the likelihood that an occurred threat would exploit an identified vulnerability and result in an adverse effect. A regulated entity might consider assigning a likelihood value (
                        <E T="03">e.g.,</E>
                         “very low,” “low,” “moderate,” “high,” or “very high”) to each threat/vulnerability pairing. As an example, the regulated entity may determine that the likelihood of a phishing attack occurring is very high and that the likelihood of the event exploiting a human vulnerability is moderate, resulting in an overall likelihood rating of high.
                    </P>
                    <P>
                        • Determine the impact of a threat exploiting a vulnerability. As with likelihood determination, a regulated entity may choose to express this effect in qualitative terms or use any other scale that the entity chooses. When selecting an impact rating, the regulated entity may consider how the threat event can affect the loss or degradation of the confidentiality, integrity, or availability of ePHI. Some tangible impacts can be measured quantitatively in terms of lost revenue, the cost of repairing the system, or the level of effort required to correct problems caused by a successful threat action. Other impacts cannot be measured in specific units (
                        <E T="03">e.g.,</E>
                         the loss of public confidence, the loss of credibility, or damage to an organization's interests), but they can be qualitatively described.
                    </P>
                    <P>• Determine the level of risk to ePHI while considering the information gathered and determinations made during the previous steps. The level of risk is determined by analyzing the values assigned to the overall likelihood of threat occurrence and the resulting impact of threat occurrence.</P>
                    <P>
                        • Document the risk assessment results. Once the risk assessment has been completed as described above, the results of the risk assessment should be documented. Principally, the regulated entity should document all threat/vulnerability pairs (
                        <E T="03">i.e.,</E>
                         a scenario in which an identified threat can exploit a vulnerability) applicable to the organization, the likelihood and impact calculations, and the overall risk to ePHI for the threat/vulnerability pair. Regulated entities should consider sharing the risk assessment results with organizational leadership, whose review can be crucial to the organization's ongoing risk management.
                    </P>
                    <P>
                        The Department has also published guidance that explains the differences between a risk analysis and a gap analysis, and the use of both in an entity's risk management program.
                        <SU>470</SU>
                        <FTREF/>
                         While a risk analysis is a comprehensive identification of risks and vulnerabilities to all ePHI, a gap analysis typically provides a partial assessment of an entity's enterprise and is often used to provide a high-level overview of what safeguards are in place (or missing) and may also be used to review a regulated entity's compliance with particular standards and implementation specifications of the Security Rule.
                    </P>
                    <FTNT>
                        <P>
                            <SU>470</SU>
                             “Risk Analyses vs. Gap Analyses—What is the difference?” Cybersecurity Newsletter, Office for Civil Rights, U.S. Department of Health and Human Services (Apr. 2018), 
                            <E T="03">https://www.hhs.gov/sites/default/files/cybersecurity-newsletter-april-2018.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        Other NIST guidance on conducting risk assessments explains that the result of a risk analysis is a determination of risk posed to the regulated entity's ePHI and related information systems.
                        <FTREF/>
                        <SU>471</SU>
                          
                        <PRTPAGE P="940"/>
                        Consistent with the discussion above, a key step is determining the risk level posed to such ePHI by threats and vulnerabilities and how critical it is to address and mitigate the identified risk. In general, the descriptive words “very high” or “critical” are used to indicate that a threat event could be expected to have multiple severe or catastrophic adverse effects on organizational operations, organizational assets, individuals, other organizations, or the country.
                        <SU>472</SU>
                        <FTREF/>
                         A “high” risk would indicate that a threat event could be expected to have a severe or catastrophic adverse effect on the same, while a “moderate” risk could indicate that the threat event could have a serious adverse effect on the same. Risks that are “low” and “very low” could be expected to have a limited and negligible effect, respectively, on organizational operations or assets, individuals, other organizations, or the country.
                    </P>
                    <FTNT>
                        <P>
                            <SU>471</SU>
                             Joint Task Force, “Guide for Conducting Risk Assessments,” NIST Special Publication 800-30, Revision 1, National Institute of Standards and 
                            <PRTPAGE/>
                            Technology, U.S. Department of Commerce (Sept. 2012), 
                            <E T="03">https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>472</SU>
                             
                            <E T="03">Id.</E>
                             at Appendix I; 
                            <E T="03">see also</E>
                             “Reducing the Significant Risk of Known Exploited Vulnerabilities,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security (Nov. 3, 2021), 
                            <E T="03">https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        The Department believes that determinations of risk level and criticality may vary based on the specific type of regulated entity and the regulated entity's specific circumstances. For example, a health care provider must consider the higher levels of risks to physical and technical security that are created by regular entry and exit of individuals seeking health care and other members of the public into its facilities, creating potentially numerous avenues for access to ePHI through technology assets; in contrast, a health plan that generally does not permit physical entry by individuals into its office building may determine that the risks to ePHI from physical entry by individuals or other members of the public is low because its workforce members do not generally physically interact with the public. As another example, a vulnerability permitting unauthenticated remote code execution on a device connected to a regulated entity's relevant electronic information systems would likely constitute either a high or critical risk. However, should such a device not have the ability to connect to the network, the risk might be low or moderate because the likelihood of triggering a network vulnerability on a non-networked device is low, even though the impact of such trigger might be high. Thus, it is essential that a regulated entity consider its specific circumstances when assessing the criticality of a risk and to address such risks in a manner that is appropriate to its specific facts and circumstances.
                        <SU>473</SU>
                        <FTREF/>
                         In yet another example, a regulated entity in possession of legacy devices or devices that are nearing the end of their lifespan should assess the risks associated with continued use of such devices as part of its risk analysis and ensure that replacement of such devices and/or the implementation of compensating controls are included in its risk management plan.
                    </P>
                    <FTNT>
                        <P>
                            <SU>473</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461, p. 16-22.
                        </P>
                    </FTNT>
                    <P>
                        Despite our having made available an abundance of free and widely-publicized guidance tools, OCR unfortunately has learned through its compliance and enforcement activities that regulated entities often do not perform compliant risk analyses. As discussed above, in 2016 and 2017, the Department conducted audits of 166 covered entities and 41 business associates for their compliance with selected provisions of the HIPAA Rules.
                        <SU>474</SU>
                        <FTREF/>
                         These audits confirmed that only small percentages of covered entities (14 percent) and business associates (17 percent) were substantially fulfilling their regulatory responsibilities to safeguard ePHI they hold through risk analysis activities. Entities generally failed to:
                    </P>
                    <FTNT>
                        <P>
                            <SU>474</SU>
                             “2016-2017 HIPAA Audits Industry Report,” 
                            <E T="03">supra</E>
                             note 121.
                        </P>
                    </FTNT>
                    <P>• Identify and assess the risks to all of the ePHI in their possession or even develop and implement policies and procedures for conducting a risk analysis.</P>
                    <P>• Identify threats and vulnerabilities to consider their potential likelihoods and effects, and to rate the risk to ePHI.</P>
                    <P>• Review and periodically update a risk analysis in response to changes in the environment and/or operations, security incidents, or occurrence of a significant event.</P>
                    <P>• Conduct risk analyses consistent with policies and procedures.</P>
                    <P>
                        Failing to document any efforts to develop, maintain, and update policies and procedures for conducting risk analyses was common. For example, health care providers commonly submitted documentation of some security activities performed by a third-party security vendor, without submitting documentation of any risk analysis that served as the basis of such activities.
                        <SU>475</SU>
                        <FTREF/>
                         Many regulated entities used and relied on outside persons to manage or perform risk analyses for their organizations; however, these outside persons frequently failed to meet the requirements of the Security Rule. Regulated entities also frequently and incorrectly assumed that a purchased security product satisfied all of the Security Rule's requirements.
                    </P>
                    <FTNT>
                        <P>
                            <SU>475</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>The responsibility to maintain an appropriate risk analysis rests with the regulated entity. Accordingly, it is essential that regulated entities understand and comply with risk analysis requirements to appropriately safeguard PHI.</P>
                    <P>
                        Numerous OCR investigations reflect the failure of regulated entities to develop and implement holistic risk analysis programs. For example, OCR's investigation of a health system in the aftermath of a ransomware attack found evidence of potential failures to: conduct a compliant risk analysis to determine the potential risks and vulnerabilities to ePHI in its systems; implement a contingency plan to respond to emergencies, like a ransomware attack, that damage systems that contain ePHI; and implement policies and procedures to allow only authorized users access to ePHI.
                        <SU>476</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>476</SU>
                             Press Release, “HHS Office for Civil Rights Settles HIPAA Security Rule Failures for $950,000,” U.S. Department of Health and Human Services (July 1, 2024), 
                            <E T="03">https://prod-wwwhhsgov.cloud.hhs.gov/about/news/2024/07/01/hhs-office-civil-rights-settles-hipaa-security-rule-failures-950000.html.</E>
                        </P>
                    </FTNT>
                    <P>
                        In another recently concluded investigation involving a large medical center, the covered entity reported that over a seven-month period, one of its employees inappropriately accessed the ePHI of more than 12,000 patients and then sold certain patient information to an identity theft ring.
                        <SU>477</SU>
                        <FTREF/>
                         OCR's investigation indicated potential violations of the requirement to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all of the ePHI held by the medical center, as well as the requirement at 45 CFR 164.308(a)(1)(ii)(D) to implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking.
                    </P>
                    <FTNT>
                        <P>
                            <SU>477</SU>
                             
                            <E T="03">See</E>
                             “Montefiore Medical Center,” 
                            <E T="03">supra</E>
                             note 248.
                        </P>
                    </FTNT>
                    <P>
                        In another case, the OCR settled a ransomware cyberattack investigation with a business associate.
                        <SU>478</SU>
                        <FTREF/>
                         The cyberattack affected the ePHI of over 
                        <PRTPAGE P="941"/>
                        200,000 individuals when the business associate's network server was infected with ransomware. It took the company more than 18 months to detect the intrusion, and they only did so when the ransomware was used by the intruder to encrypt the company's files. Among other factors, OCR's investigation found evidence of potential failures to conduct an accurate and thorough risk analysis and to implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.
                    </P>
                    <FTNT>
                        <P>
                            <SU>478</SU>
                             
                            <E T="03">See</E>
                             “Doctors' Management Services, Inc.,” 
                            <E T="03">supra</E>
                             note 246.
                        </P>
                    </FTNT>
                    <P>
                        Given the compliance deficiencies that OCR regularly sees—those cited as examples and what OCR has observed more broadly—we believe that stronger requirements coupled with greater specificity regarding the components of a risk analysis would help and encourage regulated entities to appropriately perform such activities. Accordingly, the Department proposes to elevate the requirement to conduct a risk analysis from an implementation specification at 45 CFR 164.308(a)(1)(ii)(A) to a standard at proposed 45 CFR 164.308(a)(2)(i). Under the proposal, and consistent with NCVHS' recommendations,
                        <SU>479</SU>
                        <FTREF/>
                         a regulated entity would be required to conduct an accurate and comprehensive written assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI created, received, maintained, or transmitted by the regulated entity.
                    </P>
                    <FTNT>
                        <P>
                            <SU>479</SU>
                             
                            <E T="03">See</E>
                             Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, Appendix p. 4-6.
                        </P>
                    </FTNT>
                    <P>
                        The Department proposes eight implementation specifications for the risk analysis standard, consistent with previously issued guidance described above. The proposed implementation specification for a written assessment at proposed paragraph (a)(2)(ii)(A) would require the regulated entity, at a minimum, to perform and document all of the following: 
                        <SU>480</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>480</SU>
                             Proposed 45 CFR 164.308(a)(2)(ii)(A).
                        </P>
                    </FTNT>
                    <P>
                        • Review the technology asset inventory and the network map to identify where ePHI may be created, received, maintained, or transmitted within its information systems.
                        <SU>481</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>481</SU>
                             Proposed 45 CFR 164.308(a)(2)(ii)(A)(
                            <E T="03">1</E>
                            ).
                        </P>
                    </FTNT>
                    <P>
                        • Identify all reasonably anticipated threats to the confidentiality, integrity, and availability of ePHI that it creates, receives, maintains, or transmits.
                        <SU>482</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>482</SU>
                             Proposed 45 CFR 164.308(a)(2)(ii)(A)(
                            <E T="03">2</E>
                            ).
                        </P>
                    </FTNT>
                    <P>
                        • Identify potential vulnerabilities and predisposing conditions to the regulated entity's relevant electronic information systems—that is, its electronic information systems that create, receive, maintain, or transmit ePHI or that otherwise affect the confidentiality, integrity, or availability of ePHI.
                        <SU>483</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>483</SU>
                             Proposed 45 CFR 164.308(a)(2)(ii)(A)(
                            <E T="03">3</E>
                            ).
                        </P>
                    </FTNT>
                    <P>
                        • Create an assessment and documentation of the security measures it uses to ensure that the measures protect the confidentiality, integrity, and availability of the ePHI created, received, maintained, or transmitted by the regulated entity.
                        <SU>484</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>484</SU>
                             Proposed 45 CFR 164.308(a)(2)(ii)(A)(
                            <E T="03">4</E>
                            ).
                        </P>
                    </FTNT>
                    <P>
                        • Make a reasonable determination of the likelihood that each identified threat would exploit the identified vulnerabilities.
                        <SU>485</SU>
                        <FTREF/>
                         For example, a regulated entity located on the west coast could consult actuarial tables to reasonably determine the likelihood that an earthquake would affect access to electrical power to maintain its relevant electronic information systems.
                    </P>
                    <FTNT>
                        <P>
                            <SU>485</SU>
                             Proposed 45 CFR 164.308(a)(2)(ii)(A)(
                            <E T="03">5</E>
                            ).
                        </P>
                    </FTNT>
                    <P>
                        • Make a reasonable determination of the potential impact of each identified threat should it successfully exploit the identified vulnerabilities.
                        <SU>486</SU>
                        <FTREF/>
                         For example, the regulated entity described above could make a reasonable determination of how and the extent to which the lack of electrical power caused by an earthquake would affect the availability and integrity of ePHI in its relevant electronic information system.
                    </P>
                    <FTNT>
                        <P>
                            <SU>486</SU>
                             Proposed 45 CFR 164.308(a)(2)(ii)(A)(
                            <E T="03">6</E>
                            ).
                        </P>
                    </FTNT>
                    <P>
                        • Create an assessment of risk level for each identified threat and vulnerability.
                        <SU>487</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>487</SU>
                             Proposed 45 CFR 164.308(a)(2)(ii)(A)(
                            <E T="03">7</E>
                            ).
                        </P>
                    </FTNT>
                    <P>
                        • Create an assessment of risks to ePHI posed by entering into or continuing a business associate agreement or other written arrangement with any prospective or current business associate, respectively, based on the written verification obtained from the prospective or current business associate.
                        <SU>488</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>488</SU>
                             Proposed 45 CFR 164.308(a)(2)(ii)(A)(
                            <E T="03">8</E>
                            ).
                        </P>
                    </FTNT>
                    <P>Under the proposed implementation specification for maintenance at proposed 45 CFR 164.308(a)(2)(ii)(B), a regulated entity additionally would be required to review, verify, and update the written assessment on an ongoing basis, but in any event no less frequently than at least once every 12 months, and in response to a change in the regulated entity's environment or operations that may affect ePHI. As discussed above, a change in the regulated entity's environment or operations that may affect ePHI would include, but would not be limited to, the adoption of new technology assets; the upgrading, updating, or patching of technology assets; newly recognized threats to the confidentiality, integrity, or availability of ePHI; a sale, transfer, merger, or consolidation of all or part of the regulated entity with another person; a security incident that affects the confidentiality, integrity, or availability of ePHI; and relevant changes in Federal, State, Tribal, or territorial law.</P>
                    <HD SOURCE="HD3">e. Section 164.308(a)(3)(i)—Standard: Evaluation</HD>
                    <P>
                        The Department proposes to redesignate the existing evaluation standard at 45 CFR 164.308(a)(8) as 45 CFR 164.308(a)(3)(i) and to revise the redesignated evaluation standard to require the technical and nontechnical evaluation(s) to be in writing and performed to determine whether change in the regulated entity's environment or operations may affect the confidentiality, integrity, or availability of ePHI. Evaluating the effects of a potential change on a regulated entity's environment or operations, including the effects on the confidentiality, integrity, and availability of ePHI, is a critical step in the change control process. An evaluation serves a similar purpose to a risk analysis. However, while a risk analysis looks at the entirety of a regulated entity's enterprise regularly and in response to a change in the regulated entity's environment or operations, an evaluation looks at a specific change that a regulated entity intends to make before the change is made. Thus, this proposal, if adopted, would ensure that a regulated entity proactively considers whether any risks or vulnerabilities to ePHI or its relevant electronic information systems will be introduced by changes it intends to make to its environment or operations and responds by implementing appropriate safeguards in a timely fashion.
                        <SU>489</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>489</SU>
                             
                            <E T="03">See</E>
                             NCVHS recommendation to test at multiple points in the life cycle of a system, including “at every significant change throughout the life of the system[.]” Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, Appendix p. 6.
                        </P>
                    </FTNT>
                    <P>
                        We also propose to delete the requirement that the evaluation be performed “based initially on the standards implemented under this rule” because an evaluation is performed to assess the effect(s) of a planned change on the environment, which can be observed when those effects are compared to the environment reflected in the risk analysis. Additionally, the Department proposes to add two implementation specifications at 
                        <PRTPAGE P="942"/>
                        proposed 45 CFR 164.308(a)(3)(ii). The proposed implementation specification for performance at proposed 45 CFR 164.308(a)(3)(ii)(A) would require that a regulated entity conduct the evaluation within a reasonable period of time before making a change to its environment or operations, while the proposed implementation specification for response at proposed 45 CFR 164.308(a)(3)(ii)(B) would require a regulated entity to respond to the evaluation in accordance with its risk management plan.
                    </P>
                    <P>A change in the regulated entity's environment or operations would include, but would not be limited to, the adoption of new technology assets; the upgrading, updating, or patching of technology assets; newly recognized threats to the confidentiality, integrity, or availability of ePHI; a sale, transfer, merger or consolidation of all or part of the regulated entity with another person; a security incident that affects the confidentiality, integrity, or availability of ePHI; and relevant changes in Federal, State, Tribal, and territorial law.</P>
                    <P>
                        NIST guidance provides descriptions of key activities and sample questions that would help regulated entities meet this evaluation standard.
                        <SU>490</SU>
                        <FTREF/>
                         They include:
                    </P>
                    <FTNT>
                        <P>
                            <SU>490</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461; “Security Rule Guidance Material,” Office for Civil Rights, U.S. Department of Health and Human Services (Feb. 16, 2024), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html?language=es.</E>
                        </P>
                    </FTNT>
                    <P>• Determine whether internal or external evaluation is most appropriate. Which staff has the technical experience and expertise to evaluate the systems? If an outside vendor is used, what factors should be considered when selecting the vendor, such as credentials and experience?</P>
                    <P>
                        • Develop standards and measurements for reviewing all standards and implementation specifications of the Security Rule. Have management, operational, and technical issues been considered? Do the elements of each evaluation procedure (
                        <E T="03">e.g.,</E>
                         questions, statements, or other components) address individual, measurable security safeguards for ePHI?
                    </P>
                    <P>• Conduct an evaluation. Has the process been formally communicated to those who have been assigned roles and responsibilities in the evaluation process? Has the organization explored the use of automated tools to support the process?</P>
                    <P>• Document results, including: each evaluation finding and remediation options, recommendations, and decisions; known gaps between identified risks, mitigating security controls, and any acceptance of risk, including justification; developed security program priorities and established targets for continuous improvement; use of evaluation results to inform security changes to protect ePHI; communication of evaluation results, metrics, and/or measurements to relevant organizational personnel.</P>
                    <P>
                        • Repeat evaluations periodically. Establish the frequency of evaluations, repeating evaluations when environmental and operational changes that affect the security of ePHI are made (
                        <E T="03">e.g.,</E>
                         if new technology is adopted or if there are newly recognized risks to the confidentiality, integrity, or availability of ePHI).
                    </P>
                    <P>Despite the existing standard and the availability of guidance, many regulated entities do not evaluate how changes in their environment, such as a merger or acquisition or implementation of new technology, may affect the security of ePHI. In some instances, regulated entities assert that they have done so, but have no documentation of the purported evaluation. The Department believes that this proposal, if adopted, would clarify our expectations for implementing these safeguards.</P>
                    <HD SOURCE="HD3">f. Section 164.308(a)(4)(i)—Standard: Patch Management</HD>
                    <P>
                        As described in Department guidance, regulated entities can defend themselves from common cyberattacks, but hackers continue to target the health care industry in search of ways to access valuable ePHI.
                        <SU>491</SU>
                        <FTREF/>
                         Accordingly, timely implementation of patches for known vulnerabilities is crucial to maintaining the security of ePHI. Many cyberattacks could be prevented or substantially mitigated if regulated entities implemented activities to manage the implementation of patches, updates, and upgrades to comply with the Security Rule's requirements for risk management, which can deter one of the common types of attacks: exploitation of known vulnerabilities. If an attack is successful, the intruder often will encrypt a regulated entity's ePHI to hold it for ransom, or exfiltrate the data for future purposes including identity theft or blackmail. Cyberattacks are especially concerning in the health care sector because they can disrupt the provision of health care services. Exploitable vulnerabilities can exist in many parts of a regulated entity's information systems, but often, known vulnerabilities can be mitigated by applying vendor patches, updating software or system configurations, or upgrading to a newer version of the product. If a patch, update, or upgrade is unavailable, vendors often suggest actions to take, that is, compensating controls, to mitigate a newly discovered vulnerability. Such actions could include modifications of configuration files or disabling of affected services. Regulated entities should pay careful attention to cybersecurity alerts describing newly discovered vulnerabilities. These alerts often include information on mitigation activities and patching.
                    </P>
                    <FTNT>
                        <P>
                            <SU>491</SU>
                             
                            <E T="03">See</E>
                             “Defending Against Common Cyber-Attacks,” 
                            <E T="03">supra</E>
                             note 396.
                        </P>
                    </FTNT>
                    <P>
                        Risk management processes that are compliant with the Security Rule include identifying and mitigating risks and vulnerabilities that unpatched software poses to an organization's ePHI. Mitigation activities could include installing patches if patches are available and patching is reasonable and appropriate. In situations where patches are not available (
                        <E T="03">e.g.,</E>
                         obsolete or unsupported software) or testing or other concerns weigh against patching as a mitigation solution,
                        <SU>492</SU>
                        <FTREF/>
                         regulated entities should implement reasonable compensating controls to reduce the risk of identified vulnerabilities to a reasonable and appropriate level (
                        <E T="03">e.g.,</E>
                         restricting network access or disabling network services to reduce vulnerabilities that could be exploited via network access). Security vulnerabilities may be present in many types of software, including databases, EHRs, operating systems, email, and device firmware. Each type of program would have its own unique set of vulnerabilities and challenges for applying patches, but identifying and mitigating the risks unpatched software 
                        <PRTPAGE P="943"/>
                        poses to ePHI is important to ensuring that ePHI is protected.
                        <SU>493</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>492</SU>
                             It may not be reasonable and appropriate for a regulated entity to patch software or update a system configuration where the risk of introducing a change is greater than the status quo risk or where the regulated entity does not own or manage a networked device. For example, instances where it might not be reasonable and appropriate to patch or update an information system include: (1) where a system needs to run continuously for mission critical support and is not patched or updated during its lifetime; and (2) where the regulated entity's testing of such patch or update indicates potential adverse impacts or where industry is reporting adverse impacts of such patch or update. This does not negate the regulated entity's need to address the vulnerability with a compensating control. For example, where a hospital discovers a vulnerability on a device that is connected to its network but owned and managed by a business associate, the hospital may not have access to install a patch, but it should employ a compensating control, such as disabling or limiting that device's access to the hospital's network.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>493</SU>
                             
                            <E T="03">See</E>
                             “Guidance on Software Vulnerabilities and Patching,” Cybersecurity Newsletter, Office for Civil Rights, U.S. Department of Health and Human Services (June 2018), 
                            <E T="03">https://www.hhs.gov/sites/default/files/june-2018-newsletter-software-patches.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        Although older applications or devices may no longer be supported with patches for new vulnerabilities, regulated entities must still take appropriate action if a newly discovered vulnerability affects an older application or device. If an obsolete, unsupported system cannot be upgraded or replaced, additional safeguards should be implemented or existing safeguards enhanced to mitigate known vulnerabilities until upgrade or replacement can occur (
                        <E T="03">e.g.,</E>
                         increase access restrictions, remove or restrict network access, disable unnecessary features or services).
                        <SU>494</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>494</SU>
                             
                            <E T="03">See</E>
                             “Securing Your Legacy [System Security],” Cybersecurity Newsletter, Office for Civil Rights, U.S. Department of Health and Human Services (Oct. 2021), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity-newsletter-fall-2021/index.html.</E>
                        </P>
                    </FTNT>
                    <P>
                        Patches can be applied to software and firmware on all types of devices—telephones, computers, servers, routers, and more. Installation of vendor-recommended patches is typically a routine process. However, regulated entities should be prepared if issues arise as a result of applying patches. Software and hardware are often interconnected and dependent on the functionality and output of other information systems or components of other information systems. When certain changes are made, including the installation of a patch, software dependent on the changed application may not perform as expected because settings or data may be affected. Thus, in complex environments, patch management plays a crucial role in the safe and correct implementation of these changes.
                        <SU>495</SU>
                        <FTREF/>
                         Enterprise patch management is the process of identifying, prioritizing, acquiring, installing, and verifying the installation of patches, updates, and upgrades throughout an organization.
                        <SU>496</SU>
                        <FTREF/>
                         NIST has issued a series of guidance documents that regulated entities can use to design their own patch management processes as part of their risk management plans.
                    </P>
                    <FTNT>
                        <P>
                            <SU>495</SU>
                             
                            <E T="03">See</E>
                             “Guidance on Software Vulnerabilities and Patching,” 
                            <E T="03">supra</E>
                             note 493.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>496</SU>
                             
                            <E T="03">See</E>
                             Murugiah Souppaya, et al., “Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology,” NIST Special Publication 800-40, Revision 4, National Institute of Standards and Technology, U.S. Department of Commerce (Apr. 2022), 
                            <E T="03">https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r4.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        Consistent with previously issued guidance, the discussion above, and recommendations from NCVHS,
                        <SU>497</SU>
                        <FTREF/>
                         the Department proposes a new standard for patch management at proposed 45 CFR 164.308(a)(4)(i) that would require a regulated entity to implement written policies and procedures for applying patches and updating the configurations of its relevant electronic information systems. This proposed standard would ensure that a regulated entity is aware of its liability for appropriately safeguarding ePHI by installing patches, updates, and upgrades throughout its relevant electronic information systems.
                    </P>
                    <FTNT>
                        <P>
                            <SU>497</SU>
                             Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, Appendix p. 1; Letter from NCVHS Chair Jacki Monson (2022), 
                            <E T="03">supra</E>
                             note 123, p. 8-9.
                        </P>
                    </FTNT>
                    <P>
                        The Department proposes six implementation specifications at proposed 45 CFR 164.308(a)(4)(ii) that would be associated with the proposed standard for patch management. The proposed implementation specification for policies and procedures at proposed paragraph (a)(4)(ii)(A) would require a regulated entity to establish written policies and procedures for identifying, prioritizing, acquiring, installing, evaluating, and verifying the timely installation of patches, updates, and upgrades throughout its electronic information systems that create, receive, maintain, or transmit ePHI or that otherwise affect the confidentiality, integrity, or availability of ePHI. Under the proposed implementation specification for maintenance at proposed paragraph (a)(4)(ii)(B), a regulated entity would be required to review its patch management written policies and procedures at least once every 12 months and modify them as reasonable and appropriate based on that review. The proposed implementation specification for application at proposed paragraph (a)(4)(ii)(C) would require a regulated entity to patch, update, and upgrade the configurations of its relevant electronic information systems in accordance with its written policies and procedures and based on the results of: the regulated entity's risk analysis that would be required by proposed 45 CFR 164.308(a)(2), the vulnerability scans that would be required under proposed 45 CFR 164.312(h)(2)(i), the monitoring of authoritative sources that would be required under proposed 45 CFR 164.312(h)(2)(ii), and penetration tests proposed at 45 CFR 164.312(h)(2)(iii). The proposal would require that such actions be taken within a reasonable and appropriate period of time, except to the extent that an exception in proposed paragraph (h)(2)(ii)(D) applies. Specifically, a reasonable and appropriate period of time to patch, update, or upgrade the configuration of a relevant electronic information system would be within 15 calendar days of identifying the need to address a critical risk where a patch, update, or upgrade is available; or, where a patch, update, or upgrade is not available, within 15 calendar days of a patch, update, or upgrade becoming available. The proposal would require that, within 30 calendar days of identifying the need to address a high risk,
                        <SU>498</SU>
                        <FTREF/>
                         a regulated entity patch, update, or upgrade the configuration of a relevant electronic information system where a patch, update, or upgrade is available; or, where a patch, update, or upgrade is not available, within 30 calendar days of a patch, update, or upgrade becoming available. For all other patches, updates, or upgrades to the configurations of relevant electronic information systems, a reasonable and appropriate period of time would be determined by the regulated entity's written policies and procedures for identifying, prioritizing, acquiring, installing, evaluating, and verifying the timely installation of patches, updates, and upgrades.
                    </P>
                    <FTNT>
                        <P>
                            <SU>498</SU>
                             An explanation of risk rating is provided above in the discussion of the proposed standard for risk analysis and associated implementation specifications.
                        </P>
                    </FTNT>
                    <P>
                        For the proposed exceptions to apply, we propose in proposed paragraph (a)(4)(ii)(D) that a regulated entity would be required to document that an exception applies and that all other applicable conditions are met. The first proposed exception in proposed 45 CFR 164.308(a)(4)(ii)(D)(
                        <E T="03">1</E>
                        ) would be for when a patch, update, or upgrade to the configuration of a relevant electronic information system is not available to address a risk identified in the regulated entity's risk analysis. The second proposed exception would be in proposed 45 CFR 164.308(a)(4)(ii)(D)(
                        <E T="03">2</E>
                        ) for when the only available patch, update, or upgrade would adversely affect the confidentiality, integrity, or availability of ePHI. The Department anticipates that this proposed exception would apply when a regulated entity tests a patch, update, or upgrade and determines that it would adversely affect the confidentiality, integrity, or availability of ePHI or where there are reports from government sources or persons with appropriate knowledge of an experience with generally accepted cybersecurity principles and methods for ensuring the confidentiality, integrity, and availability of ePHI indicating that the patch, update, or 
                        <PRTPAGE P="944"/>
                        upgrade is likely to adversely affect the confidentiality, integrity, or availability of ePHI.
                    </P>
                    <P>In proposed paragraph (a)(4)(ii)(E), the Department proposes to require a regulated entity document in real-time the existence of the applicable exception and to implement reasonable and appropriate compensating controls. Similarly, in proposed paragraph (a)(4)(ii)(F), we propose that, where an exception applies, a regulated entity would be required to implement reasonable and appropriate security measures as compensating controls to address the identified risk according to the timeliness requirements in proposed 45 CFR 164.308(a)(5)(ii)(D) until such time as a patch, update, or upgrade that does not adversely affect the confidentiality, integrity, or availability of ePHI becomes available.</P>
                    <P>
                        This proposed standard aligns with the Department's enhanced CPG for Cybersecurity Mitigation by quickly requiring a regulated entity to prioritize and mitigate vulnerabilities discovered by vulnerability scanning and penetration testing.
                        <SU>499</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>499</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">g. Section 164.308(a)(5)(i)—Standard: Risk Management</HD>
                    <P>The Department proposes to elevate the implementation specification for risk management to a standard at proposed 45 CFR 164.308(a)(5)(i). This proposed standard would require a regulated entity to establish and implement a plan for reducing the risks identified through its risk analysis activities. Specifically, it would require a regulated entity to implement security measures sufficient to reduce risks and vulnerabilities to all ePHI to a reasonable and appropriate level. What would constitute a reasonable and appropriate level depends on the regulated entity's specific circumstances, including but not limited to its size, needs and capabilities, risk profile, the ability of security measures to reduce or eliminate a particular identified risk or vulnerability, and the ubiquity of such security measures. We also propose four implementation specifications that would require regulated entities to engage in activities that are consistent with previously issued guidance described below.</P>
                    <P>
                        Under the proposed implementation specification for planning at proposed paragraph (a)(5)(ii)(A), a regulated entity would be required to establish and implement a written risk management plan for reducing risks to all ePHI, including, but not limited to, those risks identified by the regulated entity's risk analysis,
                        <SU>500</SU>
                        <FTREF/>
                         to a reasonable and appropriate level. Proposed paragraph (a)(5)(i)(B) contains the proposed implementation specification for maintenance and would require the regulated entity to review the written risk management plan at least once every 12 months, and as reasonable and appropriate in response to changes in its risk analysis. The Department would interpret “reasonable and appropriate” in both paragraphs as requiring the regulated entity to take into account not only its specific circumstances, but also the criticality of the risks identified. We propose an implementation specification for priorities at proposed 45 CFR 164.308(a)(5)(ii)(C) that would require a regulated entity's written risk management plan to prioritize the risks identified in the regulated entity's risk analysis based on the risk levels determined by that analysis. Finally, in the proposed implementation specification for implementation at proposed 45 CFR 164.308(a)(5)(ii)(D), we propose to require that a regulated entity implement security measures in a timely manner to address the risks identified in the regulated entity's risk analysis in accordance with the priorities established under paragraph (a)(5)(ii)(C). The proposed risk management standard aligns with the Department's essential CPG to Mitigate Known Vulnerabilities.
                        <SU>501</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>500</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(2).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>501</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <P>
                        The Department previously issued guidance on risk management, including links to NIST resources, that is consistent with what we propose in this NPRM.
                        <SU>502</SU>
                        <FTREF/>
                         We encourage regulated entities to refer to similar NIST guidance for descriptions of risk management activities.
                        <SU>503</SU>
                        <FTREF/>
                         The results of a risk analysis, performed in accordance with the proposed standard for risk analysis, generally provide the regulated entity with a list of applicable “threat/vulnerability pairs” as well as the overall “risk rating” of each pair to the confidentiality, integrity, and availability of ePHI.
                        <SU>504</SU>
                        <FTREF/>
                         For example, some threat/vulnerability pairs may result in a risk rating of moderate or high level of risk to ePHI, while other pairs may result in a risk rating of low level of risk. The regulated entity would need to determine what risk rating poses an unacceptable level of risk to ePHI and address any threat/vulnerability pairs that indicate a risk rating above the organization's risk tolerance.
                        <SU>505</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>502</SU>
                             
                            <E T="03">See</E>
                             “6 Basics of Risk Analysis and Risk Management,” HIPAA Security Series, Volume 2, Paper 6, Centers for Medicare &amp; Medicaid Services (June 2005, revised Mar. 2007), 
                            <E T="03">https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/administrative/securityrule/riskassessment.pdf?language=es.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>503</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>504</SU>
                             
                            <E T="03">See id.</E>
                             at 18.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>505</SU>
                             
                            <E T="03">See id.</E>
                             at 25.
                        </P>
                    </FTNT>
                    <P>
                        Under this proposed standard, the regulated entity would be required to reduce the risks to its ePHI to a level that is reasonable and appropriate for its specific circumstances. Ultimately, the regulated entity's risk assessment processes should inform its decisions about the manner in which it will implement security measures to comply with the Security Rule's standards and implementation specifications.
                        <SU>506</SU>
                        <FTREF/>
                         Additionally, each regulated entity would be required to document the security controls it has implemented because it has determined them to be reasonable and appropriate, including analyses, decisions, and the rationale for decisions made to refine or adjust the security controls.
                        <SU>507</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>506</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>507</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.306(d) and 164.316(b)(1).
                        </P>
                    </FTNT>
                    <P>
                        As stated by NIST, “the documentation and retention of risk assessment and risk management activities” is “important for future risk management efforts.” 
                        <SU>508</SU>
                        <FTREF/>
                         In general, risk management activities “should be performed with regular frequency to examine past decisions, reevaluate risk likelihood and impact levels, and assess the effectiveness of past remediation efforts.” 
                        <SU>509</SU>
                        <FTREF/>
                         Risk management plans should address risk appetite, risk tolerance, workforce duties, responsible parties, the frequency of risk management, and required documentation.
                        <SU>510</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>508</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461, p. 27.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>509</SU>
                             
                            <E T="03">See id.</E>
                             at 31.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>510</SU>
                             
                            <E T="03">See id.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">h. Section 164.308(a)(6)(i)—Standard: Sanction Policy</HD>
                    <P>
                        Consistent with other proposals to elevate certain critical implementation specifications to standards, we propose to elevate the implementation specification for sanction policy at 45 CFR 164.308(a)(ii)(C) to a standard for sanction policy at proposed 45 CFR 164.308(a)(6)(i). We propose this standard because applying appropriate sanctions against workforce members who fail to comply with security requirements, and thus imperil the 
                        <PRTPAGE P="945"/>
                        security of ePHI, serves as an important tool for improving compliance by other workforce members with the regulated entity's safeguards for ePHI. While the Department does not propose to modify the language of the standard, we are proposing three implementation specifications that are consistent with guidance that was previously issued by the Department.
                    </P>
                    <P>Specifically, under the proposed implementation specification for policies and procedures at proposed 45 CFR 164.308(a)(6)(ii)(A), a regulated entity would be required to establish written policies and procedures for sanctioning workforce members who fail to comply with the regulated entity's security policies and procedures. The proposed implementation specification for modifications at paragraph (a)(6)(ii)(B) would require a regulated entity to review its written sanctions policies and procedures at least once every 12 months, and, based on that review, modify such policies and procedures as reasonable and appropriate. The proposed implementation specification for application at proposed paragraph (a)(6)(ii)(C) would direct a regulated entity to apply appropriate sanctions against workforce members who fail to comply with such security policies and procedures and to document when it sanctions a workforce member and the circumstances in which it applies such sanctions.</P>
                    <P>
                        The policy choices represented in this NPRM are informed by the compliance challenges OCR has observed through its enforcement activities. These challenges demonstrate that regulated entities would benefit from greater precision and clarity about their legal obligations in the proposed standard. Additionally, according to a recent survey of IT and IT security practitioners in healthcare, careless users were the top cause of data loss and exfiltration, while accidental loss was the second highest cause. Thirty-one percent of respondents indicated that the data loss or exfiltration was caused by a failure of workforce members to follow organizational policies.
                        <SU>511</SU>
                        <FTREF/>
                         As described in existing Department guidance, an organization's sanction policies can be an important tool for supporting accountability and improving cybersecurity and data protection.
                        <SU>512</SU>
                        <FTREF/>
                         Sanction policies can be used to address the intentional actions of malicious insiders, such as a workforce member that accesses the ePHI of a public figure or steals ePHI to sell as part of an identity-theft ring, as well as the failure of workforce members to comply with policies and procedures, such as failing to secure data on a network server or investigate a potential security incident.
                    </P>
                    <FTNT>
                        <P>
                            <SU>511</SU>
                             “The 2024 Study on Cyber Insecurity in Health Care: The Cost and Impact on Patient Safety and Care,” 
                            <E T="03">supra</E>
                             note 143, p. 7.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>512</SU>
                             
                            <E T="03">See</E>
                             “How Sanction Policies Can Support HIPAA Compliance,” Cybersecurity Newsletter, Office for Civil Rights, U.S. Department of Health and Human Services (Oct. 2023), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity-newsletter-october-2023/index.html#ftn10.</E>
                        </P>
                    </FTNT>
                    <P>
                        Sanction policies that are appropriately applied can improve a regulated entity's general compliance with the HIPAA Rules. Imposing consequences on workforce members who violate a regulated entity's policies and procedures implemented as required by the Security Rule or the HIPAA Rules generally can be effective in creating a culture of HIPAA compliance and improved cybersecurity. Knowledge that there is a negative consequence to noncompliance enhances the likelihood of compliance.
                        <SU>513</SU>
                        <FTREF/>
                         Training workforce members on a regulated entity's sanction policy can also promote compliance and greater cybersecurity vigilance by informing workforce members in advance which actions are prohibited and punishable.
                        <SU>514</SU>
                        <FTREF/>
                         A sanction policy that clearly communicates a regulated entity's expectations should ensure that workforce members understand their individual compliance obligations and consequences of noncompliance.
                    </P>
                    <FTNT>
                        <P>
                            <SU>513</SU>
                             68 FR 8334, 8347 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>514</SU>
                             65 FR 82462, 82747 (Dec. 28, 2000).
                        </P>
                    </FTNT>
                    <P>
                        Regulated entities have the flexibility to implement the standard in a manner consistent with numerous factors, including but not limited to their size, degree of risk, and environment. The HIPAA Rules do not require regulated entities to impose any specific penalty for any particular violation, nor do they require regulated entities to implement any particular methodology for sanctioning workforce members. Rather, in any particular case, each regulated entity must determine the type, cause, and severity of sanctions imposed based upon its policies and the relative severity of the violation.
                        <SU>515</SU>
                        <FTREF/>
                         A regulated entity may structure its sanction policies in the manner most suitable to its organization. As described in previously issued guidance materials from the Department and NIST, regulated entities should consider the following when drafting or revising their sanction policies:
                    </P>
                    <FTNT>
                        <P>
                            <SU>515</SU>
                             68 FR 8334, 8347 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <P>
                        • Documenting or implementing sanction policies pursuant to a formal process.
                        <SU>516</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>516</SU>
                             65 FR 82462, 82562 (Dec. 28, 2000).
                        </P>
                    </FTNT>
                    <P>
                        • Requiring workforce members to affirmatively acknowledge that a violation of the organization's HIPAA policies or procedures may result in sanctions.
                        <SU>517</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>517</SU>
                             
                            <E T="03">See</E>
                             “Security Standards: Administrative Safeguards,” HIPAA Security Series, Volume 2, Paper 2, Centers for Medicare &amp; Medicaid Services (May 2005, revised Mar. 2007), 
                            <E T="03">https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/administrative/securityrule/adminsafeguards.pdf; see also</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461, p. 33.
                        </P>
                    </FTNT>
                    <P>
                        • Documenting the sanction process, including the personnel involved, the procedural steps, the time-period, the reason for the sanction(s), and the final outcome of an investigation.
                        <SU>518</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>518</SU>
                             Records of sanction activity should be retained for at least six years. 
                            <E T="03">See</E>
                             45 CFR 164.316 and 164.530(e)(2).
                        </P>
                    </FTNT>
                    <P>
                        • Creating sanctions that are “appropriate to the nature of the violation.” 
                        <SU>519</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>519</SU>
                             
                            <E T="03">See</E>
                             65 FR 82462, 82562 (Dec. 28, 2000).
                        </P>
                    </FTNT>
                    <P>
                        • Creating sanctions that “vary depending on factors such as the severity of the violation, whether the violation was intentional or unintentional, and whether the violation indicated a pattern or practice of improper use or disclosure of [PHI].” 
                        <SU>520</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>520</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        • Creating sanctions that “range from a warning to termination.” 
                        <SU>521</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>521</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        • Providing examples “of potential violations of policy and procedures.” 
                        <SU>522</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>522</SU>
                             
                            <E T="03">See</E>
                             “Security Standards: Administrative Safeguards,” 
                            <E T="03">supra</E>
                             note 517.
                        </P>
                    </FTNT>
                    <P>
                        Generally, it is important for a regulated entity to consider whether its sanction policies align with its general disciplinary policies, and how the individuals or departments involved in the sanction processes can work in concert, when appropriate. Regulated entities may also want to consider how sanction policies can be fairly and consistently applied throughout the organization, to all workforce members, including management.
                        <SU>523</SU>
                        <FTREF/>
                         The deterrent effect of penalizing noncompliance and misconduct paired with clear communications about the consequences of noncompliance can promote greater compliance with the HIPAA Rules through accountability, understanding, and transparency.
                    </P>
                    <FTNT>
                        <P>
                            <SU>523</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.308(a)(1)(ii)(C), 164.530(e)(1); 
                            <E T="03">see also</E>
                             65 FR 82462, 82747 (Dec. 28, 2000) (“All members of a covered entity's workforce are subject to sanctions for violations.”).
                        </P>
                    </FTNT>
                    <PRTPAGE P="946"/>
                    <HD SOURCE="HD3">i. Section 164.308(a)(7)(i)—Standard: Information System Activity Review</HD>
                    <P>
                        As described in previously issued HHS guidance, review of activity in its relevant electronic information systems and their components, including workstations,
                        <SU>524</SU>
                        <FTREF/>
                         enables a regulated entity to determine if any ePHI has been used or disclosed in an inappropriate manner.
                        <SU>525</SU>
                        <FTREF/>
                         The procedures should be customized to meet the regulated entity's risk management strategy and consider the capabilities of all information systems with ePHI.
                        <SU>526</SU>
                        <FTREF/>
                         These activities should also promote continual awareness of any information system activity that could suggest a security incident.
                        <SU>527</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>524</SU>
                             Workstations may also be referred to as “endpoints.” 
                            <E T="03">See</E>
                             “Memorandum on Improving Detection of Cybersecurity Vulnerabilities and Incidents on Federal Government Systems through Endpoint Detection and Response,” Office of Management and Budget, Executive Office of the President, p. 1 (Oct. 8, 2021) 
                            <E T="03">https://www.whitehouse.gov/wp-content/uploads/2021/10/M-22-01.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>525</SU>
                             
                            <E T="03">See</E>
                             “Security Standards: Administrative Safeguards,” 
                            <E T="03">supra</E>
                             note 517, p. 5-6.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>526</SU>
                             
                            <E T="03">See id.</E>
                             at 6.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>527</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Detecting and preventing data leakage initiated by malicious authorized users is a significant challenge.
                        <SU>528</SU>
                        <FTREF/>
                         Identifying potential malicious activity in relevant electronic information systems, including in workstations and other components, as soon as possible is key to preventing or mitigating the impact of such activity.
                        <SU>529</SU>
                        <FTREF/>
                         To identify potential suspicious activity, organizations should consider an insider's interactions with information systems and their components. A regulated entity can detect anomalous user behavior or indicators of misuse by either a trusted employee or third-party vendor who has access to critical systems, workstations and other system components, and data.
                        <SU>530</SU>
                        <FTREF/>
                         To minimize this risk, an organization may employ safeguards that detect suspicious user activities, such as traffic to an unauthorized website, downloading data to an external device (
                        <E T="03">e.g.,</E>
                         thumb drive), or access to a network server by an unauthorized mobile device. Maintaining audit controls (
                        <E T="03">e.g.,</E>
                         system event logs, application audit logs) and regularly reviewing audit logs, access reports, and security incident tracking reports are important security measures that can assist in detecting and identifying suspicious activity or unusual patterns of data access.
                        <SU>531</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>528</SU>
                             
                            <E T="03">See</E>
                             “Managing Malicious Insider Threats,” Cybersecurity Newsletter, Office for Civil Rights, U.S. Department of Health and Human Services (Aug. 2019), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity-newsletter-summer-2019/index.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>529</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>530</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>531</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Regulated entities should regularly review activity in their relevant electronic information systems (including the components of such systems) for potential concerns and consider ways to automate such reviews.
                        <SU>532</SU>
                        <FTREF/>
                         Additionally, regulated entities are responsible for establishing and implementing appropriate standard operating procedures, including determining the types of audit trail data and monitoring procedures that would be needed to derive exception reports.
                        <SU>533</SU>
                        <FTREF/>
                         They also must activate the necessary review processes and maintain auditing and logging activity.
                        <SU>534</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>532</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461, p. 33.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>533</SU>
                             
                            <E T="03">See id.</E>
                             at 34.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>534</SU>
                             
                            <E T="03">See id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Department and NIST guidance advise regulated entities to consider many questions when establishing their policies and procedures for reviewing activity in their relevant electronic information systems review.
                        <SU>535</SU>
                        <FTREF/>
                         These include:
                    </P>
                    <FTNT>
                        <P>
                            <SU>535</SU>
                             
                            <E T="03">See</E>
                             “Security Standards: Administrative Safeguards,” 
                            <E T="03">supra</E>
                             note 517, p. 7; 
                            <E T="03">see also</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461, p. 30-34.
                        </P>
                    </FTNT>
                    <P>• What logs or reports are generated by the information systems?</P>
                    <P>• Is there a policy that establishes what reviews will be conducted?</P>
                    <P>• Are there corresponding procedures that describe the specifics of the reviews?</P>
                    <P>• Who is responsible for the overall process and results?</P>
                    <P>• How often will review results be analyzed?</P>
                    <P>
                        • Where will audit information reside (
                        <E T="03">e.g.,</E>
                         separate server)? Will it be stored external to the organization (
                        <E T="03">e.g.,</E>
                         cloud service provider)?
                    </P>
                    <P>
                        Compliance challenges observed through OCR's enforcement activities suggest that regulated entities would benefit from an expanded standard to provide more details on compliance expectations. Investigations of reported breaches of unsecured PHI discussed above as examples of risk analysis failures also identified a potential failure by the regulated entities to conduct appropriate information system activity review.
                        <SU>536</SU>
                        <FTREF/>
                         In an investigation involving a large health care provider, the ePHI of more than 12,000 patients was sold to an identity theft ring by employees who, for six months, inappropriately accessed patient account information.
                        <SU>537</SU>
                        <FTREF/>
                         Compliance with the requirement to implement procedures to regularly review records of activity in relevant electronic information systems, such as audit logs, access reports, and security incident tracking, could have identified and mitigated these disclosures.
                        <SU>538</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>536</SU>
                             
                            <E T="03">See</E>
                             Press Release, “HHS Office for Civil Rights Settles HIPAA Security Rule Failures for $950,000,” U.S. Department of Health and Human Services (July 1, 2024), 
                            <E T="03">https://prod-wwwhhsgov.cloud.hhs.gov/about/news/2024/07/01/hhs-office-civil-rights-settles-hipaa-security-rule-failures-950000.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>537</SU>
                             
                            <E T="03">See</E>
                             “Montefiore Medical Center,” 
                            <E T="03">supra</E>
                             note 248.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>538</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.308(a)(1)(ii)(D).
                        </P>
                    </FTNT>
                    <P>
                        Similarly, a business associate experienced an intrusion into its systems that it failed to notice for over 20 months. Eventually, the ePHI of more than 200,000 individuals associated with several covered entities was encrypted in a ransomware cyberattack.
                        <SU>539</SU>
                        <FTREF/>
                         Among other factors, OCR's investigation indicated that the business associate potentially failed to implement procedures for regularly reviewing records of activity in its relevant electronic information system, such as audit logs, access reports, and security incident tracking reports.
                        <SU>540</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>539</SU>
                             
                            <E T="03">See</E>
                             “Doctors' Management Services, Inc.,” 
                            <E T="03">supra</E>
                             note 246.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>540</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Consistent with previously issued guidance and based on OCR's enforcement experience, the Department proposes to elevate the existing implementation specification for information system activity review to a standard and to redesignate it as proposed 45 CFR 164.308(a)(7)(i). The purpose of the proposal is to impose specific requirements on a regulated entity to review the activity occurring in its relevant electronic information systems, including the activity occurring in the components of such systems. By virtue of these proposed requirements, we would specify actions that a regulated entity is required to take to ensure that only appropriate users access ePHI and that it responds quickly to any suspicious activity in its relevant electronic information systems, including in components thereof, such as workstations that connect to or otherwise access its relevant electronic information systems. We also propose to revise the language to provide regulated entities with additional direction regarding their review of suspicious activities. The proposed standard, if adopted, would require a regulated entity to implement written policies and procedures for regularly reviewing 
                        <PRTPAGE P="947"/>
                        records of activity in its relevant electronic information systems.
                    </P>
                    <P>
                        The Department proposes five implementation specifications for the proposed standard for information system activity review. The proposed implementation specification for policies and procedures at proposed 45 CFR 164.308(a)(7)(ii)(A) would require a regulated entity to establish written policies and procedures for retaining and reviewing records of activity in the regulated entity's relevant electronic information systems by persons and technology assets. Such written policies and procedures should require review of activity in the regulated entity's relevant electronic information systems as a whole, as well as the system's components, including but not limited to any workstations. They should also include information on the frequency for reviewing such records. The frequency of review may vary based on the specific type of record being reviewed and the information it contains. According to the proposed implementation specification for scope at proposed 45 CFR 164.308(a)(7)(ii)(B), records of activity in the regulated entity's relevant electronic information systems by persons and technology assets would include, but would not be limited to, audit trails, event logs, firewall logs, system logs, data backup logs, access reports, anti-malware logs, and security incident tracking reports. The proposed implementation specification for records review at proposed 45 CFR 164.308(a)(7)(ii)(C) would require a regulated entity to review records of activity in its relevant electronic information systems by persons and technology assets as often as reasonable and appropriate for the type of report or log. They would also be required to document such review. A proposed implementation specification for record retention at proposed 45 CFR 164.308(a)(7)(ii)(D) would require a regulated entity to retain records of activity in its relevant electronic information systems by persons and technology assets. Under the proposal, the regulated entity would be required to retain such records for an amount of time that is reasonable and appropriate for the specific type of report or log. For example, it may be reasonable and appropriate to retain audit trails for a different amount of time than security incident tracking reports because of the type of information they contain and their purpose. The proposed implementation specification for response at proposed 45 CFR 164.308(a)(7)(ii)(E) would require a regulated entity to respond to a suspected or known security incident identified during the review of activity in its relevant electronic information systems, including any components thereof, such as workstations, in accordance with the regulated entity's security incident plan.
                        <SU>541</SU>
                        <FTREF/>
                         Finally, the proposed implementation specification for maintenance at proposed 45 CFR 164.308(a)(7)(ii)(F) would require a regulated entity to review and test its written policies and procedures for reviewing activity in its relevant electronic information systems at least once every 12 months. The regulated entity would be expected to modify such policies and procedures as reasonable and appropriate, based on the results of that review.
                    </P>
                    <FTNT>
                        <P>
                            <SU>541</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(12)(ii)(B).
                        </P>
                    </FTNT>
                    <P>Consider a large regulated entity that may have thousands of workforce members accessing various networks and relevant electronic information systems, generating large amounts of log and audit data. Given the size, complexity, and capabilities of entities of such size, a reasonable and appropriate process for reviewing activity may include the adoption of an automated solution that performs rules-based enterprise log aggregation and analysis to identify anomalous or suspicious patterns of behavior in the regulated entity's relevant electronic information systems and the components thereof, including but not limited to workstations, in real-time and sends alerts of potential security incidents to a workforce member or team for further review and action. By contrast, for a small regulated entity, it might be reasonable and appropriate to have designated staff that manually review log files and audit trails multiple times per week.</P>
                    <HD SOURCE="HD3">j. Section 164.308(a)(8)—Standard: Assigned Security Responsibility</HD>
                    <P>The Department proposes to redesignate the standard for assigned security responsibility at 45 CFR 164.308(a)(2) as proposed 45 CFR 164.308(a)(8). OCR's enforcement experience demonstrates that, in practice, many regulated entities follow informal policies and procedures that are not documented, and have not documented the identification of the Security Official in writing.</P>
                    <P>Based on OCR's enforcement experience, and consistent with existing guidance, we propose to modify the standard to specify that a regulated entity must identify in writing the Security Official who is responsible for the establishment and implementation of the policies and procedures, whether written or otherwise, and deployment of technical controls. These proposals are consistent with our general intention in this NPRM to propose to clarify that policies and procedures required by the Security Rule should be reduced to writing and to distinguish between the implementation of written policies and procedures and the deployment of technical controls.</P>
                    <P>
                        As we previously explained in guidance,
                        <SU>542</SU>
                        <FTREF/>
                         the purpose of this standard is to identify who would be operationally responsible for assuring that the regulated entity complies with the Security Rule. It is comparable to the Privacy Rule standard for personnel designations at 45 CFR 164.530(a)(1), which requires all covered entities to designate a Privacy Official. The Security Official and Privacy Official can, but need not be, the same person. While one workforce member must be designated as having overall responsibility, other workforce members may be assigned specific security responsibilities (
                        <E T="03">e.g.,</E>
                         facility security, network security). When making this decision, regulated entities should consider basic questions, such as: Has the organization agreed upon, and clearly identified and documented, the responsibilities of the Security Official? How are the roles and responsibilities of the Security Official crafted to reflect the size, complexity, and technical capabilities of the organization?
                    </P>
                    <FTNT>
                        <P>
                            <SU>542</SU>
                             
                            <E T="03">See</E>
                             “Security Standards: Administrative Safeguards,” 
                            <E T="03">supra</E>
                             note 517, p. 7.
                        </P>
                    </FTNT>
                    <P>
                        NIST guidance urges the regulated entity to select a workforce member who is able to assess the effectiveness of security to serve as the point of contact for security policy, implementation, and monitoring.
                        <SU>543</SU>
                        <FTREF/>
                         It further recommends that a regulated entity should document the responsibilities in a job description and communicate this assigned role to the entire organization. NIST provides additional sample items for consideration by a regulated entity organizing its security practices, including identifying the workforce members in the organization who oversee the development and communication of security policies and procedures, direct IT security purchasing and investment, and ensure that security concerns have been addressed in system implementation. NIST also offers that a regulated entity should ask whether the security official has adequate access and communications with senior officials in the organization and whether there is a 
                        <PRTPAGE P="948"/>
                        complete job description that accurately reflects assigned security duties and responsibilities.
                    </P>
                    <FTNT>
                        <P>
                            <SU>543</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">k. Section 164.308(a)(9)(i)—Standard: Workforce Security</HD>
                    <P>The purpose of the workforce security standard is to ensure that workforce members only have access to ePHI that they need to perform their assigned functions and are prevented from accessing ePHI that they are not authorized to access to perform such functions. The proposed changes to the standard and implementation specifications would clarify the actions required of a regulated entity to assure such limits.</P>
                    <P>
                        Individuals have been harmed in the past by the failure of regulated entities to comply with the Security Rule requirements for workforce security. For example, a former employee of a large covered entity was able to access their former worksite and workstation using still-active credentials for more than a week after their employment was terminated.
                        <SU>544</SU>
                        <FTREF/>
                         OCR's investigation found evidence of a potential failure to terminate the former employee's access to PHI, which enabled the former employee to download the ePHI of nearly 500 individuals, including their names, addresses, dates of birth, race/ethnicity, gender, and sexually transmitted infection test results onto a USB drive. This type of real-world experience and OCR's observations more broadly inform the changes proposed in this NPRM.
                    </P>
                    <FTNT>
                        <P>
                            <SU>544</SU>
                             
                            <E T="03">See</E>
                             Press Release, “City Health Department failed to terminate former employee's access to protected health information,” U.S. Department of Health and Human Services (Oct. 30, 2020), 
                            <E T="03">https://public3.pagefreezer.com/content/HHS.gov/31-12-2020T08:51/https://www.hhs.gov/about/news/2020/10/30/city-health-department-failed-terminate-former-employees-access-protected-health-information.html.</E>
                        </P>
                    </FTNT>
                    <P>
                        Moreover, this proposal is consistent with guidance issued by HHS and NIST for implementing this standard and associated implementation specifications. For example, in guidance issued in 2005, we explained that regulated entities must identify workforce members who need access to ePHI to carry out their duties.
                        <SU>545</SU>
                        <FTREF/>
                         For each workforce member or job function, the regulated entity must identify the ePHI that is needed, when it is needed, and make reasonable efforts to control access to the ePHI, a concept generally referred to as role-based access (
                        <E T="03">i.e.,</E>
                         authorizing access to ePHI only when such access is appropriate based on the workforce member's role).
                        <SU>546</SU>
                        <FTREF/>
                         This also includes identification of the computer systems and applications that provide access to the ePHI. A regulated entity must provide only the minimum necessary access to ePHI that is required for a workforce member to do their job.
                        <SU>547</SU>
                        <FTREF/>
                         As described in HHS guidance, access authorization is the process of determining whether a particular user (or a computer system) has the right, consistent with their function, to carry out a certain activity, such as reading a file or running a program.
                        <SU>548</SU>
                        <FTREF/>
                         Implementation may vary among regulated entities, depending on the size and complexity of their workforce, and their electronic information systems that contain ePHI. For example, in a small medical practice, all staff members may need to access all ePHI in their information systems because each staff member may perform multiple functions. In this case, the regulated entity would document the reasons for implementing policies and procedures that permit this type of global access. If the documented rationale is reasonable and appropriate, this may be an acceptable approach. The implementation specification provision for authorization and/or supervision provides the necessary checks and balances to ensure that all members of the workforce have appropriate access (or, in some cases, no access) to ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>545</SU>
                             
                            <E T="03">See</E>
                             “Security Standards: Administrative Safeguards,” 
                            <E T="03">supra</E>
                             note 517, p. 8-11.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>546</SU>
                             
                            <E T="03">See</E>
                             “Summary of the HIPAA Security Rule,” U.S. Department of Health and Human Services (Oct. 19, 2022), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>547</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.502(b) and 164.514(d).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>548</SU>
                             
                            <E T="03">See</E>
                             “Security Standards: Administrative Safeguards,” 
                            <E T="03">supra</E>
                             note 517, p. 9.
                        </P>
                    </FTNT>
                    <P>
                        NIST guidance provides descriptions of key activities and sample questions for regulated entities implementing this implementation specification.
                        <SU>549</SU>
                        <FTREF/>
                         To implement procedures for the authorization and/or supervision of workforce members who work with ePHI or in locations where it might be accessed, the guidance advises regulated entities to consider whether chains of command and lines of authority have been established, as well as the identity and roles of supervisors. A regulated entity also should establish clear job descriptions and responsibilities, which includes defining roles and responsibilities for all job functions; assigning appropriate levels of security oversight, training, and access; and identifying in writing who has the business need and who has been granted permission to view, alter, retrieve, and store ePHI and at what times, under what circumstances, and for what purposes.
                        <SU>550</SU>
                        <FTREF/>
                         To determine the most reasonable and appropriate authorization and/or supervision procedures, a regulated entity must be able to answer some basic questions about existing policies and procedures. For example, are detailed job descriptions used to determine what level of access the person holding the position should have to ePHI? Who has or should have the authority to determine who can access ePHI, 
                        <E T="03">e.g.,</E>
                         supervisors or managers? Are there written job descriptions that are correlated with appropriate levels of access to ePHI? Are these job descriptions reviewed and updated on a regular basis? Have workforce members been provided copies of their job descriptions and informed of the access granted to them, as well as the conditions by which this access can be used? As noted above, a smaller regulated entity may address compliance by implementing a simpler approach, but it is still liable for ensuring that workforce members only have access to ePHI that they need to perform their assigned functions.
                        <SU>551</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>549</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>550</SU>
                             
                            <E T="03">See id.</E>
                             at 36.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>551</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(9)(i).
                        </P>
                    </FTNT>
                    <P>
                        NIST also recommends establishing criteria and procedures for hiring and assigning tasks and ensuring that these requirements are included as part of the personnel hiring process.
                        <SU>552</SU>
                        <FTREF/>
                         In its guidance, NIST provides questions and suggestions for regulated entities to consider with respect to these criteria, procedures, and requirements. NIST guidance also describes this implementation specification as calling for regulated entities to implement appropriate screening of persons who would have access to ePHI, and a procedure for obtaining clearance from appropriate offices or workforce members where access is provided or terminated.
                        <SU>553</SU>
                        <FTREF/>
                         Similarly, the Department's guidance on workforce clearance procedures states that the clearance process must establish the procedures to verify that a workforce member would in fact have the appropriate access for their job function.
                        <SU>554</SU>
                        <FTREF/>
                         A regulated entity may choose to perform this type of screening procedure separate from, or as a part of, the authorization and/or supervision procedure. Sample questions for 
                        <PRTPAGE P="949"/>
                        regulated entities to consider include the following: Are there existing procedures for determining that the appropriate workforce members have access to the necessary information? Are the procedures used consistently within the organization when determining access of related workforce job functions? NIST guidance describes this implementation specification as calling for regulated entities to implement appropriate screening of persons who would have access to ePHI, and a procedure for obtaining clearance from appropriate offices or workforce members where access is provided or terminated.
                        <SU>555</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>552</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461, p. 36.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>553</SU>
                             
                            <E T="03">See id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>554</SU>
                             
                            <E T="03">See</E>
                             “Security Standards: Administrative Safeguards,” 
                            <E T="03">supra</E>
                             note 517, p. 10.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>555</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461, p. 37.
                        </P>
                    </FTNT>
                    <P>
                        We issued guidance in 2017 addressing termination procedures.
                        <SU>556</SU>
                        <FTREF/>
                         Data breaches caused by current and former workforce members are a recurring issue across many industries, including the health care industry. Effective identity and access management policies and controls are essential to reduce the risks posed by these types of insider threats. Identity and access management can include many processes, but, most commonly, it would include the processes by which appropriate access to data is granted and terminated by creating and managing user accounts. Ensuring that user accounts are terminated—and in a timely manner—so that former workforce members do not have access to data, is one important way identity and access management can help reduce risks posed by insider threats. Additionally, effective termination procedures also reduce the risk that inactive user accounts (
                        <E T="03">e.g.,</E>
                         user accounts that are not being used or are inactive but are not fully terminated or disabled) could be used by a current or former workforce member with malicious motives to get access to ePHI. The Department's guidance also offers tips to prevent unauthorized access to PHI by former workforce members, such as having standard procedures of all action items to be completed when an individual leaves.
                        <SU>557</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>556</SU>
                             
                            <E T="03">See</E>
                             “Insider Threats and Termination Procedures,” Cybersecurity Newsletter, Office for Civil Rights, U.S. Department of Health and Human Services (Nov. 2017), 
                            <E T="03">https://www.hhs.gov/sites/default/files/november-cybersecurity-newsletter-11292017.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>557</SU>
                             
                            <E T="03">See</E>
                             “Managing Malicious Insider Threats,” 
                            <E T="03">supra</E>
                             note 528.
                        </P>
                    </FTNT>
                    <P>
                        Guidance that we issued in 2019 further explains that “security is a dynamic process.” 
                        <SU>558</SU>
                        <FTREF/>
                         Good security practices entail continuous awareness, assessment, and action in the face of changing circumstances. The information users can and should be allowed to access may change over time; organizations should recognize this in their policies and procedures and in their implementation of those policies and procedures. For example, if a user is promoted, demoted, or transfers to a different department, a user's need to access data may change. In such situations, the user's data access privileges should be re-evaluated and, as needed, modified to match the new role, if needed.
                        <SU>559</SU>
                        <FTREF/>
                         As described in other HHS guidance, these procedures should also address the complexity of the organization and the sophistication of its relevant electronic information systems.
                        <SU>560</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>558</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>559</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.308(a)(4)(ii)(C).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>560</SU>
                             
                            <E T="03">See</E>
                             “Security Standards: Administrative Safeguards,” 
                            <E T="03">supra</E>
                             note 517, p. 10-11.
                        </P>
                    </FTNT>
                    <P>
                        NIST guidance provides additional descriptions of key activities and sample questions for regulated entities to consider when implementing this standard and associated implementation specifications.
                        <SU>561</SU>
                        <FTREF/>
                         Regulated entities should establish a standard set of procedures that should be followed to recover access control devices (
                        <E T="03">e.g.,</E>
                         identification badges, keys, access cards) when employment ends and, likewise, they should timely deactivate computer access (
                        <E T="03">e.g.,</E>
                         disable user IDs and passwords) and facility access (
                        <E T="03">e.g.,</E>
                         change facility security codes/PINs). Sample questions for implementation include the following: Are there separate procedures for voluntary termination (
                        <E T="03">e.g.,</E>
                         retirement, promotion, transfer, change of employment) versus involuntary termination (
                        <E T="03">e.g.,</E>
                         termination for cause, reduction in force, involuntary transfer, criminal or disciplinary actions)? Is there a standard checklist for all action items that should be completed when a workforce member leaves (
                        <E T="03">e.g.,</E>
                         return of all access devices, deactivation of accounts, and delivery of any needed data solely under the workforce member's control)? Do other organizations need to be notified to deactivate accounts to which that the workforce member had access in the performance of their employment duties?
                    </P>
                    <FTNT>
                        <P>
                            <SU>561</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461.
                        </P>
                    </FTNT>
                    <P>However, regulated entities often do not establish or implement written procedures, nor, even in instances where they have established or implemented them, have they done so in an appropriate fashion to protect ePHI from improper access by current or former workforce members.</P>
                    <P>
                        Consistent with the guidance described above and other proposals in this NPRM, the Department proposes to redesignate the workforce security standard at 45 CFR 164.308(a)(3)(i) as proposed 45 CFR 164.308(a)(9)(i), to add a paragraph heading to clarify the organization of the regulatory text, and to modify the regulatory text clarify that a regulated entity must implement written policies and procedures ensuring that workforce members have appropriate access to ePHI and to relevant electronic information systems. The regulated entity must also implement written policies and procedures preventing workforce members from accessing ePHI and relevant electronic information systems if they are not authorized to do so. The modifications we propose to the implementation specification for authorization and/or supervision would clarify that a regulated entity is required to establish and implement written procedures for the authorization and/or supervision of workforce members who access ePHI or relevant electronic information systems or who work in facilities where ePHI or relevant electronic information systems might be accessed.
                        <SU>562</SU>
                        <FTREF/>
                         We propose similar modifications to the implementation specification for workforce clearance procedure, which would require a regulated entity to establish and implement written procedures to determine that the access of a workforce member to ePHI or relevant electronic information systems is appropriate, in accordance with written policies and procedures for granting and revising access to ePHI and relevant electronic information systems as required by proposed 45 CFR 164.308(a)(10)(ii)(B).
                        <SU>563</SU>
                        <FTREF/>
                         Additionally, we propose several clarifications to the implementation specification for termination procedures. Specifically, the proposed implementation specification for modification and termination procedures at proposed 45 CFR 164.308(a)(9)(ii)(C) would require procedures for terminating a workforce member's access to ePHI and relevant electronic information systems, and to facilities where ePHI or relevant electronic information systems might be accessed. Proposed paragraph (a)(9)(ii)(C)(
                        <E T="03">1</E>
                        ) would require a regulated entity to establish and implement written procedures for terminating a workforce member's access to ePHI and relevant electronic information systems, 
                        <PRTPAGE P="950"/>
                        and to locations where ePHI or relevant electronic information systems might be accessed. Proposed paragraph (a)(9)(ii)(C)(
                        <E T="03">2</E>
                        ) would require that the workforce member's access be terminated as soon as possible, but no later than one hour after the workforce member's employment or other arrangement ends. A proposed implementation specification for notification at proposed 45 CFR 164.308(a)(9)(ii)(D) would require a regulated entity to establish and implement written procedures for notifying another regulated entity of a change in, or termination of, a workforce member's authorization to access ePHI or relevant electronic information systems. Proposed paragraph (a)(9)(ii)(D)(
                        <E T="03">1</E>
                        ) would require the regulated entity to establish and implement written procedures for notifying another regulated entity after a change in or termination of a workforce member's authorization to access ePHI or relevant electronic information systems that are maintained by such other regulated entity where the workforce member is or was authorized to access such ePHI or relevant electronic information systems by the regulated entity making the notification. Proposed paragraph (a)(9)(ii)(D)(
                        <E T="03">2</E>
                        ) would require the notice to be provided as soon as possible, but no later than 24 hours after the workforce member's authorization to access ePHI or relevant electronic information systems is changed or terminated. Finally, a proposed new implementation specification for maintenance at proposed 45 CFR 164.308(a)(9)(ii)(E) would require a regulated entity to review and test its written workforce security policies and procedures at least once every 12 months and to modify them as reasonable and appropriate.
                        <SU>564</SU>
                        <FTREF/>
                         The proposed implementation specifications for termination procedures and notification implementation align with the Department's essential CPG for Revoke Credentials for Departing Workforce Members, Including Employees, Contractors, Affiliates, and Volunteers by requiring a regulated entity to promptly remove access following a change in or termination of a user's authorization to access ePHI.
                        <SU>565</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>562</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(9)(ii)(A).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>563</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(9)(ii)(B).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>564</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(9)(ii)(E).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>565</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">l. Section 164.308(a)(10)(i)—Standard: Information Access Management</HD>
                    <P>
                        The purpose of the standard for information access management is to protect ePHI by reducing the risk that other persons or technology assets may access the information for their own reasons. Existing HHS guidance explains that restricting access to only those persons and entities with a need for access is a basic tenet of security.
                        <SU>566</SU>
                        <FTREF/>
                         By implementing this standard, the risk of inappropriate disclosure, alteration, or destruction of ePHI is minimized. A regulated entity must determine those persons and technology assets that need access to ePHI within its environment. The implementation specifications associated with the standard on information access management are closely related to those associated with the standard for workforce security.
                        <SU>567</SU>
                        <FTREF/>
                         Compliance with the proposed and existing standards for information access management should support a regulated entity's compliance with the Privacy Rule's minimum necessary requirements, which requires a regulated entity to evaluate its practices and enhance safeguards as needed to limit unnecessary or inappropriate access to and disclosure of PHI.
                        <SU>568</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>566</SU>
                             
                            <E T="03">See</E>
                             “Security Standards: Administrative Safeguards,” 
                            <E T="03">supra</E>
                             note 517, p.11.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>567</SU>
                             
                            <E T="03">See, e.g.,</E>
                             Resolution Agreement, “Banner Health,” Office for Civil Rights, U.S. Department of Health and Human Services (Dec. 20, 2022), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/banner-health-ra-cap/index.html;</E>
                             “Montefiore Medical Center,” 
                            <E T="03">supra</E>
                             note 248.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>568</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.502(b) and 164.514(d).
                        </P>
                    </FTNT>
                    <P>
                        OCR's enforcement experience demonstrates that many regulated entities have not adequately implemented this standard. Thus, we believe it is necessary to consider strengthening the requirement. For example, on one occasion, a large covered entity's failure to implement its written policies and procedures to ensure that employees only had access to ePHI that they had proper authorization or authority to access enabled an employee to access the ePHI of more than 24,000 individuals.
                        <SU>569</SU>
                        <FTREF/>
                         This failure also enabled other employees to inappropriately access the ePHI of a celebrity.
                        <SU>570</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>569</SU>
                             
                            <E T="03">See</E>
                             Press Release, “OCR Imposes a $2.15 Million Civil Money Penalty against Jackson Health System for HIPAA Violation,” U.S. Department of Health and Human Services (Oct. 19, 2019), 
                            <E T="03">https://public3.pagefreezer.com/browse/HHS.gov/31-12-2020T08:51/https://www.hhs.gov/about/news/2019/10/23/ocr-imposes-a-2.15-million-civil-money-penalty-against-jhs-for-hipaa-violations.html; see also</E>
                             Notice of Proposed Determination, “Jackson Health System,” Office for Civil Rights, U.S. Department of Health and Human Services (July 22, 2019), 
                            <E T="03">https://public3.pagefreezer.com/browse/HHS.gov/31-12-2020T08:51/https://www.hhs.gov/sites/default/files/jackson-health-system-notice-of-final-determination_508.pdf;</E>
                             Notice of Final Determination, “Jackson Health System,” Office for Civil Rights, U.S. Department of Health and Human Services (Oct. 15, 2019), 
                            <E T="03">https://public3.pagefreezer.com/browse/HHS.gov/31-12-2020T08:51/https://www.hhs.gov/sites/default/files/jackson-health-system-notice-of-final-determination_508.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>570</SU>
                             
                            <E T="03">See</E>
                             Press Release, “HHS Office for Civil Rights Settles HIPAA Investigation with Arizona Hospital System Following Cybersecurity Hacking,” U.S. Department of Health and Human Services (Feb. 2, 2023), 
                            <E T="03">https://www.hhs.gov/about/news/2023/02/02/hhs-office-for-civil-rights-settles-hipaa-investigation-with-arizona-hospital-system.html.</E>
                        </P>
                    </FTNT>
                    <P>To ensure that regulated entities implement recommendations and best practices for securing ePHI, we propose to require in the standard for information access management and associated implementation specifications that a regulated entity must establish and implement written policies and procedures for authorizing access to ePHI and relevant electronic information systems that are consistent with the Privacy Rule. The Department also proposes to redesignate the standard at 45 CFR 164.308(a)(4)(i) as proposed 45 CFR 164.308(a)(10)(i) and to add a paragraph heading to clarify the organization of the regulatory text. Additionally, the Department proposes to modify three of the associated existing implementation specifications and to add three new implementation specifications as follows.</P>
                    <P>Specifically, the Department proposes to redesignate the implementation specification for isolating health care clearinghouse functions as proposed 45 CFR 164.308(a)(10)(ii)(A) and to modify it to require a health care clearinghouse that is part of a larger organization to establish and implement written policies and procedures that protect the ePHI and relevant electronic information systems of the clearinghouse from unauthorized access by the larger organization.</P>
                    <P>
                        The existing implementation specification for isolating health care clearinghouse functions only applies in the situation where a health care clearinghouse is part of a larger organization. This would remain true under the proposal to revise this implementation specification, if adopted. In these situations, the health care clearinghouse is responsible for protecting the ePHI that it is creating, receiving, maintaining, and transmitting. As discussed in NIST guidance, if a health care clearinghouse is part of a larger organization, the clearinghouse must implement policies and procedures that protect the ePHI of the clearinghouse from unauthorized access by the larger organization.
                        <SU>571</SU>
                        <FTREF/>
                         This necessarily includes its relevant electronic information systems. First, the regulated entity must determine 
                        <PRTPAGE P="951"/>
                        whether any of its components constitute a health care clearinghouse under the Security Rule.
                        <SU>572</SU>
                        <FTREF/>
                         If no health care clearinghouse functions exist within the organization, the regulated entity should document this finding. If a health care clearinghouse does exist within the organization, the regulated entity must implement procedures that are consistent with the Privacy Rule.
                        <SU>573</SU>
                        <FTREF/>
                         Questions for regulated entities to consider include: If health care clearinghouse functions are performed, are policies and procedures implemented to protect ePHI from the other functions of the larger organization? Does the health care clearinghouse share hardware or software with a larger organization of which it is a part? Does the health care clearinghouse share staff or physical space with staff from a larger organization? Has a separate network or subsystem been established for the health care clearinghouse, if reasonable and appropriate? Has staff of the health care clearinghouse been trained to safeguard ePHI from disclosure to the larger organization, if required for compliance with the Privacy Rule? 
                        <SU>574</SU>
                        <FTREF/>
                         Regulated entities should also consider whether additional technical safeguards are needed to separate ePHI in electronic information systems used by the health care clearinghouse to protect against unauthorized access by the larger organization.
                    </P>
                    <FTNT>
                        <P>
                            <SU>571</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>572</SU>
                             45 CFR 160.103 (definition of “Health care clearinghouse”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>573</SU>
                             45 CFR 164.500(b); 
                            <E T="03">see also</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461, p. 38.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>574</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461, p. 38.
                        </P>
                    </FTNT>
                    <P>
                        We also propose to redesignate the implementation specification for access authorization as proposed 45 CFR 164.308(a)(10)(ii)(B) and to modify it to emphasize that a regulated entity must establish and implement written policies and procedures for granting and revising access to ePHI and the regulated entity's relevant electronic information systems as necessary and appropriate for each prospective user and technology asset to carry out their assigned function(s) (
                        <E T="03">i.e.,</E>
                         role-based access policies). Additionally, we propose to redesignate the implementation specification for access establishment and modification as 45 CFR 164.308(a)(10)(ii)(D) and to modify the heading to “Access determination and modification.” We also propose to modify this implementation specification to require a regulated entity to establish and implement written policies and procedures that, based on its access authorization policies, establish, document, review, and modify the access of each user and technology asset to specific components of the regulated entity's relevant electronic information systems. Such written policies and procedures would be required to be based upon the regulated entity's policies for authorizing access. Under this proposal, and consistent with the existing implementation specification,
                        <SU>575</SU>
                        <FTREF/>
                         the regulated entity would be required to establish standards for granting access to ePHI and relevant electronic information systems and provide formal authorization from the appropriate authority before granting access to ePHI or relevant electronic information systems. Regulated entities should regularly review personnel access to ePHI and relevant electronic information systems to ensure that access is still authorized and needed, and modify personnel access to ePHI and electronic information systems, as needed, based on review activities.
                    </P>
                    <FTNT>
                        <P>
                            <SU>575</SU>
                             45 CFR 164.308(a)(4)(ii)(C).
                        </P>
                    </FTNT>
                    <P>
                        The existing implementation specification for access authorization calls for the regulated entity to implement policies and procedures for granting access to ePHI, for example, through components of its information system.
                        <SU>576</SU>
                        <FTREF/>
                         The Department's proposal to revise this implementation specification would provide greater specificity than our existing requirements, and echo NIST guidance on this topic. Specifically, NIST guidance 
                        <SU>577</SU>
                        <FTREF/>
                         describes the key steps for developing policies and procedures for granting access to ePHI as follows:
                    </P>
                    <FTNT>
                        <P>
                            <SU>576</SU>
                             45 CFR 164.308(a)(4)(ii)(B).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>577</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461.
                        </P>
                    </FTNT>
                    <P>• Decide and document procedures for how access to ePHI would be granted to workforce members within the organization.</P>
                    <P>
                        • Select the basis for restricting access to ePHI. Select an access control method (
                        <E T="03">e.g.,</E>
                         identity-based, role based, or other reasonable and appropriate means of access).
                    </P>
                    <P>• Decide and document how access to ePHI would be granted for privileged functions.</P>
                    <P>• Ensure that there is a list of personnel with authority to approve user requests to access ePHI and systems with ePHI.</P>
                    <P>• Identify authorized users with access to ePHI, including data owners and data custodians.</P>
                    <P>• Consider whether multiple access control methods are needed to protect ePHI according to the results of the risk assessment.</P>
                    <P>
                        • Determine whether direct access to ePHI would ever be appropriate for individuals external to the organization (
                        <E T="03">e.g.,</E>
                         business partners or patients seeking access to their own ePHI).
                    </P>
                    <P>
                        Other questions that a regulated entity should consider when establishing such policies and procedures include: Have appropriate authorization and clearance procedures, as specified in the standard for workforce security,
                        <SU>578</SU>
                        <FTREF/>
                         been performed prior to granting access? Do the organization's systems have the capacity to set access controls? Are there additional access control requirements for users who would be accessing privileged functions? Have organizational personnel been explicitly authorized to approve user requests to access ePHI and/or systems with ePHI?
                    </P>
                    <FTNT>
                        <P>
                            <SU>578</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.308(a)(3); proposed 45 CFR 164.308(a)(9)(i).
                        </P>
                    </FTNT>
                      
                    <P>
                        The Department proposes three additional implementation specifications for authentication management, maintenance, and network segmentation. These specifications clarify the Department's expectations for compliance and are consistent with NIST guidance. We believe that the proposed additions would assist regulated entities in their efforts to prevent or mitigate attacks by malicious internal and external actors. For the implementation specification on authentication management at proposed 45 CFR 164.308(a)(10)(ii)(C), we propose to require a regulated entity to establish and implement written policies and procedures for verifying the identities of users and technology assets before accessing the regulated entity's relevant electronic information systems, including written policies and procedures for implementing MFA technical controls.
                        <SU>579</SU>
                        <FTREF/>
                         The proposed implementation specification for network segmentation at proposed 45 CFR 164.308(a)(10)(ii)(E) would require a regulated entity to establish and implement written policies and procedures that ensure that its relevant electronic information systems are segmented to limit access to ePHI to authorized workstations.
                    </P>
                    <FTNT>
                        <P>
                            <SU>579</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.312(f)(2)(ii) through (iv).
                        </P>
                    </FTNT>
                    <P>
                        Finally, to address the Department's general concerns regarding the ongoing failure of many regulated entities to regularly review and revise their policies and procedures, the proposed implementation specification for maintenance at proposed 45 CFR 
                        <PRTPAGE P="952"/>
                        164.308(a)(10)(ii)(F) would require a regulated entity to review the written policies and procedures required by this standard at least once every 12 months and to modify them as reasonable and appropriate.
                    </P>
                    <HD SOURCE="HD3">m. Section 164.308(a)(11)(i)—Standard: Security Awareness Training</HD>
                    <P>
                        A covered entity's workforce is its frontline not only in patient care and patient service, but also in safeguarding the privacy and security of PHI.
                        <SU>580</SU>
                        <FTREF/>
                         The health care sector's risk landscape continues to grow with the increasing number of interconnected, smart devices of all types, the increased use of interconnected medical record and billing systems, and the increased use of applications and cloud computing. This standard reflects the fact that training on data security for workforce members is essential for protecting an organization against cyberattacks.
                    </P>
                    <FTNT>
                        <P>
                            <SU>580</SU>
                             
                            <E T="03">See</E>
                             “Train Your Workforce, so They Don't Get Caught by a Phish!,” Cybersecurity Newsletter, Office for Civil Rights, U.S. Department of Health and Human Services (July 2017), 
                            <E T="03">https://www.hhs.gov/sites/default/files/july-2017-ocr-cyber-newsletter.pdf.</E>
                        </P>
                    </FTNT>
                    <P>An organization's training program should be an ongoing, evolving process and flexible enough to educate workforce members on new cybersecurity threats and how to respond to them. As such, regulated entities should consider how often to train workforce members on security issues, given the risks and threats to their enterprises, and how often to send security updates to their workforce members. Many regulated entities have determined that twice-annual training and monthly security updates are necessary, given their risks analyses.</P>
                    <P>
                        Regulated entities should apply security updates and reminders to quickly communicate new and emerging cybersecurity threats to workforce members such as new social engineering ploys (
                        <E T="03">e.g.,</E>
                         fake tech support requests and new phishing scams) and malicious software attacks including new ransomware variants. Entities need to address what type of training to provide to workforce members on security issues, given the risks and threats to their enterprises. Computer-based training, classroom training, monthly newsletters, posters, email alerts, and team discussions are all tools that different organizations use to fulfill their training requirements. Entities must also address how to document that training to workforce members was provided, including dates and types of training, training materials, and evidence of workforce participation.
                    </P>
                    <P>
                        HHS has issued many types of training materials on securing PHI.
                        <SU>581</SU>
                        <FTREF/>
                         NIST has also provided detailed guidance for developing and implementing workforce training programs.
                        <SU>582</SU>
                        <FTREF/>
                         Despite this existing guidance, regulated entities often fail to provide appropriate training to adequately safeguard ePHI. For example, in one investigation, OCR investigators found evidence that not only had an ambulance company potentially failed to conduct a risk analysis, it also potentially failed to implement a security training program or to train any of its employees.
                        <SU>583</SU>
                        <FTREF/>
                         Such failures can contribute to breaches of individuals' unsecured ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>581</SU>
                             
                            <E T="03">See</E>
                             “Training Materials,” Office for Civil Rights, U.S. Department of Health and Human Services, 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/training/index.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>582</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>583</SU>
                             
                            <E T="03">See</E>
                             Resolution Agreement, “West Georgia Ambulance, Inc.” Office for Civil Rights, U.S. Department of Health and Human Services (Dec. 23, 2019), 
                            <E T="03">https://www.hhs.gov/sites/default/files/west-georgia-ra-cap.pdf.</E>
                        </P>
                    </FTNT>
                    <P>To ensure security awareness training compliance, a regulated entity needs to regularly educate its workforce members on the evolving technological threats to ePHI, how to use the technology that the regulated entity has adopted and implemented, and the specific procedures workforce members must follow to ensure that the ePHI remains protected. Additionally, while many educational programs for clinicians provide general training on the HIPAA Rules, the curriculums vary widely. Without providing its own training on the Security Rule, a regulated entity cannot ensure that the training its workforce received elsewhere meets the required standards.</P>
                    <P>
                        Given the failure of regulated entities to implement the security awareness and training standard and consistent with existing guidance, the Department proposes to provide more detailed requirements for security awareness training. Specifically, the Department proposes to rename and redesignate the standard for security awareness and training at 45 CFR 164.308(a)(5)(i) as the standard for security awareness training at proposed 45 CFR 164.308(a)(11)(i) and to add a paragraph heading to clarify the organization of the regulatory text. The proposed standard would require a regulated entity to implement security awareness training for all workforce members on protection of ePHI and information systems as necessary and appropriate for the members of the workforce to carry out their assigned function(s) (
                        <E T="03">i.e.,</E>
                         role-based training). The proposals to revise this standard would also align with the Department's essential CPG for Basic Cybersecurity Training because they would require a regulated entity to educate users on how to access ePHI and electronic information systems in a manner that protects the confidentiality, integrity, and availability of ePHI.
                        <SU>584</SU>
                        <FTREF/>
                         Additionally, the proposals would align with the essential CPG for Email Security by requiring a regulated entity to train workforce members to guard against, detect, and report suspected or known security incidents, including, but not limited to, malicious software and social engineering.
                        <SU>585</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>584</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>585</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>We propose four implementation specifications for the proposed security awareness training standard. The proposed implementation specification for training at 45 CFR 164.308(a)(11)(ii)(A) would require a regulated entity to establish and implement security awareness training for all workforce members that addresses the following:</P>
                    <P>
                        • The written policies and procedures required by the Security Rule, as necessary and appropriate for the workforce members to carry out their assigned functions.
                        <SU>586</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>586</SU>
                             Proposed 45 CFR 164.308(a)(11)(ii)(A)(
                            <E T="03">1</E>
                            ).
                        </P>
                    </FTNT>
                    <P>
                        • Guarding against, detecting, and reporting suspected or known security incidents, including but not limited to malicious software and social engineering.
                        <SU>587</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>587</SU>
                             Proposed 45 CFR 164.308(a)(11)(ii)(A)(
                            <E T="03">2</E>
                            ).
                        </P>
                    </FTNT>
                    <P>
                        • The written policies and procedures for accessing the regulated entity's electronic information systems, including, but not limited to, safeguarding passwords, setting unique passwords of sufficient strength to ensure the confidentiality, integrity, and availability of ePHI, and establishing limitations on sharing passwords. Consistent with the recommendation from NCVHS, such policies and procedures should ensure that the regulated entity does not employ default passwords and should prevent workforce members from sharing of credentials.
                        <SU>588</SU>
                        <FTREF/>
                         We do not propose that passwords be required to meet a particular standard because best practices for password configuration may change over time; however, we believe that it is essential for a regulated 
                        <PRTPAGE P="953"/>
                        entity to educate its workforce members on best practices for setting passwords and to ensure that its workforce members implement such best practices.
                    </P>
                    <FTNT>
                        <P>
                            <SU>588</SU>
                             Proposed 45 CFR 164.308(a)(11)(ii)(A)(
                            <E T="03">3</E>
                            ); Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, Appendix p. 1; Letter from NCVHS Chair Jacki Monson (2022), 
                            <E T="03">supra</E>
                             note 123, p. 6-7.
                        </P>
                    </FTNT>
                    <P>
                        The Department proposes to replace the implementation specification for periodic security updates 
                        <SU>589</SU>
                        <FTREF/>
                         with one addressing the timing and frequency of security awareness training at proposed 45 CFR 164.308(a)(11)(ii)(B). Specifically, we propose to require a regulated entity to provide such training to each member of the regulated entity's workforce by the compliance date for this rulemaking, if finalized, and at least once every 12 months thereafter.
                        <SU>590</SU>
                        <FTREF/>
                         For example, under this proposal, workforce members would receive security awareness training on the protection of ePHI and on the regulated entity's Security Rule policies and procedures that is based on their specific role at least once a year. A regulated entity would be required to provide role-based security awareness training to a new workforce member within a reasonable period of time, but no later than 30 days after the workforce member first has access to the regulated entity's relevant electronic information systems.
                        <SU>591</SU>
                        <FTREF/>
                         We also propose to require that the regulated entity provide such training.
                        <SU>592</SU>
                        <FTREF/>
                         For example, if the entity implements a new EHR system, it would be required to also train its workforce, as appropriate, on measures to guard against security incidents related to the installation, maintenance and/or use of the system.
                    </P>
                    <FTNT>
                        <P>
                            <SU>589</SU>
                             45 CFR 164.308(a)(5)(ii)(A).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>590</SU>
                             Proposed 45 CFR 164.308(a)(11)(ii)(B)(
                            <E T="03">1</E>
                            ).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>591</SU>
                             Proposed 45 CFR 164.308(a)(11)(ii)(B)(
                            <E T="03">2</E>
                            ).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>592</SU>
                             Proposed 45 CFR 164.308(a)(11)(ii)(B)(
                            <E T="03">3</E>
                            ).
                        </P>
                    </FTNT>
                    <P>Additionally, the Department proposes at proposed 45 CFR 164.308(a)(11)(ii)(C) an implementation specification for ongoing education. This would require a regulated entity to provide its workforce members with ongoing reminders of their security responsibilities and notice of relevant threats, including but not limited to, new and emerging malicious software and social engineering. Lastly, we propose a new implementation specification for documentation at proposed 45 CFR 164.308(a)(11)(ii)(D) that would require a regulated entity to document that it has provided training and ongoing reminders to its workforce members.</P>
                    <HD SOURCE="HD3">n. Section 164.308(a)(12)(i)—Standard: Security Incident Procedures</HD>
                    <P>Addressing security incidents is an integral part of an overall security program. While a regulated entity will never be able to prevent all security incidents, implementing the Security Rule standards would reduce the amount and negative consequences of security incidents it encounters. Even regulated entities with detailed security policies and procedures and advanced technology may experience security incidents, but through sufficient planning and continued monitoring generally can mitigate the negative effects of such incidents on regulated entities, and, ultimately, individuals. The security incident procedures standard is intended to help ensure that a regulated entity conducts such planning and monitoring to allow it to mitigate such negative effects.</P>
                    <P>
                        The Department has also provided guidance that a regulated entity can use to devise its security incident plans. The policies and procedures a regulated entity establishes to prepare for and respond to security incidents can pay dividends with faster recovery times and reduced compromises of ePHI.
                        <SU>593</SU>
                        <FTREF/>
                         A well thought-out, well-tested security incident response plan is integral to ensuring the confidentiality, integrity, and availability of a regulated entity's ePHI. A timely response to a security incident can be one of the best ways to prevent, mitigate, and recover from future cyberattacks. For example, responding to a single intrusion or inappropriate access can prevent a pattern of repeated malicious actions. It is extremely important that a regulated entity analyzes an incident to establish what has occurred and its root cause. Doing so will enable the regulated entity to use that information to update its security incident response plans. The Department has previously issued guidance addressing such activities as forming a security incident response team, identifying and responding to security incidents, mitigating harmful effects of and documenting a security incident, and breach reporting.
                        <SU>594</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>593</SU>
                             
                            <E T="03">See</E>
                             “HIPAA Security Rule Security Incident Procedures,” Cybersecurity Newsletter, Office for Civil Rights U.S. Department of Health and Human Services (Oct. 2022), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity-newsletter-october-2022/index.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>594</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        NIST also offers guidance for addressing security incidents.
                        <SU>595</SU>
                        <FTREF/>
                         It describes four key activities with detailed descriptions and sample questions:
                    </P>
                    <FTNT>
                        <P>
                            <SU>595</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461.
                        </P>
                    </FTNT>
                    <P>• Determine the goals of an incident response.</P>
                    <P>• Develop and deploy an incident response team or other reasonable and appropriate response mechanism.</P>
                    <P>• Develop and implement policy and procedures to respond to and report security incidents.</P>
                    <P>• Incorporate post-incident analysis into updates and revisions.</P>
                    <P>
                        NIST has also issued comprehensive guidelines for incident handling, particularly for analyzing incident related data and determining the appropriate response to each incident.
                        <SU>596</SU>
                        <FTREF/>
                         For example, the NIST Cybersecurity Framework addresses these activities as part of the core function of “[respond—a]ctions regarding a detected cybersecurity incident are taken.” 
                        <SU>597</SU>
                        <FTREF/>
                         “Respond” supports the ability of the regulated entity “to contain the effects of cybersecurity incidents. Outcomes within this Function [include] incident management, analysis, mitigation, reporting, and communication.” 
                        <SU>598</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>596</SU>
                             
                            <E T="03">See</E>
                             Paul Cichonski, et al., “Computer Security Incident Handling Guide: Recommendations of the National Institute of Standards and Technology,” NIST Special Publication 800-61, Revision 2, National Institute of Standards and Technology, U.S. Department of Commerce (Aug. 2012), 
                            <E T="03">https://www.nist.gov/privacy-framework/nist-sp-800-61.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>597</SU>
                             “The NIST Cybersecurity Framework (CSF) 2.0,” (removed emphasis on “Actions regarding a detected cybersecurity incident are taken” in original), 
                            <E T="03">supra</E>
                             note 15, p. 9.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>598</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Despite this existing guidance, OCR's enforcement experience indicates that many regulated entities have not met the existing standard, so we believe that additional specificity regarding their obligations and liability for incident response is warranted. Accordingly, the Department proposes to redesignate the standard for security incident procedures as 45 CFR 164.308(a)(12)(i), to add a paragraph heading to clarify the organization of the regulatory text, and to modify the regulatory text to clarify that a regulated entity would be required to implement written policies and procedures to “respond to,” rather than “address,” security incidents. Additionally, we propose to clarify expectations by adding an implementation specification for planning and testing at proposed 45 CFR 164.308(a)(12)(ii)(A)(
                        <E T="03">1</E>
                        ) that would require a regulated entity to establish written security incident response plan(s) and procedures documenting how workforce members are to report suspected or known security incidents and how the regulated entity will respond to suspected or known security incidents.
                        <SU>599</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>599</SU>
                             Proposed 45 CFR 164.308(a)(12)(ii)(A)(
                            <E T="03">1</E>
                            ).
                        </P>
                    </FTNT>
                    <P>
                        Internal reporting is an essential component of security incident procedures.
                        <SU>600</SU>
                        <FTREF/>
                         Plans and procedures for 
                        <PRTPAGE P="954"/>
                        reporting of suspected or known security incidents may address to whom, when, and how such incidents are to be reported. The recipient(s) and the content of such reports, according to such plans and procedures, may vary based on the type of incident and the role of the workforce member making the report. We do not propose to dictate the form, format, or content of such report. Rather, we believe that regulated entities would be best situated to identify the point(s) of contact for their organization (
                        <E T="03">e.g.,</E>
                         Chief Information Security Officer, IT security team, business associate engaged to support incident response activities for the regulated entity) for such reports and the type of information they need to determine how to respond to the suspected or known security incident.
                    </P>
                    <FTNT>
                        <P>
                            <SU>600</SU>
                             
                            <E T="03">See, e.g.,</E>
                             Joint Task Force, “Security and Privacy Controls for Information Systems and 
                            <PRTPAGE/>
                            Organizations,” NIST Special Publication 800-53, Revision 5, National Institute of Standards and Technology, U.S. Department of Commerce, p. 157 (Sept. 2020), 
                            <E T="03">https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        The proposal to require a regulated entity to establish written security incident response plans and procedures for how it will respond to suspected or known security incidents would align with the enhanced CPG for Third Party Incident Reporting because it would address the procedures for how and when a business associate would report to a covered entity or another business associate known or suspected security incidents, as required by proposed 45 CFR 164.314(a)(2)(i)(C).
                        <SU>601</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>601</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18; 
                            <E T="03">see also</E>
                             proposed 45 CFR 164.314(a)(2)(i)(C).
                        </P>
                    </FTNT>
                    <P>
                        Under proposed 45 CFR 164.308(a)(12)(ii)(A)(
                        <E T="03">2</E>
                        ) and (
                        <E T="03">3</E>
                        ), the regulated entity would be required to implement written procedures for testing and revising the security incident response plan(s) and then, using those written procedures, review and test its security incident response plans at least once every 12 months and document the results of such tests. The regulated entity would also be required to modify the plan(s) and procedures as reasonable and appropriate, based on the results of such tests and the regulated entity's circumstances.
                    </P>
                    <P>
                        This proposal, if finalized, would include requirements that align with the Department's essential CPG for Basic Incident Planning and Preparedness to have effective responses to and recovery from security incidents.
                        <SU>602</SU>
                        <FTREF/>
                         It also aligns with the Department's enhanced CPG for Centralized Incident Planning and Preparedness by requiring a regulated entity to maintain, revise, and test security incident response plans.
                        <SU>603</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>602</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>603</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Additionally, the Department proposes to redesignate the implementation specification for response and reporting at 45 CFR 164.308(a)(6)(ii) as 45 CFR 164.308(a)(12)(ii)(B) and to rename it “Response.” We also propose to modify the existing implementation specification by separating it into two paragraphs: one at paragraph (a)(12)(ii)(B)(
                        <E T="03">1</E>
                        ) for identifying and responding to suspected or known security incidents, and the other at paragraph (a)(12)(ii)(B)(
                        <E T="03">2</E>
                        ) for mitigating, to the extent practicable, the harmful effects of suspected or known security incidents. The Department also proposes to add three additional paragraphs to this implementation specification. Proposed 45 CFR 164.308(a)(12)(ii)(B)(
                        <E T="03">3</E>
                        ) would require a regulated entity to identify and remediate, to the extent practicable, the root cause(s) of suspected or known security incidents, while proposed 45 CFR 164.308(a)(12)(ii)(B)(
                        <E T="03">4</E>
                        ) would require the regulated entity to eradicate the security incidents that are suspected or known to the regulated entity. We would expect eradication to include the removal of malicious software, inappropriate materials, and any other components of the incident from the regulated entity's relevant electronic information systems.
                        <SU>604</SU>
                        <FTREF/>
                         Finally, proposed 45 CFR 164.308(a)(12)(ii)(B)(
                        <E T="03">5</E>
                        ) would require a regulated entity to develop and maintain documentation of investigations, analyses, mitigation, and remediation for security incidents that are suspected or known. For example, verbal reports of a suspected or known security incident would be required to be documented in writing. Under proposed 45 CFR 164.316(b)(1), if finalized, a regulated entity would be required to maintain such documentation for six years from the date of its creation or the date when it last was in effect, whichever is later. These proposals are consistent with existing guidance described above and with other proposals or existing regulatory standards to secure health information.
                        <SU>605</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>604</SU>
                             
                            <E T="03">See</E>
                             “Computer Security Incident Handling Guide: Recommendations of the National Institute of Standards and Technology,” 
                            <E T="03">supra</E>
                             note 597.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>605</SU>
                             
                            <E T="03">See, e.g.,</E>
                             “New York State Register,” 
                            <E T="03">supra</E>
                             note 14; “Invitation for Preliminary Comments on Proposed Rulemaking: Cybersecurity Audits, Risk Assessments, and Automated Decisionmaking,” 
                            <E T="03">supra</E>
                             note 14; 
                            <E T="03">see also</E>
                             Cal. Civ. Code Section 1798.185.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">o. Section 164.308(a)(13)(i)—Standard: Contingency Plan</HD>
                    <P>
                        The purpose of any contingency plan is to allow an organization to return to its daily operations as quickly as possible after an unforeseen event.
                        <SU>606</SU>
                        <FTREF/>
                         The contingency plan protects resources, minimizes customer inconvenience, and identifies key staff, assigning specific responsibilities in the context of the recovery. Contingency plans are critical to protecting the availability, integrity, and security of data during unexpected adverse events. Contingency plans should consider not only how to respond to disasters such as fires and floods, but also how to respond to cyberattacks. Cyberattacks using malicious software, such as ransomware, may render an organization's data unreadable or unusable. In the event data is compromised by a cyberattack, restoring the data from backups may be the only option for recovering the data and restoring normal business operations. For example, the faulty software update by CrowdStrike made it impossible for health care systems worldwide to use their Windows-based systems.
                        <SU>607</SU>
                        <FTREF/>
                         There were many instances where surgical procedures and health care appointments were cancelled, schedules upended, and pharmacies were unable to fill prescriptions. Regulated entities need to make and implement contingency plans they would use when such events occur to enable themselves to get back to their core functions of providing or paying for health care.
                    </P>
                    <FTNT>
                        <P>
                            <SU>606</SU>
                             
                            <E T="03">See</E>
                             “Plan A. . .B. . .Contingency Plan!” Cybersecurity Newsletter, Office for Civil Rights, U.S. Department of Health and Human Services (Mar. 2018), 
                            <E T="03">https://www.hhs.gov/sites/default/files/march-2018-ocr-cyber-newsletter-contingency-planning.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>607</SU>
                             
                            <E T="03">See</E>
                             Kate Conger, et al., “What Is Crowdstrike?,” New York Times (July 19, 2024), 
                            <E T="03">https://www.nytimes.com/2024/07/19/business/what-is-crowdstrike.html?searchResultPosition=2; see also</E>
                             “Remediation and Guidance Hub: Falcon Content Update for Windows Hosts,” (July 31, 2024), 
                            <E T="03">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/.</E>
                        </P>
                    </FTNT>
                    <P>
                        The Department and NIST have issued extensive guidance on contingency planning, including detailed descriptions of key activities, sample questions for regulated entities to consider when standing up a contingency plan, and information on how the results of the risk analysis feed into contingency plans.
                        <SU>608</SU>
                        <FTREF/>
                         Unfortunately, many regulated entities have not implemented the required 
                        <PRTPAGE P="955"/>
                        planning and then have been unable to fully recover from ransomware attacks that bring down electronic systems that create, receive, maintain, or transmit ePHI. For example, a large health system that experienced a ransomware attack had to shut down services at multiple locations and encountered difficulties restoring those services. OCR's investigation indicated a potential failure to, among other things, implement contingency plans.
                        <SU>609</SU>
                        <FTREF/>
                         Such planning is crucial for maintaining the resilience of a regulated entity's health IT.
                    </P>
                    <FTNT>
                        <P>
                            <SU>608</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461; 
                            <E T="03">see also</E>
                             “Security Standards: Administrative Safeguards,” 
                            <E T="03">supra</E>
                             note 517, p. 19-22.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>609</SU>
                             
                            <E T="03">See</E>
                             Press Release, “HHS Office for Civil Rights Settles HIPAA Security Rule Failures for $950,000,” U.S. Department of Health and Human Services (July 1, 2024), 
                            <E T="03">https://prod-wwwhhsgov.cloud.hhs.gov/about/news/2024/07/01/hhs-office-civil-rights-settles-hipaa-security-rule-failures-950000.html.</E>
                        </P>
                    </FTNT>
                    <P>To address these inadequacies in compliance and to protect the confidentiality, integrity, and availability of ePHI, the Department proposes to redesignate the standard for a contingency plan at 45 CFR 164.308(a)(7)(i) as proposed 45 CFR 164.308(a)(13)(i), to add a paragraph heading to clarify the organization of the regulatory text, and to modify the regulatory text to clarify it. The modified standard, as proposed, would require a regulated entity to establish (and implement as needed) a written contingency plan, consisting of written policies and procedures for responding to an emergency or other occurrence, including, but not limited to, fire, vandalism, system failure, natural disaster, or security incident, that adversely affects relevant electronic information systems.</P>
                    <P>
                        The Department proposes a new implementation specification for criticality analysis at proposed 45 CFR 164.308(a)(13)(ii)(A). This would require a regulated entity to perform and document an assessment of the relative criticality of its relevant electronic information systems and technology assets in its relevant electronic information systems. The proposal would not limit this analysis to electronic information systems that create, receive, maintain, or transmit ePHI because other electronic information systems and/or technology assets may be crucial to ensuring the confidentiality, integrity, or availability of ePHI, providing patient care, and supporting other business needs. A prioritized list of specific relevant electronic information systems and technology assets in those electronic information systems would help a regulated entity to determine their criticality and the order of restoration.
                        <SU>610</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>610</SU>
                             
                            <E T="03">See</E>
                             “Security Standards: Administrative Safeguards,” 
                            <E T="03">supra</E>
                             note 517, p. 22.
                        </P>
                    </FTNT>
                    <P>Under this proposal, the implementation specification for establishing and implementing a data backup plan would be redesignated as proposed 45 CFR 164.308(a)(13)(ii)(B) and renamed “Data backups.” It would also be modified to clarify that the procedures to create and maintain exact retrievable copies of ePHI must be in writing, and to also require such procedures to include verifying that the ePHI has been copied accurately. For example, the ability to access ePHI from a remote location in the event of a total failure should be reflected in the procedures specified for data backups.</P>
                    <P>The proposed implementation specification for backing up information systems at proposed paragraph (a)(13)(ii)(C) would require a regulated entity to establish and implement written procedures to create and maintain backups of its relevant electronic information systems, including verifying the success of such backups. Establishing such procedures would ensure that the ePHI in relevant electronic information systems is both protected and available.</P>
                    <P>
                        Additionally, the Department proposes to redesignate the implementation specification for disaster recovering planning as paragraph (a)(13)(ii)(D). We propose to clarify that a regulated entity would be required to establish (and implement as needed) written procedures to restore both its critical relevant electronic information systems and data within 72 hours of the loss, and to restore the loss of other relevant electronic information systems and data in accordance with its criticality analysis.
                        <SU>611</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>611</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(13)(ii)(A).
                        </P>
                    </FTNT>
                    <P>The Department proposes to clarify the implementation specification for emergency mode operation planning, redesignated as proposed 45 CFR 164.308(a)(13)(ii)(E), by clarifying that procedures must be written. We also propose to redesignate the implementation specification for testing and revision procedures as paragraph (a)(13)(ii)(F) and to clarify that procedures for testing and revising of the required contingency plans must be established in writing. We propose to require a regulated entity to review and implement its procedures for testing contingency plans at least once every 12 months, to document the results of such tests, and to modify those plans as reasonable and appropriate based on the results of those tests.</P>
                    <HD SOURCE="HD3">p. Section 164.308(a)(14)—Standard: Compliance Audit</HD>
                    <P>The final standard we propose under 45 CFR 164.308(a) is a new standard for compliance audits at proposed 45 CFR 164.308(a)(14). For this proposed standard, the Department proposes to require regulated entities to perform and document an audit of their compliance with each standard and implementation specification of the Security Rule at least once every 12 months.</P>
                    <P>
                        While the Security Rule does not currently require regulated entities to conduct internal or third-party compliance audits, such activities are important components of a robust cybersecurity program. The Government Accountability Office has published guidance on conducting cybersecurity performance audits for Federal agencies.
                        <SU>612</SU>
                        <FTREF/>
                         Audits are typically conducted independently from information security management, and the function generally reports to the governing body of the regulated entity. This independence can provide an objective view of the regulated entity's policies and practices. According to the Institute of Internal Auditors, an internal audit provides “[i]ndependent and objective assurance and advice on all matters related to the achievement of objectives.” 
                        <SU>613</SU>
                        <FTREF/>
                         An internal audit may be conducted by a business associate of a covered entity or a subcontractor of a business associate. These activities provide regulated entities with confidence in the effectiveness of their risk management plan. Thus, we believe that this proposal would aid a regulated entity in ensuring compliance with the Security Rule, and ultimately, protecting ePHI. We do not propose to specify whether the compliance audit should be performed by the regulated entity or an external party.
                        <SU>614</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>612</SU>
                             
                            <E T="03">See</E>
                             “Cybersecurity Program Audit Guide,” GAO-23-104705, U.S. Government Accountability Office, p. 1 (Sept. 28, 2023), 
                            <E T="03">https://www.gao.gov/products/gao-23-104705; see also</E>
                             “Security and Privacy Controls for Information Systems and Organizations,” 
                            <E T="03">supra</E>
                             note 600.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>613</SU>
                             
                            <E T="03">See</E>
                             “The IIA's Three Lines Model: An update of the Three Lines of Defense,” The Institute of Internal Auditors, p. 4 (Sept. 9, 2020), 
                            <E T="03">https://www.theiia.org/globalassets/documents/resources/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense-july-2020/three-lines-model-updated-english.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>614</SU>
                             We believe that health plans that are subject to HIPAA and to the Employee Retirement Income Security Act of 1974 could comply with the proposed compliance audit requirement and follow the Employee Benefits Security Administration's Cybersecurity Program Best Practices, which specifies that all such plans have a reliable annual third party audit of security controls. “Cybersecurity Program Best Practices,” Employee Benefits Security Administration, U.S. Department of Labor, p. 1, 2 (Apr. 2021), 
                            <E T="03">
                                https://www.dol.gov/
                                <PRTPAGE/>
                                sites/dolgov/files/ebsa/pdf_files/best-practices.pdf;
                            </E>
                             “Cybersecurity Guidance Update,” Employee Benefits Security Administration, U.S. Department of Labor (Sept. 6, 2024), 
                            <E T="03">https://www.dol.gov/agencies/ebsa/key-topics/retirement-benefits/cybersecurity/compliance-assistance-release-2024-01.</E>
                        </P>
                    </FTNT>
                    <PRTPAGE P="956"/>
                    <HD SOURCE="HD3">q. Section 164.308(b)(1) and (2)—Standard: Business Associate Contracts and Other Arrangements</HD>
                    <P>
                        Vendor management and identification of risks in a supply chain are essential to controlling the introduction of new threats and risks to a regulated entity.
                        <SU>615</SU>
                        <FTREF/>
                         NIST guidance explains that regulated entities, are permitted to include more stringent cybersecurity measures in business associate agreements than those required by the Security Rule.
                        <SU>616</SU>
                        <FTREF/>
                         Such requirements would need to be agreed upon by both parties to the business associate agreement.
                        <SU>617</SU>
                        <FTREF/>
                         The guidance also recommends establishing a process for measuring contract performance and terminating the contract if security requirements are not being met. Important considerations include: Is there a process for reporting security incidents related to the agreement? Are additional assurances of protections for ePHI from the business associate necessary? If so, where would such additional assurances be documented (
                        <E T="03">e.g.,</E>
                         in the business associate agreement, service-level agreement, or other documentation) and how would they be met (
                        <E T="03">e.g.,</E>
                         providing documentation of implemented safeguards, audits, certifications)?
                    </P>
                    <FTNT>
                        <P>
                            <SU>615</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>616</SU>
                             
                            <E T="03">Id.</E>
                             at 54.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>617</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        The Security Rule requires a regulated entity to protect the confidentiality, integrity, and availability of all ePHI that it creates, receives, maintains, or transmits.
                        <SU>618</SU>
                        <FTREF/>
                         It also requires a regulated entity to obtain written satisfactory assurances that its business associate will appropriately safeguard ePHI before allowing the business associate to create, receive, maintain, or transmit ePHI on its behalf.
                        <SU>619</SU>
                        <FTREF/>
                         However, the Security Rule does not require a regulated entity to verify that entities that create, receive, maintain, or transmit ePHI on its behalf are in fact taking the necessary steps to protect such ePHI. The lack of such a requirement may leave a gap in protections from risks to ePHI related to regulated entities' vendors and supply chains. Accordingly, the Department proposes several modifications to the Security Rule to provide greater assurance that business associates and their subcontractors are protecting ePHI because a subcontractor to a business associate is also a business associate. The Department proposes to redesignate 45 CFR 164.308(b)(1) and (2) as proposed 45 CFR 164.308(b)(1)(i) and (ii), respectively. Additionally, we propose to make a technical correction to the standard for business associate contracts and other arrangements for organizational clarity, separating proposed paragraph (b)(1)(i) into paragraphs (b)(1)(i)(A) and (B). We believe this is a non-substantive change that would have no effects on any regulatory, recordkeeping, or reporting requirement, nor would it change the Department's interpretation of any regulation. We also propose to modify both to require a regulated entity to verify that the business associate has deployed the technical safeguards required by 45 CFR 164.312 
                        <SU>620</SU>
                        <FTREF/>
                         in addition to obtaining satisfactory assurances that its business associate would comply with the Security Rule.
                        <SU>621</SU>
                        <FTREF/>
                         To assist regulated entities in complying with the new standard, we propose to redesignate the implementation specifications at 45 CFR 164.308(b)(3) as 45 CFR 164.308(b)(2) and propose to add an implementation specification for written verification at proposed 45 CFR 164.308(b)(2)(ii) that would require the regulated entity to obtain written verification from the business associate that the business associate has deployed the required technical safeguards.
                        <SU>622</SU>
                        <FTREF/>
                         The Department proposes to require that the regulated entity obtain this written verification documenting the business associate's deployment of the required technical safeguards at least once every 12 months.
                        <SU>623</SU>
                        <FTREF/>
                         Additionally, we propose that the verification include a written analysis of the business associate's relevant electronic information systems.
                        <SU>624</SU>
                        <FTREF/>
                         The written analysis would be required to be performed by a person with appropriate knowledge of and experience with generally accepted cybersecurity principles and methods for ensuring the confidentiality, integrity, and availability of ePHI to verify the business associate's compliance with each standard and implementation specification in 45 CFR 164.312.
                        <SU>625</SU>
                        <FTREF/>
                         We also propose to require that the written verification be accompanied by a written certification by a person who has the authority to act on behalf of the business associate that the analysis has been performed and is accurate.
                        <SU>626</SU>
                        <FTREF/>
                         The proposal would permit the parties to determine the appropriate person to perform the analysis and how that person is engaged or compensated. This person may be a member of the covered entity's or business associate's workforce or an external party.
                    </P>
                    <FTNT>
                        <P>
                            <SU>618</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.306(a)(1).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>619</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.308(b).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>620</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(b)(1)(i) and (ii).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>621</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>622</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(b)(2)(ii).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>623</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>624</SU>
                             Proposed 45 CFR 164.308(b)(2)(ii)(A).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>625</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>626</SU>
                             Proposed 45 CFR 164.308(b)(2)(ii)(B).
                        </P>
                    </FTNT>
                    <P>
                        This proposed new requirement that a regulated entity obtain written verification from its business associates that they have deployed technical safeguards combined with the existing requirement to obtain written satisfactory assurances that they safeguard ePHI, aligns with the Department's essential CPG for Vendor/Supplier Cybersecurity Requirements.
                        <SU>627</SU>
                        <FTREF/>
                         This CPG calls for regulated entities to identify, assess, and mitigate risks to ePHI used by or disclosed to business associates.
                        <SU>628</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>627</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18; 
                            <E T="03">see also</E>
                             proposed 45 CFR 164.308(b)(2)(i).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>628</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">r. Section 164.308(b)(3)—Standard: Delegation To Business Associate</HD>
                    <P>
                        Based on the OCR's investigations and enforcement experience, we believe that some regulated entities are not aware that they retain compliance responsibility for implementing requirements of the Security Rule, even when they have delegated the functions of designated security official to a business associate. Therefore, the Department proposes a new standard for delegation to a business associate at proposed 45 CFR 164.308(b)(3). The proposed standard would clarify that a regulated entity may permit a business associate to serve as its designated security official.
                        <SU>629</SU>
                        <FTREF/>
                         However, a regulated entity that delegates actions, activities, or assessments required by the Security Rule to a business associate remains liable for compliance with all the applicable provisions of the Security Rule.
                        <SU>630</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>629</SU>
                             Proposed 45 CFR 164.308(b)(3)(i).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>630</SU>
                             Proposed 45 CFR 164.308(b)(3)(ii).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">4. Request for Comment</HD>
                    <P>
                        The Department requests comment on the foregoing proposals, including any benefits, drawbacks, or unintended consequences. We also request comment on the following considerations in particular. For any proposed timeframe that a commenter believes is not appropriate, we request comment and explanation on a more appropriate timeframe.
                        <PRTPAGE P="957"/>
                    </P>
                    <P>a. Whether the Department should require a regulated entity to implement any additional administrative safeguards. If so, please explain.</P>
                    <P>b. Whether the Department should not require a regulated entity to implement any of the existing or proposed standards for implementation specifications. If so, please explain.</P>
                    <P>c. Whether there are additional implementation specifications that should be adopted for any of the standards for administrative safeguards.</P>
                    <P>d. Whether the Department should provide any exceptions to the administrative safeguards or related implementation specifications. If so, please explain when and why any exceptions should apply.</P>
                    <P>e. Whether once every 12 months is the appropriate frequency between reviews of policies, procedures, and other activities required by the other standards for administrative safeguards.</P>
                    <P>f. Whether there are any special considerations for business associates and business associate agreements that the Department should be aware of with respect to administrative safeguards.</P>
                    <P>g. Whether there are any requirements for business associates and business associate agreements that the Department should include in administrative safeguards that it did not propose.</P>
                    <P>h. Whether the Department should require covered entities to report to their business associates (or business associates to their subcontractors) the activation of the covered entities' (or business associates') contingency plans. If so, please explain the appropriate circumstances of and the appropriate amount of time for such notification.</P>
                    <P>i. Whether once every 12 months is an appropriate length of time in which a covered entity must verify and document that a business associate has deployed technical safeguards pursuant to the requirements.</P>
                    <P>j. Whether the Department should require covered entities to obtain satisfactory assurances and verify that a business associate has implemented physical or other safeguards in addition to deploying technical safeguards before permitting it to create, receive, maintain, or transmit ePHI on its behalf.</P>
                    <P>k. Whether on an ongoing basis, but at least once every 12 months and when there is a change to a regulated entity's environment or operations that affects ePHI, is the appropriate frequency for updating the technology asset inventory and network map?</P>
                    <P>l. Whether on an ongoing basis, but at least once every 12 months and when there is a change to the regulated entity's environment or operations that affects ePHI, is the appropriate frequency for performing a risk analysis?</P>
                    <P>m. Whether there are additional events for which the Department should require a regulated entity to update its risk analysis. If so, please explain.</P>
                    <P>n. Whether the Department should include or exclude any specific circumstances from its explanation of environmental or operational changes when determining whether review or update of the written inventory of technology assets and network map or review of the risk analysis written assessment is warranted.</P>
                    <P>o. Whether the proposed requirement in the standard for evaluation, to perform a written technical and nontechnical evaluation within a reasonable period of time before making a change in the regulated entity's environment or operations pursuant to the requirements, is sufficiently clear. If not, how should the Department clarify it? For example, should the Department require a specific amount of time, and if so, what length of time?</P>
                    <P>p. Whether at least once every 12 months is the appropriate frequency for reviewing and updating written policies and procedures for patch management, sanctions policies and procedures information system activity review, workforce security, and information access management.</P>
                    <P>q. Whether as reasonable and appropriate in response to changes in the risk analysis, but at least once every 12 months, is the appropriate frequency for reviews of a regulated entity's written risk management plan.</P>
                    <P>r. Whether the proposed frequency for security awareness training is appropriate.</P>
                    <P>s. Whether the proposed substance of the security awareness training is appropriate, and any recommendations for additional required content.</P>
                    <P>t. Whether the proposed timelines for applying patches, updates, and upgrades are appropriate.</P>
                    <P>u. Whether the Department should set a time limit for applying patches, updates, and upgrades to configurations of relevant electronic information systems to address moderate and low risks. If so, please explain and provide a recommendation.</P>
                    <P>v. Whether the amount of time regulated entities currently retain records of information system activity varies by the type of record, and for how long such records are retained.</P>
                    <P>w. Whether the Department should specify the length of time for which records of information system activity should be retained. If so, please explain.</P>
                    <P>
                        x. Whether the Department should require that a regulated entity notify other regulated entities of the termination of a workforce member's access to ePHI in less than 24 hours after the workforce member's termination. If so, please explain what would be an appropriate period of time (
                        <E T="03">e.g.,</E>
                         three business hours, 12 hours).
                    </P>
                    <P>y. Whether at least once every 12 months is the appropriate frequency for testing security incident response plans, documenting the results, and revising such plans.</P>
                    <P>z. Whether it is reasonable and appropriate to require that regulated entities restore loss of critical relevant electronic information systems and data in 72 hours or less.</P>
                    <P>aa. Whether the Department should require a regulated entity to restore all of its relevant electronic information systems and data within 72 hours?</P>
                    <P>bb. Whether the Department should require some regulated entities to restore their relevant electronic information systems and data in less than 72 hours? If so, please explain.</P>
                    <P>cc. Whether at least once every 12 months is the appropriate frequency for the testing of contingency plans?</P>
                    <P>dd. Whether annual auditing of a regulated entity's compliance with the Security Rule is appropriate.</P>
                    <P>ee. Whether the Department should specify the level of detail or standard required for the annual compliance audit. If so, please explain.</P>
                    <P>ff. Whether the Department should require a regulated entity to obtain written verification of their business associates' implementation of the administrative and physical safeguards that are required by the Security Rule, in addition to the proposed requirement to obtain verification of implementation of the technical safeguards. If so, please explain.</P>
                    <P>gg. Whether there are other requirements for which the Department should require that the person performing them have a specific level or type of expertise. If so, please explain.</P>
                    <HD SOURCE="HD2">E. Section 164.310—Physical Safeguards</HD>
                    <HD SOURCE="HD3">1. Current Provisions</HD>
                    <P>
                        A person with physical access to electronic media or a regulated entity's electronic information systems that create, receive, maintain, or transmit or that otherwise affect the confidentiality, integrity, and availability of ePHI might have the opportunity to change the configurations of its relevant electronic information systems, install malicious software or otherwise adversely affect technology assets in its relevant 
                        <PRTPAGE P="958"/>
                        electronic information systems, change information, or access ePHI or other sensitive information.
                        <SU>631</SU>
                        <FTREF/>
                         Any of these actions has the potential to adversely affect the confidentiality, integrity, or availability of ePHI, which means that physical safeguards for electronic media and a regulated entity's relevant electronic information systems are critical to protecting the security of ePHI. Thus, the physical safeguards standards address the essential requirements for regulated entities to apply to limit physical access to their relevant electronic information systems to only authorized workforce members. As discussed above, ePHI is increasingly transmitted using interconnected systems that rely on cloud computing. The shift to a cloud-based infrastructure may increase regulated entities' reliance on business associates to maintain and access ePHI stored in the cloud.
                        <SU>632</SU>
                        <FTREF/>
                         Additionally, the shift to cloud computing enables regulated entities' workforce members to access ePHI and relevant electronic information systems from a greater number of locations. Accordingly, regulated entities must appropriately expand and/or ensure that applied physical safeguards take into account these new arrangements.
                    </P>
                    <FTNT>
                        <P>
                            <SU>631</SU>
                             “Considerations for Securing Electronic Media and Devices,” Office for Civil Rights, U.S. Department of Health and Human Services, p. 1 (Aug. 2018), 
                            <E T="03">https://www.hhs.gov/sites/default/files/cybersecurity-newsletter-august-2018-device-and-media-controls.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>632</SU>
                             
                            <E T="03">See, e.g.,</E>
                             Sonali Sachdeva, et al., “Unraveling the role of cloud computing in health care system and biomedical sciences,” Heliyon (Apr. 2, 2024) (“These days numerous commercial merchants are intermingling with hospitals as well as healthcare providers to establish healthcare-based cloud computing networks.”), 
                            <E T="03">https://www-ncbi-nlm-nih-gov.hhsnih.idm.oclc.org/pmc/articles/PMC11004887/; see also id.</E>
                             (“[. . .] Microsoft, Google and Amazon have instantly realized that the majority of hospitals will not continue working with servers that are privately owned as well as controlled.”); “Increase in health-care cyberattacks affecting patients with cancer,” 
                            <E T="03">supra</E>
                             note 180 (In 2021, an attack against oncology services targeted data stored in cloud-based systems and affected patients in several States.).
                        </P>
                    </FTNT>
                    <P>Section 164.310 includes the four standards with which a regulated entity must comply to physically secure relevant electronic information systems and the premises where they are located. These standards require regulated entities to implement physical safeguards for facility access controls, workstation use, workstation security, and device and media controls in a manner that conforms with 45 CFR 164.306(c), the general compliance provision for the security standards.</P>
                    <P>
                        As discussed above in greater detail, physical safeguards encompass the physical measures, and related policies and procedures, to protect relevant electronic information systems and related buildings and equipment from natural and environmental hazards, and unauthorized intrusion.
                        <SU>633</SU>
                        <FTREF/>
                         The standard for facility access controls applies to protect the physical premises, while the standards for workstation use, workstation security, and device and media controls are aimed at protecting the electronic information systems and electronic media that create, receive, maintain, or transmit ePHI or that otherwise affect its confidentiality, integrity, and availability.
                    </P>
                    <FTNT>
                        <P>
                            <SU>633</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.304 (definition of “Physical safeguards”).
                        </P>
                    </FTNT>
                    <P>The standard for facility access controls at 45 CFR 164.310(a)(1) requires a regulated entity to implement policies and procedures that limit physical access to electronic information systems and facilities that contain those systems. Section 164.310(a)(1) also requires a regulated entity to ensure its policies and procedures allow persons who are properly authorized to access its facilities.</P>
                    <P>
                        Under 45 CFR 164.310(a)(2), a regulated entity must implement the standard for facility access controls in accordance with four implementation specifications. The implementation specification for contingency operations addresses the establishment (and implementation as needed) of procedures that allow for facility access in support of the restoration of lost data under a disaster recovery plan and emergency mode operations.
                        <SU>634</SU>
                        <FTREF/>
                         Section 164.310(a)(2)(ii) contains the specification for a facility security plan and addresses the implementation of policies and procedures to safeguard facilities and equipment in such facilities from unauthorized physical access, tampering, and theft. The implementation of procedures for role-based access control, including for visitors and for access to software programs for testing and revision is addressed in 45 CFR 164.310(a)(2)(iii), while 45 CFR 164.310(a)(2)(iv) addresses the implementation of policies and procedures for the documentation of repairs and modifications to physical security components of a facility, such as hardware, walls, doors, and locks.
                    </P>
                    <FTNT>
                        <P>
                            <SU>634</SU>
                             45 CFR 164.310(a)(2)(i).
                        </P>
                    </FTNT>
                    <P>
                        Section 164.310(b) requires a regulated entity to implement policies and procedures specifying proper workstation functions, the manner in which those functions are to be performed, and the physical attributes of the environment for where specific workstations or classes of workstation used for accessing ePHI.
                        <SU>635</SU>
                        <FTREF/>
                         This standard is not accompanied by standalone implementation specifications, compared to the standards for facility access controls at 45 CFR 164.310(a) and device and media controls at 45 CFR 164.310(d). Section 164.310(c), the standard for workstation security, also is not accompanied by standalone addressable or required implementation specifications, but it does require a regulated entity to implement physical safeguards that restrict all workstations, such as a laptop or desktop computer or any other device that performs similar functions, that access ePHI to authorized users.
                        <SU>636</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>635</SU>
                             45 CFR 164.310(b).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>636</SU>
                             45 CFR 164.310(c).
                        </P>
                    </FTNT>
                    <P>
                        Device and media controls can help regulated entities respond to and recover from security incidents and breaches.
                        <SU>637</SU>
                        <FTREF/>
                         Proper understanding of and implementation of such controls may enable regulated entities to quickly determine which devices and electronic media may be implicated in an actual or suspected security incident, or breach, and respond accordingly.
                        <SU>638</SU>
                        <FTREF/>
                         For example, if cybercriminals gained access to an organization's network by exploiting a vulnerability present in a particular electronic device, a robust and accurate inventory and tracking process could identify how many devices are affected and where they are located. With this information, a regulated entity should be able to make more effective use of its resources and respond more effectively to an actual or suspected security incident or breach involving such devices. Thus, it is important for regulated entities to implement the device and media controls required under 45 CFR 164.310(d). Accordingly, the standard for device and media controls at 45 CFR 164.310(d), requires a regulated entity to implement policies and procedures to govern how hardware and electronic media containing ePHI are received or removed from a facility and within a facility. Section 164.310(d)(2) includes two required and two addressable implementation specifications. Paragraphs (d)(2)(i) and (ii) on disposal and media re-use, respectively require a regulated entity to implement policies and procedures that address the final disposition of ePHI and the hardware or electronic media on which it is stored, and the removal of ePHI before the electronic media is re-used. Section 164.308(d)(2)(iii) addresses the 
                        <PRTPAGE P="959"/>
                        maintenance of a record of the movement of hardware and electronic media and any person responsible for such hardware or electronic media, while the provision on data backup and storage at 45 CFR 164.310(d)(2)(iv) addresses the creation of a retrievable, exact copy of ePHI before moving the equipment.
                    </P>
                    <FTNT>
                        <P>
                            <SU>637</SU>
                             “Considerations for Securing Electronic Media and Devices,” 
                            <E T="03">supra</E>
                             note 631, p. 2.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>638</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">2. Issues To Address</HD>
                    <P>
                        The Department has concerns regarding the effectiveness of the language used in the physical safeguards in 45 CFR 164.310 for the same reasons discussed in the context of 45 CFR 164.306 and 164.316. For example, while 45 CFR 164.310 contemplates that a regulated entity must implement the standards and implementation specifications required under 45 CFR 164.310 in accordance with the general documentation and maintenance requirements found in 45 CFR 164.306 and 164.316, at least one court has stated that compliance obligations are limited to the plain words of regulatory text and that a requirement to “implement” does not mean that a requirement must be in place throughout the regulated entity's enterprise.
                        <SU>639</SU>
                        <FTREF/>
                         Additionally, the standards for facility access controls, workstation use, and device and media controls all require a regulated entity to implement policies and procedures, while the standard for workstation security requires regulated entities to implement physical safeguards. The differences in regulatory text among these provisions could be interpreted to mean that a regulated entity's obligations differ depending on whether a provision requires it to implement only policies and procedures or whether the provision requires the implementation of something more. This may confuse regulated entities and lead some to believe that less comprehensive protection is needed for ePHI subject only to policies and procedures.
                    </P>
                    <FTNT>
                        <P>
                            <SU>639</SU>
                             
                            <E T="03">See University of Texas M.D. Anderson Cancer Center, supra</E>
                             note 258, p. 479.
                        </P>
                    </FTNT>
                    <P>The Department believes that the current Security Rule provides a clear path for regulated entities to protect the confidentiality, integrity, and availability of ePHI. However, as discussed above, we also believe recent caselaw has created confusion about the steps regulated entities must take to adequately protect the confidentiality, integrity, and availability of ePHI, as required by the statute. Further, the conditions highlighted by caselaw may also cause regulated entities to misinterpret the regulatory text that connects the current maintenance requirement at 45 CFR 164.306(e), the documentation requirement at 45 CFR 164.316, and the requirement to implement physical safeguards. For example, regulated entities may be confused about how 45 CFR 164.316 requires a regulated entity to document the policies and procedures for specific physical safeguard in 45 CFR 164.310 (or across any other safeguard). In this case, the regulated entity also might not apply the implementation specifications to retain, make available, and review documentation of how it has operationalized the physical safeguard. Failing to connect these provisions would lead to inadequate protection of ePHI and/or an inability to demonstrate compliance with the Security Rule.</P>
                    <P>Our experience enforcing the Security Rule provides examples of the types of breaches that can occur because of absent or insufficient physical safeguards:</P>
                    <P>
                        • An investigation of a large health system indicated potential failures to implement policies and procedures and facility access controls to limit physical access to the electronic information systems housed within a large data support center. While the health system did have video surveillance, the investigation found indications that laptops were stored in an interior room that was unlocked and the facility did not have an alarm system.
                        <SU>640</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>640</SU>
                             Resolution Agreement, “Advocate Health Care Network Medical Group,” Office for Civil Rights, U.S. Department of Health and Human Services (July 8, 2016).
                        </P>
                    </FTNT>
                    <P>
                        • A large university hospital experienced a breach of unsecured PHI when it lost an unencrypted flash drive and unencrypted laptop. The Department's investigation found that the covered entity may have failed to use device and media controls, which might have prevented the loss of these devices.
                        <SU>641</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>641</SU>
                             Resolution Agreement, “University of Rochester Medical Center,” Office for Civil Rights, U.S. Department of Health and Human Services (Oct. 30, 2019) (describing a violation of the standard for device and media controls).
                        </P>
                    </FTNT>
                    <P>Given the increased portability of devices, media, workstations, and information systems, such components may often be located outside of a regulated entity's physical location. For example, OCR has investigated several incidents involving portable electronic media and mobile workstations that were removed from the regulated entity's physical environment and subsequently lost. As a result, the Department believes that we should more broadly construe the physical environment where ePHI is stored and accessed because it is essential that regulated entities have policies and procedures in place to address the portability of components of their information systems, as well as the ability of workforce members to access such information systems offsite using portable workstations.</P>
                    <P>Additionally, the standard for device and media controls at 45 CFR 164.310(d)(1) applies only to devices and media, rather than all technology assets that may be components of a regulated entity's relevant electronic information systems. The Department is concerned that a regulated entity may have other types of technology assets that may either create, receive, maintain, or transmit ePHI or otherwise affect its confidentiality, integrity, or availability and that can be removed from, brought to, or moved within its facilities. The confidentiality, integrity, or availability of the regulated entity's ePHI could be negatively affected in the absence of written policies and procedures governing the movement of such technology assets.</P>
                    <P>
                        Finally, we believe that it is important to address several issues in the standards and implementation specifications for the physical safeguards that are also addressed in other proposals: addressing the Department's expectations regarding implementation specifications; 
                        <SU>642</SU>
                        <FTREF/>
                         memorializing policies and procedures in writing; documenting the implementation of the aforementioned policies and procedures; reviewing such policies and procedures on a regular cadence; modifying such policies and procedures when reasonable and appropriate; 
                        <SU>643</SU>
                        <FTREF/>
                         and clarifying the scope of the electronic information systems and their components that regulated entities are expected to consider when establishing their policies and procedures.
                        <SU>644</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>642</SU>
                             
                            <E T="03">See</E>
                             discussion of 45 CFR 164.306.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>643</SU>
                             
                            <E T="03">See University of Texas M.D. Anderson Cancer Center, supra</E>
                             note 258.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>644</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.304 (proposed definitions of “Relevant electronic information systems” and “Technology assets”).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">3. Proposals</HD>
                    <P>The Department proposes to retain the four standards that comprise the Security Rule's physical safeguards required by 45 CFR 164.306 and codified in 45 CFR 164.310. However, we propose several modifications to 45 CFR 164.310 to address the issues identified above.</P>
                    <HD SOURCE="HD3">a. Section 164.310—Physical Safeguards</HD>
                    <P>
                        The Department proposes to expand the introductory language at 45 CFR 
                        <PRTPAGE P="960"/>
                        164.310 to clarify that the Security Rule requires that physical safeguards be applied to all ePHI in the possession of the regulated entity, that is, throughout the regulated entity's facilities. The Department also proposes to expand this section to expressly require a regulated entity to implement physical safeguards in accordance with not only 45 CFR 164.306, but also 45 CFR 164.316 to connect the overarching documentation requirements.
                    </P>
                    <P>
                        Consistent with the proposals to revise the general requirements in 45 CFR 164.306(c) and (d), the Department proposes to remove any distinction between addressable and required implementation specifications in this section such that all specifications would be required. Also consistent with changes proposed elsewhere in this NPRM, the Department proposes to modify all four physical safeguard standards to require that the requisite policies and procedures be in writing 
                        <SU>645</SU>
                        <FTREF/>
                         and implemented throughout the enterprise.
                        <SU>646</SU>
                        <FTREF/>
                         Under this proposal, a regulated entity that could not produce a written policy describing how it will implement a required physical safeguard and demonstrate that the safeguard is in effect and operational throughout the enterprise would not be in compliance with the standard. Consistent with our proposals to require that regulated entities maintain their administrative safeguards, the Department also proposes to require a regulated entity to maintain its security measures by reviewing and testing the required security measures at least once every 12 months, and by modifying the same as reasonable and appropriate. Additionally, we propose to modify certain standards and implementation specifications to ensure that regulated entities understand their obligations to ensure the confidentiality, integrity, and availability of ePHI by implementing physical safeguards to protect their relevant electronic information systems and/or the technology assets in their relevant electronic information systems.
                    </P>
                    <FTNT>
                        <P>
                            <SU>645</SU>
                             
                            <E T="03">See</E>
                             discussion of proposals to revise 45 CFR 164.316.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>646</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.304 (proposed definition of “Implement”).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">b. Section 164.310(a)(1)—Standard: Facility Access Controls</HD>
                    <P>The Department proposes to modify the standard for facility access controls at 45 CFR 164.310(a)(1) to clarify that the policies and procedures required by this standard must be in writing and address physical access to all of a regulated entity's relevant electronic information systems and the facility or facilities in which these systems are housed and to add a paragraph to clarify the organization of the regulatory text. The Department also proposes to modify the implementation specifications associated with the standard for facility access controls. Specifically, we propose to modify the implementation specifications for contingency operations, facility security plan, and access control and validation procedures at 45 CFR 164.310(a)(2)(i) through (iii) to clarify that we expect a regulated entity to not only establish and implement policies and procedures, but also that we expect them to be in writing.</P>
                    <P>
                        The Department's proposal would also require that the procedures for contingency operations proposed at 45 CFR 164.310(a)(2)(i) support the regulated entity's contingency plan, instead of the current requirement specifying that the procedures support the restoration of lost data under the disaster recovery plan and emergency mode operations plan in the event of an emergency.
                        <SU>647</SU>
                        <FTREF/>
                         This proposal would align the implementation specification for contingency operations with the standard for contingency planning at proposed 45 CFR 164.308(a)(13)(i) by specifically ensuring that the written policies and procedures support the required contingency plan. It also would avoid duplicating the implementation specification for disaster recovery planning at proposed 45 CFR 164.308(a)(13)(ii)(D), which would require a regulated entity to address the restoration of lost data and systems in the disaster recovery plan component of its contingency plan. We propose to modify 45 CFR 164.310(a)(2)(ii) to clarify that the written policies and procedures that constitute the facility security plan must apply to all of the regulated entity's facilities and equipment contained within those facilities. The Department proposes to retitle the implementation specification for access control and validation procedures at 45 CFR 164.310(a)(2)(iii) as “Access management and validation procedures” and to require regulated entities to establish and implement written procedures to both authorize and manage a person's role-based access to facilities.
                    </P>
                    <FTNT>
                        <P>
                            <SU>647</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(13).
                        </P>
                    </FTNT>
                    <P>In the implementation specification for maintenance records, the Department proposes at 45 CFR 164.310(a)(2)(iv), to change the provision heading to “Physical maintenance records” and to add security cameras to the list of examples of physical security components about which a regulated entity is required to implement written policies and procedures to document repairs and modifications. Both proposals are consistent with and recognize the evolution of the role that technology plays in managing and granting physical access to facilities.</P>
                    <P>Consistent with our proposals to add maintenance requirements where we believe it is necessary for regulated entities to review, test, and modify their security measures on a particular cadence, we also propose to add an implementation specification for maintenance at proposed 45 CFR 164.310(a)(2)(v). The maintenance provision would require that, for each facility, a regulated entity review and test its written policies and procedures at least once every 12 months, and to modify those policies and procedures as reasonable and appropriate based on that review.</P>
                    <HD SOURCE="HD3">c. Section 164.310(b)(1)—Standard: Workstation Use and Section 164.310(c)—Standard: Workstation Security</HD>
                    <P>
                        Further, in the standards for workstation use and workstation security at 45 CFR 164.310(b) (redesignated as proposed 45 CFR 164.310(b)(1) and (c), respectively), the Department proposes several changes that would recognize the increasingly mobile nature of ePHI and workstations that connect to the information systems of regulated entities. The purpose of these proposals is to ensure that regulated entities properly consider physical safeguards for all workstations, including those that are mobile, and not only those that are located in regulated entities' facilities. The Department also proposes to modify both standards to clarify the organization of the regulatory text. The Department proposes to modify the standard for workstation use to clarify that policies and procedures established by a regulated entity to govern the use of workstations be in writing and address all workstations that access ePHI or the regulated entity's relevant electronic information systems. These proposed changes are consistent with the Department's longstanding expectations and other proposals in this NPRM described above. In 45 CFR 164.310(b)(2)(i)(C), the Department proposes to require a regulated entity to establish and implement written policies and procedures that, among other things, specify the physical attributes of workstation surroundings, including the removal of workstations from a facility and the movement of workstations within and outside of a facility. This proposal is consistent with 
                        <PRTPAGE P="961"/>
                        the proposed revision to the definition of “workstation” discussed above. Additionally, we propose to add an implementation specification for maintenance at proposed 45 CFR 164.310(b)(2)(ii) to require that a regulated entity review and test its written policies and procedures at least once every 12 months, and to modify those policies and procedures as reasonable and appropriate based on that review.
                    </P>
                    <P>
                        Relatedly, the Department proposes to modify the standard for workstation security at 45 CFR 164.310(c) to require a regulated entity to implement physical safeguards for workstations that access ePHI or relevant electronic information systems to comply with its written policies and procedures for workstation use. This proposal would also make clear that such physical safeguards must be modified in response to any modifications to the written policies and procedures for workstation use. As part of their policies and procedures for workstation security, the Department encourages regulated entities to consider, among other things, whether there are workstations located in public areas or other areas that are more vulnerable to theft, unauthorized use, or unauthorized viewing; whether such devices should be relocated; the physical security controls for workstations that are in use (
                        <E T="03">e.g.,</E>
                         cable locks, privacy screens, secured rooms, cameras) and whether they are easy to use; and whether there are additional physical security controls that could reasonably be put into place.
                        <SU>648</SU>
                        <FTREF/>
                         Additionally, consistent with the Department's proposal to require that a regulated entity provide role-based security awareness training on its Security Rule policies and procedures,
                        <SU>649</SU>
                        <FTREF/>
                         the Department expects that such training would address the physical safeguards it has implemented, particularly those policies and procedures for mobile devices that are used to create, receive, maintain, or transmit ePHI or that otherwise affect the confidentiality, integrity, or availability of ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>648</SU>
                             
                            <E T="03">See</E>
                             “Workstation Security: Don't Forget About Physical Security,” Office for Civil Rights, U.S. Department of Health and Human Services, p. 2 (May 2018), 
                            <E T="03">https://www.hhs.gov/sites/default/files/cybersecurity-newsletter-may-2018-workstation-security.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>649</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(11)(ii)(A)(
                            <E T="03">1</E>
                            ).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">d. Section 164.310(d)(1)—Standard: Technology Asset Controls</HD>
                    <P>
                        The Department proposes to modify the standard at 45 CFR 164.310(d)(1) by changing the heading to “Technology asset controls” from “Device and media controls,” and replacing “hardware and electronic media” in 45 CFR 164.310(d)(1) and (2) with “technology assets.” We believe that this modification would more accurately capture the various categories of components of a regulated entity's relevant electronic information systems that may be received in, removed from, or moved within a facility and that also affect the confidentiality, integrity, or availability of ePHI. Thus, we believe that this modification would provide regulated entities with a clearer understanding of their compliance obligations with respect to the physical safeguards that should be implemented to protect ePHI when technology assets are received by, removed from, or moved within a facility. While we are not proposing other significant changes to 45 CFR 164.310(d)(1) at this time, we remind regulated entities to consider the appropriateness of the policies and procedures they have implemented with respect to the movement of technology assets that maintain ePHI into and out of their facilities and the movement of these items within their facilities. The processes a regulated entity chooses to implement to govern the movement of technology assets may vary based on the type of technology asset.
                        <SU>650</SU>
                        <FTREF/>
                         For example, once installed, a server or desktop computer may not need to be moved for the entirety of its lifecycle within the regulated entity, while portable electronic devices and media, such as smartphones, tablets, and USB flash drives are designed to be mobile and may move frequently into, out of, and within a regulated entity's facilities.
                        <SU>651</SU>
                        <FTREF/>
                         Thus, the regulated entity's policies and procedures must account for these differences.
                        <SU>652</SU>
                        <FTREF/>
                         Further, we note that the proposed definition of workstation includes mobile devices. Mobile devices that serve as workstations are subject to the requirements in this paragraph and those in paragraphs (b) and (c).
                    </P>
                    <FTNT>
                        <P>
                            <SU>650</SU>
                             “Considerations for Securing Electronic Media and Devices,” 
                            <E T="03">supra</E>
                             note 631, p. 1.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>651</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>652</SU>
                             
                            <E T="03">See id.</E>
                             for a list of questions that regulated entities should consider when developing their policies and procedures regarding device and media controls.
                        </P>
                    </FTNT>
                    <P>
                        The Department also proposes to modify the standard at 45 CFR 164.310(d)(1) to clarify the organization of regulatory text and to clarify its longstanding expectations that policies and procedures must be in writing and to replace “contain” with “maintain,” consistent with terminology used throughout the HIPAA Rules. The Department believes that having written policies for the disposal of ePHI and the technology assets on which it is stored and for the removal of ePHI from electronic media such that the ePHI cannot be recovered continues to be important to ensuring the physical safety of ePHI. Improper disposal of technology assets puts the ePHI stored in or on such assets at risk for a potential breach, and as discussed elsewhere, data breaches can result in substantial costs to regulated entities and the individuals affected by the breach. We also propose in the related implementation specifications at 45 CFR 164.310(d)(2)(i) and (ii) to require that written policies and procedures for disposal of ePHI and sanitization of electronic media be tied to current standards for sanitizing electronic media before the media are made available for re-use.
                        <SU>653</SU>
                        <FTREF/>
                         For example, photocopiers today are often connected to the same network as workstations and generally store the information, including ePHI, transmitted to them. This capability is a significant change from photocopier capabilities that existed when the Security Rule was first issued in 2003. Under this proposal, a regulated entity would be required to include in its written policies and procedures for disposing of ePHI, and the technology assets on which it is maintained, policies and procedures addressing ePHI maintained on photocopiers, consistent with the current standards for disposing and removing ePHI from electronic media.
                        <SU>654</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>653</SU>
                             
                            <E T="03">See</E>
                             Richard Kissel, et al., “Guidelines for Media Sanitization,” NIST Special Publication 800-88, Revision 1, National Institute of Standards and Technology, U.S. Department of Commerce (Dec. 2014), 
                            <E T="03">https://csrc.nist.gov/publications/detail/sp/800-88/rev-1/final; see also</E>
                             “Proper Disposal of Electronic Devices,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security (Feb. 1, 2021), 
                            <E T="03">https://www.cisa.gov/news-events/news/proper-disposal-electronic-devices.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>654</SU>
                             
                            <E T="03">See</E>
                             “Guidelines for Media Sanitization,” 
                            <E T="03">supra</E>
                             note 653; 
                            <E T="03">see also</E>
                             “Proper Disposal of Electronic Devices,” 
                            <E T="03">supra</E>
                             note 653.
                        </P>
                    </FTNT>
                    <P>We have previously explained in guidance that a regulated entity should consider all of the following as part of its risk analysis:</P>
                    <P>• Disposal of hardware and software, and the documentation of such disposal.</P>
                    <P>• Destruction of ePHI in such a manner that it cannot be recreated.</P>
                    <P>• Secure removal of ePHI that was previously stored on hardware or electronic media such that it cannot be accessed and reused.</P>
                    <P>
                        • The identification of all removable media and their use (
                        <E T="03">e.g.,</E>
                         CDs/DVDs, USB flash drives).
                        <PRTPAGE P="962"/>
                    </P>
                    <P>
                        • The removal of all ePHI from reusable media before the media are reused.
                        <SU>655</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>655</SU>
                             “Guidance on Disposing of Electronic Devices and Media,” Office for Civil Rights, U.S. Department of Health and Human Services, p. 1 (July 2018), 
                            <E T="03">https://www.hhs.gov/sites/default/files/cybersecurity-newsletter-july-2018-Disposal.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        Our guidance describes these considerations in greater detail. For example, regulated entities should consider how to address the replacement of technology assets, including devices and media.
                        <SU>656</SU>
                        <FTREF/>
                         Technology assets that need to be replaced should be decommissioned, meaning that they are taken out of service before the final disposition of such assets.
                        <SU>657</SU>
                        <FTREF/>
                         Steps a regulated entity should consider as part of its decommissioning process include: ensuring technology assets are securely erased and then either securely destroyed or recycled; ensuring that the regulated entity's technology asset inventory is updated to accurately reflect the status of decommissioned technology assets or technology assets slated to be decommissioned; and ensuring that privacy is protected through proper migration to another electronic information system or total destruction of the ePHI.
                        <SU>658</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>656</SU>
                             
                            <E T="03">Id.</E>
                             at 2.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>657</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>658</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>The Department proposes to remove the implementation specifications for accountability and data backup and storage at 45 CFR 164.310(d)(2)(iii) and (iv). We believe that the accountability provisions would be subsumed and replaced by the proposed standard for technology asset inventory at proposed 45 CFR 164.308(a)(1)(i). Thus, when the proposed new standard and implementation specifications are read together, the written policies and procedures that govern the receipt and removal of technology assets that maintain ePHI into and out of a facility, and the movement of these assets within the facility, should include tracking relevant information in the technology asset inventory. Similarly, we are proposing to delete the specification for data backup and storage because it is redundant to the administrative safeguard on data backups at proposed 45 CFR 164.308(a)(13)(ii)(B).</P>
                    <P>
                        As referenced above, in place of the implementation specifications we are proposing to delete, the Department proposes a new implementation specification at proposed 45 CFR 164.310(d)(2)(iii) that would require a regulated entity to review and test the written policies and procedures related to the implementation specifications for technology assets at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate. Such environmental or operational changes may range from new and emerging threats to the confidentiality, integrity, or availability of ePHI (
                        <E T="03">e.g.,</E>
                         a new virus) to the adoption of new technology assets by the regulated entity (
                        <E T="03">e.g.,</E>
                         a new operating system, new types of workstations). Given the constant evolution of IT and methods for restoring data that has been disposed of or was on electronic media that has been sanitized, the Department believes that it is essential for a regulated entity to at least consider the reasonableness and appropriateness of its policies and procedures for disposal and electronic media sanitation, not only annually, but also in the face of any environmental or operational changes. We expect that pursuant to our proposals to strengthen the standard for risk analysis, a regulated entity would be able to identify such environmental and operational changes before they occur.
                    </P>
                    <HD SOURCE="HD3">4. Request for Comment</HD>
                    <P>The Department requests comment on the foregoing proposals, including any benefits, drawbacks, or unintended consequences. We also request comment on the following considerations in particular:</P>
                    <P>a. Whether every 12 months is an appropriate frequency for review of a regulated entity's written policies and procedures for physical safeguards. If not, please explain.</P>
                    <P>b. Whether the written policies and procedures for physical safeguards should be reviewed at different intervals, based on the specific standard or implementation specification. If so, please explain.</P>
                    <P>c. Whether the Department should include additional examples in regulatory text at proposed 45 CFR 164.310(a)(2)(iv) of physical components of a facility related to security for which there should be written policies and procedures to document repairs and modifications.</P>
                    <P>d. Whether the standard at proposed 45 CFR 164.310(d)(1) and its associated implementation specifications at paragraph (d)(2) should apply to technology assets that do not maintain ePHI, but do access the regulated entity's relevant electronic information systems.</P>
                    <HD SOURCE="HD2">F. Section 164.312—Technical Safeguards</HD>
                    <HD SOURCE="HD3">1. Current Provisions</HD>
                    <P>Section 164.312 includes five standards for technical safeguards, which are the requirements concerning the implementation of technology and technical policies and procedures to protect the confidentiality, integrity, and availability of ePHI and related information systems. A regulated entity must comply with the standards for technical safeguards in accordance with 45 CFR 164.306(c), the provision that describes the general rules for the security standards.</P>
                    <P>
                        Under 45 CFR 164.312(a)(1), a regulated entity is required to establish policies and procedures for electronic information systems to allow access only to those persons or software programs that have been granted access rights as specified in 45 CFR 164.308(a)(4). Regulated entities may comply with this standard by implementing a combination of access control methods and technical controls, consistent with the implementation specifications for this standard. The Security Rule does not identify a specific access control method or technology to implement. Regardless of the technology or information system used, access controls should be appropriate for the workforce member's role and/or function.
                        <SU>659</SU>
                        <FTREF/>
                         For example, a workforce member responsible for monitoring and administering information systems with ePHI, such as an administrator or a superuser,
                        <SU>660</SU>
                        <FTREF/>
                         should only have access to ePHI as appropriate for their role and/or job function.
                    </P>
                    <FTNT>
                        <P>
                            <SU>659</SU>
                             “Security Standards: Technical Safeguards,” 
                            <E T="03">supra</E>
                             note 343, p. 4.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>660</SU>
                             A superuser is “a user that is authorized (and therefore, trusted) to perform security-relevant functions that ordinary users are not authorized to perform.” NIST definition of “superuser,” Glossary, Computer Security Resource Center, National Institute of Standards and Technology, U.S. Department of Commerce, 
                            <E T="03">https://csrc.nist.gov/glossary/term/superuser.</E>
                        </P>
                    </FTNT>
                    <P>
                        The implementation specifications that provide instructions for satisfying the access control standard are found at 45 CFR 164.312(a)(2). Two are required and two are addressable.
                        <SU>661</SU>
                        <FTREF/>
                         The implementation specifications address unique user identifiers,
                        <SU>662</SU>
                        <FTREF/>
                         emergency access procedures,
                        <SU>663</SU>
                        <FTREF/>
                         automatic logoff,
                        <SU>664</SU>
                        <FTREF/>
                         and encryption and decryption.
                        <SU>665</SU>
                        <FTREF/>
                         The implementation 
                        <PRTPAGE P="963"/>
                        specification for unique user identification requires a regulated entity to assign unique identifiers to users to facilitate the identification of specific users of an information system.
                        <SU>666</SU>
                        <FTREF/>
                         By assigning a unique identifier to each user, a regulated entity can track the specific activity of that user when they are logged into an information system and hold the user accountable for functions they perform in the information system when they access that system.
                    </P>
                    <FTNT>
                        <P>
                            <SU>661</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.306(d) for an explanation of “required” and “addressable” implementation specifications.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>662</SU>
                             45 CFR 164.312(a)(2)(i).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>663</SU>
                             45 CFR 164.312(a)(2)(ii).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>664</SU>
                             45 CFR 164.312(a)(2)(iii).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>665</SU>
                             45 CFR 164.312(a)(2)(iv).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>666</SU>
                             45 CFR 164.312(a)(2)(i).
                        </P>
                    </FTNT>
                    <P>
                        Under the implementation specification for emergency access procedures, a regulated entity is required to establish procedures, such as documented operational practices and instructions to workforce members, for obtaining access to necessary ePHI during an emergency and to implement such procedures as needed.
                        <SU>667</SU>
                        <FTREF/>
                         In accordance with this implementation specification, a regulated entity must identify the types of situations in which its normal procedures for accessing an information system or application that contains ePHI may not work and establish procedures for obtaining access in those situations.
                        <SU>668</SU>
                        <FTREF/>
                         These procedures must be established prior to an emergency to instruct workforce members on possible ways to gain access to needed ePHI where, for example, the electrical system has been severely damaged or rendered inoperative, or where a software update fails and prevents the regulated entity from accessing ePHI in its EHR.
                    </P>
                    <FTNT>
                        <P>
                            <SU>667</SU>
                             45 CFR 164.312(a)(2)(ii).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>668</SU>
                             “Security Standards: Technical Safeguards,” 
                            <E T="03">supra</E>
                             note 343, p. 5.
                        </P>
                    </FTNT>
                    <P>
                        The implementation specification for automatic logoff associated with the standard for access control addresses the need for a regulated entity to, when reasonable and appropriate, implement electronic procedures that terminate an electronic session after a period of inactivity.
                        <SU>669</SU>
                        <FTREF/>
                         Automatic logoff is an effective way to prevent unauthorized users from accessing ePHI on a workstation when it is left unattended for a period of time.
                        <SU>670</SU>
                        <FTREF/>
                         While many applications have configuration settings that automatically log a user out of the system after a period of inactivity, some systems have more limited capabilities and may activate a screen saver that is password protected.
                        <SU>671</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>669</SU>
                             45 CFR 164.312(a)(2)(iii).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>670</SU>
                             “Security Standards: Technical Safeguards,” 
                            <E T="03">supra</E>
                             note 343, p. 6.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>671</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        The implementation specification under the standard for access control addresses encryption and decryption and requires regulated entities, when it is reasonable and appropriate, to implement a mechanism to encrypt and decrypt ePHI.
                        <SU>672</SU>
                        <FTREF/>
                         Encrypting data, including ePHI, reduces the likelihood that anyone other than the party that has the key to the encryption algorithm would be able to decrypt (
                        <E T="03">i.e.,</E>
                         translate) the data and convert it into plain, comprehensible text.
                        <SU>673</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>672</SU>
                             45 CFR 164.312(a)(2)(iv).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>673</SU>
                             “Security Standards: Technical Safeguards,” 
                            <E T="03">supra</E>
                             note 343, p. 7.
                        </P>
                    </FTNT>
                    <P>
                        The standard for audit controls requires a regulated entity to implement hardware, software, and/or procedural mechanisms that record and examine activity in electronic information systems that contain or use ePHI. Most electronic information systems provide some level of audit controls with a reporting method, such as audit reports.
                        <SU>674</SU>
                        <FTREF/>
                         These controls are useful for recording and examining information system activity, especially when determining whether a security violation has occurred.
                        <SU>675</SU>
                        <FTREF/>
                         The Security Rule does not identify data that must be gathered by the audit controls or how often the audit reports should be reviewed.
                        <SU>676</SU>
                        <FTREF/>
                         Instead, a regulated entity must consider its risk analysis and organizational factors, such as current technical infrastructure and hardware and software security capabilities, to determine reasonable and appropriate audit controls for information systems that contain or use ePHI.
                        <SU>677</SU>
                        <FTREF/>
                         The audit controls standard has no implementation specifications.
                    </P>
                    <FTNT>
                        <P>
                            <SU>674</SU>
                             “Understanding the Importance of Audit Controls,” Cybersecurity Newsletter, Office for Civil Rights, U.S. Department of Health and Human Services, p. 1 (Jan. 2017), 
                            <E T="03">https://www.hhs.gov/sites/default/files/january-2017-cyber-newsletter.pdf?language=es.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>675</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>676</SU>
                             
                            <E T="03">Id.</E>
                             at 2.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>677</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Section 164.312(c)(1), the standard for integrity, requires a regulated entity to implement policies and procedures to protect ePHI from improper alteration or destruction. The integrity of data can be compromised by both technical and non-technical sources. Workforce members or business associates may make accidental or intentional changes that improperly alter or destroy ePHI. Data can also be altered or destroyed without human intervention, such as by electronic media errors or failures.
                        <SU>678</SU>
                        <FTREF/>
                         The purpose of this standard is to establish and implement policies and procedures for protecting ePHI from being compromised regardless of the source. Improperly altered or destroyed ePHI can result in clinical quality problems for a covered entity, including patient safety issues.
                        <SU>679</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>678</SU>
                             “Security Standards: Technical Safeguards,” 
                            <E T="03">supra</E>
                             note 343, p. 7.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>679</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Section 164.312(c)(2) contains the addressable implementation specification for the integrity standard that requires a regulated entity, when reasonable and appropriate, to implement electronic mechanisms to corroborate that ePHI has not been altered or destroyed in an unauthorized manner. To determine which electronic mechanisms should be implemented to ensure the integrity of ePHI, a regulated entity must consider the various risks to the integrity of ePHI identified during the risk analysis. Once a regulated entity has identified risks to the integrity of its data, it must identify security measures that will reduce the risks.
                        <SU>680</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>680</SU>
                             
                            <E T="03">Id.</E>
                             at 9.
                        </P>
                    </FTNT>
                    <P>The standard for person or entity authentication at 45 CFR 164.312(d) requires a regulated entity to establish policies and procedures for verifying that a person seeking access to ePHI is the one claimed. This standard addresses technical controls for ensuring access is allowed only to those persons or software programs that have been granted access rights under the administrative safeguard for information access management at 45 CFR 164.308(a)(4). This standard has no implementation specifications.</P>
                    <P>
                        Under the standard for transmission security at 45 CFR 164.312(e)(1), a regulated entity is required to implement technical security measures to guard against unauthorized access to ePHI when transmitted electronically, such as through the internet. A regulated entity must identify the available and appropriate means to protect ePHI as it is transmitted, select appropriate solutions, and document its decisions.
                        <SU>681</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>681</SU>
                             
                            <E T="03">Id.</E>
                             at 10.
                        </P>
                    </FTNT>
                    <P>
                        The two addressable implementation specifications for the transmission security standards are under 45 CFR 164.312(e)(2). The implementation specification for integrity controls requires a regulated entity, when it is reasonable and appropriate, to implement security measures to ensure that electronically transmitted ePHI is not improperly modified without detection until the ePHI has been disposed.
                        <SU>682</SU>
                        <FTREF/>
                         The implementation specification for encryption requires a regulated entity, when it is reasonable and appropriate, to implement a mechanism to encrypt ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>682</SU>
                             45 CFR 164.312(e)(2)(i).
                        </P>
                    </FTNT>
                    <PRTPAGE P="964"/>
                    <HD SOURCE="HD3">2. Issues To Address</HD>
                    <P>While the intention of 45 CFR 164.312 is for regulated entities to develop and put into place technical controls, the Department is aware that regulated entities have not always achieved the degree of protection for ePHI that we intended. Absent a definition of “implement,” some regulated entities might interpret the term to mean something other than implementing technical controls to ensure the confidentiality, integrity, and availability of ePHI. This misinterpretation may leave ePHI partially unprotected because regulated entities may not implement safeguards throughout their enterprise. As discussed above with respect to both the administrative and physical safeguards, the Department is also concerned that regulated entities are not making the connection between the maintenance requirement at 45 CFR 164.306(d) and the requirement to implement technical safeguards, and therefore, are not reviewing or updating their policies and procedures for technical safeguards. Additionally, the Department believes that regulated entities may not be recognizing that their obligations under the Security Rule to protect ePHI are not limited to protecting electronic information systems that create, receive, maintain, or transmit ePHI, but necessarily include other electronic information systems that affect the confidentiality, integrity, or availability of ePHI.</P>
                    <P>
                        While the Security Rule relies on a flexible and scalable approach to compliance, the health care industry's shift to a digital environment has substantially increased both the risk to ePHI and the prevalence of technological solutions for addressing those risks. Additionally, the cost of such solutions has, in many cases, decreased over time, as is often the case with technology. For example, when the original Security Rule was published, tools to encrypt ePHI had limited availability, were more costly, and were not user-friendly, particularly for small health care providers.
                        <SU>683</SU>
                        <FTREF/>
                         By contrast, in 2024, the technical ability to encrypt data may be seamless in many applications, inexpensive, and widely available in commercial software and hardware products.
                        <SU>684</SU>
                        <FTREF/>
                         Where an encryption solution is not integrated into an application, software, or hardware, third-party solutions are often available.
                        <SU>685</SU>
                        <FTREF/>
                         Thus, we do not believe that it is appropriate for such provisions to be “addressable.” 
                        <SU>686</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>683</SU>
                             68 FR 8334, 8357 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>684</SU>
                             For example, the ONC Health IT Certification Program requires that certified health IT certified to the end-user device encryption certification criterion at 45 CFR 170.315(d)(7) must encrypt electronic health information stored on end-user devices after use of the technology on those devices stops or prevent electronic health information from being locally stored on end-user devices after use of the technology on those devices stops. 
                            <E T="03">See also</E>
                             “Security Standards: Technical Safeguards,” 
                            <E T="03">supra</E>
                             note 343, p. 7.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>685</SU>
                             “How to Protect the Data that is Stored on Your Devices,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security (access July 26, 2024), 
                            <E T="03">https://www.cisa.gov/resources-tools/training/how-protect-data-stored-your-devices; see also</E>
                             Karen Scarfone, et al., “[Information Technology Laboratory (ITL)] Bulletin: August 2020, Security Considerations for Exchanging Files Over the internet,” National Institute of Standards and Technology, U.S. Department of Commerce (Aug. 2020), 
                            <E T="03">https://csrc.nist.gov/files/pubs/shared/itlb/itlbul2020-08.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>686</SU>
                             45 CFR 164.306(d).
                        </P>
                    </FTNT>
                    <P>Based on its own investigations and compliance reviews, news reports, and published studies, the Department is aware that many regulated entities have failed to implement adequate technical controls, or, in some cases, any technical controls. For example:</P>
                    <P>
                        • A large health system that operates in multiple States experienced a massive data breach resulting from a hacking incident. OCR's investigation found indications of potential failures to sufficiently monitor its activity in its information systems that was insufficient to protect against a cyberattack, implement an authentication process to safeguard its ePHI, and have security measures in place to protect ePHI from unauthorized access when it was being transmitted electronically.
                        <SU>687</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>687</SU>
                             “Banner Health,” 
                            <E T="03">supra</E>
                             note 567.
                        </P>
                    </FTNT>
                    <P>
                        • A Rhode Island nonprofit health system experienced a data breach resulting from the theft of a laptop. OCR's investigation found indications of potential failures to encrypt ePHI, despite the entity's determination to implement encryption, and a lack of device and media controls.
                        <SU>688</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>688</SU>
                             Resolution Agreement, “Lifespan,” Office for Civil Rights, U.S. Department of Health and Human Services (June 26, 2020), 
                            <E T="03">https://www.hhs.gov/sites/default/files/lifespan-ra-cap-signed.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        • At a large covered entity, workforce members used their log-in credentials to access medical records maintained in the entity's EHR without a job-related purpose.
                        <SU>689</SU>
                        <FTREF/>
                         OCR's investigation found evidence of potential violations of the requirement to implement reasonable and appropriate policies and procedures to comply with the standards, implementation specifications, or other requirements of the Security Rule.
                        <SU>690</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>689</SU>
                             Resolution Agreement, “Yakima Valley Memorial Hospital,” Office for Civil Rights, U.S. Department of Health and Human Services (May 15, 2023), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/yakima-ra-cap/index.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>690</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        • At another covered entity, the potential failure to implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use ePHI, among other things, enabled a workforce member to sell the ePHI of more than 12,000 individuals.
                        <SU>691</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>691</SU>
                             
                            <E T="03">See</E>
                             “Montefiore Medical Center,” 
                            <E T="03">supra</E>
                             note 248.
                        </P>
                    </FTNT>
                    <P>
                        Some investigations have found indications that regulated entities may implement technical controls that address some, but not all, users of and technology assets in a relevant electronic information system, such as software, hardware, and persons involved in the development, configuration, and implementation of technical controls.
                        <SU>692</SU>
                        <FTREF/>
                         And other investigations have suggested that the potential failure of a regulated entity to have security measures in place to protect ePHI from unauthorized access when it is transmitted electronically has resulted in increased risk and breaches of ePHI.
                        <SU>693</SU>
                        <FTREF/>
                         Common network segmentation practices would have substantially reduced the risk to the security ePHI and could have prevented such breaches.
                    </P>
                    <FTNT>
                        <P>
                            <SU>692</SU>
                             
                            <E T="03">See, e.g.,</E>
                             “HHS Office for Civil Rights Settles HIPAA Investigation with Arizona Hospital System Following Cybersecurity Hacking,” 
                            <E T="03">supra</E>
                             note 570.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>693</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Beyond the health care sector, threat actors have been able to gain access to networks by compromising user accounts and taking advantage of insufficient network segregation. For example, the 2014 Home Depot breach involved the compromise of a third-party vendor's username and password to enter Home Depot's network, which allowed hackers to obtain elevated rights to navigate to self-checkout point-of-sale system.
                        <SU>694</SU>
                        <FTREF/>
                         The Department is concerned about the potential effects of such incidents in health care, where they would jeopardize the confidentiality, integrity, and availability of ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>694</SU>
                             “The Home Depot Reports Findings in Payment Data Breach Investigation,” Home Depot (Nov. 6, 2014), 
                            <E T="03">https://ir.homedepot.com/news-releases/2014/11-06-2014-014517315.</E>
                        </P>
                    </FTNT>
                    <P>
                        Finally, consistent with the concerns expressed above about the implications of recent caselaw and the uncertainty it might cause among regulated entities assessing whether they have adequately protected their ePHI, the Department is concerned that the existing Security Rule may not provide sufficient instruction to regulated entities about 
                        <PRTPAGE P="965"/>
                        how they must maintain specific security measures.
                    </P>
                    <HD SOURCE="HD3">3. Proposals</HD>
                    <P>The Department retains the requirements for technical safeguards generally and proposes additions and modifications to the existing standards and implementation specifications.</P>
                    <HD SOURCE="HD3">a. Section 164.312—Technical Safeguards</HD>
                    <P>The Department proposes to expand the primary provision at 45 CFR 164.312 to clarify that regulated entities as a general matter must implement and document the implementation of technical safeguards adopted for compliance with the Security Rule. This proposal would clarify that the requirement to implement and document technical safeguards would apply to all technical safeguards, including technical controls, implemented by a regulated entity to protect the confidentiality, integrity, and availability of all ePHI it creates, receives, maintains, or transmits.</P>
                    <P>As noted above, the current provision at 45 CFR 164.312 does not reference the documentation requirements in 45 CFR 164.316. Therefore, for clarity, we propose to explicitly require in 45 CFR 164.312 that documentation of technical safeguards conforms to the requirements in 45 CFR 164.316. This proposed change would clarify that a regulated entity must document the policies and procedures required to comply with this rule and how entities considered the flexibility factors in 45 CFR 164.306(b). It would also clarify that a regulated entity must document each action, activity, and assessment required by the Security Rule. The Department considers the documentation requirements and other provisions of 45 CFR 164.316 to apply to all of the safeguards, including the technical safeguards, and this proposal is intended to remove any potential uncertainty among regulated entities. Additionally, we propose to add maintenance requirements separately to the implementation specifications for particular technical safeguards in 45 CFR 164.312, as discussed below and consistent with our proposals to add similar requirements to particular administrative and physical safeguards.</P>
                    <P>Additionally, as discussed above, the Department proposes to remove the distinction between required and addressable implementation specifications and make all implementation specifications required, with specific, limited exceptions. Also as discussed above, we propose to modify certain standards and implementation specifications to clarify that the technical safeguards apply to ensure the confidentiality, integrity, and availability of ePHI, which requires a regulated entity to implement the technical safeguards in or on all relevant electronic information systems. These proposals are discussed in greater detail below.</P>
                    <HD SOURCE="HD3">b. Section 164.312(a)(1)—Standard: Access Control</HD>
                    <P>
                        The Department proposes to clarify the standard for access control at 45 CFR 164.312(a)(1) by requiring a regulated entity to deploy technical controls in relevant electronic information systems to allow access only to those users and technology assets that have been granted access rights. This proposed modification would ensure that a regulated entity deploys technical controls, rather than solely ensuring that it implements technical policies and procedures, consistent with our proposals to define “deploy” and “implement.” 
                        <SU>695</SU>
                        <FTREF/>
                         Thus, the proposal would clarify that a regulated entity is not expected to merely establish a policy and procedure, but must also put into place, ensure the operation of, and verify the continued operation of, technical controls for access to its relevant electronic information systems such that the failure to have such technical control in operation throughout its enterprise would be a violation of the new proposed standard. Additionally, the Department's proposal would clarify that access controls would apply to persons with authorized access and to technology assets.
                    </P>
                    <FTNT>
                        <P>
                            <SU>695</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.304 (proposed definitions of “Deploy” and “Implement”).
                        </P>
                    </FTNT>
                    <P>
                        Access controls are one of the key mechanisms by which a regulated entity protects ePHI. Such technical controls ensure that access to the regulated entity's electronic information systems is limited to only users and technology assets that have been granted access rights under the policies and procedures adopted in accordance with the standard for information access management under 45 CFR 164.308.
                        <SU>696</SU>
                        <FTREF/>
                         The Security Rule does not identify a specific type of access control method or technology to deploy, nor are we proposing to do so in this rule.
                        <SU>697</SU>
                        <FTREF/>
                         As discussed above, access rights should be role-based and the technical controls should assist the regulated entity in implementing such policies and procedures. For example, workforce members responsible for monitoring and administering a regulated entity's relevant electronic information systems, such as someone responsible for cybersecurity or providing technical support to users, must only have access to ePHI and to the regulated entity's relevant electronic information systems as appropriate for their role and job function.
                    </P>
                    <FTNT>
                        <P>
                            <SU>696</SU>
                             “Security Standards: Technical Safeguards,” 
                            <E T="03">supra</E>
                             note 343, p. 3.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>697</SU>
                             
                            <E T="03">Id.</E>
                             at 4.
                        </P>
                    </FTNT>
                    <P>We also propose at 45 CFR 164.312(a)(1) to add a paragraph heading to clarify the organization of the regulatory text.</P>
                    <P>The Department proposes to modify the existing implementation specifications under the standard for access control and to add five new implementation specifications. Additionally, we propose to redesignate the implementation specification for encryption and decryption as a standard.</P>
                    <P>We propose to modify the implementation specification for unique user identification at 45 CFR 164.312(a)(2)(i) by renaming the implementation specification as “Unique identification” and adding a requirement to assign a unique identifier for tracking each technology asset. These proposed modifications would clarify for regulated entities that the purpose of this requirement is to enable a regulated entity to identify and track unauthorized activity in its relevant electronic information systems. Such unauthorized activity may include activity by unauthorized persons or technology assets. It may also include activity by persons who are authorized to access the regulated entity's relevant information systems but who access ePHI that they do not need to access for their job or function.</P>
                    <P>
                        The Department also proposes to expand the types of identifiers a regulated entity may assign to users and technology assets beyond names to include numbers and/or other identifiers and to clarify that a unique identifier must be assigned to each user and technology asset in the regulated entity's relevant electronic information systems. This proposed modification would better meet the goals of this implementation specification by requiring a regulated entity to be able to discern and track activities among all users and technology assets, regardless of whether that user or technology asset is a person, hardware, software program, or device. The proposed implementation specification for unique identification aligns with the Department's essential CPG for Unique Credentials, which calls for regulated entities to use unique credentials to 
                        <PRTPAGE P="966"/>
                        help detect and track anomalous activities.
                        <SU>698</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>698</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <P>
                        Additionally, we propose to add an implementation specification at proposed 45 CFR 164.312(a)(2)(ii) for administrative and increased access privileges. Access controls should enable an authorized user to access the minimum necessary information needed to perform their job functions.
                        <SU>699</SU>
                        <FTREF/>
                         Rights and/or privileges should be granted to authorized users based on the policies and procedures required under the administrative safeguard for information access management.
                        <SU>700</SU>
                        <FTREF/>
                         For example, a workforce member who has certain role-based administrative access privileges should have separate user identities for non-administrative access privileges and administrative access privileges. Separating a single workforce member's user identities based on access privilege substantially limits the risk that an intruder will be able to access ePHI through a workforce member's user identity when they are using the administrative access privileges.
                        <SU>701</SU>
                        <FTREF/>
                         A regulated entity may be able to improve the control and review of the use of administrative access privileges, such as through a privileged access management system, to understand how privileged accounts are used within its environment and help detect and prevent the misuse of privileged accounts.
                        <SU>702</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>699</SU>
                             
                            <E T="03">Id.</E>
                             at 3-4.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>700</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.308(a)(4) and proposed 45 CFR 164.308(a)(10).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>701</SU>
                             
                            <E T="03">See</E>
                             “Controlling Access to ePHI: For Whose Eyes Only?,” 
                            <E T="03">supra</E>
                             note 416.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>702</SU>
                             “Defending Against Common Cyber-Attacks,” 
                            <E T="03">supra</E>
                             note 396.
                        </P>
                    </FTNT>
                    <P>
                        The proposed implementation specification would require a regulated entity to separate the unique user identities required by the implementation specification for unique user identification based on the type of access privileges used by a specific unique user. For example, the adoption of health IT that is certified through the ONC Health IT Certification Program as having the technical capability to establish user permissions for accessing, and performing actions with, electronic health information based on unique identifiers may contribute to a regulated entity's compliance with the proposed new implementation specification for administrative and increased access privileges, should the proposal be finalized.
                        <SU>703</SU>
                        <FTREF/>
                         This proposed new implementation specification aligns with the Department's essential CPG for Separate User and Privileged Accounts by addressing the separation of privileged or administrator access rights from common user accounts.
                        <SU>704</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>703</SU>
                             
                            <E T="03">See</E>
                             45 CFR 170.315(d)(1).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>704</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <P>
                        Additionally, the Department proposes to redesignate the implementation specification for emergency access procedures at 45 CFR 164.312(a)(2)(ii) as proposed 45 CFR 164.312(a)(2)(iii) and to modify it to require a regulated entity to establish both written procedures and technical procedures for obtaining necessary ePHI during an emergency and to implement them as needed. For example, we note that the adoption of health IT that is certified through the ONC Health IT Certification Program as having the technical capability to permit an identified set of users to access electronic health information during an emergency may contribute to a regulated entity's compliance with the proposed implementation specification for emergency access procedures, should the proposal be finalized.
                        <SU>705</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>705</SU>
                             
                            <E T="03">See</E>
                             45 CFR 170.315(d)(6).
                        </P>
                    </FTNT>
                    <P>
                        Under the Department's proposal, the implementation specification for automatic logoff at 45 CFR 164.312(a)(2)(iii) would be redesignated as proposed 45 CFR 164.312(a)(2)(iv) and modified to require a regulated entity to deploy technical controls that terminate an electronic session after a period of inactivity. Deploying a mechanism to automatically terminate an electronic session after a period of inactivity reduces the risk of unauthorized access when a user forgets or is unable to terminate their session.
                        <SU>706</SU>
                        <FTREF/>
                         Failure to deploy automatic logoff not only increases the risk of unauthorized access and potential alteration or destruction of ePHI; it also impedes an organization's ability to properly investigate such unauthorized access because it would appear to originate from an authorized user.
                        <SU>707</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>706</SU>
                             “Controlling Access to ePHI: For Whose Eyes Only?,” 
                            <E T="03">supra</E>
                             note 416.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>707</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        The Department proposes that the period of inactivity be both predetermined and reasonable and appropriate. When determining the length of the period of inactivity, a regulated entity should consider the access privileges of a given user or technology asset, the system(s) being accessed, the environment in which the system access occurs, and other appropriate factors in determining a reasonable and appropriate time of inactivity before session termination. For example, in an emergency setting, a user may not have time to manually log out of a system. User identities with administrative and other high-level access that present a greater risk to the confidentiality, integrity, and availability of ePHI should have appropriately shorter periods of inactivity because of the increased risk. While many applications have configuration settings for automatic logoff,
                        <SU>708</SU>
                        <FTREF/>
                         a regulated entity must determine whether the default automatic logoff is reasonable and appropriate and make modifications if it is not. For example, the adoption of health IT that is certified through the ONC Health IT Certification Program as having the technical capability to automatically stop a user's access to health information after inactivity for a predetermined period and require a user to re-enter their credentials to resume or regain access may contribute to a regulated entity's compliance with the proposed implementation specification for automatic logoff, should the proposal be finalized.
                        <SU>709</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>708</SU>
                             For example, Windows 10 operating system allows users to customize security options to automatically logout a user after a specified period of inactivity.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>709</SU>
                             
                            <E T="03">See</E>
                             45 CFR 170.315(d)(5).
                        </P>
                    </FTNT>
                    <P>
                        Additionally, we propose to add an implementation specification for log-in attempts at proposed 45 CFR 164.312(a)(2)(v). The proposal would require a regulated entity to deploy technical controls that disable or suspend the access of a user or technology asset to relevant electronic information systems after a certain number of unsuccessful authentication attempts. Although incorrectly keying in a known password by the intended user may occur infrequently, a repeated and persistent failure is a strong indication of an attempt at unauthorized access. For example, brute force attacks are attempts to gain unauthorized access by guessing the password many times in a row.
                        <SU>710</SU>
                        <FTREF/>
                         Technical controls that limit the number of incorrect log-in attempts by disabling or suspending the access of a user or technology asset to relevant electronic information systems are appropriate to address unsuccessful login attempts.
                        <SU>711</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>710</SU>
                             “Brute Force Attacks Conducted by Cyber Actors,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security (May. 6, 2020), 
                            <E T="03">https://www.cisa.gov/news-events/alerts/2018/03/27/brute-force-attacks-conducted-cyber-actors.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>711</SU>
                             “Security and Privacy Controls for Information Systems and Organizations,” 
                            <E T="03">supra</E>
                             note 600, p. 39.
                        </P>
                    </FTNT>
                    <P>
                        The proposal would require a regulated entity to determine the number of unsuccessful authentication attempts that would trigger disabling or suspending access to relevant electronic information system. The number should 
                        <PRTPAGE P="967"/>
                        be reasonable and appropriate for the type of user or technology asset, the electronic information system or technology asset to which access is sought, and the type of information maintained on such information system or technology asset. For example, a regulated entity may determine that any authentication failure of an administrative privileged access account should disable the account because of the level of risk compared to an authentication failure of a non-administrative privileged account. The Department does not propose to define disable or suspend and relies upon the industry understanding that disabling a user's access would require intervention to restore the capability to use the user identity, while a suspension may prevent additional log-in attempts for a temporary, limited period of time.
                    </P>
                    <P>
                        Consistent with NCVHS' recommendation and existing guidance, the Department also proposes to add an implementation specification for network segmentation at 45 CFR 164.312(a)(2)(vi) that would require a regulated entity to deploy technical controls to segment its relevant electronic information systems in a reasonable and appropriate manner.
                        <SU>712</SU>
                        <FTREF/>
                         Under this proposal, a regulated entity with multiple, distinct electronic information systems would be required to separate relevant electronic information systems using reasonable and appropriate technical controls. Network segmentation is a physical or virtual division of a network into multiple segments, creating boundaries between the operational and IT networks to reduce risks, such as threats caused by phishing attacks.
                        <SU>713</SU>
                        <FTREF/>
                         For example, where a regulated entity operates both a point-of-sale system and an EHR on the same network, the EHR could be compromised through a successful attack by an intruder moving laterally (
                        <E T="03">i.e.,</E>
                         within the same network) from a previously compromised point-of-sale system because the intruder's movements were not impeded by network segmentation. Accordingly, we believe that it is appropriate to require regulated entities to deploy technical controls to segment the networks to which their relevant electronic information systems are connected.
                        <SU>714</SU>
                        <FTREF/>
                         What constitutes reasonable and appropriate network segmentation depends on the regulated entity's risk analysis and how it has implemented its network(s) and relevant electronic information systems. This proposed new implementation specification aligns with the Department's enhanced CPG for Network Segmentation because where the CPG is implemented, an intruder's ability to freely move within a regulated entity's network and protect ePHI is minimized.
                        <SU>715</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>712</SU>
                             
                            <E T="03">See</E>
                             Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, Appendix p. 3 (recommending that the Department require network segmentation as part of a layered security approach, segregating network components based on user characteristics, such as corporate network compared to business associate network); “Layering Network Security Through Segmentation,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security, 
                            <E T="03">https://www.cisa.gov/sites/default/files/publications/layering-network-security-segmentation_infographic_508_0.pdf;</E>
                             “Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients,” 
                            <E T="03">supra</E>
                             note 16, pp. 23 and 31; PR.IR-01, “The NIST Cybersecurity Framework (CSF) 2.0,” 
                            <E T="03">supra</E>
                             note 15.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>713</SU>
                             “Layering Network Security Through Segmentation,” 
                            <E T="03">supra</E>
                             note 712.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>714</SU>
                             Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, Appendix p. 3.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>715</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <P>The proposed implementation specification for data controls at proposed 45 CFR 164.312(a)(2)(vii) would require a regulated entity to deploy technical controls to allow access to ePHI based on the regulated entity's policies and procedures for granting users and technology assets access relevant electronic information systems as specified in proposed 45 CFR 164.308(a)(10). This implementation specification would require a regulated entity to have in place technical controls that distinguish between users and technology assets, that are permitted to access the regulated entity's relevant electronic information systems and those that are not permitted to do so and would require that the controls permit or disallow access accordingly.</P>
                    <P>
                        Properly deployed network-based solutions can limit the ability of a hacker to gain access to an organization's network or impede the ability of a hacker already in the network from accessing other electronic information systems—especially systems containing sensitive data.
                        <SU>716</SU>
                        <FTREF/>
                         Access controls could include role-based access, user-based access, or any other access control mechanisms the organization deems appropriate.
                        <SU>717</SU>
                        <FTREF/>
                         Access controls need not be limited to computer systems—firewalls, network segmentation, and network access control solutions are effective means of limiting access to relevant electronic information systems.
                        <SU>718</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>716</SU>
                             “Controlling Access to ePHI: For Whose Eyes Only?,” 
                            <E T="03">supra</E>
                             note 416.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>717</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>718</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>Additionally, we propose to add an implementation specification for maintenance at proposed 45 CFR 164.312(a)(2)(viii). Under this proposal, a regulated entity would be expressly required to review and test the effectiveness of the procedures and technical controls required by the implementation specifications associated with the standard for access control at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate.</P>
                    <HD SOURCE="HD3">c. Section 164.312(b)(1)—Standard: Encryption and Decryption</HD>
                    <P>
                        Encryption can reduce the risks and costs of unauthorized access to ePHI.
                        <SU>719</SU>
                        <FTREF/>
                         For example, if a hacker gains access to unsecured ePHI on a network server or if a device containing unsecured ePHI is stolen, a breach of PHI will be presumed and reportable under the Breach Notification Rule.
                        <SU>720</SU>
                        <FTREF/>
                         The Breach Notification Rule applies to unsecured PHI, which is PHI that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified by the Secretary in guidance issued under the HITECH Act.
                        <SU>721</SU>
                        <FTREF/>
                         The Department's guidance on rendering unsecured PHI unusable, unreadable, or indecipherable to persons who are not authorized to access such PHI states that ePHI at rest (
                        <E T="03">i.e.,</E>
                         stored in an information system or electronic media) is considered secured if it is encrypted in a manner consistent with NIST Special Publication 800-111 
                        <SU>722</SU>
                        <FTREF/>
                         (“SP 800-111”). The ePHI encrypted in a manner consistent with SP 800-111 is not considered unsecured PHI and therefore qualifies for what is commonly known as the Breach Notification safe harbor, meaning that it is not subject to the requirements of the Breach Notification Rule.
                        <SU>723</SU>
                        <FTREF/>
                         Thus, by encrypting ePHI in a manner consistent with the Secretary's guidance, a regulated entity may not only fulfill its encryption obligation under the Security Rule, but also make use of the 
                        <PRTPAGE P="968"/>
                        Breach Notification Rule's safe-harbor provision.
                        <SU>724</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>719</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>720</SU>
                             
                            <E T="03">See</E>
                             45 CFR 402. The presumption applies unless it can be rebutted in accordance with the breach risk assessment described in 45 CFR 164.402(2).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>721</SU>
                             45 CFR 164.402.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>722</SU>
                             Karen Scarfone, et al., “Guide to Storage Encryption Technologies for End User Devices: Recommendations of the National Institute of Standards and Technology,” NIST Special Publication 800-111, National Institute of Standards and Technology, U.S. Department of Commerce (Nov. 2007), 
                            <E T="03">https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-111.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>723</SU>
                             74 FR 19600, 19009-19010 (Apr. 27, 2009).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>724</SU>
                             45 CFR 164.402.
                        </P>
                    </FTNT>
                    <P>
                        As the use of mobile computing devices (
                        <E T="03">e.g.,</E>
                         laptops, smartphones, tablets) has become more pervasive, the risks to sensitive data stored on such devices also have increased.
                        <SU>725</SU>
                        <FTREF/>
                         And while in 2003 and even in 2013, encryption might have been out of reach for many regulated entities because of cost or a similar reason,
                        <SU>726</SU>
                        <FTREF/>
                         today, encryption solutions are generally considered to be widely accessible. The cost of such solutions has decreased significantly, as has the difficulty in implementing such solutions. In fact, many applications have encryption solutions embedded in them.
                        <SU>727</SU>
                        <FTREF/>
                         Once enabled, a device's encryption solution can protect stored sensitive data, including ePHI, from unauthorized access in the event the device is lost or stolen. The same is true for most software today.
                        <SU>728</SU>
                        <FTREF/>
                         Thus, while encryption of a particular regulated entity's ePHI might not have been reasonable and appropriate in 2003 or 2013, the Department believes encryption generally is reasonable and appropriate today.
                        <SU>729</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>725</SU>
                             “Controlling Access to ePHI: For Whose Eyes Only?,” 
                            <E T="03">supra</E>
                             note 416.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>726</SU>
                             
                            <E T="03">See</E>
                             68 FR 8334, 8357 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>727</SU>
                             “Controlling Access to ePHI: For Whose Eyes Only?,” 
                            <E T="03">supra</E>
                             note 416.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>728</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>729</SU>
                             
                            <E T="03">See</E>
                             discussion of 45 CFR 164.312, 
                            <E T="03">infra.</E>
                        </P>
                    </FTNT>
                    <P>
                        Because the prevalence of encryption solutions has increased, as has their affordability and the role they play in protecting information, including ePHI, the Department believes it is appropriate to consider requiring encryption and elevating it from an implementation specification to a standard to increase its visibility and prominence. Based on this and consistent with NCVHS' recommendation, the Department proposes to redesignate the implementation specification for encryption and decryption at 45 CFR 164.312(a)(2)(iv) as a standard at proposed 45 CFR 164.312(b)(1).
                        <SU>730</SU>
                        <FTREF/>
                         The proposed standard would incorporate the requirements of two implementation specifications that address encryption—the one addressed here and the one at 45 CFR 164.312(e)(2)(ii).
                        <SU>731</SU>
                        <FTREF/>
                         The Department proposes that the new standard would require a regulated entity to configure and implement technical controls to encrypt and decrypt all ePHI in a manner that is consistent with prevailing cryptographic standards. This proposed new standard aligns with the Department's essential CPG for Strong Encryption by calling for regulated entities to deploy encryption to protect ePHI and with the recommendation of NCVHS.
                        <SU>732</SU>
                        <FTREF/>
                         We also note that the adoption of health IT that is certified through the ONC Health IT Certification Program as having the technical capability to encrypt and decrypt electronic health information, using an encryption algorithm that meets certain requirements, may contribute to a regulated entity's compliance with the proposed standard for encryption and decryption, should the proposal be finalized.
                        <SU>733</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>730</SU>
                             Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, Appendix p. 2.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>731</SU>
                             The Department is also proposing to delete the implementation specification for encryption at 45 CFR 164.312(e)(2)(ii) because we are proposing to address the substantive requirements of that implementation specification in proposed 45 CFR 164.312(b)(2).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>732</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18; Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, Appendix p. 2.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>733</SU>
                             
                            <E T="03">See</E>
                             45 CFR 170.315(d)(7) and 170.210(a).
                        </P>
                    </FTNT>
                    <P>Under the proposal, a regulated entity would need to ensure that an encryption solution that it adopts meets prevailing cryptographic standards prior to using it. The Department uses the phrase “prevailing cryptographic standards” to refer to widely accepted standards for encryption and decryption that are recommended by authoritative sources and that ensure the confidentiality, integrity, and availability of ePHI at the time the regulated entity performs its risk analysis and establishes or modifies its risk management plan. The Department would expect a regulated entity to deploy updated encryption solutions as prevailing cryptographic standards evolve, consistent with both of the proposed requirements discussed above: (1) to review, verify, and update its risk analysis in response to changes in its environment that may affect ePHI; and (2) to review and modify, as reasonable and appropriate, its risk management plan in response to changes in its risk analysis. Thus, a regulated entity using an encryption algorithm that is known to be insecure would not be in compliance with the proposed requirement to deploy an encryption algorithm that meets prevailing cryptographic standards. We are not proposing to define prevailing cryptographic standards in regulatory text at this time.</P>
                    <P>
                        The Department proposes to add one implementation specification for the proposed standard for encryption and decryption. Specifically, proposed 45 CFR 164.312(b)(2) would require regulated entities to encrypt all ePHI at rest and in transit, with limited exceptions.
                        <SU>734</SU>
                        <FTREF/>
                         Thus, a regulated entity would be required to encrypt all ePHI it maintains, as well as all ePHI it transmits, unless an exception applies, and the following conditions are met:
                    </P>
                    <FTNT>
                        <P>
                            <SU>734</SU>
                             For example, adoption of health IT that is certified through the ONC Health IT Certification Program as having the technical capability to encrypt, or prevent the local storage of, electronic health information stored on end-user devices after use of the technology on those devices stops may contribute to a regulated entity's compliance with the proposed implementation specification for encryption and decryption. 
                            <E T="03">See</E>
                             45 CFR 170.315(d)(7). Additionally, the proposed implementation specification generally is consistent with the Health Data, Technology, and Interoperability: Patient Engagement, Information Sharing, and Public Health Interoperability (HTI-2) NPRM proposal to modify 45 CFR 170.315(d)(7), should it be finalized, to include requirements that authentication credentials be protected using industry-standard encryption and decryption. 
                            <E T="03">See</E>
                             89 FR 63536-37, 63778 (Aug. 5, 2024).
                        </P>
                    </FTNT>
                    <P>• Each exception applies only to the ePHI directly affected by the circumstances described in the specific exception.</P>
                    <P>• Each exception applies only to the extent that the regulated entity documents its understanding that the exception applies to the scenario in which the regulated entity relies upon the exception and why or how the exception applies, and that any additional applicable conditions are met.</P>
                    <P>
                        The first proposed exception at proposed 45 CFR 164.312(b)(3)(i) would apply to a technology asset currently used by a regulated entity that does not support encryption according to prevailing cryptographic standards. Because the requirements for encryption under the Security Rule today are addressable, a regulated entity may be in compliance with the encryption requirement without actual encryption of ePHI if encryption is not reasonable and appropriate, provided that the entity meets certain conditions. Additionally, technology assets in use today may rely on cryptographic standards that are no longer accepted industry practice. The Department recognizes that it may take some time for a regulated entity to adopt compliant technology assets. Thus, we propose this exception for such technology assets that do not support encryption consistent with prevailing cryptographic standards in limited circumstances. Specifically, to meet this exception, a regulated entity would be required to establish a written plan to migrate ePHI to technology assets that support encryption consistent with prevailing cryptographic standards and to implement such plan. The regulated entity would be required to establish and implement the written plan within 
                        <PRTPAGE P="969"/>
                        a reasonable and appropriate period of time. For example, it would not be reasonable or appropriate for a regulated entity to establish a plan to migrate ePHI on a single flash drive within 30 days and not complete migration of that ePHI for a period of a year because migrating ePHI from a flash drive to a more secure medium is a simple and quick process that the regulated entity already determined could be completed within 30 days. Thus, a year would be an unreasonably long period to leave ePHI insufficiently encrypted, particularly after a need to migrate the ePHI has been established. In such circumstances, the regulated entity would not be complying with the requirements of this proposed exception.
                    </P>
                    <P>
                        The second proposed exception at proposed 45 CFR 164.312(b)(3)(ii) would be available for ePHI transmitted in response to an individual request, pursuant to 45 CFR 164.524, to receive their ePHI in an unencrypted manner. Unencrypted manners for an individual to receive their ePHI may include some types of text messaging, instant messaging, and other applications on a smartphone or another computing device that are capable of making an access request and receiving ePHI.
                        <SU>735</SU>
                        <FTREF/>
                         This exception for individual access requests under 45 CFR 164.524 would not apply when the individual would receive their ePHI using technology controlled by the regulated entity, such as a patient portal 
                        <SU>736</SU>
                        <FTREF/>
                         or other technology for the transmission of ePHI (
                        <E T="03">e.g.,</E>
                         API technology).
                        <SU>737</SU>
                        <FTREF/>
                         Such email or messaging technologies are considered to be among a covered entity's technology assets because they are components of a covered entity's relevant electronic information systems, and the requirement to encrypt ePHI would apply.
                    </P>
                    <FTNT>
                        <P>
                            <SU>735</SU>
                             Messaging in the context of telehealth is discussed in Department guidance on telehealth. 
                            <E T="03">See</E>
                             “Guidance on How the HIPAA Rules Permit Covered Health Care Providers and Health Plans to Use Remote Communication Technologies for Audio-Only Telehealth,” Office for Civil Rights, U.S. Department of Health and Human Services (June 13, 2022), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-audio-telehealth/index.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>736</SU>
                             For example, health IT certified through the ONC Health IT Certification Program as meeting the “[v]iew, download, and transmit to 3rd party” certification criterion must be able to create and transmit continuity of care document summaries to patients through email via an encrypted method of electronic transmission. 
                            <E T="03">See</E>
                             45 CFR 170.315(e)(1).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>737</SU>
                             The ONC Health IT Certification Program sets forth at 45 CFR 170.550(h) the privacy and security certification framework for Health IT Modules. Section 170.550(h) identifies a mandatory minimum set of the certification criteria that ONC ACBs must ensure are also included as part of specific Health IT Modules that are presented for certification. For example, to meet the “[s]tandardized API for patient and population services” certification criterion, the ONC Health IT Certification Program requires that a Health IT Module presented for testing and certification must demonstrate the ability to establish a secure and trusted connection with an application requesting data for patients. 
                            <E T="03">See</E>
                             45 CFR 170.315(g)(10); 
                            <E T="03">see also</E>
                             45 CFR 170.215.
                        </P>
                    </FTNT>
                    <P>
                        Under the right of access, an individual who is the subject of PHI has the right to inspect and request a copy of PHI about them in a designated record set, subject to certain exceptions. A regulated entity is required to provide such access in the form and format requested by the individual, if it is readily producible in such form and format. Thus, if an individual requests that the regulated entity provide them access in a manner that does not support encryption, a regulated entity is generally required to do so if it does not jeopardize the security of the regulated entity's information systems. For the exception to apply, a regulated entity would be required to have informed the individual of the risks associated with the transmission, receipt, and storage of unencrypted ePHI when the individual requests unencrypted access and to document that the individual has been informed of such risks.
                        <SU>738</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>738</SU>
                             
                            <E T="03">See</E>
                             “Resource for Health Care Providers on Educating Patients about Privacy and Security Risks to Protected Health Information when Using Remote Communication Technologies for Telehealth,” Office for Civil Rights, U.S. Department of Health and Human Services, (Oct. 17, 2023), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/resource-health-care-providers-educating-patients/index.html.</E>
                        </P>
                    </FTNT>
                    <P>
                        Consistent with the information blocking regulations, the information provided by regulated entities that are also actors must: focus on any current privacy and/or security risks posed by the technology or the third-party developer of the technology; be factually accurate, unbiased, objective, and not unfair or deceptive; and be provided in a non-discriminatory manner.
                        <SU>739</SU>
                        <FTREF/>
                         For example, a regulated entity that is an actor must provide information to individuals about the privacy and security risks of all mobile health applications in the same manner.
                    </P>
                    <FTNT>
                        <P>
                            <SU>739</SU>
                             
                            <E T="03">See</E>
                             45 CFR part 171; 85 FR 25642, 25815 (May 1, 2020).
                        </P>
                    </FTNT>
                    <P>
                        We are not proposing to require that the documentation be in any particular form or format. Rather, the required information could be on a standard form, chart note, or checkbox, as examples. The Department does not propose to apply this exception to ePHI transmitted in other forms or formats, such as on a CD or other physical device used to maintain and transmit ePHI. The proposal would not absolve a regulated entity from compliance with other applicable laws or regulations, including the information blocking regulations.
                        <SU>740</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>740</SU>
                             
                            <E T="03">See, e.g.,</E>
                             45 CFR part 171.
                        </P>
                    </FTNT>
                    <P>
                        We recognize that emergencies or other occurrences may render it infeasible to encrypt ePHI. Thus, the third proposed exception at 45 CFR 164.312(b)(3)(iii) would apply to certain circumstances in which encryption is infeasible. Such circumstances would be limited to when there is emergency or other occurrence that adversely affects a regulated entity's relevant electronic information systems. For the proposed exception to apply, a regulated entity would be required to implement reasonable and appropriate compensating controls in accordance with and determined by its contingency plan.
                        <SU>741</SU>
                        <FTREF/>
                         The Department would expect this proposed exception to be applicable for a limited period of time and only when encryption is infeasible. As noted above, the proposed exception to encryption would narrowly apply only when a regulated entity's relevant electronic information system is adversely affected by the emergency or other occurrence. The proposed exception would no longer be applicable at such time encryption becomes feasible, regardless of whether the emergency or other occurrence continues.
                    </P>
                    <FTNT>
                        <P>
                            <SU>741</SU>
                             45 CFR 164.308(a)(13).
                        </P>
                    </FTNT>
                    <P>
                        The fourth proposed set of exceptions at proposed 45 CFR 164.312(b)(3)(iv) would be for ePHI that is created, received, maintained, or transmitted by a medical device (
                        <E T="03">i.e.,</E>
                         a “device” within the meaning of section 201(h) of the Federal Food, Drug, and Cosmetic Act, 21 U.S.C. 321(h)) that is authorized by the FDA for marketing. We propose three separate exceptions for devices that are authorized by the FDA for marketing pursuant to: a submission received before March 29, 2023; a submission received on or after March 29, 2023, where the device is no longer supported by its manufacturer; or a submission received on or after March 29, 2023, where the device is supported by its manufacturer. Where a device has been authorized by the FDA for marketing pursuant to a submission received before March 29, 2023, we propose that the exception at proposed 45 CFR 164.312(b)(3)(iv)(A) would be available only where the regulated entity deploys in a timely manner any updates or patches required or recommended by the manufacturer of the device. We also propose a similar exception at proposed 45 CFR 164.312(b)(3)(iv)(B) for devices authorized by the FDA for marketing pursuant to a submission received on or 
                        <PRTPAGE P="970"/>
                        after March 29, 2023, where the device is no longer supported by its manufacturer, provided that the regulated entity has deployed any updates or patches required or recommended by the manufacturer.
                    </P>
                    <P>
                        We recognize that, to comply with this proposal, some regulated entities may incur costs for replacing legacy medical devices (
                        <E T="03">i.e.,</E>
                         medical devices that cannot be reasonably protected against current cybersecurity threats).
                        <SU>742</SU>
                        <FTREF/>
                         We also recognize that legacy devices can pose significant risks to the confidentiality, integrity, and availability of ePHI.
                        <SU>743</SU>
                        <FTREF/>
                         By limiting these exceptions to devices that have been updated and/or patched while they were supported by their manufacturer, we believe that this proposal would balance the interest in encouraging regulated entities to dispense with legacy devices with the cost of replacing such devices. Additionally, the Department believes that regulated entities should already have plans to replace legacy devices that cannot be made cybersecure because of their existing Security Rule obligations. We also recognize that at some point, most, if not all, devices will likely become legacy devices and that there may be legitimate reasons not to immediately replace them when the manufacturer ceases to provide support. In such cases, it will continue to be important for regulated entities to plan for how to address their ongoing Security Rule obligations.
                    </P>
                    <FTNT>
                        <P>
                            <SU>742</SU>
                             
                            <E T="03">See</E>
                             “Next Steps Toward Managing Legacy Medical Device Cybersecurity Risks,” MITRE Corporation (Nov. 2023), 
                            <E T="03">https://www.mitre.org/sites/default/files/2023-11/PR-23-3695-Managing-Legacy-Medical-Device%20Cybersecurity-Risks.pdf;</E>
                             “Principles and Practices for the Cybersecurity of Legacy Medical Devices,” International Medical Device Regulators Forum, p. 8 (Apr. 11, 2023), 
                            <E T="03">https://www.imdrf.org/sites/default/files/2023-04/IMDRF%20Principles%20and%20Practices%20 of%20Cybersecurity%20for%20%20Legacy%20 Medical%20Devices%20Final%20%28N70%29_1.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>743</SU>
                             “Cybersecurity,” U.S. Food &amp; Drug Administration, U.S. Department of Health and Human Services, 
                            <E T="03">https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity.</E>
                        </P>
                    </FTNT>
                    <P>
                        Finally, we propose an exception, proposed 45 CFR 164.312(b)(3)(iv)(C), that would be available for a device authorized by the FDA for marketing pursuant to a submission received on or after March 29, 2023, where the device is supported by its manufacturer. We understand that the FDA considers security during the review of medical device marketing submissions, including those for software that is approved as a medical device, and works with device manufacturers to ensure that appropriate cybersecurity protections are built into such devices, pursuant to FDA's authority under the Consolidated Appropriations Act, 2023.
                        <SU>744</SU>
                        <FTREF/>
                         Thus, we do not believe it would be necessary or appropriate for the Security Rule to require encryption for an FDA-authorized medical device that has been authorized by the FDA for marketing pursuant to a submission received on or after March 29, 2023 where the device continues to be supported by its manufacturer.
                    </P>
                    <FTNT>
                        <P>
                            <SU>744</SU>
                             
                            <E T="03">See</E>
                             sec. 3305 of Public Law 117-328, 126 Stat. 5832 (Dec. 29, 2022) (codified at 21 U.S.C. 360n-2); 
                            <E T="03">see also</E>
                             “Cybersecurity in Medical Devices Frequently Asked Questions (FAQs),” U.S. Food &amp; Drug Administration, U.S. Department of Health and Human Services, 
                            <E T="03">https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity-medical-devices-frequently-asked-questions-faqs.</E>
                        </P>
                    </FTNT>
                    <P>Where a proposed exception applies to the proposed encryption requirement, the Department also proposes to require that a regulated entity implement alternative measures and compensating controls. Specifically, we propose at proposed 45 CFR 164.312(b)(4)(i) to require a regulated entity to document the existence of an applicable exception and implement reasonable and appropriate compensating controls. Under the proposal, we would require documentation to occur in real-time, meaning when the criteria for the exception exist and at the time compensating controls are implemented. For example, a regulated entity disclosing ePHI to an individual by unencrypted email in accordance with the right of access would be required to document in accordance with the proposed 45 CFR 164.312(b)(4)(i) that: (1) before the disclosure, the individual has requested to receive ePHI by unencrypted email or unencrypted messaging technology; and (2) before the disclosure, the regulated entity informed the individual of the risks associated with transmission of unencrypted ePHI. The exception would not apply where such individual requests to receive access to their ePHI pursuant to 45 CFR 164.524 via email or messaging technologies implemented by the covered entity.</P>
                    <P>
                        At proposed 45 CFR 164.312(b)(4)(i), the Department proposes to require that where a proposed exception applies, a regulated entity would also be required to implement an alternative measure or measures that are reasonable and appropriate compensating controls under proposed 45 CFR 164.312(b)(4)(ii). Compensating controls would be implemented in the place of encryption to protect ePHI from unauthorized access.
                        <SU>745</SU>
                        <FTREF/>
                         The Department does not propose to require that compensating controls be limited to technical controls. Rather, a regulated entity should consider the nature of the exception, operating environment, and other appropriate circumstances to determine what controls are reasonable and appropriate and implement compensating controls effective for those circumstances. For example, a regulated entity may use physical access controls, such as physically limiting access to a device, in combination with other controls to compensate for the absence of encryption.
                    </P>
                    <FTNT>
                        <P>
                            <SU>745</SU>
                             Celia Paulsen, et al., “Glossary of Key Information Security Terms,” NIST Interagency and Internal Reports 7298, Revision 3, National Institute of Standards and Technology, U.S. Department of Commerce (July 3, 2019), 
                            <E T="03">https://nvlpubs.nist.gov/nistpubs/ir/2019/NIST.IR.7298r3.pdf.</E>
                        </P>
                    </FTNT>
                    <P>Proposed paragraph (b)(4)(ii)(A) would require that if the regulated entity has determined that an exception applies, it must secure ePHI by implementing reasonable and appropriate compensating controls that are reviewed and approved by the regulated entity's designated Security Official. Because exceptions are a departure from the Security Rule framework, the Department proposes to ensure appropriate focus and review by the Security Official of the controls chosen to compensate for the absence of encryption.</P>
                    <P>With respect to the exception at proposed 45 CFR 164.312(b)(3)(iv)(C), the Department proposes at paragraph (b)(4)(ii)(B) to presume that a regulated entity had implemented reasonable and appropriate compensating controls where the regulated entity has deployed the security measures prescribed and as instructed by the FDA-authorized label for the device. This would include any updates, including patches recommended or required by the manufacturer of the device. The proposed language recognizes that while the device's label may not specifically require deployment of an encryption solution, it may provide for a specific compensating control and the manner in which that control is to be implemented. While not required, a regulated entity would be permitted to implement additional alternative security measures and compensating controls in accordance with best practices and/or its risk analysis.</P>
                    <P>
                        Finally, at proposed paragraph (b)(4)(ii)(C), the Department proposes to require that the regulated entity's Security Official review and document the implementation and effectiveness of the compensating controls during any period in which such compensating controls are in use to continue securing ePHI and relevant electronic 
                        <PRTPAGE P="971"/>
                        information systems. While regulated entities should review deployed compensating controls on a routine basis, the Department proposes to require a regulated entity to periodically review the implementation and effectiveness of compensating controls to ensure the continued protection of ePHI.
                        <SU>746</SU>
                        <FTREF/>
                         For example, if a regulated entity's plan to migrate ePHI from hardware that does not support encryption changes such that the use of the unencrypted hardware continues for a longer period of time, the regulated entity should review implemented compensating controls to ensure ongoing effectiveness and whether new compensating controls should be deployed. We propose to require the designated Security Office conduct such review at least once every 12 months or in response to environmental or operational changes, whichever is more frequent. Additionally, the Department proposes to require that the review be documented in writing and signed. If the regulated entity's Security Official review determines that certain compensating controls are no longer effective, the Department expects that the regulated entity would adopt new compensating controls that are effective to continue to meet the applicable exception. For example, a regulated entity would be expected to update any compensating controls for use of an FDA-authorized medical device when and as instructed by the manufacturer of the device.
                    </P>
                    <FTNT>
                        <P>
                            <SU>746</SU>
                             The Department does not propose to require that the periodic review include a review of whether the conditions of the exception continue to apply because, when the conditions qualifying for an exception change such that an exception no longer applies, a regulated entity would be expected to resume compliance with the standard for encryption and decryption and the associated implementation specifications without exception.
                        </P>
                    </FTNT>
                    <P>We also propose to add an implementation specification for maintenance at proposed 45 CFR 164.312(b)(5). Under this proposal, a regulated entity would be expressly required to review and test the effectiveness of the technical controls required by the standard for encryption at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate. This proposal is consistent with others in this NPRM that would require regulated entities to maintain specified administrative, physical, and technical safeguards.</P>
                    <HD SOURCE="HD3">d. Section 164.312(c)(1)—Standard: Configuration Management</HD>
                    <P>
                        The Department believes that the failure to configure technical controls appropriately and to establish and maintain secure baselines for relevant electronic information systems and technology assets in its relevant electronic information systems presents an opportunity for cyberattack and compromise of ePHI.
                        <SU>747</SU>
                        <FTREF/>
                         Accordingly, we propose to add a standard for configuration management at proposed 45 CFR 164.312(c)(1). The proposed standard would require a regulated entity to establish and deploy technical controls for securing relevant electronic information systems and technology assets in its relevant electronic information systems, including workstations, in a consistent manner. Under this proposal, a regulated entity also would be required to establish a baseline (
                        <E T="03">i.e.,</E>
                         minimum) level of security for each relevant electronic information system and technology asset in its relevant electronic information systems and to maintain such information systems and technology assets according to those secure baselines. Consistent with our proposals regarding risk analysis and risk management planning, the Department intends for a regulated entity to establish its security baseline and to maintain that baseline even when technology changes. For example, a regulated entity that uses software to access ePHI would be required to update the software with patches as reasonable and appropriate. But where a developer ceases to support a software, it would be reasonable and appropriate for the regulated entity to take steps to either replace it or to otherwise ensure that its level of security remains consistent with the regulated entity's established baseline. Under this proposal, if finalized, the Department would expect a regulated entity to continually monitor its relevant electronic information systems and technology assets in its relevant electronic information systems to ensure that the secure baselines established by the regulated entity are maintained and take appropriate actions when a relevant electronic information system or technology asset in a relevant electronic information system fails to meet the established baselines. A regulated entity's secure baselines would be determined based on its risk analysis and use of security settings that are consistent across its relevant electronic information systems and technology assets in its relevant electronic information systems. For example, the risk analysis may determine that a manufacturer's default settings for a particular technology asset are insufficient. Accordingly, the regulated entity may establish the baseline for settings that should be applied to the particular asset and similar technologies across the regulated entity's enterprise. This proposed standard aligns with the Department's enhanced CPG for Configuration Management, which calls for regulated entities to define secure device and system settings. It also aligns with the enhanced CPG for Detect and Respond to Relevant Threats and Tactics, Techniques, and Procedures by calling for regulated entities to include malware protection in their security baseline to detect threats and protect electronic information systems.
                        <SU>748</SU>
                        <FTREF/>
                         Additionally, the proposed standard also aligns with the Department's essential CPG for Email Security, which addresses the reduction of risks from email-based threats.
                        <SU>749</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>747</SU>
                             “Defending Against Common Cyber-Attacks,” 
                            <E T="03">supra</E>
                             note 396; 
                            <E T="03">see also</E>
                             “HIPAA and Cybersecurity Authentication,” 
                            <E T="03">supra</E>
                             note 368.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>748</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>749</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        The Department proposes five implementation specifications for the proposed standard for configuration management.
                        <SU>750</SU>
                        <FTREF/>
                         Under the proposed implementation specification for anti-malware protection at proposed 45 CFR 164.312(c)(2)(i), a regulated entity would be required to deploy technology assets and/or technical controls that protect all of the technology assets in its relevant electronic information systems against malicious software, such as viruses and ransomware. Anti-malware software, especially when used in combination with other technical controls such as intrusion detection/prevention solutions, can also help prevent, detect, and contain cyberattacks.
                        <SU>751</SU>
                        <FTREF/>
                         This protection would be applied to all of a regulated entity's technology assets in its relevant electronic information systems. When determining how to fulfill this proposed obligation, regulated entities may consider deploying tools such as anti-malware and endpoint detection and response (EDR) solutions. Anti-malware tools generally scan a regulated entity's electronic information systems to 
                        <PRTPAGE P="972"/>
                        identify malicious software.
                        <SU>752</SU>
                        <FTREF/>
                         Such tools may also quarantine malicious software if identified. As explained by the Office of Management and Budget, “EDR combines real-time continuous monitoring and collection of endpoint data [. . .] with rules-based automated response and analysis capabilities.” 
                        <SU>753</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>750</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.312(c)(2).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>751</SU>
                             “What Happened to My Data?: Update on Preventing, Mitigating and Responding to Ransomware,” Cybersecurity Newsletter, Office for Civil Rights, U.S. Department of Health and Human Services (Dec. 2019), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity-newsletter-fall-2019/index.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>752</SU>
                             
                            <E T="03">See</E>
                             “Understanding Anti-Virus Software,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Dept. of Homeland Security (June 30, 2009, rev. Sept. 27, 2019), 
                            <E T="03">https://www.cisa.gov/news-events/news/understanding-anti-virus-software.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>753</SU>
                             “Improving Detection of Cybersecurity Vulnerabilities and Incidents on Federal Government Systems through Endpoint Detection and Response,” M-22-01, Office of Management and Budget, Executive Office of the President, p. 1 (Oct. 8, 2021), 
                            <E T="03">https://www.whitehouse.gov/wp-content/uploads/2021/10/M-22-01.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        We propose a new implementation specification for software removal at proposed 45 CFR 164.312(c)(2)(ii) to require a regulated entity to remove extraneous software from the regulated entity's relevant electronic information systems. Software is extraneous if it is unnecessary for the regulated entity's operations. It can be a target for attack, and older applications may no longer be supported with patches for new vulnerabilities.
                        <SU>754</SU>
                        <FTREF/>
                         Removal of unnecessary software reduces an avenue of attack. The Department is not proposing to specify what would constitute necessary and unnecessary software. Rather, we intend that the regulated entity would consider removal of unwanted or unused software, for example, default software added by a computer manufacturer or reseller where such software may open an avenue for unnecessary risk because the regulated entity does not intend to use it. Accordingly, the proposal would require a regulated entity to consider all software on its relevant electronic information systems and any potential avenue of risk and address the risk through software removal where such software is unnecessary for the regulated entity's operations.
                    </P>
                    <FTNT>
                        <P>
                            <SU>754</SU>
                             “Defending Against Common Cyber-Attacks,” 
                            <E T="03">supra</E>
                             note 396.
                        </P>
                    </FTNT>
                    <P>
                        The proposed implementation specification for configuration at proposed 45 CFR 164.312(c)(2)(iii) would require a regulated entity to configure and secure operating systems and software in a manner consistent with the regulated entity's risk analysis. Generally, a regulated entity's risk analysis should guide its implementation of appropriate technical controls to reduce the risk to ePHI.
                        <SU>755</SU>
                        <FTREF/>
                         Requiring operating systems and software to be maintained in a secure manner would reduce exploitable vulnerabilities.
                        <SU>756</SU>
                        <FTREF/>
                         Often, known vulnerabilities can be mitigated by applying vendor patches or upgrading to a newer version.
                        <SU>757</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>755</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>756</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>757</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Under the proposed implementation specification for network ports at proposed 45 CFR 164.312(c)(2)(iv), a regulated entity would be required to disable network ports in accordance with the regulated entity's risk analysis.
                        <SU>758</SU>
                        <FTREF/>
                         Successful ransomware deployment often depends on the exploitation of technical vulnerabilities such as unsecured ports.
                        <SU>759</SU>
                        <FTREF/>
                         The proposal to require network ports to be disabled in accordance with the risk analysis would reduce exploitable vulnerabilities.
                        <SU>760</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>758</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(2).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>759</SU>
                             “What Happened to My Data?: Update on Preventing, Mitigating and Responding to Ransomware,” 
                            <E T="03">supra</E>
                             note 751.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>760</SU>
                             “Defending Against Common Cyber-Attacks,” 
                            <E T="03">supra</E>
                             note 396.
                        </P>
                    </FTNT>
                    <P>Lastly, the proposed implementation specification for maintenance at proposed 45 CFR 164.312(c)(2)(v) would expressly require a regulated entity to review and test the effectiveness of the technical controls required by the other implementation specifications associated with the standard for configuration management at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate.</P>
                    <HD SOURCE="HD3">e. Section 164.312(d)(1)—Standard: Audit Trail and System Log Controls</HD>
                    <P>
                        Audit controls are crucial technical safeguards that are useful for recording and examining activity in electronic information systems, especially when determining whether a security violation occurred.
                        <SU>761</SU>
                        <FTREF/>
                         A regulated entity must consider its risk analysis and organizational factors, such as current technical infrastructure, hardware, and software security capabilities, to determine reasonable and appropriate audit controls.
                        <SU>762</SU>
                        <FTREF/>
                         However, based on OCR's enforcement experience, we believe that regulated entities' understanding of and compliance with this standard could be improved by providing more specificity.
                    </P>
                    <FTNT>
                        <P>
                            <SU>761</SU>
                             “Security Standards: Technical Safeguards,” 
                            <E T="03">supra</E>
                             note 343, p. 7.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>762</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Accordingly, the Department proposes to redesignate the standard for audit controls at 45 CFR 164.312(b) as proposed 45 CFR 164.312(d)(1), rename it as the standard for audit trail and system log controls, and to add a paragraph heading to clarify the organization of the regulatory text. We also propose to modify it to require a regulated entity to deploy either or both technology assets and technical controls that record and identify activity in the regulated entity's relevant electronic information systems. The proposal would replace “procedural mechanisms” with “technical controls,” to match the general focus on technical controls in 45 CFR 164.312 and would recognize that a regulated entity may be able to meet the requirements of the standard by deploying either or both technology assets (
                        <E T="03">e.g.,</E>
                         software) or technical controls. Under the proposal, a regulated entity would be required to collect sufficient information to understand what a specific activity in its relevant electronic information systems is, such that the regulated entity would be better able to address activity that presents a risk to the confidentiality, integrity, or availability of ePHI. For example, a regulated entity should understand that a given activity in a relevant electronic information system is an attempt to access a portable workstation without authorization. The proposal also would modify the limitation on the regulated entity's obligation to record and identify activity in its relevant electronic information systems. Thus, the proposal would require a regulated entity to record and identify any activity that could present a risk to ePHI, meaning activity in all of its relevant electronic information systems, not only in its electronic information systems that create, receive, maintain, or transmit ePHI. In so doing, the Department would also require a regulated entity to record and identify activity in its electronic information systems that may affect the confidentiality, integrity, or availability of ePHI. This redesignated standard, as proposed, aligns more closely with the Department's enhanced CPG for Centralized Log Collection by addressing the deployment of technical controls to record and identify activity in all electronic information systems.
                        <SU>763</SU>
                        <FTREF/>
                         Additionally, as an example, we note that adoption of health IT certified through the ONC Health IT Certification Program may contribute to a regulated entity's compliance with the proposed standard for audit trail and system log controls where such health IT meets the criteria for auditing actions on health information and recording actions related to electronic health information and audit log status.
                        <SU>764</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>763</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>764</SU>
                             The criterion for auditing actions on health information requires adoption of health IT that has 
                            <PRTPAGE/>
                            the technical capability to record actions related to electronic health information; restrict the ability for auditing to be disabled to a limited set of users, if the technology permits; detect whether an audit log has been altered; and not allow actions recorded related to electronic health information to be changed, overwritten, or deleted by technology. 
                            <E T="03">See</E>
                             45 CFR 170.315(d)(10); 
                            <E T="03">see</E>
                             45 CFR 170.315(d)(2); 
                            <E T="03">see also</E>
                             45 CFR 170.210(e).
                        </P>
                    </FTNT>
                    <PRTPAGE P="973"/>
                    <P>
                        The Department proposes four implementation specifications under this proposed standard that are intended to improve the effectiveness of audit controls deployed by a regulated entity. The proposed implementation specification for monitoring and identifying activity at proposed 45 CFR 164.312(d)(2)(i) would require a regulated entity to deploy technology assets and/or technical controls that monitor in real-time (
                        <E T="03">i.e.,</E>
                         contemporaneously) all activity occurring in a regulated entity's relevant electronic information systems and identify indications of unauthorized persons and unauthorized activity, as determined by the regulated entity's risk analysis. As proposed, the technology assets and/or technical controls also would be required to alert workforce members of such indications in accordance with the regulated entity's policies and procedures for information system activity review at proposed 45 CFR 164.308(a)(7). Unauthorized activity may include actions by technology assets or persons that have not been authorized to access the regulated entity's ePHI or relevant electronic information systems. It may also include actions by authorized users or technology assets that are inconsistent with the regulated entity's policies and procedures for information access management at proposed 45 CFR 164.308(a)(10). The Department proposes that monitoring be continual and conducted in real-time because asynchronous review would allow for the compromise of ePHI for the period of time between the unauthorized activity and its discovery. OCR's enforcement experience has shown that some regulated entities are potentially failing to implement appropriate audit controls or to review information system activity in a timely manner, which may have contributed to a reportable breach.
                        <SU>765</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>765</SU>
                             
                            <E T="03">See, e.g.,</E>
                             “Montefiore Medical Center,” 
                            <E T="03">supra</E>
                             note 248.
                        </P>
                    </FTNT>
                    <P>
                        A regulated entity would be required, under the proposed implementation specification for recording activity at proposed 45 CFR 164.312(d)(2)(ii), to deploy technology assets and/or technical controls that record in real-time all activity in the regulated entity's relevant electronic information systems.
                        <SU>766</SU>
                        <FTREF/>
                         While technical assets and/or technical controls deployed in accordance with proposed 45 CFR 164.312(d)(2)(i) would monitor activity in its relevant electronic information systems, recording such activity would enable a regulated entity to assess any activity to better understand the activity's effects. The proposed implementation specification at proposed 45 CFR 164.312(d)(2)(iii) would require a regulated entity to deploy technology assets and/or technical controls to retain records of all activity in its relevant electronic information systems as determined by the regulated entity's policies and procedures for information system activity review at 45 CFR 164.308(a)(7)(ii)(A). The proposed implementation specification for scope of activity at proposed 45 CFR 164.312(d)(2)(iv) would clarify what would constitute activity to be monitored and recorded in the regulated entity's relevant electronic information systems as required by the proposed implementation specifications at proposed 45 CFR 164.312(d)(2)(i) and (ii). Specifically, the Department proposes that such activities would include, but would not be limited to, creating, accessing, receiving, transmitting, modifying, copying, or deleting ePHI; and creating, accessing, receiving, transmitting, modifying, copying, or deleting relevant electronic information systems and the information (
                        <E T="03">i.e.,</E>
                         not only ePHI) therein.
                    </P>
                    <FTNT>
                        <P>
                            <SU>766</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(2).
                        </P>
                    </FTNT>
                    <P>We also propose to add an implementation specification for maintenance at proposed 45 CFR 164.312(d)(2)(iv). Under this proposal, a regulated entity would be expressly required to review and test the effectiveness of the technology assets and/or technical controls required by the respective implementation specifications of this section at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate.</P>
                    <HD SOURCE="HD3">f. Section 164.312(e)—Standard: Integrity</HD>
                    <P>
                        Improper alteration or destruction of ePHI, even unintentionally, can result in clinical quality problems, including patient safety issues, for a covered entity.
                        <SU>767</SU>
                        <FTREF/>
                         Workforce members or business associates may make accidental or intentional changes that improperly alter or destroy ePHI.
                        <SU>768</SU>
                        <FTREF/>
                         Data can also be altered or destroyed without human intervention, such as by electronic media errors or failures.
                        <SU>769</SU>
                        <FTREF/>
                         It is important to protect ePHI from being compromised, regardless of the source.
                        <SU>770</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>767</SU>
                             “Security Standards: Technical Safeguards,” 
                            <E T="03">supra</E>
                             note 343, p. 8.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>768</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>769</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>770</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        The current standard for integrity at 45 CFR 164.312(c)(1) requires implementation of policies and procedures, rather than actual deployment of technical controls, to ensure integrity of ePHI. To improve the effectiveness of this standard, the Department proposes to redesignate it as proposed 45 CFR 164.312(e) and modify it for clarity. Under the proposal, a regulated entity would be required to deploy technical controls to protect ePHI from improper alteration or destruction when at rest and in transit and to review and test the effectiveness of such technical controls at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate. For example, the adoption of health IT that is certified through the ONC Health IT Certification Program as having the technical capability to verify that the electronically exchanged health information contained within the health IT has not been altered, using a hashing algorithm that meets certain requirements, may contribute to a regulated entity's compliance with the proposed standard for integrity.
                        <SU>771</SU>
                        <FTREF/>
                         The Department proposes to remove the implementation specification at 45 CFR 164.312(c)(2) because technical controls to corroborate that ePHI has not been altered or destroyed in an unauthorized manner are commonly built into hardware and protocols today. Thus, it is unnecessary to require a regulated entity to specifically deploy such controls.
                    </P>
                    <FTNT>
                        <P>
                            <SU>771</SU>
                             45 CFR 170.315(d)(8).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">g. Section 164.312(f)(1)—Standard: Authentication</HD>
                    <P>
                        Authentication ensures that a person is in fact who they claim to be before being allowed access to ePHI by providing proof of identity.
                        <SU>772</SU>
                        <FTREF/>
                         The Department proposes to redesignate the standard for person or entity authentication at 45 CFR 164.312(d) as 45 CFR 164.312(f)(1) to rename it “Authentication” to reflect its broad purpose, and to add a paragraph heading to clarify the organization of the regulatory text. Additionally, consistent with our proposals to define 
                        <PRTPAGE P="974"/>
                        “implement” and “deploy,” we propose to replace the requirement for a regulated entity to implement procedures with a requirement to deploy technical controls. Also, consistent with our proposals to clarify that a regulated entity's obligations to ensure the confidentiality, integrity, and availability extend to all of its relevant electronic information systems, we propose to clarify that the regulated entity is to deploy technical controls to verify that a person seeking access to the regulated entity's relevant electronic information systems is the one claimed. The Department also proposes to modify the existing standard to clarify that a regulated entity would be required to deploy technical controls to verify that a technology asset seeking access to the regulated entity's relevant electronic information systems is the one claimed. Thus, the proposed standard for authentication would require a regulated entity to deploy technical controls to verify that a person or technology asset seeking access to ePHI and/or the regulated entity's relevant electronic information systems is, in fact, the person or technology asset that the person or asset claims to be. We also propose to remove the reference to an entity because entity is included within the definition of person.
                    </P>
                    <FTNT>
                        <P>
                            <SU>772</SU>
                             “Security Standards: Technical Safeguards,” 
                            <E T="03">supra</E>
                             note 343, p. 9.
                        </P>
                    </FTNT>
                    <P>
                        The Department proposes four implementation specifications under this standard. Consistent with NCVHS' recommendation to eliminate the use of default passwords, the proposed implementation specification for information access management policies at proposed 45 CFR 164.312(f)(2)(i) would require a regulated entity to deploy technical controls in accordance with its information access management policies and procedures, including technical controls that require users to adopt unique passwords.
                        <SU>773</SU>
                        <FTREF/>
                         Among other things, this proposal would ensure that regulated entities change default passwords. Such unique passwords would be required to be consistent with current recommendations of authoritative sources. The Department does not propose to define authoritative sources and defers to best practices for setting and maintaining passwords of sufficient strength to ensure the confidentiality, integrity, and availability of ePHI. Under this proposal, a regulated entity would need to require its workforce members to change any default passwords to unique passwords that are consistent with current authoritative source recommendations for unique passwords, as well as prevent the sharing of passwords among workforce members. Default passwords, typically factory-set passwords, may be discovered in common product documentation and used by attackers to gain access to relevant electronic information systems.
                        <SU>774</SU>
                        <FTREF/>
                         Thus, the Department believes that it is crucial for the security of ePHI that a regulated entity eliminate the use of default passwords.
                    </P>
                    <FTNT>
                        <P>
                            <SU>773</SU>
                             Letter from NCVHS Chair Jacki Monson (2022), 
                            <E T="03">supra</E>
                             note 123, p. 6.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>774</SU>
                             “Risks of Default Passwords on the internet,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security (Oct. 7, 2016), 
                            <E T="03">https://www.cisa.gov/news-events/alerts/2013/06/24/risks-default-passwords-internet.</E>
                        </P>
                    </FTNT>
                    <P>
                        In addition to proposing the elimination of default passwords, the Department proposes a specific requirement for a regulated entity to deploy MFA in the implementation specification for MFA at proposed 45 CFR 164.312(f)(2)(ii). We propose to expressly require MFA, as recommended by NCVHS, because it increases security by ensuring that a compromise of a single credential does not allow access to unauthorized users.
                        <SU>775</SU>
                        <FTREF/>
                         MFA is an effective way to reduce the risk of brute force attacks and to increase the cost of such attack, making such an attack less appealing to intruders.
                        <SU>776</SU>
                        <FTREF/>
                         Further, deployment of MFA aligns with the Department's essential CPGs for Email Security and Multifactor Authentication because use of MFA would be applicable to email access and protect assets connected to the internet.
                        <SU>777</SU>
                        <FTREF/>
                         Accordingly, proposed 45 CFR 164.312(f)(2)(ii)(A) would require a regulated entity to deploy MFA to all technology assets in its relevant electronic information systems to verify that the person seeking access to its relevant electronic information system is the user that the person claims to be. A regulated entity should deploy MFA to all technology assets in its relevant electronic information systems in a manner consistent with its risk analysis. MFA allows for the use of different categories of factors as described earlier. A decision by a regulated entity to use specific factors during specific circumstances where MFA is deployed will be dependent upon the risks to ePHI identified by the regulated entity and the ability of technology to use such factors to authenticate specific users. For example, certain behavioral characteristics may not satisfy current standards for MFA; however, the Department anticipates that it may be reasonable and appropriate in the future for a regulated entity to adopt a solution where users provide such characteristics as one of the factors. Additionally, a regulated entity may identify varying levels of risk posed by its technology assets and elect to deploy MFA in different ways to address the risk posed by each asset. For example, consistent with its risk analysis, a regulated entity may choose to deploy a single sign-on (SSO) authentication solution using MFA to allow users to access multiple local applications, while also requiring users to authenticate using MFA to access certain cloud-based services.
                    </P>
                    <FTNT>
                        <P>
                            <SU>775</SU>
                             “Multi-Factor Authentication,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security (Jan. 5, 2022), 
                            <E T="03">https://www.cisa.gov/sites/default/files/publications/MFA-Fact-Sheet-Jan22-508.pdf;</E>
                             Letter from NCVHS Chair Jacki Monson (2022), 
                            <E T="03">supra</E>
                             note 123, pp. 7-8.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>776</SU>
                             Letter from NCVHS Chair Jacki Monson (2022), 
                            <E T="03">supra</E>
                             note 123, pp. 7-8.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>777</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <P>
                        This proposed implementation specification generally is consistent with ASTP/ONC's “Health Data, Technology, and Interoperability: Patient Engagement, Information Sharing, and Public Health Interoperability” (HTI-2) NPRM's proposed revisions to the MFA criterion requiring certified health IT to support authentication, through multiple elements, of the user's identity, according to today's standards such as those recommended by NIST, and enable user to configure, enable, and disable the MFA capabilities.
                        <SU>778</SU>
                        <FTREF/>
                         Adoption of health IT that is certified through the ONC Health IT Certification Program as meeting the proposed MFA criterion, should the proposal be finalized, may contribute to a regulated entity's compliance with the proposed implementation specification for MFA in this NPRM.
                    </P>
                    <FTNT>
                        <P>
                            <SU>778</SU>
                             
                            <E T="03">See</E>
                             89 FR 63498, 63574, 63506, 63528 (Aug. 5, 2024) (proposed 45 CFR 170.315(d)(13)(ii) of ASTP/ONC's HTI-2 NPRM).
                        </P>
                    </FTNT>
                    <P>
                        Under proposed 45 CFR 164.312(f)(2)(ii)(B), a regulated entity would be required to deploy MFA for any action that would change a user's privileges to the regulated entity's relevant electronic information systems in a manner that would alter the user's ability to affect the confidentiality, integrity, or availability of ePHI. These modified privileges may provide a user with a level of access inconsistent with a regulated entity's policies and procedures and increase the risk to ePHI by affording a user who does not need to have access to certain systems or information the opportunity to remove security measures deployed to protect ePHI. Because a user may affect the confidentiality, integrity, or availability of ePHI by accessing a relevant electronic information system, a regulated entity would be expected to 
                        <PRTPAGE P="975"/>
                        deploy MFA for changed privileges in both types of systems.
                    </P>
                    <P>Similar to the proposed standard for encryption, the Department proposes three exceptions at proposed 45 CFR 164.312(f)(2)(iii) to the proposed specific requirement to implement MFA. The first proposed exception at proposed 45 CFR 164.312(f)(2)(iii)(A) would be for a technology asset that does not support MFA but is currently in use by a regulated entity. Because the requirements for authentication under the existing Security Rule today do not expressly refer to MFA, a regulated entity that is not using MFA to meet the requirement to authenticate user identities may argue that it is in compliance with the authentication standard without using MFA. The Department recognizes that it may take some time for a regulated entity to adopt compliant software or hardware, and thus we propose an exception where such software or hardware does not support MFA. To meet this exception, a regulated entity would be required to establish a written plan to migrate ePHI to technology assets that supports MFA and to actually migrate the ePHI to such technology assets in accordance with the written plan. Accordingly, a regulated entity would be required to establish the plan, implement the plan, and actually migrate ePHI to technology assets that supports MFA within a reasonable and appropriate period of time. For example, it would not be reasonable and appropriate for a regulated entity to establish a plan to migrate to a new practice management system that supports MFA and fail to take any steps to perform the migration for an entire year. Applying the standard flexibly and at scale, a reasonable and appropriate timeframe for a system with 5,000 users may be different than one for a solo practitioner; however, both entities would be expected to progress to completion.</P>
                    <P>
                        We recognize that emergencies or other occurrences may render it infeasible for a regulated entity to use MFA, so we propose a second exception for when MFA is infeasible during an emergency or other occurrence that adversely affects the regulated entity's relevant electronic information systems or the confidentiality, integrity, or availability of ePHI.
                        <SU>779</SU>
                        <FTREF/>
                         For the proposed exception to apply, a regulated entity would be required to implement reasonable and appropriate compensating controls in accordance with its contingency plan 
                        <SU>780</SU>
                        <FTREF/>
                         and emergency access procedures.
                        <SU>781</SU>
                        <FTREF/>
                         For example, if an optical scanner used by a regulated entity as one of the required factors for MFA is rendered inoperable (
                        <E T="03">e.g.,</E>
                         is temporarily broken or adversely affected by a cyberattack), a compensating control may be to temporarily allow users to log in with their user name and a unique password, rather than with a PIN and retinal scan. The Department would make this proposed exception applicable only for the limited period of time in which MFA is infeasible for the regulated entity during the emergency or other occurrence, regardless of whether the emergency or other occurrence continues.
                    </P>
                    <FTNT>
                        <P>
                            <SU>779</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.312(f)(2)(iii)(B).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>780</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(13).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>781</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.312(a)(2)(iii).
                        </P>
                    </FTNT>
                    <P>
                        At proposed 45 CFR 164.312(f)(2)(iii)(C), we propose three exceptions that would be for a technology asset in use that is a device within the meaning of section 201(h) of the Food, Drug, and Cosmetic Act that has been authorized for marketing by the FDA. The first would be for a device authorized by the FDA for marketing pursuant to a submission received before March 29, 2023, while the second would be for a device authorized by the FDA for marketing pursuant to a submission received on or after March 29, 2023, that is no longer supported by its manufacturer. In both cases, the exception would only apply where, the regulated entity has deployed any updates or patches required or recommended by the manufacturer of the device. Similar to our proposal for exceptions to encryption at proposed 45 CFR 164.312(b)(3)(iv)(A) and (B), we recognize that some regulated entities may incur costs of replacing legacy devices because of the limitations on the proposed exception to MFA where a device was submitted to the FDA for authorization before March 29, 2023 or a device submitted for authorization on or after that date that is no longer supported by its manufacturer.
                        <SU>782</SU>
                        <FTREF/>
                         However, as discussed above, such devices can pose significant risks to the confidentiality, integrity, and availability of ePHI.
                        <SU>783</SU>
                        <FTREF/>
                         By limiting these exceptions to devices that have been updated and/or patched while they were supported by their manufacturer, we believe that this proposal would balance the interest in encouraging regulated entities to dispense with legacy devices with the cost of replacing such devices. Additionally, the Department believes that regulated entities should already have plans to replace legacy devices that cannot be made cybersecure because of their existing Security Rule obligations. As discussed above, we also recognize that at some point, most, if not all, devices will likely become legacy devices and that there may be legitimate reasons not to immediately replace them when the manufacturer ceases to provide support. In such cases, it will continue to be important for regulated entities to plan for how to address their ongoing Security Rule obligations.
                    </P>
                    <FTNT>
                        <P>
                            <SU>782</SU>
                             
                            <E T="03">See</E>
                             “Next Steps Toward Managing Legacy Medical Device Cybersecurity Risks,” 
                            <E T="03">supra</E>
                             note 742; “Principles and Practices for the Cybersecurity of Legacy Medical Devices,” 
                            <E T="03">supra</E>
                             note 742, p. 8.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>783</SU>
                             “Cybersecurity,” 
                            <E T="03">supra</E>
                             note 743.
                        </P>
                    </FTNT>
                    <P>
                        The third proposed exception to MFA at 45 CFR 164.312(f)(2)(iii)(C)(
                        <E T="03">3</E>
                        ) for devices authorized by the FDA for marketing would be available for those devices authorized for marketing by the FDA pursuant to a submission received on or after March 29, 2023, where they are supported by their manufacturer. We understand that the FDA considers security during the review of medical device marketing submissions and works with device manufacturers to ensure that appropriate cybersecurity protections are built into such devices, pursuant to FDA's authority under the Consolidated Appropriations Act, 2023.
                        <SU>784</SU>
                        <FTREF/>
                         Thus, we do not believe it would be necessary or appropriate for the Security Rule to require MFA for an FDA-authorized medical device that has been authorized by FDA for marketing pursuant to a submission received on or after March 29, 2023, where the device continues to be supported by its manufacturer. However, these devices may continue to be used by a regulated entity when they are no longer supported, consistent with the proposed exception for legacy devices that were approved pursuant to a submission received on or after March 29, 2023, as described above.
                    </P>
                    <FTNT>
                        <P>
                            <SU>784</SU>
                             
                            <E T="03">See</E>
                             sec. 3305 of Public Law 117-328, 126 Stat. 5832 (Dec. 29, 2022) (codified at 21 U.S.C. 360n-2); 
                            <E T="03">see also</E>
                             “Cybersecurity in Medical Devices Frequently Asked Questions (FAQs),” 
                            <E T="03">supra</E>
                             note 744.
                        </P>
                    </FTNT>
                    <P>
                        Where a proposed exception would apply to the proposed MFA requirement, the Department proposes to require that a regulated entity implement alternative measures and compensating controls.
                        <SU>785</SU>
                        <FTREF/>
                         Specifically, when a regulated entity seeks to comply with the Security Rule by meeting one of the proposed exceptions to the proposed MFA requirement, the Department proposes to require a regulated entity to document both the existence of the criteria demonstrating that the proposed exception would apply and the rationale for why the proposed exception would apply. 
                        <PRTPAGE P="976"/>
                        Additionally, the proposal would require a regulated entity to implement reasonable and appropriate compensating controls, as described at proposed paragraph (f)(2)(iv)(B).
                    </P>
                    <FTNT>
                        <P>
                            <SU>785</SU>
                             Proposed 45 CFR 164.312(f)(2)(iv)(A).
                        </P>
                    </FTNT>
                    <P>
                        The proposed requirements for reasonable and appropriate compensating controls are explained under proposed 45 CFR 164.312(f)(2)(iv)(B). Compensating controls are implemented in the place of MFA to protect ePHI.
                        <SU>786</SU>
                        <FTREF/>
                         The Department does not propose to require that compensating controls be technical controls. Rather, a regulated entity should consider the nature of the exception, operating environment, and other appropriate circumstances to determine what controls are reasonable and appropriate and implement compensating controls effective for those circumstances. For example, if a software program does not support MFA, deploying a firewall or increasing the sensitivity of an existing firewall protecting that software may in some circumstances constitute a reasonable and appropriate compensating control.
                        <SU>787</SU>
                        <FTREF/>
                         In some instances, physical safeguards may serve as reasonable and appropriate compensating controls. For example, limiting access to certain components of a relevant electronic information system to workforce members who meet certain requirements may be a reasonable and appropriate compensating control under some circumstances. In most cases, it would be reasonable and appropriate for a regulated entity to implement multiple compensating controls to ensure that the affected electronic information system is secured.
                    </P>
                    <FTNT>
                        <P>
                            <SU>786</SU>
                             “Glossary of Key Information Security Terms,” 
                            <E T="03">supra</E>
                             note 745.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>787</SU>
                             “Securing Your Legacy [System Security],” 
                            <E T="03">supra</E>
                             note 494.
                        </P>
                    </FTNT>
                    <P>
                        The Department proposes at proposed 45 CFR 164.312(f)(2)(iv)(B)(
                        <E T="03">1</E>
                        ) that, to comply with an exception at paragraph (f)(2)(iii)(A) or (B) or (f)(2)(iii)(C)(
                        <E T="03">1</E>
                        ) or (
                        <E T="03">2</E>
                        ), the regulated entity would be required to secure the relevant electronic information system with reasonable and appropriate compensating controls that have been reviewed, approved, and signed by the regulated entity's Security Official. Because exceptions are a departure from the designed Security Rule framework, the Department intends to ensure appropriate review by the Security Official of controls selected by the regulated entity to compensate for the absence of MFA. Merely because a regulated entity's Security Official has reviewed, approved, and signed off on compensating controls does not mean that those controls are effective. The regulated entity would also be required to give due consideration to the circumstances surrounding the exception and implement compensating controls effective for those specific circumstances.
                    </P>
                    <P>
                        With respect to the exception at proposed 45 CFR 164.312(f)(2)(iii)(C)(
                        <E T="03">3</E>
                        ), the Department proposes at proposed 45 CFR 164.312(f)(2)(iv)(B)(
                        <E T="03">2</E>
                        ) to presume that a regulated entity had implemented reasonable and appropriate compensating controls where the regulated entity has implemented the security measures prescribed and as instructed by the FDA-authorized label for the device. The proposed language recognizes that while the device's label may not specifically require deployment of an MFA solution, it may provide for a specific compensating control and the manner in which that control is to be implemented. This would include any updates, such as patches, recommended or required by the manufacturer of the device. While not required, a regulated entity would be permitted to implement additional alternative security measures and compensating controls in accordance with best practices and/or its risk analysis.
                    </P>
                    <P>
                        Additionally, the Department proposes at 45 CFR 164.312(f)(2)(iv)(B)(
                        <E T="03">3</E>
                        ) that during any period in which compensating controls are in use, the regulated entity's Security Official would be required to review the effectiveness of the compensating controls at securing its relevant electronic information systems. While regulated entities should review implemented compensating controls on a routine basis, the Department intends for a regulated entity to periodically review the implementation and effectiveness of implemented compensating controls to ensure the continued protection of ePHI.
                        <SU>788</SU>
                        <FTREF/>
                         For example, if a regulated entity's plan to migrate ePHI from hardware that does not support MFA changes such that the use of the non-MFA hardware continues for a longer period of time, the regulated entity should review implemented compensating controls to ensure ongoing effectiveness and whether new compensating controls should be implemented. We are proposing to require that the review be conducted at least once every 12 months or in response to an environmental or operational change, whichever is more frequent, and that the review be documented. Additionally, the Department proposes to require that the review be documented. If the regulated entity's Security Official review determines that certain compensating controls are no longer effective, the Department would expect the regulated entity to adopt other compensating controls that are effective to continue to meet the applicable proposed exception.
                    </P>
                    <FTNT>
                        <P>
                            <SU>788</SU>
                             The Department does not propose that the periodic review include a review that the conditions of the exception continue to apply because a regulated entity would be expected to resume compliance with the implementation specification of multi-factor authentication when such exception no longer applies.
                        </P>
                    </FTNT>
                    <P>As an example of how proposed 45 CFR 164.312(f)(2)(iii) would operate in concert with proposed 45 CFR 164.312(f)(2)(iv), a regulated entity experiencing an emergency that adversely affects a relevant electronic information system and renders MFA infeasible would be required to document the following:</P>
                    <P>• The regulated entity has experienced an emergency that has adversely affected a relevant electronic information system, including the nature of the emergency and the specific circumstances that adversely affected the specific electronic information system.</P>
                    <P>• MFA has been rendered infeasible with respect to the specific relevant electronic information system adversely affected by the emergency.</P>
                    <P>• The regulated entity has put in place reasonable and appropriate compensating controls in accordance with the regulated entity's emergency access procedures and contingency plan.</P>
                    <P>
                        As part of its documentation, a regulated entity would need to include the controls that have been deployed, a record of the fact that the compensating controls are in use, and a record indicating that the compensating controls have been reviewed and approved by the regulated entity's Security Official. Proposed 45 CFR 164.312(f)(2)(iv)(B)(
                        <E T="03">3</E>
                        ) would require the Security Official to review and document the effectiveness of the compensating controls at least once every 12 months or in response to an environmental or operational change, whichever is more frequent. A determination regarding the effectiveness of the technical controls would be based on their ability to secure the regulated entity's ePHI and its relevant electronic information systems.
                    </P>
                    <P>
                        Last, we propose to add an implementation specification for maintenance at proposed 45 CFR 164.312(f)(2)(v). Under this proposal, a regulated entity would be expressly required to review and test the effectiveness of the technical controls required by this standard at least once every 12 months or in response to 
                        <PRTPAGE P="977"/>
                        environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate.
                    </P>
                    <HD SOURCE="HD3">h. Section 164.312(g)—Standard: Transmission Security</HD>
                    <P>
                        Transmission security protects against the interception of ePHI in the communications networks used by regulated entities to transmit ePHI.
                        <SU>789</SU>
                        <FTREF/>
                         The Department proposes to redesignate the standard for transmission security as proposed 45 CFR 164.312(g) and to modify the standard consistent with other proposals made elsewhere in this NPRM, as described below. Specifically, we propose to clarify the existing standard by requiring a regulated entity to deploy technical controls to guard against unauthorized access to ePHI in transmission over an electronic communications network. For example, adoption of health IT that is certified through the ONC Health IT Certification Program as having the technical capability to establish a trusted connection using encrypted and integrity message protection or a trusted connection for transport and deploying such capability may contribute to a regulated entity's compliance with the proposed standard for transmission security.
                        <SU>790</SU>
                        <FTREF/>
                         These proposed changes are consistent with the Department's proposals to replace “implement” with “deploy” in the context of technical safeguards to differentiate between implementation of a written policy or procedure and deployment of technical controls.
                    </P>
                    <FTNT>
                        <P>
                            <SU>789</SU>
                             “Glossary of Key Information Security Terms,” 
                            <E T="03">supra</E>
                             note 745.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>790</SU>
                             
                            <E T="03">See</E>
                             45 CFR 170.315(d)(9).
                        </P>
                    </FTNT>
                    <P>Consistent with our proposals to require that regulated entities maintain their technical controls, we also propose to require a regulated entity to review and test the effectiveness of its technical controls for guarding against unauthorized access to ePHI that is being transmitted over an electronic communications network. We propose that such review and testing occur at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify such technical controls as reasonable and appropriate.</P>
                    <P>
                        The Department also proposes to remove the implementation specification for integrity controls at 45 CFR 164.312(e)(2)(i) because these requirements are incorporated in the standard for integrity at proposed 45 CFR 164.312(e), discussed above. A regulated entity would continue to be required to review the current methods used to transmit ePHI and then deploy appropriate solutions to protect ePHI from improper alteration or destruction.
                        <SU>791</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>791</SU>
                             “Security Standards: Technical Safeguards,” 
                            <E T="03">supra</E>
                             note 343, p. 10-11.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">i. Section 164.312(h)(1)—Standard: Vulnerability Management</HD>
                    <P>
                        Hackers can penetrate a regulated entity's network and gain access to ePHI by exploiting publicly known vulnerabilities.
                        <SU>792</SU>
                        <FTREF/>
                         Exploitable vulnerabilities can exist in many parts of the technology infrastructure of a regulated entity's relevant electronic information systems (
                        <E T="03">e.g.,</E>
                         server, desktop, and mobile device operating systems; application, database, and web software; router, firewall, and other device firmware).
                        <SU>793</SU>
                        <FTREF/>
                         A regulated entity can identify technical vulnerabilities in multiple, complementary ways, including:
                    </P>
                    <FTNT>
                        <P>
                            <SU>792</SU>
                             “Defending Against Common Cyber-Attacks,” 
                            <E T="03">supra</E>
                             note 396.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>793</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        • Subscribing to CISA alerts 
                        <SU>794</SU>
                        <FTREF/>
                         and bulletins.
                        <SU>795</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>794</SU>
                             
                            <E T="03">See</E>
                             “Cybersecurity Alerts &amp; Advisories,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security, 
                            <E T="03">https://www.cisa.gov/news-events/cybersecurity-advisories.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>795</SU>
                             
                            <E T="03">See</E>
                             “Bulletins,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security, 
                            <E T="03">https://www.cisa.gov/news-events/bulletins.</E>
                        </P>
                    </FTNT>
                    <P>
                        • Subscribing to alerts from the HHS Health Sector Cybersecurity Coordination Center.
                        <SU>796</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>796</SU>
                             
                            <E T="03">See</E>
                             “Health Sector Cybersecurity Coordination Center (HC3),” Office of the Chief Information Officer, U.S. Department of Health and Human Services, 
                            <E T="03">https://www.hhs.gov/about/agencies/asa/ocio/hc3/index.html.</E>
                        </P>
                    </FTNT>
                    <P>• Participating in an information sharing and analysis center (ISAC) or information sharing and analysis organization (ISAO).</P>
                    <P>• Implementing a vulnerability management program that includes using a vulnerability scanner to detect vulnerabilities such as obsolete software and missing patches.</P>
                    <P>• Periodically conducting penetration tests to identify weaknesses that could be exploited by an attacker.</P>
                    <P>
                        Additionally, CISA has compiled a database of free cybersecurity services and tools, some provided directly by CISA and others provided by private and public sector organizations.
                        <SU>797</SU>
                        <FTREF/>
                         For example, public and private critical infrastructure organizations may avail themselves of CISA's Cyber Hygiene Services.
                        <SU>798</SU>
                        <FTREF/>
                         These services are available at no cost to such organizations and can help regulated entities reduce their risk level, identify vulnerabilities that could otherwise go unmanaged and increase the accuracy and effectiveness of their response activities, among other benefits, putting them in a better place to make risk-informed decisions. CISA's Cyber Hygiene Services include both vulnerability scanning and web application scanning. CISA also has compiled a specific suite of tools and services for high-risk communities.
                        <SU>799</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>797</SU>
                             “Free Cybersecurity Services and Tools,” 
                            <E T="03">supra</E>
                             note 313.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>798</SU>
                             “Cyber Hygiene Services,” 
                            <E T="03">supra</E>
                             note 313.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>799</SU>
                             “Cybersecurity Resources for High-Risk Communities,” 
                            <E T="03">supra</E>
                             note 313.
                        </P>
                    </FTNT>
                    <P>
                        To address the potential for a bad actor to exploit publicly known vulnerabilities, and consistent with NCVHS' recommendation, the Department proposes to add a new standard for vulnerability management at 45 CFR 164.312(h)(1).
                        <SU>800</SU>
                        <FTREF/>
                         The proposed standard would require a regulated entity to deploy technical controls to identify and address technical vulnerabilities in the regulated entity's relevant electronic information systems. The deployment of technical controls should be consistent with the regulated entity's patch management policies and procedures at proposed 45 CFR 164.308(a)(4). This proposed standard aligns with the Department's enhanced CPGs for Cybersecurity Testing and Third Party Vulnerability Disclosure by calling for regulated entities to employ multiple processes to discover technical vulnerabilities, including vulnerabilities in workstations and in technology assets provided by vendors and service providers.
                        <SU>801</SU>
                        <FTREF/>
                         For example, a regulated entity should include a device owned by a person other than the regulated entity (
                        <E T="03">e.g.,</E>
                         the medical device manufacturer) in its vulnerability management activities where the device is deployed on the regulated entity's network. The regulated entity should also include all workstations (
                        <E T="03">e.g.,</E>
                         desktop computers, mobile devices) that are part of its relevant electronic information systems in its vulnerability management activities.
                    </P>
                    <FTNT>
                        <P>
                            <SU>800</SU>
                             Letter from NCVHS Chair Jacki Monson (2022), 
                            <E T="03">supra</E>
                             note 123, p. 8-9.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>801</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <P>
                        To implement this proposed standard, we propose four implementation specifications. Proposed 45 CFR 164.312(h)(2)(i)(A) would require a regulated entity to conduct automated scans of the regulated entity's relevant electronic information systems, including all of the components of such relevant electronic information systems (
                        <E T="03">e.g.,</E>
                         workstations, private networks) to identify technical vulnerabilities. Vulnerability scans detect vulnerabilities such as obsolete software 
                        <PRTPAGE P="978"/>
                        and missing patches.
                        <SU>802</SU>
                        <FTREF/>
                         Once identified, assessed, and prioritized, appropriate measures need to be implemented to mitigate these vulnerabilities (
                        <E T="03">e.g.,</E>
                         apply patches, harden systems, retire equipment).
                        <SU>803</SU>
                        <FTREF/>
                         Under the proposal, the scans would be required to be conducted in accordance with the regulated entity's risk analysis under proposed 45 CFR 164.308(a)(2) and no less frequently than once every six months.
                    </P>
                    <FTNT>
                        <P>
                            <SU>802</SU>
                             “Defending Against Common Cyber-Attacks,” 
                            <E T="03">supra</E>
                             note 396.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>803</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>Relatedly, proposed 45 CFR 164.312(h)(2)(i)(B) would add an implementation specification for maintenance of the technology assets that conduct the required automated vulnerability scans. Under this proposal, a regulated entity would be expressly required to review and test the effectiveness of the technology asset(s) that conducts the automated vulnerability scans that would be required by the proposed implementation specification at proposed 45 CFR 164.312(h)(2)(i)(A) at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate.</P>
                    <P>
                        Identification of a known vulnerability in a relevant electronic information system or a component thereof is a necessary precursor for a regulated entity to take action to mitigate the vulnerability. A 2019 study on vulnerability and patch management found that 48 percent of respondents reported that their organizations had at least one breach in the preceding two years. Of those, 60 percent said that the breaches could have occurred because an available patch for a known vulnerability had not been applied.
                        <SU>804</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>804</SU>
                             This study is not specific to health care. “Costs and Consequences of Gaps in Vulnerability Response,” ServiceNow and Ponemon Institute, p. 3 (2019), 
                            <E T="03">https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/resource-center/analyst-report/ponemon-state-of-vulnerability-response.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        Accordingly, the Department also proposes a new implementation specification for monitoring at proposed 45 CFR 164.312(h)(2)(ii) to require that a regulated entity monitor authoritative sources for known vulnerabilities on an ongoing basis and take action to remediate identified vulnerabilities in accordance with the regulated entity's patch management program.
                        <SU>805</SU>
                        <FTREF/>
                         The Department expects such monitoring to be conducted on an ongoing basis and is not proposing to specify a minimum time interval for reviewing sources. We are also not proposing to prescribe the specific sources of known vulnerabilities because such sources may change over time and the vulnerabilities for which regulated entities may be monitoring may vary greatly among regulated entities. We propose to require that the sources used must be authoritative. Examples of authoritative sources of known vulnerabilities would include NIST's National Vulnerability Database 
                        <SU>806</SU>
                        <FTREF/>
                         and CISA's Known Exploited Vulnerabilities Catalog.
                        <SU>807</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>805</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(4).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>806</SU>
                             “National Vulnerability Database,” 
                            <E T="03">supra</E>
                             note 398.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>807</SU>
                             “Known Exploited Vulnerabilities Catalog,” 
                            <E T="03">supra</E>
                             note 399.
                        </P>
                    </FTNT>
                    <P>
                        The proposed implementation specification for penetration testing at 45 CFR 164.312(h)(2)(iii) would require a regulated entity to conduct periodic testing of the regulated entity's relevant electronic information systems for vulnerabilities, commonly referred to as penetration testing. Penetration tests identify vulnerabilities in the security features of an application, system, or network by mimicking real-world attacks 
                        <SU>808</SU>
                        <FTREF/>
                         and are an effective way to identify weaknesses that could be exploited by an attacker.
                        <SU>809</SU>
                        <FTREF/>
                         The proposal would require such testing to be conducted by qualified person(s). We propose to describe a qualified person as a person with appropriate knowledge of and experience with generally accepted cybersecurity principles and methods for ensuring the confidentiality, integrity, and availability of ePHI. We believe that within the cybersecurity industry, it is understood that a person who is qualified to conduct such penetration testing is an individual who has a combination of one or more qualifying credentials, skills, or experiences to perform “ethical hacking” or “offensive security” of information systems. The proposal would require a regulated entity to conduct such testing at least once every 12 months, or in accordance with the regulated entity's risk analysis,
                        <SU>810</SU>
                        <FTREF/>
                         whichever is more frequent.
                    </P>
                    <FTNT>
                        <P>
                            <SU>808</SU>
                             “Glossary of Key Information Security Terms,” 
                            <E T="03">supra</E>
                             note 745.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>809</SU>
                             “Defending Against Common Cyber-Attacks,” 
                            <E T="03">supra</E>
                             note 396.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>810</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(2).
                        </P>
                    </FTNT>
                    <P>
                        Lastly, we are proposing a new implementation specification for patch and update installation at 45 CFR 164.312(h)(2)(iv) to require a regulated entity to configure and implement technical controls to install software patches and critical updates in a timely manner in accordance with the regulated entity's patch management program.
                        <SU>811</SU>
                        <FTREF/>
                         The proposed standard for patch management, an administrative safeguard discussed above, would require a regulated entity to establish and implement written policies and procedures for applying patches and updating relevant electronic information system configurations, while this proposal would require the regulated entity to implement technical controls to implement those written policies and procedures. In other words, proposed 45 CFR 164.312(h)(2)(iv) addresses the technical controls to effectuate a regulated entity's patch management plan. Applying patches for technology assets, including workstations, is an effective mechanism to mitigate known vulnerabilities and limit the risk of exploitation.
                        <SU>812</SU>
                        <FTREF/>
                         Although older applications or devices may no longer be supported with patches for new vulnerabilities, regulated entities still must take appropriate action if a newly discovered vulnerability affects an older application or device. If an obsolete, unsupported system cannot be upgraded or replaced, additional safeguards should be implemented or existing safeguards enhanced to mitigate known vulnerabilities until upgrade or replacement can occur (
                        <E T="03">e.g.,</E>
                         increase access restrictions, remove or restrict network access, disable unnecessary features or services).
                        <SU>813</SU>
                        <FTREF/>
                         Deployment of such technical controls would help to ensure that a regulated entity's relevant electronic information systems are updated as quickly as possible after a vulnerability has been identified and a patch released.
                    </P>
                    <FTNT>
                        <P>
                            <SU>811</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(5).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>812</SU>
                             “Defending Against Common Cyber-Attacks,” 
                            <E T="03">supra</E>
                             note 396.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>813</SU>
                             
                            <E T="03">See</E>
                             “Securing Your Legacy [System Security],” 
                            <E T="03">supra</E>
                             note 494.
                        </P>
                    </FTNT>
                    <P>
                        The proposed standard for patch management, discussed above, would work in tandem with the proposed standard for vulnerability management to ensure that regulated entities substantially reduce the risk to ePHI from known vulnerabilities.
                        <SU>814</SU>
                        <FTREF/>
                         Together, these proposals would clarify that a regulated entity is required to affirmatively seek out information about known vulnerabilities, assess the risks to the confidentiality, integrity, and availability of ePHI, and implement effective mechanisms through both policies and procedures and technical controls to reduce the risk, as well the actual occurrence, of breaches resulting from known vulnerabilities. For example, known vulnerabilities should be readily identified by a regulated entity through monitoring of 
                        <PRTPAGE P="979"/>
                        authoritative sources for known vulnerabilities, such as those referenced above, and remediating any identified vulnerabilities. When a vulnerability is discovered, a regulated entity, through its patch management program, should have in place a policy and procedure for applying any available patches or implementing reasonable and appropriate compensating controls if a patch is not available. Remediation may be as simple as applying a vendor-offered software patch or, in the case of software no longer supported by a vendor, designing and implementing reasonable and appropriate compensating controls to reduce the risk of the vulnerability. The policies and procedures required by the proposed standard for patch management in proposed 45 CFR 164.308(a)(4)(i) also would be implemented in part by the proposed implementation specifications associated with the proposed standard for vulnerability management. Those proposed implementation specifications would require the deployment of technical controls to ensure the patch management program is carried out, automated vulnerability scans, and penetration testing, all of which may identify when a patch or compensating control has not been put in place. The Department envisions that the full implementation of all of the proposed standards and implementation specifications would effectively reduce the risk to ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>814</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(5) and 164.312(h)(1).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">j. Section 164.312(i)(1)—Standard: Data Backup and Recovery</HD>
                    <P>
                        The Security Rule requires regulated entities to regularly create copies of ePHI to ensure that it can be restored in the event of a loss or disruption.
                        <SU>815</SU>
                        <FTREF/>
                         However, OCR's enforcement experience indicates that regulated entities could benefit from a more specific standard. Consistent with the proposed standard for contingency planning at 45 CFR 164.308(a)(13)(ii)(B), the Department proposes to add a standard for a new technical safeguard for data backup and recovery. This new standard would require a regulated entity to deploy technical controls to create and maintain exact retrievable copies of ePHI. The proposed changes would remove the existing implementation specification for this activity from the physical safeguards section and place it within technical safeguards. The Department also proposes to modify the language of the existing requirement by removing the limitation that it applies before moving equipment, so that it applies broadly and comprehensively. Elevating data backup and recovery to a standard would also increase the prominence of this requirement and highlight the liability of regulated entities for creating the capacity to restore systems after a data breach.
                    </P>
                    <FTNT>
                        <P>
                            <SU>815</SU>
                             
                            <E T="03">See</E>
                             “Plan A . . . B . . . Contingency Plan!,” 
                            <E T="03">supra</E>
                             note 606.
                        </P>
                    </FTNT>
                    <P>The Department proposes four new implementation specifications for the data backup and recovery standard. The first, 45 CFR 164.312(i)(2)(i), would require a regulated entity to create copies of ePHI in a manner that ensures that such copies are no more than 48 hours older than the ePHI maintained in the regulated entity's relevant electronic information systems and in accordance with the policies and procedures required by proposed 45 CFR 164.308(a)(13)(ii)(B). The second, 45 CFR 164.312(i)(2)(ii), would require a regulated entity to deploy technical controls that, in real-time, monitor, and alert workforce members about, any failures and error conditions of the backups required by the first implementation specification. The third, 45 CFR 164.312(i)(2)(iii), would require a regulated entity to deploy technical controls that record the success, failure, and any error conditions of backups required. The fourth, 45 CFR 164.312(i)(2)(iv), would require a regulated entity to test the effectiveness of its backups and document the results at least monthly. Specifically, a regulated entity would be required to restore a representative sample of backed up ePHI (after the ePHI is backed up as required by paragraph (i)(2)(i)) and document the results of such test restorations at least monthly. Such tests should include verifying regulated entity's ability to access ePHI from a remote location.</P>
                    <P>
                        These activities are included in NIST guidance for Security Rule compliance,
                        <SU>816</SU>
                        <FTREF/>
                         which directs regulated entities to consider the following questions: Is the frequency of backups appropriate for the environment? Are backup logs reviewed and data restoration tests conducted to ensure the integrity of data backups? Is at least one copy of the data backup stored offline to protect against corruption due to ransomware or other similar attacks? The potential need for these requirements also has been indicated through the rising number of ransomware attacks and the high number of individuals affected in such incidents. The Department believes these new implementation specifications, if finalized, would provide additional instruction for regulated entities about conducting data backups and enhance the ability of regulated entities to avoid costly work stoppages and interruptions in the delivery of health care when data becomes unavailable because of a disaster, security incident, or other emergency. We believe enhanced measures for data backup would reduce the need to pay ransom to hackers to recover compromised data.
                    </P>
                    <FTNT>
                        <P>
                            <SU>816</SU>
                             
                            <E T="03">See</E>
                             “Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” 
                            <E T="03">supra</E>
                             note 461, p. 49.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">k. Section 164.312(j)—Standard: Information Systems Backup and Recovery</HD>
                    <P>The Department also proposes to add a new standard for backup and recovery of relevant electronic information systems at proposed 45 CFR 164.312(j). This proposed standard would require a regulated entity to deploy technical controls to create and maintain backups of relevant electronic information systems. It would also require a regulated entity to review and test the effectiveness of such technical controls at least once every six months or in response to environmental or operational changes, whichever is more frequent, and modify them as reasonable and appropriate. The Department would not require a regulated entity to test every relevant electronic information system; rather, the requirement to test the effectiveness of the controls would permit a regulated entity to review the relevant log files and to test a representative sample of the backup of its relevant electronic information systems.</P>
                    <P>
                        This proposed standard would reduce potential gaps in the data that needs to be backed up and recovered, to ensure that regulated entities address compliance across relevant electronic information systems. It is crucial to a regulated entity's recovery from an emergency or other occurrence, including a security incident, that adversely affects its relevant electronic information systems to create and maintain backups of such information systems that comprise the infrastructure that maintains and supports the confidentiality, integrity, and availability of ePHI. The Department would expect that the extent of this activity would be affected by the size and complexity of the relevant electronic information systems used by a regulated entity. It is also consistent with NIST guidance, which directs regulated entities to consider whether backups or images of operating systems, devices, software, and configuration files necessary to support the 
                        <PRTPAGE P="980"/>
                        confidentiality, integrity, and availability of ePHI.
                        <SU>817</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>817</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">4. Request for Comment</HD>
                    <P>The Department requests comments on the foregoing proposals, including any benefits, drawbacks, or unintended consequences. We also request comment on the following considerations in particular:</P>
                    <P>a. Whether there are additional technical safeguards that the Department should require regulated entities to implement.</P>
                    <P>b. Whether there are additional implementation specifications that should be adopted for any of the proposed or existing technical safeguards.</P>
                    <P>c. Whether the Department should extend the standard for encryption and decryption and associated implementation specifications to require encryption of all relevant electronic information systems.</P>
                    <P>d. Whether there should be exceptions to any of the proposed or existing technical safeguards or related implementation specifications, in addition to those proposed for encryption and decryption and MFA. For example, are there any proposed or existing standards or implementation specifications with which small or rural regulated entities would have substantial difficulty complying? If so, please explain the type of regulated entities that would be adversely affected by the requirement, the nature of the compliance difficulty, and any alternative or compensating measures that such entities are implementing now or could implement in the event of such requirement to address the risk to ePHI posed by the specific standard or implementation specification.</P>
                    <P>e. Whether the exceptions the Department has proposed to the standard for encryption or decryption are appropriate. If not, please explain.</P>
                    <P>f. Data about the frequency and number of requests regulated entities receive pursuant to the individual right of access at 45 CFR 164.524 where an individual requests that the regulated entity transmit to the individual or a third party a copy of the individual's ePHI via unencrypted email or other unencrypted messaging technologies. Please confirm that these are requests made pursuant to the individual right of access, rather than other types of communications, such as appointment reminders or requests made pursuant to a valid authorization.</P>
                    <P>g. Whether the Department should provide any additional exceptions to standard for encryption or decryption. If so, please explain.</P>
                    <P>h. Whether there are additional criteria or parameters for encryption that regulated entities would find helpful. If yes, please explain and provide examples.</P>
                    <P>i. Whether the Department should require review of compensating controls implemented to comply with an exception to the encryption and decryption standard more frequently than once every 12 months where there are no environmental or operational changes.</P>
                    <P>
                        j. With respect to the exception to the standard for encryption and decryption for certain requests made pursuant to the individual right of access, whether there are forms and formats the Department should include or exclude from the exception (
                        <E T="03">e.g.,</E>
                         portable document format (PDF)). If so, please explain.
                    </P>
                    <P>k. Resources that regulated entities have identified to help inform individuals about the risks associated with the unencrypted transmission of ePHI, and whether the Department should compile and publish a list of such resources.</P>
                    <P>l. Whether the Department should define in regulation or guidance what constitutes a prevailing cryptographic standard. If so, please explain.</P>
                    <P>m. Whether the Department should specify the deployment of a particular form or manner of encryption, such as the use of particular algorithms, protocols, or compliance standards. If so, please explain.</P>
                    <P>n. Whether the Department should specify how much time regulated entities have to implement encryption for technology assets that do not support encryption. If so, please explain.</P>
                    <P>o. Whether the Department should provide more detailed requirements for network segmentation, such as the type(s) of technologies that should be segmented and how to determine whether certain technologies should be segmented. If so, please explain.</P>
                    <P>p. Whether the exceptions the Department has proposed to the implementation specification for MFA are appropriate. If not, please explain.</P>
                    <P>q. Whether the Department should provide additional exceptions to the implementation specification for MFA. If so, please explain.</P>
                    <P>r. Whether the Department should require a regulated entity to review its compensating controls adopted to comply with the exceptions to the implementation specification for MFA more frequently than once every 12 months.</P>
                    <P>s. The costs and burdens for regulated entities to implement MFA.</P>
                    <P>t. Whether the Department should require regulated entities to deploy an endpoint detection and response (EDR), security information and event management (SIEM), or other specific solution.</P>
                    <P>u. Whether once every six months is the appropriate frequency for the automated vulnerability scans required under the implementation specification for vulnerability management. If not, please explain.</P>
                    <P>v. Whether the Department should define in regulation or guidance what constitutes an authoritative source of known vulnerabilities. If so, please explain.</P>
                    <P>w. Whether once every 12 months is the appropriate frequency for the penetration testing required under the implementation specification for vulnerability management. If not, please explain.</P>
                    <P>x. For regulated entities that have conducted penetration tests, the amount of time and costs of such tests.</P>
                    <HD SOURCE="HD2">G. Section 164.314—Organizational Requirements</HD>
                    <HD SOURCE="HD3">1. Section 164.314(a)(1)—Standard: Business Associate Contracts or Other Arrangements</HD>
                    <HD SOURCE="HD3">a. Current Provisions</HD>
                    <P>
                        The first standard in 45 CFR 164.314 contains the requirements for business associate agreements and other arrangements. The associated implementation specifications at 45 CFR 164.314(a)(2) require that a business associate agreement include provisions compelling a business associate to do all of the following: (1) comply with the requirements of the Security Rule; 
                        <SU>818</SU>
                        <FTREF/>
                         (2) ensure that any subcontractors that create, receive, maintain, or transmit ePHI on behalf of the business associate agree to comply with the applicable requirements of the Security Rule by also entering into a business associate agreement; 
                        <SU>819</SU>
                        <FTREF/>
                         and (3) report to the covered entity any security incident of which it becomes aware, including breaches of unsecured PHI as required by the Breach Notification Rule.
                        <SU>820</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>818</SU>
                             45 CFR 164.314(a)(2)(i)(A).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>819</SU>
                             45 CFR 164.314(a)(2)(i)(B).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>820</SU>
                             45 CFR 164.314(a)(2)(i)(C).
                        </P>
                    </FTNT>
                    <P>
                        Under 45 CFR 164.314(a)(2)(ii), a covered entity that is a governmental entity is in compliance with the requirements of this section if it has in place an arrangement with a business associate that is also a governmental entity where the arrangement meets the 
                        <PRTPAGE P="981"/>
                        analogous requirements of the Privacy Rule at 45 CFR 164.504(e)(3).
                        <SU>821</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>821</SU>
                             Section 164.504(e) provides that when a covered entity and its business associate are both governmental entities, they do not have to negotiate a business associate agreement and may provide adequate assurances for its uses and disclosures of PHI if they enter into a memorandum of understanding or adopt a regulation that has the force and effect of law that incorporates the requirements of a business associate agreement. 65 FR 82462, 82597, 82677 (Dec. 28, 2000); 
                            <E T="03">see also</E>
                             68 FR 8334, 8360 (Feb. 20, 2003) (§ 164.314(a) provisions are drawn from and intended to support the analogous privacy protections provided for by 45 CFR 164.504(e) and discussed in the 2000 Privacy Rule.); 78 FR 5566, 5590 (Jan. 25, 2013) (removed the specific requirements under 45 CFR 164.314 for a memorandum of understanding when both a covered entity and business associate are government entities and referred to the parallel requirements of the Privacy Rule at 45 CFR 164.504(e)(3)).
                        </P>
                    </FTNT>
                    <P>Additionally, 45 CFR 164.314(a)(2)(iii) requires that a business associate and its subcontractor enter into a business associate agreement that meets the same requirements as those that apply to a business associate agreement between a covered entity and business associate.</P>
                    <P>
                        As described above, a business associate agreement must include a provision that requires a business associate to report to the covered entity any known security incident. The term “security incident” includes both attempted and successful unauthorized events in an information system.
                        <SU>822</SU>
                        <FTREF/>
                         The Security Rule does not prescribe the timing and frequency with which a business associate reports a security incident to the covered entity (or subcontractor to a business associate).
                        <SU>823</SU>
                        <FTREF/>
                         Instead, regulated entities may determine the appropriate timing and frequency as part of their business associate agreement, consistent with the requirements of the Breach Notification Rule.
                        <SU>824</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>822</SU>
                             45 CFR 164.304 (definition of “Security incident”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>823</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.314(a).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>824</SU>
                             Where a business associate experiences a security incident that meets the definition of a breach at 45 CFR 164.402, the business associate must comply with the requirements of the Breach Notification Rule. 
                            <E T="03">See</E>
                             45 CFR part 160 and subparts A and D of 45 CFR part 164. Specifically, the Breach Notification Rule requires a business associate to report a breach of unsecured PHI to a covered entity without unreasonable delay and in no case later than 60 days from the discovery of the breach. 
                            <E T="03">See</E>
                             45 CFR 164.410(b).
                        </P>
                    </FTNT>
                    <P>
                        Depending on the size of the regulated entity, the number of security incidents it experiences may vary, ranging from the occasional incident experienced by a small regulated entity to more than 1,000 per hour for a large regulated entity.
                        <SU>825</SU>
                        <FTREF/>
                         Given that such incidents may have little to no effect if the regulated entity's electronic information systems are able to deter it, it may not be necessary for a business associate to report the security incidents immediately to a covered entity (or a subcontractor to a business associate).
                    </P>
                    <FTNT>
                        <P>
                            <SU>825</SU>
                             Testimony of Andrew Witty, 
                            <E T="03">supra</E>
                             note 214 (According to CEO Andrew Witty, intruders attempt to gain access to UnitedHealth Group's electronic information systems every 70 seconds, or more than 450,000 times per year.).
                        </P>
                    </FTNT>
                    <P>
                        Additionally, as discussed above, regulated entities are required to establish, and implement as needed, a contingency plan 
                        <SU>826</SU>
                        <FTREF/>
                         that includes the policies and procedures for responding to an emergency or other occurrence that damages systems that contain ePHI. Such emergencies or other occurrences could include a fire, vandalism, system failure, or a natural disaster.
                        <SU>827</SU>
                        <FTREF/>
                         The Department believes that, in some instances, a security incident would also be an emergency or other occurrence that could require a regulated entity to activate its contingency plan.
                        <SU>828</SU>
                        <FTREF/>
                         As the Department previously explained, a contingency plan is the only way to protect the confidentiality, integrity, and availability of ePHI during unexpected events that may expose ePHI because the usual security measures may be disabled, ignored, or not observed.
                        <SU>829</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>826</SU>
                             45 CFR 164.308(a)(7)(i).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>827</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>828</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.308(a)(7)(i); proposed 45 CFR 164.308(a)(13)(i).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>829</SU>
                             68 FR 8334, 8351 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">b. Issues To Address</HD>
                    <P>
                        In recent years, there has been an increase in the number and types of emergencies or other occurrences that cause damage to systems that contain ePHI and may require a regulated entity to activate its contingency plan. For example, we have experienced an increase in extreme weather events over the last 40 years as a result of the changing climate.
                        <SU>830</SU>
                        <FTREF/>
                         Additionally, as discussed in greater detail above, there has been a significant increase in the number of breaches of unsecured PHI reported to the Department over the last five years.
                        <SU>831</SU>
                        <FTREF/>
                         And increasingly, ePHI is created, received, maintained, and transmitted using cloud-based software that may be located in a remote location, which means that covered entities more frequently rely on business associates to access ePHI.
                        <SU>832</SU>
                        <FTREF/>
                         Not only could the covered entity's ability to access ePHI or the relevant electronic information systems of the business associate that are affected by such an event, but the incident could also have repercussions for the covered entity's ePHI or its relevant electronic information systems. For example, a business associate's relevant electronic information systems may become infected with malicious software that spreads across devices connected to a network (
                        <E T="03">e.g.,</E>
                         the NotPetya malware.
                        <SU>833</SU>
                        <FTREF/>
                        ) If the covered entity is also connected to the same network, providing prompt notice to the covered entity of the security incident and activation of its contingency plan could enable the covered entity to prevent or mitigate damage to the covered entity's relevant electronic information systems.
                    </P>
                    <FTNT>
                        <P>
                            <SU>830</SU>
                             “Since 1980, the United States has experienced 265 weather and climate disasters in which the overall damages reached or exceeded US$1 billion.” Kristie L. Ebi, et al., “Extreme Weather and Climate Change: Population Health and Health System Implications,” Annual Review of Public Health (Jan. 2021), 
                            <E T="03">https://pubmed.ncbi.nlm.nih.gov/33406378/; see also</E>
                             “Climate Change Indicators: U.S. and Global Temperature,” U.S. Environmental Protection Agency (June 27, 2024) (“2023 was the warmest year on record [. . .] and 2014-2023 was the warmest decade on record since thermometer-based observations began.”), 
                            <E T="03">https://www.epa.gov/climate-indicators/climate-change-indicators-us-and-global-temperature.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>831</SU>
                             “Annual Report to Congress on HIPAA Privacy, Security, and Breach Notification Rule Compliance, For Calendar Year 2022,” Office for Civil Rights, U.S. Department of Health and Human Services, p. 8 (2022) (From 2018 to 2022, the number of breaches affecting fewer than 500 individuals increased 1 percent and breaches affecting 500 or more individuals rose 107 percent.), 
                            <E T="03">https://www.hhs.gov/sites/default/files/compliance-report-to-congress-2022.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>832</SU>
                             “Unraveling the role of cloud computing in health care system and biomedical sciences,” 
                            <E T="03">supra</E>
                             note 632 (“These days numerous commercial merchants are intermingling with hospitals as well as healthcare providers to establish healthcare-based cloud computing networks.”); 
                            <E T="03">see also id.</E>
                             (“[. . .] Microsoft, Google and Amazon have instantly realized that the majority of hospitals will not continue working with servers that are privately owned as well as controlled.”); “Increase in health-care cyberattacks affecting patients with cancer,” 
                            <E T="03">supra</E>
                             note 180 (In 2021, an attack against oncology services targeted data stored in cloud-based systems and affected patients in several States.).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>833</SU>
                             Nicole Perlroth, et al., “Cyberattack Hits Ukraine Then Spreads Internationally,” The New York Times (June 27, 2017) (discussing a worldwide ransomware attack in 2017), 
                            <E T="03">https://www.nytimes.com/2017/06/27/technology/ransomware-hackers.html.</E>
                        </P>
                    </FTNT>
                    <P>
                        When considered altogether, these developments mean that a regulated entity is more likely to experience an emergency or other occurrence that damages systems that contain ePHI than it was in either 2003 
                        <SU>834</SU>
                        <FTREF/>
                         or 2013.
                        <SU>835</SU>
                        <FTREF/>
                         Unfortunately, based on the Department's experience, neither the increased risk nor the Security Rule's requirement that a business associate notify a covered entity (or that a subcontractor notify a business associate) of any security incident, including breaches of unsecured PHI, has been sufficient to encourage prompt notifications by a business associate to the covered entity (or of a subcontractor to a business associate) that its ability to 
                        <PRTPAGE P="982"/>
                        access ePHI or the electronic information systems that create, receive, maintain, or transmit ePHI may be affected. This lack of prompt notification delays a covered entity (or business associate) from responding and protecting its ePHI and electronic information systems accordingly.
                    </P>
                    <FTNT>
                        <P>
                            <SU>834</SU>
                             
                            <E T="03">See</E>
                             68 FR 8334 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>835</SU>
                             
                            <E T="03">See</E>
                             78 FR 5566 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">c. Proposal</HD>
                    <P>
                        To address these risk trends and deficiencies in protections, the Department proposes to add an implementation specification at proposed 45 CFR 164.314(a)(2)(i)(D) that would require a business associate agreement to include a provision for a business associate to report to the covered entity activation of its contingency plan that would be required under 45 CFR 164.308(a)(13) without unreasonable delay, but no later than 24 hours after activation.
                        <SU>836</SU>
                        <FTREF/>
                         This proposal, if finalized, would not alter the business associate's breach reporting obligations under the Breach Notification Rule.
                        <SU>837</SU>
                        <FTREF/>
                         The Department believes that it is necessary to notify the covered entity in a timely manner of the contingency plan activation because of the downstream implications for such activation. Receiving such prompt notice could enable the covered entity to take the necessary steps to protect its own relevant electronic information systems, as well as to implement its own contingency plan if necessary and appropriate (
                        <E T="03">e.g.,</E>
                         enable the covered entity to access a remote or offline backup of its ePHI if necessary to ensure that patient care is unaffected—or to reduce the effect on patient care as much as possible). For example, in 2020, a software company was the target of an attack that used software containing malware to infiltrate the electronic information systems of subsequent users of the software. This allowed cybercriminals to gain access to several government systems and thousands of private systems worldwide.
                        <SU>838</SU>
                        <FTREF/>
                         Requiring a business associate to provide prompt notice to the covered entity when the business associate activates its contingency plan could enable regulated entities to maintain individuals' confidence in their commitment to protecting the confidentiality, integrity, and availability of ePHI in the event of an emergency or other occurrence that adversely affects relevant electronic information systems.
                        <SU>839</SU>
                        <FTREF/>
                         Additionally, the modified standard would align with the enhanced CPG for Third Party Incident Reporting because this proposal would require a business associate to both report to a covered entity or another business associate activation of its contingency plan within 24 hours of such activation and report known or suspected security incidents.
                        <SU>840</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>836</SU>
                             A subcontractor of a business associate also would be required to make such report to the business associate. 
                            <E T="03">See</E>
                             45 CFR 164.314(a)(2)(iii) (applying the requirements in paragraphs (a)(2)(i) and (ii) to business associate agreements between business associates and subcontractors in the same manner as they apply to business associate agreements between covered entities and business associates).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>837</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.410.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>838</SU>
                             Saheed Oladimeji, et al., “SolarWinds hack explained: Everything you need to know,” TechTarget (Nov. 3, 2023) (SolarWinds is a software company and one of its products that was part of a supply chain attack is an IT performance monitoring system that had privileged access to IT systems.), 
                            <E T="03">https://www.techtarget.com/whatis/feature/SolarWinds-hack-explained-Everything-you-need-to-know.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>839</SU>
                             As discussed in greater detail above, the Department is proposing to renumber the standard for the contingency plan as 45 CFR 164.308(a)(13) and to require a written contingency plan for responding to an emergency or other occurrence that adversely affects relevant electronic information systems, as opposed to the current standard which applies when the emergency or other occurrence damages information systems that contain ePHI.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>840</SU>
                             Proposed 45 CFR 164.314(a)(2)(i)(C) and (D); “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <P>
                        As discussed above, the Department proposes to require a regulated entity to activate its contingency plan to respond to an emergency or other occurrence that adversely affects relevant electronic information systems.
                        <SU>841</SU>
                        <FTREF/>
                         The Department believes that regulated entities activate their contingency plans infrequently because such plans are only activated when there is an emergency or other occurrence that rises to a level beyond a security incident that is thwarted or other event that does not adversely affect the confidentiality, integrity, or availability of ePHI. Thus, the need to make the proposed notification would also arise infrequently.
                    </P>
                    <FTNT>
                        <P>
                            <SU>841</SU>
                             Proposed 45 CFR 164.308(a)(13)(i).
                        </P>
                    </FTNT>
                    <P>
                        For example, a business associate may not be required to notify a covered entity within a certain time after a relevant electronic information system receives a basic internet command such as a ping,
                        <SU>842</SU>
                        <FTREF/>
                         which happens frequently. This is because a ping in and of itself generally does not adversely affect relevant electronic information systems when it is blocked by firewall policies, and thus does not require activation of the regulated entity's contingency plan. Instead, the business associate would be required to provide such notice in instances where internet commands received by the business associate indicate potential malicious activity, such as a denial of service attack, leading to activation of its contingency plan because of an event that adversely affects the business associate's relevant electronic information systems that create, receive, maintain, or transmit ePHI or adversely affects the confidentiality, integrity, or availability of its ePHI. However, in both such instances, a business associate would still be required to provide notice to the covered entity of the ping as a security incident in accordance with the business associate agreement.
                        <SU>843</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>842</SU>
                             The ping command is a network diagnostic, and firewalls often block incoming pings to prevent attackers from learning more about the organization's network. Karen Scarfone, et al., “Guidelines on Firewalls and Firewall Policy,” NIST Special Publication 800-41, Revision 1, National Institute of Standards and Technology, U.S. Department of Commerce, p. 31 (Sept. 2009), 
                            <E T="03">https://doi.org/10.6028/NIST.SP.800-41r1.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>843</SU>
                             45 CFR 164.314(a)(2)(i)(C).
                        </P>
                    </FTNT>
                    <P>The proposal itself would only require that the business associate notify the covered entity of its activation of the contingency plan; it does not include any specific requirements with respect to the form, content, or manner of the notice. Instead, we propose to permit the covered entity and business associate to negotiate such terms and include them in their business associate agreement if they so choose.</P>
                    <P>
                        We recognize that when such an emergency or other occurrence transpires, the focus of the affected regulated entity must be on activating its contingency plan and restoring access to ePHI and the affected relevant electronic information systems. Similarly, when the contingency plan activation is in response to a successful security incident,
                        <SU>844</SU>
                        <FTREF/>
                         it may take some time to investigate and determine the cause of the security incident. Thus, this proposal would not require reporting on the cause of the contingency plan activation; it would require reporting solely on the fact that it has activated the plan. Accordingly, we believe that 24 hours would provide a business associate with sufficient time to do all of the following: determine that there is an emergency or other occurrence adversely affecting the business associate's relevant electronic information systems; determine that it needs to activate its contingency plan; identify any covered entities that need to be notified; and notify such covered entities.
                    </P>
                    <FTNT>
                        <P>
                            <SU>844</SU>
                             While we are proposing in this NPRM in 45 CFR 164.308(a)(13)(i) to specifically include a security incident as an example of an emergency or occurrence that may damage a relevant electronic information system for which a contingency plan would be required, we believe that this is a clarification, rather than a change.
                        </P>
                    </FTNT>
                    <P>
                        This proposed requirement to provide notice without unreasonable delay, but no later than 24 hours after a 
                        <PRTPAGE P="983"/>
                        contingency plan is activated, would also apply when a business associate that is a governmental entity enters into an arrangement with a covered entity that is also a governmental entity where such arrangement meets the requirements of the Privacy Rule at 45 CFR 164.504(e)(3) in accordance with 45 CFR 164.314(a)(2)(ii) and when a business associate enters into a business associate agreement with a subcontractor in accordance with 45 CFR 164.314(a)(2)(iii) to notify its business associate when it has activated its contingency plan.
                    </P>
                    <P>Additionally, the Department proposes conforming changes to the references of 45 CFR 164.308(b) throughout 45 CFR 164.314 consistent with proposals made to modify 45 CFR 164.308(b). The Department does not intend these to be substantive changes, but rather an alignment with the proposed structural modifications in 45 CFR 164.308(b).</P>
                    <P>As discussed above, the Department proposes to remove the term “required” from the implementation specification at 45 CFR 164.314(a)(2) consistent with its proposal to eliminate the distinction between addressable and required implementation specifications. We also propose a few miscellaneous non-substantive corrections to update citations in the standard at 45 CFR 164.314(a)(1)(i) and (a)(2)(iii). We do not believe that these technical amendments would add or change any regulatory, recordkeeping, or reporting requirements, nor would they change the Department's interpretation of any regulation.</P>
                    <HD SOURCE="HD3">2. Section 164.314(b)(1)—Standard: Requirements for Group Health Plans</HD>
                    <HD SOURCE="HD3">a. Current Provision</HD>
                    <P>
                        The second standard in 45 CFR 164.314 requires that, except when ePHI disclosed to a plan sponsor is summary health information 
                        <SU>845</SU>
                        <FTREF/>
                         or enrollment or disenrollment information,
                        <SU>846</SU>
                        <FTREF/>
                         group health plan 
                        <SU>847</SU>
                        <FTREF/>
                         documents must provide that the plan sponsor will reasonably and appropriately safeguard ePHI created, received, maintained, or transmitted to or by the plan sponsor on behalf of the group health plan. Section 164.314(b)(2) requires that the plan documents of a group health plan must be amended to incorporate provisions to require the plan sponsor to:
                    </P>
                    <FTNT>
                        <P>
                            <SU>845</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.504(f)(1)(ii).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>846</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.504(f)(1)(iii).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>847</SU>
                             45 CFR 160.103 (definition of “Group health plan”).
                        </P>
                    </FTNT>
                    <P>
                        • Implement reasonable and appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of the ePHI that it creates, receives, maintains, or transmits on behalf of the group health plan.
                        <SU>848</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>848</SU>
                             45 CFR 164.314(b)(2)(i).
                        </P>
                    </FTNT>
                    <P>
                        • Ensure that the separation between the group health plan and plan sponsor required by the Privacy Rule at 45 CFR 164.504(f)(2)(iii) 
                        <SU>849</SU>
                        <FTREF/>
                         is supported by reasonable and appropriate security measures.
                        <SU>850</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>849</SU>
                             45 CFR 164.504(f)(2)(iii) requires the plan documents to describe an employee or class of employee who receives PHI for payment, health care operations or other matters related to the group health plan; restrict access to PHI and use of PHI by such employees to the plan administration functions that the plan sponsor performs for the group health plan; and provide an effective mechanism for resolving any issues of noncompliance by such persons.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>850</SU>
                             45 CFR 164.314(b)(2)(ii).
                        </P>
                    </FTNT>
                    <P>
                        • Ensure that any agent to whom it provides ePHI, agrees to implement reasonable and appropriate security measures to protect the information.
                        <SU>851</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>851</SU>
                             45 CFR 164.314(b)(2)(iii).
                        </P>
                    </FTNT>
                    <P>
                        • Report to the group health plan any security incident of which it becomes aware.
                        <SU>852</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>852</SU>
                             45 CFR 164.314(b)(2)(iv).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">b. Issues To Address</HD>
                    <P>
                        Plan sponsors are not directly liable for compliance with the Security Rule because they are not regulated entities, 
                        <E T="03">i.e.,</E>
                         covered entities or business associates under HIPAA. Therefore, plan sponsors' obligations to apply safeguards to ensure the confidentiality, integrity, and availability of ePHI are limited to the requirements set forth in the plan documents of its group health plan. While 45 CFR 164.314(b) generally requires that plan documents call for the implementation of Security Rule-like safeguards, the current provision does not specifically require the group health plan to require the plan sponsor or any agent to whom it provides ePHI to comply with the requirements of the Security Rule. Given the concerns we have regarding Security Rule compliance generally by regulated entities, the Department is also concerned that group health plans have not sufficiently ensured that plan documents require that plan sponsors reasonably and appropriately safeguard ePHI created, received, maintained, or transmitted to or by the plan sponsor on behalf of the group health plan. Additionally, the Department is concerned that group health plans may not be monitoring plan sponsors to ensure that ePHI is disclosed to a plan sponsor only if the plan sponsor voluntarily agrees to use and disclose the information only as permitted or required by the regulations.
                        <SU>853</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>853</SU>
                             65 FR 82462, 82508 (Dec. 28, 2000).
                        </P>
                    </FTNT>
                    <P>
                        Plan sponsors may perform certain functions that are integrally related to, or similar to, the administrative functions of group health plans, and in carrying out these functions, need access to ePHI held by the group health plan. For example, plan sponsors may perform plan administration functions on behalf of the group health plan which are specified in plan documents. The increase in cybercrime and other emergencies adversely affecting electronic information systems is not limited to regulated entities or to the health care sector; plan sponsors are experiencing similar increases in events that require the activation of contingency plans.
                        <SU>854</SU>
                        <FTREF/>
                         And plan sponsors may not be reasonably and appropriately protecting the confidentiality, integrity, and availability of ePHI absent an express requirement that plan documents obligate a plan sponsor to implement the security measures in the Security Rule. Additionally, regulated entities may not have the ability to determine whether alternate security measures will accomplish the same result because they do not have access to the information systems of plan sponsors, nor would it be appropriate for them to have such access.
                    </P>
                    <FTNT>
                        <P>
                            <SU>854</SU>
                             
                            <E T="03">See</E>
                             “2024 Data Breach Investigations Report,” Verizon Business (2024), 
                            <E T="03">https://www.verizon.com/business/resources/reports/dbir/.</E>
                        </P>
                    </FTNT>
                    <P>Additionally, the Department believes that prompt notification by a plan sponsor to the group health plan that the ability of the plan sponsor or the group health plan to access ePHI or relevant electronic information systems may be affected by a security incident is important for the same reasons discussed above in 45 CFR 164.314(a). This lack of prompt notification delays a group health plan from responding and protecting its ePHI and relevant electronic information systems accordingly.</P>
                    <HD SOURCE="HD3">c. Proposal</HD>
                    <P>
                        The Department proposes to modify the implementation specifications at 45 CFR 164.314(b)(2)(i) through (iii) to address concerns that group health plans may not recognize that reasonable and appropriate safeguarding of ePHI requires the implementation of security measures that are the same as, or at least equivalent to, the security measures in the Security Rule. First, we propose to rename the implementation specifications as “Safeguard implementation,” “Separation,” and 
                        <PRTPAGE P="984"/>
                        “Agents,” respectively. We also propose to modify all three implementation specifications to require that plan documents of the group health plan would obligate a plan sponsor or any agent to whom it provides ePHI to implement the administrative, physical, and technical safeguards of the Security Rule. The Department recognizes that plan sponsors may need access to ePHI in certain situations, such as when they perform functions that are integrally related to, or similar to, those performed by group health plans, and we believe that such information must be protected by plan sponsors in the same manner in which it is protected by group health plans and other regulated entities.
                        <SU>855</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>855</SU>
                             65 FR 82462, 82508 (Dec. 28, 2000); 
                            <E T="03">see also</E>
                             68 FR 8334, 8360 (Feb. 20, 2003) (§ 164.314(b) provisions are drawn from and intended to support the analogous privacy protections provided for by 45 CFR 164.504(f) and discussed in the 2000 Privacy Rule.).
                        </P>
                    </FTNT>
                    <P>
                        The security measures we are proposing in this NPRM are consistent with the CISA Cross-Sector CPGs,
                        <SU>856</SU>
                        <FTREF/>
                         and thus should be consistent with measures plan sponsors are implementing to protect their own electronic information systems, regardless of the obligations imposed on them by plan documents. For example, the Department seeks to ensure that plan sponsors are implementing administrative safeguards, such as performing a risk analysis,
                        <SU>857</SU>
                        <FTREF/>
                         to protect the confidentiality, integrity, and availability of all ePHI in its information systems; documenting required policies and procedures; and documenting implementation of such administrative safeguards, including the required policies and procedures.
                        <SU>858</SU>
                        <FTREF/>
                         Thus, requiring plan sponsors to implement the same security measures that regulated entities are implementing would maintain confidence in the commitment of plan sponsors to protecting the confidentiality, integrity, and availability of ePHI in light of the increasing cybersecurity threats as discussed above.
                    </P>
                    <FTNT>
                        <P>
                            <SU>856</SU>
                             “Cross-Sector Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 164.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>857</SU>
                             Proposed 45 CFR 164.308(a)(2)(i).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>858</SU>
                             Proposed 45 CFR 164.308, 164.310, 164.312, and 164.316.
                        </P>
                    </FTNT>
                    <P>Additionally, the Department proposes to rename the implementation specification at 45 CFR 164.314(b)(2)(iv) as “Security incident awareness.”</P>
                    <P>
                        Similar to the discussion above, the Department proposes to add a new implementation specification for contingency plan activation at proposed 45 CFR 164.314(b)(2)(v) that would require plan documents to include a provision requiring a plan sponsor to report to the group health plan without unreasonable delay, but no later than 24 hours after activation of its contingency plan.
                        <SU>859</SU>
                        <FTREF/>
                         As discussed above, the Department believes that a group health plan needs to be notified in a timely manner when a plan sponsor activates its contingency plan because of the potential implications on the ability of a group health plan to protect the confidentiality, integrity, and availability of ePHI in its relevant electronic information systems. Accordingly, we believe that 24 hours would provide a plan sponsor sufficient time to do all of the following: determine that there is an emergency or other occurrence adversely affecting the plan sponsor's relevant electronic information systems; determine that it needs to activate its contingency plan; activate its contingency plan; identify any group health plans that need to be notified; and notify such group health plans.
                    </P>
                    <FTNT>
                        <P>
                            <SU>859</SU>
                             The plan sponsor would implement a contingency plan because it is one of the requirements of the administrative safeguards of the Security Rule and would be implemented based on the proposed requirements in 45 CFR 164.314(b)(2)(i).
                        </P>
                    </FTNT>
                    <P>Similarly, as discussed above, we propose to permit the group health plan and plan sponsor to negotiate the form, content, or manner of the notice and include them in their plan documents if they so choose.</P>
                    <P>The Department believes that requiring a plan sponsor to provide prompt notice to the group health plan when the plan sponsor activates its contingency plan would enable group health plans and plan sponsors to maintain individuals' confidence in their commitment to protecting the confidentiality, integrity, and availability of ePHI.</P>
                    <P>Additionally, consistent with our proposal to revise 45 CFR 164.306, the Department proposes to remove the term “required” from the implementation specification at 45 CFR 164.314(b)(2) consistent with our overall proposal to eliminate the distinction between “required” and “addressable” implementation specifications. However, a regulated entity would still be required to comply with all standards and implementation specifications as applicable to its situation, as proposed in 45 CFR 164.306(c).</P>
                    <HD SOURCE="HD3">3. Request for Comment</HD>
                    <P>The Department requests comment on the foregoing proposals, including any benefits, drawbacks, or unintended consequences. We also request comment on the following considerations in particular:</P>
                    <P>a. How group health plans currently ensure that plan sponsors implement reasonable and appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of ePHI.</P>
                    <P>b. Whether it is appropriate for group health plans to require plan sponsors to implement the administrative, physical, and technical safeguards of the Security Rule. If not, please explain and provide alternatives for how the Department should ensure the confidentiality, integrity, and availability of ePHI when it is disclosed to plan sponsors.</P>
                    <P>c. Whether business associates currently notify covered entities (or subcontractors notify business associates) upon activation of their contingency plans, and if so, the manner and timing of such notice.</P>
                    <P>d. Whether plan sponsors currently notify group health plans upon activation of their contingency plans, and if so, the manner and timing of such notice.</P>
                    <P>e. Whether it would be appropriate to require a business associate to notify a covered entity (or a subcontractor to notify a business associate) within 24 hours of activating its contingency plan. If not, please explain why and what would be an appropriate amount of time for such notification.</P>
                    <P>f. Whether it would be appropriate to require a plan sponsor to notify a group health plan within 24 hours of activating its contingency plan. If not, please explain why and what would be an appropriate amount of time for such notification.</P>
                    <P>g. The manner, timing, frequency, and process used by business associates to report security incidents to a covered entity (or subcontractors to business associates).</P>
                    <P>h. The manner, timing, frequency, and process used by a plan sponsor to report security incidents to a group health plan.</P>
                    <HD SOURCE="HD2">H. Section 164.316—Documentation Requirements</HD>
                    <HD SOURCE="HD3">1. Current Provisions</HD>
                    <P>
                        Section 164.316(a) requires a regulated entity to implement reasonable and appropriate policies and procedures that comply with the Security Rule, taking into account the size, complexity, and capabilities of the regulated entity; 
                        <SU>860</SU>
                        <FTREF/>
                         the regulated entity's technical infrastructure, hardware, and software capabilities; 
                        <SU>861</SU>
                        <FTREF/>
                         the costs of security measures; 
                        <SU>862</SU>
                        <FTREF/>
                         and the probability and criticality of 
                        <PRTPAGE P="985"/>
                        potential risks to ePHI.
                        <SU>863</SU>
                        <FTREF/>
                         Such policies and procedures must be consistent with the other requirements of the Security Rule. A regulated entity is permitted to change its policies and procedures, but it must document and implement such change in accordance with the Security Rule.
                    </P>
                    <FTNT>
                        <P>
                            <SU>860</SU>
                             45 CFR 164.306(b)(2)(i).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>861</SU>
                             45 CFR 164.306(b)(2)(ii).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>862</SU>
                             45 CFR 164.306(b)(2)(iii).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>863</SU>
                             45 CFR 164.306(b)(2)(iv).
                        </P>
                    </FTNT>
                    <P>The standard and implementation specifications for documentation are in 45 CFR 164.316(b). Paragraph (b)(1) requires a regulated entity to maintain the policies and procedures it implements to comply with the Security Rule in written form. Additionally, where the Security Rule requires an action, activity, or assessment to be documented, the regulated entity must maintain a written record of the action, activity, or assessment. In both cases, the written record may be electronic. Paragraph (b)(2) includes the current implementation specifications for the documentation standard. Such documentation must be retained for the later of either: (1) six years from its creation, or (2) the date it was last effective. Additionally, it must be available to those responsible for implementing the documented policies and procedures. Finally, regulated entities must periodically review their documentation and update it as needed in response to environmental or operational changes affecting the security of ePHI.</P>
                    <HD SOURCE="HD3">2. Issues To Address</HD>
                    <P>Although this section currently addresses policies and procedures and documentation, it does not require or include standards to govern how regulated entities must implement, maintain, and document implementation of all security measures. Implementing, maintaining, and documenting implementation of all security measures is important to ensure that regulated entities make well-reasoned decisions about implementing the requirements of this rule. Just as the Department believes that it is necessary to consider expanding the definition of “security measures” to better reflect that security measures should be multi-layered, we also believe that it is necessary to consider providing a more complete instruction concerning how regulated entities must implement, maintain, and document their implementation of the required security measures.</P>
                    <P>
                        Additionally, OCR's own experience in investigations and audits leads us to believe that many regulated entities may not be documenting their security measures or their implementation of those measures.
                        <SU>864</SU>
                        <FTREF/>
                         It is critical for a regulated entity to commit to writing the security measures required by the Security Rule to ensure consistent implementation and compliance with the Security Rule. Verbal instructions may be forgotten or misconstrued, and what the regulated entity believes to be common knowledge may not be or may be relayed incorrectly between workforce members.
                    </P>
                    <FTNT>
                        <P>
                            <SU>864</SU>
                             
                            <E T="03">See</E>
                             Resolution Agreement, “Peachstate Health Management, Inc.,” Office for Civil Rights, U.S. Department of Health and Human Services (Apr. 28, 2021), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/peachstate/index.html;</E>
                             “West Georgia Ambulance, Inc.,” 
                            <E T="03">supra</E>
                             note 583; 
                            <E T="03">see also</E>
                             “2016-2017 HIPAA Audits Industry Report,” 
                            <E T="03">supra</E>
                             note 121, p. 27 (the Department found that only 31 percent of regulated entities audited had safeguarded ePHI through risk analysis activities, including developing and implementing policies and procedures).
                        </P>
                    </FTNT>
                    <P>Additionally, based on OCR's enforcement experience, the Department believes that regulated entities may not be periodically reviewing and updating their documentation when they modify their security measures in response to environmental or operational changes affecting the security of their ePHI. Given the constant evolution of technology and the everchanging behavior of cybercriminals in response to technological evolution, the Department believes that regular review of cybersecurity-related security measures is essential for protecting the confidentiality, integrity, and availability of ePHI and relevant electronic information systems.</P>
                    <HD SOURCE="HD3">3. Proposals</HD>
                    <P>As discussed above, the Department has proposed to revise other provisions of the Security Rule to clarify the differences between administrative and technical safeguards and between policies and procedures on the one hand and technical controls on the other hand. We have also proposed to revise other provisions of the Security Rule to clarify that a regulated entity is required to implement and maintain its administrative, physical, and technical safeguards, including its policies and procedures. These proposals clarify that such maintenance requires the review, testing, and modification of the regulated entity's security measures on a regular cadence, meaning that the regulated entity's security measures can be modified at any time. Given these proposals, the Department believes that we must also propose to revise 45 CFR 164.316 to delete the standard for policies and procedures and to modify the Security Rule's documentation requirements. Accordingly, the Department proposes to rename this section as “Documentation Requirements” and to redesignate the documentation standard as paragraph (a). We also propose to require that a regulated entity document how it considered the factors in 45 CFR 164.306(b) in the development of its written policies and procedures.</P>
                    <P>We also propose to modify the documentation standard to clarify that all required written documentation may be in electronic form. Additionally, we propose to modify the standard's two paragraphs. Specifically, the Department proposes at proposed 45 CFR 164.316(a)(1) to require that a regulated entity document the policies and procedures it has implemented to comply with the Security Rule, and as part of that documentation, explain how it considered the factors at 45 CFR 164.306(b) in the development of its policies and procedures. Relatedly, we also propose to modify 45 CFR 164.316(a)(2) to require a regulated entity to document all of the actions, activities, and assessments required by the Security Rule. The Department believes that both proposals would help to address two common problems observed in Security Rule investigations: a failure by the regulated entity to document its policies and procedures and a failure to document actions, activities, and assessments taken to comply with the Security Rule. Without such documentation, it is challenging for a regulated entity to assess and ensure its own compliance. Accordingly, we believe that our proposals to require a regulated entity to document its implementation of the Security Rule requirements would aid both the regulated entity and the Department.</P>
                    <P>
                        Consistent with our proposal to redesignate the documentation standard as 45 CFR 164.316(a), we propose to redesignate the implementation specifications for documentation time limits, availability, and updates as proposed at 45 CFR 164.316(b)(1) through (3), respectively. Under proposed 45 CFR 164.316(b)(3), the Department proposes to require a regulated entity to update its documentation at least once every 12 months and within a reasonable and appropriate period of time after a security measure is modified.
                        <SU>865</SU>
                        <FTREF/>
                         As 
                        <PRTPAGE P="986"/>
                        discussed above, the Department recognizes that the health care environment has changed in a way that necessitates thorough and frequent review of and updates to documentation. By proposing to specify how often documentation must be updated, the Department would clarify that we expect regulated entities to review and update their documentation at regular intervals, in addition to doing so in response any changes to a security measure. Cybersecurity and data protection is an evolving process, which makes formal, updated, and detailed documentation imperative for data protection. By reviewing and updating its documentation, including its written policies and procedures, at least annually and in response to changes to its security measures, a regulated entity should have a full understanding of its implemented security measures and be able to determine which measures should be updated to protect the confidentiality, integrity, and availability of ePHI.
                    </P>
                    <FTNT>
                        <P>
                            <SU>865</SU>
                             In 2003, the Department declined a commenter's suggestion to change the term “periodically” to “at least annually.” At that time, we said that documentation must be updated as needed to reflect security measures currently in effect and that the requirement allowed individual entities to establish review and update cycles as deemed necessary because it would vary dependent 
                            <PRTPAGE/>
                            upon a given entity's size, configuration, environment, operational changes, and the security measures implemented. 68 FR 8334, 8361 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <P>As discussed above and consistent with the proposed changes to 45 CFR 164.306, the Department is proposing to remove the term “required” from 45 CFR 164.316(b)(1) through (3).</P>
                    <HD SOURCE="HD3">4. Request for Comment</HD>
                    <P>The Department requests comment on the foregoing proposals, including any benefits, drawbacks, or unintended consequences. We also request comment on the following consideration in particular:</P>
                    <P>a. Whether it would be appropriate to require regulated entities to review and update documentation for security measures at least once every 12 months. If not, please explain.</P>
                    <P>b. Whether it is clear that 45 CFR 164.316 provides regulated entities with directions on when and how they are to document all security measures across all safeguard requirements. If not, please explain.</P>
                    <P>c. Whether it is feasible for regulated entities to document all of the actions, activities, and assessments required by the Security Rule as proposed at 45 CFR 164.316(a)(2). If not, please explain.</P>
                    <HD SOURCE="HD2">I. Section 164.318—Transition Provisions</HD>
                    <HD SOURCE="HD3">1. Current Provisions and Issues To Address</HD>
                    <P>
                        Section 164.318 established the compliance dates for the initial implementation of the security standards for health plans, health care clearinghouses, and health care providers in 2005 and 2006.
                        <SU>866</SU>
                        <FTREF/>
                         Covered entities have been required to comply with the security standards for almost 20 years, and the initial implementation of the security standards is no longer applicable. Because of this, the Department believes that these provisions are no longer necessary.
                    </P>
                    <FTNT>
                        <P>
                            <SU>866</SU>
                             HIPAA set forth the compliance dates for the initial standards. 42 U.S.C. 1320d-4; 
                            <E T="03">see also</E>
                             68 FR 8334, 8351 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">2. Proposal</HD>
                    <P>The Department proposes to remove the information in 45 CFR 164.318 and replace the language with provisions for transitioning to the revised Security Rule, should the proposals included in this NPRM be adopted.</P>
                    <P>
                        The Department understands that regulated entities may be concerned with the anticipated administrative burden and cost of revising their business associate agreements or other written arrangements to comply with a revised Security Rule. For example, a regulated entity would need to update its business associate agreements to add a provision specifying that the business associate will report to the covered entity 
                        <SU>867</SU>
                        <FTREF/>
                         that it activated its contingency plan no later than 24 hours after activation of such plan.
                        <SU>868</SU>
                        <FTREF/>
                         A regulated entity may have existing contracts that are not set to terminate or expire until after the compliance date for a final rule modifying the Security Rule, and we understand that a six-month compliance period may not provide enough time to reopen and renegotiate all contracts, in addition to ensuring that all regulated entities are compliant with the revised Security Rule. Accordingly, the Department proposes to relieve some of the burden on regulated entities by adding a specified period of transition for certain existing contracts.
                    </P>
                    <FTNT>
                        <P>
                            <SU>867</SU>
                             Similarly, a business associate subcontractor would need to report to the business associate. 
                            <E T="03">See</E>
                             “Business Associate Contracts,” Office for Civil Rights, U.S. Department of Health and Human Services (June 16, 2017) (A “business associate” also is a subcontractor that creates, receives, maintains, or transmits PHI on behalf of another business associate), 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>868</SU>
                             Proposed 45 CFR 164.314(a)(2)(i)(D).
                        </P>
                    </FTNT>
                    <P>
                        The Department's authority to provide a transition period is expressed in 45 CFR 160.104(c), which allows the Secretary to establish the compliance date for any modified standard or implementation specification, considering the extent of the modification and the time needed to comply with the modification.
                        <SU>869</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>869</SU>
                             The Department has previously included transition provisions to ensure that important functions of the health care system were not impeded. 
                            <E T="03">See, e.g.,</E>
                             65 FR 82462 (Dec. 28, 2000); 67 FR 53182 (Aug. 14, 2002); 78 FR 5566 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <P>Given these considerations, to allow regulated entities enough time to update thousands of existing business associate agreements or other written arrangements, the Department proposes to provide additional time to update the contracts required by 45 CFR 164.314(a)(1).</P>
                    <P>Specifically, the Department proposes to add new transition provisions under 45 CFR 164.318 to allow regulated entities to continue to operate under certain existing business associate agreements or other written arrangements until the earlier of: (1) the date such contract or other arrangement either is renewed on or after the compliance date of the final rule; or (2) a year after the effective date of the final rule. The additional transition period would be available to regulated entities if both of the following conditions are met: (1) prior to the publication date of the final rule, the covered entity or business associate had an existing business associate agreement or other written arrangement with a business associate or subcontractor, respectively, that complied with the Security Rule prior to the effective date of a final rule revising the Security Rule; and (2) such contract or arrangement would not be renewed or modified between the effective date and the compliance date of the final rule.</P>
                    <P>
                        Under the proposed transition provisions, a business associate would be permitted to create, receive, maintain, or transmit ePHI pursuant to an existing business associate agreement or other written arrangement with another regulated entity that does not require the regulated entity to obtain satisfactory assurances that meet the requirements of the revised Security Rule for up to one year after the revised Security Rule becomes effective, assuming that a final Security Rule is published; and that the agreement is compliant with the Security Rule at the time the final rule is published and that it is not renewed or modified between the effective and compliance dates.
                        <SU>870</SU>
                        <FTREF/>
                         The transition provisions would also allow for the business associate to create, receive, maintain, or transmit ePHI on behalf of another regulated entity where the existing business associate agreement does not require that the regulated entity verify that the 
                        <PRTPAGE P="987"/>
                        business associate has deployed technical safeguards in accordance with the Security Rule under the same circumstances as those described above.
                        <SU>871</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>870</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(b)(1)(i).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>871</SU>
                             
                            <E T="03">See id.</E>
                        </P>
                    </FTNT>
                    <P>
                        During the transition period, the Department proposes to allow a business associate to create, receive, maintain, or transmit ePHI pursuant to a business associate agreement or other written arrangement with another regulated entity without including in the agreement that the business associate will: (1) comply with the revised Security Rule; 
                        <SU>872</SU>
                        <FTREF/>
                         (2) ensure that any subcontractors that create, receive, maintain, or transmit ePHI on behalf of the business associate agree to comply with the revised Security Rule by entering into a business associate agreement or other arrangement that meets the requirements of the revised rule; 
                        <SU>873</SU>
                        <FTREF/>
                         and (3) report to the covered entity 
                        <SU>874</SU>
                        <FTREF/>
                         activation of its contingency plan.
                        <SU>875</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>872</SU>
                             45 CFR 164.314(a)(2)(i)(A).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>873</SU>
                             45 CFR 164.314(a)(2)(i)(B).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>874</SU>
                             Or to the business associate from a business associate subcontractor.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>875</SU>
                             Proposed 45 CFR 164.314(a)(2)(i)(D).
                        </P>
                    </FTNT>
                    <P>Additionally, the Department intends that, in cases where a contract renews automatically without any change in terms or other action by the parties (also known as “evergreen contracts”), such contracts would be eligible for the extension if they automatically renew between the effective and compliance dates. Thus, regulated entities with an evergreen contract will be deemed to be in compliance with the Security Rule's requirements for business associate agreements or other written arrangements and such deemed compliance would not terminate when these contracts automatically renew. These transition provisions would apply to written contracts or other written arrangements as specified above.</P>
                    <P>
                        These transition provisions would apply only to the requirement to amend contracts or other arrangements with business associates, and they would not affect any other compliance obligations under the Security Rule. For example, beginning on the compliance date of the final rule, assuming a final rule is published and that it is finalized as proposed, a business associate would be required to implement and document its implementation of the administrative, physical, and technical safeguards required by a revised Security Rule, except with respect to 45 CFR 164.308(b) and 164.314(a), even if the business associate's contract with the covered entity 
                        <SU>876</SU>
                        <FTREF/>
                         has not yet been amended.
                    </P>
                    <FTNT>
                        <P>
                            <SU>876</SU>
                             Or business associate's contract with the subcontractor.
                        </P>
                    </FTNT>
                    <P>Given the possibility of a similar burden on group health plans and plan sponsors to update plan documents by the compliance date, the Department is considering, but not proposing, a similar transition provision for plan documents. We are not proposing such provisions at this time because, unlike business associates, plan sponsors do not have independent obligations under the Security Rule. Instead, the obligations of plan sponsors are based entirely on the content of the plan documents. Accordingly, if the plan documents are not updated, plan sponsors are not obligated to comply with the requirements of the Security Rule because they are not regulated entities.</P>
                    <P>In particular, the Department is considering, but not proposing at this time, adding a new paragraph (d) introductory text under 45 CFR 164.318, with the heading “Standard: Effect of prior plan documents for group health plans,” stating that notwithstanding any other provisions of the subpart, a group health plan may allow a plan sponsor to create, receive, maintain, or transmit electronic protected health information pursuant to a written plan document with such group health plan that does not comply with § 164.314(b), only in accordance with paragraph (d)(1). The Department is also considering adding a new paragraph (d)(1) under 45 CFR 164.318, with the heading “Implementation specification: Plan documents for group health plans,” stating that the requirements of paragraph (b) apply to the plan document between a group health plan and a plan sponsor in the same manner as such requirements apply to written contracts or other arrangements between a covered entity and a business associate.</P>
                    <P>Similarly, the Department is considering, but not proposing at this time, adding a new paragraph (d)(2) under 45 CFR 164.318, with the heading “Group health plan responsibilities,” stating that nothing in the section shall alter the requirements of a group health plan or plan sponsor to comply with the applicable provisions of the part other than § 164.314(b).</P>
                    <HD SOURCE="HD3">3. Request for Comment</HD>
                    <P>The Department requests comment on the foregoing proposals, including any benefits, drawbacks, or unintended consequences. We also request comment on the following considerations in particular:</P>
                    <P>a. Whether the Department's proposal to provide regulated entities with additional time to revise business associate agreements or other written contracts is appropriate. If not, please explain.</P>
                    <P>b. Whether the Department should also provide group health plans and plan sponsors additional time to revise plan documents by adding a transition provision to grandfather certain existing plan documents for a specified period of time.</P>
                    <P>c. Whether the Department should consider additional constraints or specificity for a new paragraph (d) to allow group health plans more time to comply with the Security Rule requirements for plan documents.</P>
                    <HD SOURCE="HD2">J. Section 164.320—Severability</HD>
                    <P>The Department intends that, if any provisions of this subpart, including the provisions of this NPRM, if finalized, were held to be invalid or unenforceable facially, or as applied to any person, plaintiff, or stayed pending further judicial or agency action, such provision shall be severable from other provisions of this subpart, and from other rules and regulations currently in effect, and not affect the remainder of this subpart. It is also our intent that, unless such provision shall be held to be utterly invalid or unenforceable, it shall be construed to give the provision maximum effect to the provision permitted by law, including in the application of the provision to other persons not similarly situated or to other dissimilar circumstances from those where the provision may be held to be invalid or unenforceable.</P>
                    <P>The provisions of this subpart, including the proposals of this NPRM, are intended to operate independently of each other, even if multiple provisions serve the same or similar general purpose(s) or policy goal(s). Where a provision is necessarily dependent on another, the context generally makes that clear, such as by cross-reference to a particular standard, requirement, or implementation specification. Where a provision that is dependent on one that is stayed or held invalid or unenforceable, as described in the preceding paragraph, is included in paragraph or section within 45 CFR part 160 or 164, we intend that other provisions of such paragraph(s) or section(s) that operate independently of said provision would remain in effect.</P>
                    <P>
                        The Department intends the individual standards in 45 CFR 164.308, 164.310, 164.312, 164.314, and 164.316 to apply separately to govern how a regulated entity must protect the security of all ePHI it creates, receives, 
                        <PRTPAGE P="988"/>
                        maintains, or transmits. Accordingly, if finalized, this provision would provide that if any one or several standards in 45 CFR 164.308, 164.310, 164.312, 164.314, and 164.316 are deemed invalid by a court, or non-applicable to a particular person or circumstance, all remaining standards shall be unaffected and shall remain in force, and any remaining component of the adjudicated provision, not invalid or found to be unenforceable or inapplicable, shall be considered by the Department to be still in effect.
                    </P>
                    <P>For example, the standard for risk analysis proposed in 45 CFR 164.308(a)(2) would protect ePHI from risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI, while the modified standard for workforce security proposed in 45 CFR 164.308(a)(9) would protect ePHI from inappropriate access by a regulated entity's workforce. An invalidated standard for workforce security would not render the entire rule unworkable because a regulated entity could still meet the requirement to conduct the risk analysis without regard to whether the entity meets the requirements included in the standard for workforce security. Similarly, were a court to invalidate the Department's proposal in 45 CFR 164.310(a)(1) requiring that implemented policies and procedures to limit physical access to relevant electronic information systems and the facility or facilities in which they are housed be in writing, a regulated entity could still meet a requirement to implement the policies and procedures. Similar considerations apply to the proposal for written policies and procedures in proposed 45 CFR 164.316(a), and to proposals that are deemed inapplicable to certain persons or circumstances.</P>
                    <P>Further, the Department believes it is necessary to clarify how regulated entities would continue to apply implementation specifications in the event a court invalidates or deems inapplicable a governing standard over a specific implementation specification, or if a court invalidates or deems inapplicable one or several implementation specifications without taking adverse action on the governing standard. The Department does not interpret that this severability proposal, if finalized, would apply to implementation specifications in the same manner as it would apply to standards. Because the implementation specifications are regulatory instructions on how a regulated entity is to comply with a particular standard, if any standard is stricken, all implementation specifications underneath are similarly stricken. Conversely, the Department does not intend for the overarching standard to be affected by a court's decision to invalidate or make a determination of non-applicability to particular person or circumstance all implementation specifications under a particular standard. The Security Rule would still retain its flexible and scalable approach, and, therefore, a regulated entity could use any reasonable and appropriate security measure to implement the standard consistent with 45 CFR 164.306(b), even if all implementation specifications under the standard are stricken.</P>
                    <P>
                        If a court invalidates or deems inapplicable less than all implementation specifications under a specific standard (
                        <E T="03">i.e.,</E>
                         only one or several), the ability of a regulated entity to execute the remaining implementation specification(s) depends on whether the remaining implementation specifications are dependent on one another or operate together to impose requirements on regulated entities. For example, several proposed implementation specifications under the standard for facility access controls at 45 CFR 164.310(a)(1) would require a regulated entity to both establish and implement written procedures pertaining to specific requirements such as contingency operations, facility security planning and access control and validation, and then subsequently review the written policies and procedures every 12 months. Should a court invalidate or deem inapplicable the implementation specification to establish and implement written policies procedures, the secondary specification requiring review of said procedures would also become invalid.
                    </P>
                    <P>The Department believes that each definition is independent of all other definitions.</P>
                    <P>This list of examples is not intended to be exhaustive. The absence from this list of any particular provision should not be construed to mean that the Department considers that provision to be not severable from other parts of the rule.</P>
                    <P>To ensure that our intent for severability of provisions is clear in the CFR, the Department proposes to add a section on severability at 45 CFR 164.320. Proposed 45 CFR 164.320 would state our intent that if any provision of this subpart is held to be invalid or unenforceable, it shall be construed to give maximum effect to the provision permitted by law unless the holding shall be one of utter invalidity or unenforceability, in which case the provision shall be severable from this subpart and shall not affect the remainder thereof or the application of the provision to other persons not similarly situated or to other dissimilar circumstances.</P>
                    <P>The Department requests comment on the foregoing proposal, including any benefits, drawbacks, or unintended consequences.</P>
                    <HD SOURCE="HD2">K. New and Emerging Technologies Request for Information</HD>
                    <P>Technology is constantly evolving, able to perform increasingly complex tasks, including those with the potential to improve health care and communication between individuals and care providers. These new and evolved technologies will continue to transform health care in a variety of ways, including providing regulated entities with new tools for faster and more accurate diagnoses, effective treatments, and more efficient administration.</P>
                    <P>
                        As a regulated entity considers the application of new technologies or the use of existing tools in innovative ways, it also must consider whether these technologies create, receive, maintain, or transmit ePHI, and, if so, how to secure them. The Security Rule was designed to be technology-neutral for this very reason and continues to provide the foundation for ensuring the confidentiality, integrity, and availability of all ePHI as technology changes.
                        <SU>877</SU>
                        <FTREF/>
                         As a result, while the technology may be new or developing, securing ePHI involved with the technology can be successfully executed through compliance with the Security Rule.
                    </P>
                    <FTNT>
                        <P>
                            <SU>877</SU>
                             45 CFR 164.306(a).
                        </P>
                    </FTNT>
                    <P>
                        Before implementing new and emerging technologies, a regulated entity must conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
                        <SU>878</SU>
                        <FTREF/>
                         It must then implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.
                        <SU>879</SU>
                        <FTREF/>
                         Such administrative, physical, and technical safeguards apply to all instances of ePHI maintained or transmitted by the regulated entity, regardless of the technology used. Below, we discuss some examples of new technologies, such as quantum computing, AI, and virtual and augmented reality (VR and AR), and 
                        <PRTPAGE P="989"/>
                        how the Security Rule would apply in each case.
                    </P>
                    <FTNT>
                        <P>
                            <SU>878</SU>
                             45 CFR 164.508(a)(1)(ii)(A).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>879</SU>
                             45 CFR 164.308(a)(1)(ii)(B).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">1. Quantum Computing</HD>
                    <P>
                        Several Federal agencies have considered the potential benefits and drawbacks of quantum information science,
                        <SU>880</SU>
                        <FTREF/>
                         that is, the study of “the impacts of quantum physics properties on information science. Those properties can increase computational power and speed significantly over classical computers, provide precision measurements; enhance sensing capabilities; and increase the accuracy of position, navigation, and timing services.” 
                        <SU>881</SU>
                        <FTREF/>
                         According to NIST, “In recent years, there has been a substantial amount of research on quantum computers—machines that exploit quantum mechanical phenomena to solve mathematical problems that are difficult or intractable for conventional computers.” 
                        <SU>882</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>880</SU>
                             
                            <E T="03">See</E>
                             “Post-Quantum Cryptography, Quantum Background,” U.S. Department of Homeland Security (last accessed July 23, 2024), 
                            <E T="03">https://www.dhs.gov/quantum; see also</E>
                             “Quantum-Readiness: Migration to Post-Quantum Cryptography,” Cybersecurity &amp; Infrastructure Security Agency, National Security Agency, and National Institute of Standards and Technology, p. 1 (Aug. 21, 2023), 
                            <E T="03">https://media.defense.gov/2023/Aug/21/2003284212/-1/-1/0/CSI-QUANTUM-READINESS.PDF.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>881</SU>
                             “Post-Quantum Cryptography, Quantum Background,” 
                            <E T="03">supra</E>
                             note 880.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>882</SU>
                             
                            <E T="03">See</E>
                             “Post-Quantum Cryptography PQC,” Computer Security Resource Center, National Institute of Standards and Technology, U.S. Department of Commerce (July 19, 2024), 
                            <E T="03">https://www.nist.gov/pqcrypto.</E>
                        </P>
                    </FTNT>
                    <P>
                        However, the increase in computational capability threatens the security of asymmetric cryptography,
                        <SU>883</SU>
                        <FTREF/>
                         which is critical to encryption solutions, a key protection for ePHI and other sensitive information today. Scientists warn that when such quantum computers are built, they will have the ability to break many of the systems for asymmetric cryptography that are in use today.
                        <SU>884</SU>
                        <FTREF/>
                         Thus, experts anticipate that quantum computing will adversely affect the confidentiality and integrity of digital communications.
                        <SU>885</SU>
                        <FTREF/>
                         “The goal of post-quantum cryptography (also called quantum-resistant cryptography) is to develop cryptographic systems that are secure against both quantum and classical computers, and can interoperate with existing communications protocols and networks.” 
                        <SU>886</SU>
                        <FTREF/>
                         A recent National Security Memorandum affirmed that “alongside its potential benefits, quantum computing also poses significant risks to the economic and national security of the United States. . . . [including the potential to break] much of the public-key cryptography used on digital systems across the United States and around the world.” 
                        <SU>887</SU>
                        <FTREF/>
                         Accordingly, the White House has directed Federal agencies to take specific steps to “mitigate the threat of [cryptanalytically relevant quantum computers] through a timely and equitable transition of the Nation's cryptographic systems to interoperable quantum-resistant cryptography.” 
                        <SU>888</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>883</SU>
                             
                            <E T="03">See</E>
                             “Post-Quantum Cryptography, Quantum Background,” 
                            <E T="03">supra</E>
                             note 880.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>884</SU>
                             
                            <E T="03">See</E>
                             “Post-Quantum Cryptography PQC,” 
                            <E T="03">supra</E>
                             note 882.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>885</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>886</SU>
                             
                            <E T="03">See id.</E>
                             (removed emphasis from “post-quantum cryptography” in original).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>887</SU>
                             National Security Memorandum on Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems, National Security Memorandum/NSM-10, The White House (May 4, 2022), 
                            <E T="03">https://www.whitehouse.gov/briefing-room/statements-releases/2022/05/04/national-security-memorandum-on-promoting-united-states-leadership-in-quantum-computing-while-mitigating-risks-to-vulnerable-cryptographic-systems/.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>888</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        NCVHS examined these security issues and provided recommendations to the Department for applying the safeguards of the HIPAA Rules to potential quantum computing threats. Specifically, NCVHS declared that incorporation of recent Administration guidance for Federal agencies “on vulnerable cryptographic systems is necessary to strengthen the Technical Safeguards within the Security Rule.” 
                        <SU>889</SU>
                        <FTREF/>
                         This joint guidance, developed by NIST, CISA, and NSA, encourages “the early planning for migration to post-quantum cryptographic standards by developing a Quantum-Readiness Road map.” 
                        <SU>890</SU>
                        <FTREF/>
                         It also recommends that organizations prepare a cryptographic inventory, discuss post-quantum roadmaps with technology vendors, consider their supply chain's readiness for quantum computing, and consider the responsibilities of their technology vendors with respect to preparing for quantum readiness.
                        <SU>891</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>889</SU>
                             
                            <E T="03">See</E>
                             Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, Appendix p. 2 (providing NCVHS recommendations to strengthen the HIPAA Security Rule).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>890</SU>
                             
                            <E T="03">See</E>
                             “Quantum-Readiness: Migration to Post-Quantum Cryptography,” Cybersecurity &amp; Infrastructure Security Agency, National Security Agency, and National Institute of Standards and Technology, p. 1 (Aug. 21, 2023), 
                            <E T="03">https://media.defense.gov/2023/Aug/21/2003284212/-1/-1/0/CSI-QUANTUM-READINESS.PDF.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>891</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>The Department encourages regulated entities to incorporate these activities as part of their ongoing risk management programs. For example, the steps presented in the joint guidance—surveying the environment for potential risks and vulnerabilities that endanger ePHI, identifying workforce members with responsibility for addressing them, inventorying quantum-vulnerable systems, including that inventory in its risk analysis and risk management, and working with technology vendors to ensure their readiness—are all activities that already are required by the administrative safeguards of the Security Rule.</P>
                    <P>We believe these obligations would be clarified by the proposals in this NPRM. For example, the Department proposes to require that a regulated entity not only conduct an accurate assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI it creates, receives, maintains, or transmits, but would add an express requirement that the assessment be comprehensive and in writing. We also propose to specify that the required assessment include, among other things, identification of all reasonably anticipated threats and potential vulnerabilities and predisposing conditions, making a reasonable determination and documentation of the likelihood that each identified threat will exploit the identified vulnerabilities, and performing a written assessment of the risk level for each identified threat and vulnerability. Under the NPRM, a regulated entity would be expected to, as part of the risk analysis, consider whether quantum computing poses a reasonably anticipated threat to the confidentiality, integrity, or availability of its ePHI and whether there is a vulnerability or predisposing condition that corresponds to that threat, and to document those considerations; make a reasonable determination and document the likelihood that the threat will exploit the identified vulnerabilities; and assign a risk level to the identified threat and vulnerability.</P>
                    <HD SOURCE="HD3">2. Artificial Intelligence (AI)</HD>
                    <P>
                        Section 238(g) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 defined AI to include the following: 
                        <SU>892</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>892</SU>
                             Sec. 238(g) of Public Law 115-232, 132 Stat. 1697-98 (Aug. 13, 2018) (10 U.S.C. 2358 note) (definition of “AI”).
                        </P>
                    </FTNT>
                    <P>• Any artificial system that performs tasks under varying and unpredictable circumstances without significant human oversight, or that can learn from experience and improve performance when exposed to data sets.</P>
                    <P>
                        • An artificial system developed in computer software, physical hardware, or other context that solves tasks requiring human-like perception, 
                        <PRTPAGE P="990"/>
                        cognition, planning, learning, communication, or physical action.
                    </P>
                    <P>• An artificial system designed to think or act like a human, including cognitive architectures and neural networks.</P>
                    <P>• A set of techniques, including machine learning, that is designed to approximate a cognitive task.</P>
                    <P>• An artificial system designed to act rationally, including an intelligent software agent or embodied robot that achieves goals using perception, planning, reasoning, learning, communicating, decision making, and acting.</P>
                    <P>
                        AI requires enormous amounts of data to develop, but it also has enormous potential benefits. The Department has previously stated that these “technologies have the potential to drive innovation, increase market competition, and vastly improve care for patients and populations.” 
                        <SU>893</SU>
                        <FTREF/>
                         According to experts, “[. . .]AI is unlocking new possibilities by advancing medicine in entirely unimaginable ways and solving some of the grand global healthcare challenges.” 
                        <SU>894</SU>
                        <FTREF/>
                         And FDA agrees: “AI technologies are transforming health care by producing diagnostic, therapeutic, and prognostic medical recommendations, or decisions, in some cases independently, informed by the vast amount of data generated during the delivery of health care.” 
                        <SU>895</SU>
                        <FTREF/>
                         In medical devices, areas for AI application include:
                    </P>
                    <FTNT>
                        <P>
                            <SU>893</SU>
                             Kathryn Marchesini, et al., “Getting the Best out of Algorithms in Health Care,” HealthITbuzz, Assistant Secretary for Technology Policy, U.S. Department of Health and Human Services (June 15, 2022), 
                            <E T="03">https://www.healthit.gov/buzz-blog/electronic-health-and-medical-records/getting-the-best-out-of-algorithms-in-health-care.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>894</SU>
                             
                            <E T="03">See</E>
                             Nazish Khalid, et al., “Privacy-preserving artificial intelligence in healthcare: Techniques and applications,” Computers in Biology and Medicine, Volume 158, p. 1 (May 2023), 
                            <E T="03">https://www.sciencedirect.com/science/article/pii/S001048252300313X?ref=pdf_download&amp;fr=RR-2&amp;rr=8a7dac430d6d07d5.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>895</SU>
                             
                            <E T="03">See</E>
                             “Artificial Intelligence Program: Research on AI/[Machine Learning] ML-Based Medical Devices,” U.S. Food &amp; Drug Administration, U.S. Department of Health and Human Services (June 10, 2024), 
                            <E T="03">https://www.fda.gov/medical-devices/medical-device-regulatory-science-research-programs-conducted-osel/artificial-intelligence-program-research-aiml-based-medical-devices.</E>
                        </P>
                    </FTNT>
                    <P>• Image acquisition and processing</P>
                    <P>• Early disease detection</P>
                    <P>• More accurate diagnosis, prognosis, and risk assessment</P>
                    <P>• Identification of new patterns in human physiology and disease progression</P>
                    <P>• Development of personalized diagnostics</P>
                    <P>
                        • Therapeutic treatment response monitoring 
                        <SU>896</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>896</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        For example, clinicians are using AI to distill large volumes of EHR information about a complex patient into a summarized note that they can use to consider diagnoses and treatment. AI also has been used for aid in the detection of diabetic retinopathy, screening for breast and lung cancer, and classification of skin conditions.
                        <SU>897</SU>
                        <FTREF/>
                         Others are using ambient AI scribes, a technology that uses microphones to transcribe encounters with patients in real-time.
                        <SU>898</SU>
                        <FTREF/>
                         This tool creates clinical documentation that clinicians can later edit, which can lead to improved interactions with patients and reduced time on documentation.
                        <SU>899</SU>
                        <FTREF/>
                         Newer AI tools may search medical records for relevant information regarding common conditions and other risk factors 
                        <SU>900</SU>
                        <FTREF/>
                         or offer relevant questions for clinicians to pose to make an accurate diagnosis.
                        <SU>901</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>897</SU>
                             
                            <E T="03">See</E>
                             Michael D. Howell, et al., “Three Epochs of Artificial Intelligence in Health Care,” Journal of the American Medical Association, Volume 331, Number 3 (Jan. 16, 2024), 
                            <E T="03">https://jamanetwork.com/journals/jama/fullarticle/2813874.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>898</SU>
                             
                            <E T="03">See</E>
                             Aaron A. Tierney, et al., “Ambient Artificial Intelligence Scribes to Alleviate the Burden of Clinical Documentation,” New England Journal of Medicine Catalyst (Feb. 21, 2024), 
                            <E T="03">https://catalyst.nejm.org/doi/full/10.1056/CAT.23.0404.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>899</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>900</SU>
                             Julia Adler-Milstein, et al., “Next-Generation Artificial Intelligence for Diagnosis: From Predicting Diagnostic Labels to `Wayfinding,'” Journal of the American Medical Association (Dec. 9, 2021), 
                            <E T="03">https://jamanetwork-com.hhsnih.idm.oclc.org/journals/jama/fullarticle/2787207.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>901</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Unfortunately, AI can also be used to harm individuals, both intentionally and unintentionally. Bad actors are using generative AI to threaten the privacy and security of ePHI more effectively through phishing and other social engineering. As explained by NCVHS, “AI tools can create mass scale [cyberattacks] that are highly effective and major threats to ePHI.” 
                        <SU>902</SU>
                        <FTREF/>
                         Experts anticipate that AI “will ultimately pioneer the malicious use of [. . .] ‘Offensive AI’—highly sophisticated and malicious attack code—[that] will be able to mutate itself as it learns about its environment, and to expertly compromise systems with minimal chance of detection.” 
                        <SU>903</SU>
                        <FTREF/>
                         Such experts are concerned about the level of destruction that will lie in its wake and compare it to an arms race that can only escalate.
                        <SU>904</SU>
                        <FTREF/>
                         Indeed, it seems likely that regulated entities will need to invest in AI to defend against malicious use of AI in the future.
                        <SU>905</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>902</SU>
                             
                            <E T="03">See</E>
                             Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, Appendix p. 8 (providing NCVHS recommendations to strengthen the HIPAA Security Rule); s
                            <E T="03">ee also</E>
                             William Dixon, et al., “3 ways AI will change the nature of cyber attacks,” World Economic Forum (June 19, 2019), 
                            <E T="03">https://www.weforum.org/agenda/2019/06/ai-is-powering-a-new-generation-of-cyberattack-its-also-our-best-defence/.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>903</SU>
                             “3 ways AI will change the nature of cyber attacks,” 
                            <E T="03">supra</E>
                             note 902.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>904</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>905</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        After assessing current and potential AI threats, NCVHS recommended that the Department clarify how the HIPAA Rules apply to AI.
                        <SU>906</SU>
                        <FTREF/>
                         We agree with their assessment and recommendation. Specifically, ePHI, including ePHI in AI training data, prediction models, and algorithm data that is maintained by a regulated entity for covered functions is protected by the HIPAA Rules and all applicable standards and specifications.
                        <SU>907</SU>
                        <FTREF/>
                         For example, generative AI tools have produced in their output the names and personal information of persons included in the tools' sources of training data.
                        <SU>908</SU>
                        <FTREF/>
                         Similar uses of generative AI by regulated entities, including the training of AI models on patient data, could result in impermissible uses and disclosures, including exposure to bad actors that can exploit the information.
                        <SU>909</SU>
                        <FTREF/>
                         As part of its risk analysis and risk management activities, a regulated entity must consider the risk associated with different uses and data.
                        <SU>910</SU>
                        <FTREF/>
                         Accordingly, we expect that a regulated entity interested in using AI would include the use of such tools in its risk analyses and associated risk management activities. The regulated entity's risk analysis must include consideration of, among other things, the type and amount of ePHI accessed by the AI tool, to whom the data is disclosed, and to whom the output is provided. The NIST AI Risk Management Framework is a helpful resource for regulated entities to better 
                        <PRTPAGE P="991"/>
                        understand, measure, and manage risks, effects, and harms of AI.
                        <SU>911</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>906</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>907</SU>
                             Where a regulated entity is maintaining ePHI for research purposes as described by 45 CFR 164.512(i), the regulated entity is not performing a covered function.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>908</SU>
                             
                            <E T="03">See</E>
                             Jordan Pearson, “ChatGPT Can Reveal Personal Information From Real People, Google Researchers Show,” Vice (Nov. 29, 2023), 
                            <E T="03">https://www.vice.com/en/article/chatgpt-can-reveal-personal-information-from-real-people-google-researchers-show/; see also</E>
                             Bridget McArthur, “AI chatbot blamed for psychosocial workplace training gaffe at Bunbury prison,” ABC Southwest (Aug. 20, 2024), 
                            <E T="03">https://www.abc.net.au/news/2024-08-21/ai-chatbot-psychosocial-training-bunbury-regional-prison/104230980.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>909</SU>
                             
                            <E T="03">See</E>
                             Nick Easen, “Why generative AI presents a fundamental security risk,” Raconteur (Sept. 9, 2024), 
                            <E T="03">https://www.raconteur.net/technology/why-generative-ai-presents-a-fundamental-security-threat.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>910</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.308(a)(1)(ii)(A) and (B); proposed 45 CFR 164.308(a)(2)(i) and (a)(5)(i).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>911</SU>
                             “Artificial Intelligence Risk Management Framework, (AI RMF 1.0),” NIST AI 100-1, National Institute of Standards and Technology, U.S. Department of Commerce (Jan. 2023), 
                            <E T="03">https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf; see also</E>
                             “Joint Guidance on Deploying AI System Securely,” Cybersecurity &amp; Infrastructure Security Agency, U.S. Department of Homeland Security (Apr. 15, 2024), 
                            <E T="03">https://www.cisa.gov/news-events/alerts/2024/04/15/joint-guidance-deploying-ai-systems-securely.</E>
                        </P>
                    </FTNT>
                    <P>
                        The Security Rule requires a regulated entity to conduct repeated risk analyses that consider any changes to its environment or operations, such as updates or changes in technology or clinical administration, and to apply all reasonable updated protections to safeguard ePHI.
                        <SU>912</SU>
                        <FTREF/>
                         Accordingly, as technology such as AI evolves, the Department would expect a regulated entity to perform a risk analysis to consider the effects of such changes on the confidentiality, integrity, and availability of ePHI. As NCVHS observed, “[I]t is important to conduct risk analyses on AI throughout the life cycle of the system.” 
                        <SU>913</SU>
                        <FTREF/>
                         We believe the proposals in this NPRM would clarify our expectations for when and how regulated entities need to consider, prepare for, and address such changes. For example, the Department proposes to expressly require that a regulated entity develop a written inventory of its technology assets. Under this proposal, the Department would expect that AI software used to create, receive, maintain, or transmit ePHI or that interacts with ePHI, including where ePHI is used to train the AI software, would be listed as part of its technology asset inventory, which feeds into the regulated entity's risk analysis. Making AI safe and secure with respect to ePHI requires efforts in a variety of areas—biotechnology, cybersecurity, critical infrastructure—to address risks.
                        <SU>914</SU>
                        <FTREF/>
                         The Federal Government seeks to ensure that the collection, use, and retention of ePHI is lawful and secure, and that it mitigates privacy and confidentiality risks. Across the administration, Federal agencies are considering potential uses for AI, as well as their benefits and risks, consistent with E.O. 11410 and its principles to advance and govern the development and use of AI.
                        <SU>915</SU>
                        <FTREF/>
                         These principles include making AI safe and secure and protecting privacy and civil liberties. For example, the Department finalized regulations earlier this year that improve transparency by health IT developers of certified health IT, including those that are business associates, that supply a particular type of AI—predictive decision support interventions (DSIs).
                        <SU>916</SU>
                        <FTREF/>
                         Specifically, the regulations require such health IT developers to provide greater transparency about the design, development, training, evaluation, and use of such predictive DSIs.
                        <SU>917</SU>
                        <FTREF/>
                         This approach promotes responsible AI and makes it possible for covered entities to access a consistent, baseline set of information about the algorithms they use to support their decision making and to assess such algorithms for fairness, appropriateness, validity, effectiveness, and safety.
                        <SU>918</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>912</SU>
                             45 CFR 164.508.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>913</SU>
                             
                            <E T="03">See</E>
                             Letter from NCVHS Chair Jacki Monson (2023), 
                            <E T="03">supra</E>
                             note 123, Appendix p. 8.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>914</SU>
                             88 FR 75191 (Nov. 1, 2023).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>915</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>916</SU>
                             89 FR 1192 (Jan. 9, 2024).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>917</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>918</SU>
                             “Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing,” HTI-1 final rule, The Office of the National Coordinator for Health IT, U.S. Department of Health and Human Services (Mar. 7, 2024), 
                            <E T="03">https://www.healthit.gov/topic/laws-regulation-and-policy/health-data-technology-and-interoperability-certification-program#:~:text=ONC%27s%20HTI%2D1%20final%20rule,implementation%20specifications%2C%20and%20certification%20criteria.</E>
                        </P>
                    </FTNT>
                    <P>Additionally, the Department proposes to require that regulated entities monitor authoritative sources for known vulnerabilities and to remediate such vulnerabilities in accordance with their patch management program. We also propose to require that patches, updates, and upgrades that address critical and high risks be applied promptly. Together, these proposals would support the rapid response to vulnerabilities that will be necessary as AI becomes more prevalent. Thus, the Department believes that the adoption of the cybersecurity best practices proposed in this NPRM is an important first step to ensuring that AI tools are deployed by regulated entities in a manner that protects the confidentiality, integrity, and availability of ePHI.</P>
                    <HD SOURCE="HD3">3. Virtual and Augmented Reality (VR and AR)</HD>
                    <P>
                        Research on VR and AR technologies is widespread and has produced numerous applications in the health care fields. Such technologies are being used in medical education and patient care, including AR-assisted surgeries, VR-based pain management therapies, and immersive patient education tools.
                        <SU>919</SU>
                        <FTREF/>
                         Additionally, innovators are working on ways to incorporate AI with VR and AR for improved diagnostics and treatment planning.
                        <SU>920</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>919</SU>
                             
                            <E T="03">See</E>
                             Tarun Kumar Vashishth, et al., “Virtual Reality (VR) and Augmented Reality (AR) Transforming Medical Applications” (Oct. 2023), 
                            <E T="03">https://www.researchgate.net/publication/374814301_Virtual_Reality_VR_and_Augmented_Reality_AR_Transforming_Medical_Applications.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>920</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        However, as with quantum computing and AI, VR and AR technologies raise new privacy and security concerns. VR and AR involve the use of diverse technologies and the collection of a wide array of sensitive information, including comprehensive biometric data.
                        <SU>921</SU>
                        <FTREF/>
                         According to experts, “[. . .] VR and AR present distinct security challenges, encompassing typical vulnerabilities associated with electronic devices, as well as potential risks of physical harm and leakage of highly sensitive data.” 
                        <SU>922</SU>
                        <FTREF/>
                         VR, like any connected computing device, “is susceptible to standard cybersecurity concerns and various types of cyberthreats, necessitating proactive anticipation.” 
                        <SU>923</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>921</SU>
                             
                            <E T="03">See</E>
                             Evangelia Manika, et al., “AR and VR devices in the healthcare business: legal and ethical challenges,” International Bar Association (July 6, 2023), 
                            <E T="03">https://www.ibanet.org/AR-VR-devices-in-the-healthcare-business; see also</E>
                             Sajin Somarajan, “Minimizing AR/VR Security And Privacy Risks,” Infosys Digital Experience (accessed July 23, 2024), 
                            <E T="03">https://blogs.infosys.com/digital-experience/mobility/minimizing-ar-vr-security-and-privacy-risks.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>922</SU>
                             
                            <E T="03">See</E>
                             “AR and VR devices in the healthcare business: legal and ethical challenges,” 
                            <E T="03">supra</E>
                             note 921; 
                            <E T="03">see also</E>
                             “Minimizing AR/VR Security And Privacy Risks,” 
                            <E T="03">supra</E>
                             note 921.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>923</SU>
                             
                            <E T="03">See</E>
                             “AR and VR devices in the healthcare business: legal and ethical challenges,” 
                            <E T="03">supra</E>
                             note 921; 
                            <E T="03">see also</E>
                             “Minimizing AR/VR Security And Privacy Risks,” 
                            <E T="03">supra</E>
                             note 921.
                        </P>
                    </FTNT>
                    <P>
                        These cybersecurity risks, such as hacking, social engineering, malicious software, and ransomware, can be mitigated through holistic risk analysis and risk management, consistent with the Security Rule administrative standards in 45 CFR 164.308. In addition, patch management,
                        <SU>924</SU>
                        <FTREF/>
                         access control,
                        <SU>925</SU>
                        <FTREF/>
                         authentication,
                        <SU>926</SU>
                        <FTREF/>
                         and appropriate business associate agreements 
                        <SU>927</SU>
                        <FTREF/>
                         are examples of some of the required safeguards that would apply to VR and AR systems.
                    </P>
                    <FTNT>
                        <P>
                            <SU>924</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.308(a)(4)(i).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>925</SU>
                             45 CFR 164.312(a)(1).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>926</SU>
                             45 CFR 164.312(d); 
                            <E T="03">see</E>
                             proposed 45 CFR 164.308(a)(10)(ii)(C) and 164.312(f)(1).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>927</SU>
                             45 CFR 164.308(b) and 164.314(a).
                        </P>
                    </FTNT>
                    <P>
                        We believe the proposals in this NPRM to clarify these safeguards would substantially improve the ability of regulated entities to address these cybersecurity risks. For example, the Department proposes to require that a regulated entity obtains from a business associate written verification that the business associate has deployed the technical safeguards required by the Security Rule, including a written analysis of the business associate's information systems from a person with 
                        <PRTPAGE P="992"/>
                        appropriate knowledge of and experience with generally accepted cybersecurity principles and methods for ensuring the confidentiality, integrity, and availability of ePHI verifying compliance with the requirements of 45 CFR 164.312 and a written certification that the analysis has been performed and is accurate. Under this proposal, a regulated entity would be required to obtain such verification from a business associate-developer of VR/AR software, ensuring that ePHI that is created, received, maintained, or transmitted using the VR/AR software is protected to the same extent as ePHI that is created, received, maintained, or transmitted using other technology assets that are components of the regulated entity's relevant electronic information systems.
                    </P>
                    <P>
                        Many regulated entities are piloting innovative technologies. Such entities generally have separate departments that research, develop, test, and deploy such technologies.
                        <SU>928</SU>
                        <FTREF/>
                         Regulated entities might consider integrating workforce members with expertise in security and privacy into their technology development groups to ensure that privacy and security, including the Security Rule-required safeguards, are embedded into the design of new and emerging technologies.
                        <SU>929</SU>
                        <FTREF/>
                         Doing so can help improve security “while boosting quality, efficiency, and productivity.” 
                        <SU>930</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>928</SU>
                             
                            <E T="03">See</E>
                             Raj Mehta, et al., “The future of cyber in the future of health. The evolving role of cybersecurity in health care,” Deloitte (2020), 
                            <E T="03">https://www2.deloitte.com/us/en/pages/advisory/articles/future-of-cybersecurity-healthcare.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>929</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>930</SU>
                             
                            <E T="03">Id.</E>
                             regarding “DevSecOps.”
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">4. Request for Comment</HD>
                    <P>The Department requests comment on the foregoing discussion of how the Security Rule protects ePHI used in new and developing technologies, including any benefits, drawbacks, or unintended consequences. We also request comment on the following considerations in particular:</P>
                    <P>a. Whether the Department's understanding of how the Security Rule applies to new technologies involving ePHI is not comprehensive and if so, what issues should also be considered.</P>
                    <P>b. Whether there are technologies that currently or in the future may harm the security and privacy of ePHI in ways that the Security Rule could not mitigate without modification, and if so, what modifications would be required.</P>
                    <P>c. Whether there are additional policy or technical tools that the Department may use to address the security of ePHI in new technologies.</P>
                    <HD SOURCE="HD1">V. Regulatory Impact Analysis</HD>
                    <HD SOURCE="HD2">A. Executive Order 12866 and Related Executive Orders on Regulatory Review</HD>
                    <P>
                        The Department of Health and Human Services (HHS or “Department”) has examined the effects of this proposed rule under Executive Order (E.O.) 12866, Regulatory Planning and Review,
                        <SU>931</SU>
                        <FTREF/>
                         E.O. 13563, Improving Regulation and Regulatory Review,
                        <SU>932</SU>
                        <FTREF/>
                         E.O. 14094, Modernizing Regulatory Review,
                        <SU>933</SU>
                        <FTREF/>
                         the Regulatory Flexibility Act 
                        <SU>934</SU>
                        <FTREF/>
                         (RFA), the Unfunded Mandates Reform Act of 1995 
                        <SU>935</SU>
                        <FTREF/>
                         (UMRA), and E.O. 13132 on Federalism.
                        <SU>936</SU>
                        <FTREF/>
                         E.O.s 12866 and 13563 direct the Department to assess all costs and benefits of available regulatory alternatives and, when regulation is necessary, to select regulatory approaches that maximize net benefits (including potential economic, environmental, public health and safety, and other advantages; distributive effects; and equity). The proposed rule meets the criteria as significant under section 3(f)(1) of E.O. 12866, as amended by E.O. 14094.
                    </P>
                    <FTNT>
                        <P>
                            <SU>931</SU>
                             58 FR 51735 (Oct. 4, 1993).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>932</SU>
                             76 FR 3821 (Jan. 21, 2011).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>933</SU>
                             88 FR 21879 (Apr. 11, 2023).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>934</SU>
                             Public Law 96-354, 94 Stat. 1164 (Sept. 19, 1980) (codified at 5 U.S.C. 601-612).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>935</SU>
                             Public Law 104-4, 109 Stat. 48 (Mar. 22, 1995) (codified at 2 U.S.C. 1501).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>936</SU>
                             64 FR 43255 (Aug. 4, 1999).
                        </P>
                    </FTNT>
                    <P>The RFA requires us to analyze regulatory options that would minimize any significant effect of a rule on small entities. As discussed in greater detail below, this analysis concludes, and the Secretary certifies, that the notice of proposed rulemaking (NPRM), if adopted, would not result in a significant economic effect on a substantial number of small entities.</P>
                    <P>
                        The UMRA (section 202(a)) generally requires us to prepare a written statement, which includes an assessment of anticipated costs and benefits, before proposing “any rule that includes any Federal mandate that may result in the expenditure by State, local, and Tribal governments, in the aggregate, or by the private sector, of $100,000,000 or more (adjusted annually for inflation) in any 1 year.” 
                        <SU>937</SU>
                        <FTREF/>
                         The current threshold after adjustment for inflation is $183 million, using the most current (2024) Implicit Price Deflator for the Gross Domestic Product. UMRA does not address the total cost of a rule. Rather, it addresses certain categories of cost, mainly Federal mandate costs resulting from imposing enforceable duties on State, local, or Tribal governments or the private sector; or increasing the stringency of conditions in, or decreasing the funding of, State, local, or Tribal governments under entitlement programs.
                    </P>
                    <FTNT>
                        <P>
                            <SU>937</SU>
                             Sec. 202 of Public Law 104-4, 109 Stat. 64 (Mar. 22, 1995) (codified at 2 U.S.C. 1532(a)).
                        </P>
                    </FTNT>
                    <P>
                        This proposed rule, if adopted, would impose mandates that would result in the expenditure by State, local, and Tribal governments, in the aggregate, or by the private sector, of more than $183 million in any one year. The impact analysis in this proposed rule addresses such effects both qualitatively and quantitatively. Each covered entity and business associate (collectively, “regulated entity”), including government entities that meet the definition of covered entity (
                        <E T="03">e.g.,</E>
                         State Medicaid agencies), would be required to: conduct a Security Rule compliance audit; report to covered entities or business associates, as applicable, upon activation of their contingency plan; deploy multi-factor authentication (MFA) in and penetration testing of relevant electronic information systems; complete network segmentation; disable unused ports and remove extraneous software; update cybersecurity policies and procedures; revise business associate agreements; and update workforce training. Business associates would be required to conduct an analysis and provide verification of their compliance with technical safeguards and covered entities would be required to obtain verification from business associates (and business associates from their subcontractors). Additionally, group health plans would need to revise plan documents to require plan sponsors to comply with administrative, physical, and technical safeguards according to the Security Rule standards. Finally, through contractual language, health plan sponsors would need to enhance safeguards for electronic protected health information (ePHI) according to the Security Rule standards. Costs for all regulated entities to change their policies and procedures alone would increase costs above the UMRA threshold in one year, and costs of health plan sponsors would increase total costs further. Although Medicaid makes Federal matching funds available for States for certain administrative costs, these are limited to costs specific to operating the Medicaid program. There are no Federal funds directed at Health Insurance Portability and Accountability Act of 1996 (HIPAA) compliance activities.
                    </P>
                    <P>
                        The Department believes that pursuant to Subtitle E of the Small Business Regulatory Enforcement 
                        <PRTPAGE P="993"/>
                        Fairness Act of 1996,
                        <SU>938</SU>
                        <FTREF/>
                         the Office of Management and Budget's (OMB's) Office of Information and Regulatory Affairs would be likely to determine that when finalized, this rule meets the criteria set forth in 5 U.S.C. 804(2) because it is projected to have an annualized effect on the economy of more than $100,000,000.
                    </P>
                    <FTNT>
                        <P>
                            <SU>938</SU>
                             Also referred to as the Congressional Review Act, 5 U.S.C. 801 
                            <E T="03">et seq.</E>
                        </P>
                    </FTNT>
                    <P>The Justification for this Rulemaking and Summary of Proposed Rule Provisions section at the beginning of this preamble contain a summary of this rule and describe the reasons it is needed. We present a detailed analysis below.</P>
                    <HD SOURCE="HD3">1. Summary of Costs and Benefits</HD>
                    <P>
                        The Department identified ten categories of quantifiable costs arising from these proposals that would apply to all regulated entities: (1) conducting a Security Rule compliance audit; (2) obtaining written verification from their business associates or subcontractors that the business associates or subcontractors, respectively, have conducted the required verification of compliance with technical safeguards; (3) notifying other regulated entities when workforce members' access to ePHI is terminated; (4) completing network segmentation; (5) disabling ports and removing extraneous software; (6) deploying MFA; (7) deploying penetration testing; (8) updating policies and procedures; (9) updating workforce training programs; and (10) revising business associate agreements. Additionally, group health plans would be required to update plan documents to require health plan sponsors' compliance with the administrative, physical, and technical safeguards according to the Security Rule and notification of group health plans when health plan sponsors activate their contingency plan. Business associates would have additional obligations to verify compliance with technical safeguards and provide it in writing to covered entities (and subcontractors to business associates) and to notify covered entities upon activation of their contingency plans. Finally, although plan sponsors are not directly subject to the HIPAA Rules, by virtue of the plan document requirements, the Department estimates that certain group health plan sponsors (
                        <E T="03">e.g.,</E>
                         employers that provide group health benefits) would likely incur some quantifiable costs to improve safeguards for their electronic information systems that affect the confidentiality, integrity, or availability of ePHI and to notify group health plans upon activation of plan sponsors' contingency plan.
                    </P>
                    <P>The Department estimates that the first-year costs attributable to this proposed rule total approximately $9 billion. These costs are associated with regulated entities and health plan sponsors engaging in the regulatory actions described above. For years two through five, estimated annual costs of approximately $6 billion are attributable to costs of recurring compliance activities. Table 1 reports the present value and annualized estimates of the costs of this proposed rule covering a 5-year time horizon. Using a 2 percent discount rate, the Department estimates that this proposed rule would result in annualized costs of $6.8 billion for regulated entities and health plan sponsors combined.</P>
                    <GPOTABLE COLS="5" OPTS="L2,i1" CDEF="s50,12,12,r50,12">
                        <TTITLE>
                            Table 1—Accounting Table, Costs of the Proposed Rule, $ Billions 
                            <E T="01">
                                <SU>a</SU>
                            </E>
                        </TTITLE>
                        <BOXHD>
                            <CHED H="1">Costs</CHED>
                            <CHED H="1">
                                Primary 
                                <LI>estimate</LI>
                            </CHED>
                            <CHED H="1">Year dollars</CHED>
                            <CHED H="1">Discount rate</CHED>
                            <CHED H="1">
                                Period 
                                <LI>covered</LI>
                            </CHED>
                        </BOXHD>
                        <ROW>
                            <ENT I="01">Present Value</ENT>
                            <ENT>$34</ENT>
                            <ENT>2023</ENT>
                            <ENT>Undiscounted</ENT>
                            <ENT>2026-2030</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Present Value</ENT>
                            <ENT>32</ENT>
                            <ENT>2023</ENT>
                            <ENT>2%</ENT>
                            <ENT>2026-2030</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Annualized</ENT>
                            <ENT>7</ENT>
                            <ENT>2023</ENT>
                            <ENT>2%</ENT>
                            <ENT>2026-2030</ENT>
                        </ROW>
                        <TNOTE>
                            <SU>a</SU>
                             Figures are rounded.
                        </TNOTE>
                    </GPOTABLE>
                    <P>As a result of the proposed changes in this NPRM, the enhanced security posture of regulated entities would likely reduce the number of breaches of ePHI and mitigate the effects of breaches that nonetheless occur. The Department has partially quantified these effects and presents them in a break-even analysis. The break-even analysis estimates that if the proposed changes in the NPRM reduce the number of individuals affected by breaches by 7 to 16 percent, the revised Security Rule would pay for itself. Alternatively, the same cost savings may be achieved by lowering the cost per affected individual's ePHI by 7 percent ($35) to 16 percent ($82), respectively.</P>
                    <P>The changes to the Security Rule would likely result in important benefits and some costs that the Department is unable to fully quantify at this time. As explained further below, unquantified benefits include reductions in reputational, financial, and legal harm from breaches of individuals' ePHI, reductions in disruptions to health care delivery, increased confidence among parties to health care business transactions, and improved quality of health care.</P>
                    <GPOTABLE COLS="1" OPTS="L2,i1" CDEF="s200">
                        <TTITLE>Table 2—Potential Non-Quantified Benefits</TTITLE>
                        <BOXHD>
                            <CHED H="1">
                                Benefits 
                                <SU>a</SU>
                            </CHED>
                        </BOXHD>
                        <ROW>
                            <ENT I="01">Would benefit individuals by shielding them from unwanted disclosure of their ePHI and resulting reputational, financial, and legal harms from ePHI misuse.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Would reduce reputational damage to regulated entities resulting from breaches.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Would increase confidence among parties to health care business transactions that ePHI is protected to a higher degree than previously.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Would reduce risk of breaches of ePHI by health plan sponsors.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Would help to prevent health care cost increases to recoup financial losses from responding to breaches.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Would help guard against potential data loss.</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Would help minimize potential disruption of service for individuals served by any of the affected entities.</ENT>
                        </ROW>
                        <TNOTE>
                            <SU>a</SU>
                             Some of the items in this list represent differing perspectives on the same effect. In such cases, if more thorough quantification became feasible, we would take steps to avoid double-counting when summing the quantitative estimates.
                        </TNOTE>
                    </GPOTABLE>
                    <PRTPAGE P="994"/>
                    <P>The Department also recognizes that there may be some costs that are not readily quantifiable, notably, actions that regulated entities may take to comply with existing requirements more fully as a result of proposed clarifications. For example, this would include completing a technology asset inventory, which is a baseline expectation for the existing requirement of conducting a risk assessment; documenting completion of existing requirements; adding more specificity to the required contingency plan, such as designating staff roles with specific responsibilities when a contingency occurs; testing safeguards as part of reviewing and updating policies and procedures and technical controls; and deploying encryption for ePHI in a more concerted manner (including documenting provision of notification in response to individuals' access requests for transmission of ePHI in an unencrypted manner and has been informed of the risks associated with the transmission, receipt, and storage of unencrypted ePHI). These activities are specified in the NPRM, but they would be more in the nature of clarifications to and increased specificity of existing requirements. Because the degree of additional effort by regulated entities to meet these requirements would be dependent on multiple factors and likely to be highly variable, the additional cost is difficult to quantify.</P>
                    <P>We acknowledge that there may be a small burden associated with documenting that an individual was informed of the risks of unencrypted transmission of ePHI; however, we believe there are few requests that fall into this category. Because we do not have a basis to make an estimate, we have requested data on potential burdens associated with this proposed exception to the proposed standard for encryption in the preamble discussion of 45 CFR 164.312.</P>
                    <P>
                        The cost of complying with the exceptions to encryption and MFA for medical devices authorized by the U.S. Food &amp; Drug Administration for marketing may depend in part on the extent to which a regulated entity relies on legacy devices because the regulated entity may be required to adopt compensating controls. New devices are likely to have encryption and MFA built into them, not requiring compensating controls. The Department is unable to estimate the range of costs to adopt compensating controls for legacy devices because there is no reliable data to accurately assess the extent to which legacy devices are used in the United States.
                        <SU>939</SU>
                        <FTREF/>
                         The Department requests comment on the number of legacy devices in use and the costs of applying compensating controls to such devices.
                    </P>
                    <FTNT>
                        <P>
                            <SU>939</SU>
                             “Next Steps Toward Managing Legacy Medical Device Cybersecurity Risks,” 
                            <E T="03">supra</E>
                             note 742, p. 6.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">2. Baseline Conditions</HD>
                    <P>The Security Rule, in conjunction with the Privacy and Breach Notification Rules, protects the privacy and security of individuals' PHI, that is, individually identifiable health information (IIHI). The Security Rule's protections are limited to ePHI, while the Privacy and Breach Notification Rules protect both electronic and non-electronic PHI. The Security Rule establishes standards to protect individuals' ePHI and requires reasonable and appropriate administrative, physical, and technical safeguards. The Security Rule specifies a series of administrative, physical, and technical security requirements that must be performed or implemented for regulated entities to safeguard ePHI. Specifically, entities regulated by the Security Rule must: (1) ensure the confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit; (2) protect against reasonably anticipated threats to the security and integrity of the information; (3) protect against reasonably anticipated impermissible uses or disclosures; and (4) ensure compliance by their workforce. A major goal of the Security Rule is protecting the security of individuals' health information while allowing for the development of a health information system to improve the efficiency and effectiveness of the health care system.</P>
                    <P>The Administrative Simplification provisions of HIPAA (title II) provide the Secretary of HHS with the authority to publish standards for the privacy and security of health information. The Department first proposed standards for the security of ePHI on August 12, 1998, and published a final rule on February 20, 2003. The Department modified the Security Rule in 2013. Recently, as the preamble to this NPRM discusses, changes in the health care environment and insufficient compliance by regulated entities with the existing Security Rule require the modifications proposed here.</P>
                    <P>
                        For purposes of this Regulatory Impact Analysis (RIA), the proposed rule adopts the list of covered entities (with an updated count) and certain cost assumptions identified in the Department's Information Collection Request (ICR) associated with the HIPAA Privacy Rule to Support Reproductive Health Care Privacy (“2024 ICR”).
                        <SU>940</SU>
                        <FTREF/>
                         The Department also relies on certain estimates and assumptions from the 1998 Proposed Rule 
                        <SU>941</SU>
                        <FTREF/>
                         that remain relevant, the 2003 Final Rule,
                        <SU>942</SU>
                        <FTREF/>
                         and the 2013 Omnibus Rule,
                        <SU>943</SU>
                        <FTREF/>
                         as referenced in the analysis that follows.
                    </P>
                    <FTNT>
                        <P>
                            <SU>940</SU>
                             “View ICR,” Office of Information and Regulatory Affairs, Office of Management and Budget (July 9, 2024), 
                            <E T="03">https://www.reginfo.gov/public/do/PRAViewICR?ref_nbr=202401-0945-002.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>941</SU>
                             63 FR 43242 (Aug. 12, 1998).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>942</SU>
                             68 FR 8334 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>943</SU>
                             78 FR 5566 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <P>The Department quantitatively analyzes and monetizes the effect that this proposed rule would have on the actions of regulated entities to: conduct a Security Rule compliance audit; provide or obtain verification of business associates' compliance with technical safeguards; notify other regulated entities when workforce members' access to ePHI is altered or terminated; notify covered entities or business associates, as applicable, upon activation of a contingency plan; complete network segmentation; disable unused ports and remove extraneous software; deploy MFA and penetration testing; update health plan documents; update policies and procedures; update workforce training; and revise business associate agreements. The Department also quantitatively analyzes the effects on group health plan sponsors for ensuring that safeguards for their relevant electronic information systems meet Security Rule standards and notifying group health plans upon activation of the plan sponsors' contingency plans.</P>
                    <P>Additionally, the Department quantitatively analyzes the benefits of the proposed modifications to regulated entities due to an expected reduction in costs of remediation of breaches and risk of breaches by regulated entities.</P>
                    <P>The Department analyzes the remaining benefits and costs qualitatively because many of the proposed modifications are clarifications of existing requirements and predicting other concrete actions that such a diverse scope of regulated entities might take in response to this rule is inherently uncertain.</P>
                    <HD SOURCE="HD3">Analytic Assumptions</HD>
                    <P>
                        The Department bases its assumptions for calculating estimated costs and benefits on several publicly available datasets, including data from the U.S. Census Bureau (“Census”), the U.S. Department of Labor's (DOL) Bureau of Labor Statistics, the Small Business Administration (SBA), and the Department's Centers for Medicare &amp; 
                        <PRTPAGE P="995"/>
                        Medicaid Services (CMS) and Agency for Healthcare Research and Quality (AHRQ). For the purposes of this analysis, the Department assumes that employee benefits plus indirect costs equal approximately 100 percent of pre-tax wages and adjusts the hourly wage rates by multiplying by two, for a fully loaded hourly wage rate. The Department adopts this as the estimate of the hourly value of time for changes in time use for on-the-job activities.
                    </P>
                    <P>
                        Implementing the proposals likely would require regulated entities to engage workforce members or consultants for certain activities. The Department assumes that an information security analyst would perform most of the activities proposed in the NPRM, consistent with the existing Security Rule requirements. The Department expects that a computer and information systems manager would revise policies and procedures, a training and development specialist would revise the necessary workforce training, a lawyer would revise business associate agreements, and a compensation and benefits manager would revise health plan documents for plan sponsors. To the extent that these assumptions affect the Department's estimate of costs, the Department solicits comment on its assumptions, particularly assumptions in which the Department identifies the level of workforce member (
                        <E T="03">e.g.,</E>
                         analyst, manager, licensed professional) that would be engaged in activities and the amount of time that particular types of workforce members spend conducting activities related to this RIA as further described below. Table 3 lists pay rates for occupations referenced in the cost estimates for the NPRM.
                    </P>
                    <GPOTABLE COLS="3" OPTS="L2,i1" CDEF="s100,12,12">
                        <TTITLE>
                            Table 3—Occupational Pay Rates 
                            <SU>944</SU>
                        </TTITLE>
                        <BOXHD>
                            <CHED H="1">Occupation code and title</CHED>
                            <CHED H="1">
                                Fully loaded
                                <LI>hourly wage</LI>
                            </CHED>
                            <CHED H="1">
                                2023 Average
                                <LI>hourly wage</LI>
                            </CHED>
                        </BOXHD>
                        <ROW>
                            <ENT I="01">15-1212 Information Security Analysts</ENT>
                            <ENT>$119.94</ENT>
                            <ENT>$59.97</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">13-1151 Training and Development Specialists</ENT>
                            <ENT>69.20</ENT>
                            <ENT>34.60</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">11-3111 Compensation and Benefits Manager</ENT>
                            <ENT>145.14</ENT>
                            <ENT>72.57</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">11-3021 Computer and Information Systems Managers</ENT>
                            <ENT>173.76</ENT>
                            <ENT>86.88</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">23-1011 Lawyers</ENT>
                            <ENT>169.68</ENT>
                            <ENT>84.84</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">13-1111 Management Analysts</ENT>
                            <ENT>111.08</ENT>
                            <ENT>55.54</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">43-0000 Office and Administrative Support Occupations</ENT>
                            <ENT>46.10</ENT>
                            <ENT>23.05</ENT>
                        </ROW>
                    </GPOTABLE>
                    <P>
                        The Department
                        <FTREF/>
                         assumes that most regulated entities would be able to incorporate changes to their workforce training into existing cybersecurity awareness training programs and Security Rule training rather than conduct a separate training because the total time frame for compliance from date of publication of a final rule would be 240 days.
                        <SU>945</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>944</SU>
                             
                            <E T="03">See</E>
                             “Occupational employment and wages—May 2023,” U.S. Department of Labor, Bureau of Labor Statistics, Table 1. National employment and wage data from the Occupational Employment and Wage Statistics survey by occupation (Apr. 3, 2024), 
                            <E T="03">https://www.bls.gov/news.release/pdf/ocwage.pdf.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>945</SU>
                             This includes 60 days from publication of a final rule to the effective date and an additional 180 days until the compliance date.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">Regulated Entities Affected</HD>
                    <P>
                        The changes proposed in this NPRM would apply to covered entities (
                        <E T="03">i.e.,</E>
                         health care providers that conduct covered electronic transactions, health plans, and health care clearinghouses) and their business associates (including subcontractors). The Department estimates the number of covered entities to be 822,600 business establishments (see table 4). By calculating costs for establishments, rather than firms,
                        <SU>946</SU>
                        <FTREF/>
                         some burdens may be overestimated because certain costs would be borne by a parent organization rather than each separate facility. Similarly, benefits and transfers would be overestimated because entity assumptions flow through to those quantifications. However, decisions about the level of an organization that is responsible for implementing certain requirements likely varies across the health care industry. The Department requests data on the extent to which certain burdens are borne by each facility versus an umbrella organization.
                    </P>
                    <FTNT>
                        <P>
                            <SU>946</SU>
                             A firm may be an umbrella organization that encompasses multiple establishments.
                        </P>
                    </FTNT>
                    <P>
                        According to Census data,
                        <SU>947</SU>
                        <FTREF/>
                         there are 954 Direct Health and Medical Insurance Carrier firms out of a total 5,822 Insurance Carrier firms, such that health and medical insurance firms make up approximately 16.4 percent of insurance firms [= 954/5,822].
                        <SU>948</SU>
                        <FTREF/>
                         Also, according to Census data, there are 2,506 Third Party Administration of Insurance and Pension Funds firms and 8,375 establishments. This category also includes clearinghouses. The Department assumes that 16.4 percent of these firms service health and medical insurance because that is equivalent to the share of insurance firms that are health and medical. As a result, the Department estimates that 411 firms categorized as Third Party Administrators are affected by the proposals in this NPRM [= 2,506 × .164]. Similarly, the Department estimates that 1,374 associated establishments would be affected by the proposals in this NPRM [= 8,375 total establishments × .164]. Most of these are business associates. Based on data from the Department's HIPAA audits and experience administering the HIPAA Rules, we are aware of approximately 36 clearinghouses. See table 4 below.
                    </P>
                    <FTNT>
                        <P>
                            <SU>947</SU>
                             “2021 [Statistics of U.S. Businesses] SUSB Annual Data Tables by Establishment Industry,” United States Census Bureau, U.S. &amp; States, 6-digit NAICS (Dec. 2023), 
                            <E T="03">https://www.census.gov/data/tables/2021/econ/susb/2021-susb-annual.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>948</SU>
                             This percentage was rounded.
                        </P>
                    </FTNT>
                    <P>
                        There were 56,289 community pharmacies, including 19,261 pharmacy and drug store firms, operating in the U.S. in 2023.
                        <SU>949</SU>
                        <FTREF/>
                         Small pharmacies generally use pharmacy services administration organizations (PSAOs) to provide administrative services, such as conducting negotiations. Based on information from industry, the Department estimates that the proposed rule would affect fewer than 10 PSAOs and we include this within the estimated 1 million business associates affected by the proposals in this NPRM.
                        <SU>950</SU>
                        <FTREF/>
                         The Department assumes that 
                        <PRTPAGE P="996"/>
                        costs affecting pharmacies are incurred at each pharmacy and drug store establishment and each PSAO.
                    </P>
                    <FTNT>
                        <P>
                            <SU>949</SU>
                             
                            <E T="03">See</E>
                             “2023 NCPA Digest, sponsored by Cardinal Health,” National Community Pharmacists Association, Table 5, p. 9 (2023), 
                            <E T="03">https://www.cardinalhealth.com/content/dam/corp/web/documents/Report/cardinal-health-2023-ncpa-digest.pdf; see also</E>
                             “2021 [Statistics of U.S. Businesses] SUSB Annual Data Tables by Establishment Industry,” 
                            <E T="03">supra</E>
                             note 947.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>950</SU>
                             
                            <E T="03">See</E>
                             Scott Pace, “The Role and Value of Pharmacy Services Administrative Organizations (PSAOs),” Impact Management Group, p. 3 (July 20, 2022), 
                            <E T="03">https://content.naic.org/sites/default/files/call_materials/The%20Role%20and%20Value%20of%20Pharmacy%20Services%20Administrative%20July%202022.pdf; see also</E>
                             “The Role of Pharmacy Services Administrative Organizations for Independent Retail and Small Chain Pharmacies,” Avalere Health, p. 4 (Sept. 30, 2021), 
                            <E T="03">
                                https://documents.ncsl.org/wwwncsl/
                                <PRTPAGE/>
                                Foundation/sponsor-views/The_Role_of_PSAOs_Independent_Pharmacies.pdf.
                            </E>
                        </P>
                    </FTNT>
                    <GPOTABLE COLS="5" OPTS="L2,i1" CDEF="s25,r50,12,14,15">
                        <TTITLE>Table 4—Estimated Number, Type, and Size Threshold of Covered Entities</TTITLE>
                        <BOXHD>
                            <CHED H="1">Covered Entities</CHED>
                            <CHED H="2">NAICS code</CHED>
                            <CHED H="2">Type of entity</CHED>
                            <CHED H="2">Firms</CHED>
                            <CHED H="2">Establishments</CHED>
                            <CHED H="2">
                                Small business
                                <LI>administration</LI>
                                <LI>(SBA)</LI>
                                <LI>
                                    size threshold 
                                    <SU>c</SU>
                                </LI>
                                <LI>(million)</LI>
                            </CHED>
                        </BOXHD>
                        <ROW>
                            <ENT I="01">524114</ENT>
                            <ENT>Health and Medical Insurance Carriers</ENT>
                            <ENT>954</ENT>
                            <ENT>5,552</ENT>
                            <ENT>$47</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">524292</ENT>
                            <ENT>
                                Clearinghouses 
                                <SU>a</SU>
                            </ENT>
                            <ENT>36</ENT>
                            <ENT>36</ENT>
                            <ENT>47</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">622</ENT>
                            <ENT>Hospitals</ENT>
                            <ENT>3,095</ENT>
                            <ENT>7,465</ENT>
                            <ENT>47 </ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">446110</ENT>
                            <ENT>
                                Pharmacies 
                                <SU>b</SU>
                            </ENT>
                            <ENT>31,671</ENT>
                            <ENT>56,289</ENT>
                            <ENT>37.5</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">6211-6213</ENT>
                            <ENT>Office of Drs. &amp; Other Professionals</ENT>
                            <ENT>429,476</ENT>
                            <ENT>527,951</ENT>
                            <ENT>9-16 </ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">6215</ENT>
                            <ENT>Medical Diagnostic Laboratories &amp; Imaging</ENT>
                            <ENT>8,714</ENT>
                            <ENT>19,477</ENT>
                            <ENT>19-41.5 </ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">6214</ENT>
                            <ENT>Outpatient Care</ENT>
                            <ENT>26,084</ENT>
                            <ENT>54,642</ENT>
                            <ENT>19-47 </ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">6219</ENT>
                            <ENT>Other Ambulatory Care</ENT>
                            <ENT>10,547</ENT>
                            <ENT>16,114</ENT>
                            <ENT>20.5-40</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">623</ENT>
                            <ENT>Skilled Nursing &amp; Residential Facilities</ENT>
                            <ENT>42,421</ENT>
                            <ENT>95,175</ENT>
                            <ENT>16-34 </ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">6216</ENT>
                            <ENT>Home Health Agencies</ENT>
                            <ENT>27,433</ENT>
                            <ENT>38,040</ENT>
                            <ENT>19 </ENT>
                        </ROW>
                        <ROW RUL="n,n,s">
                            <ENT I="01">532283</ENT>
                            <ENT>Home Health Equipment Rental</ENT>
                            <ENT>488</ENT>
                            <ENT>1,859</ENT>
                            <ENT>41</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="03">Total</ENT>
                            <ENT/>
                            <ENT>580,9198</ENT>
                            <ENT>822,600</ENT>
                            <ENT/>
                        </ROW>
                        <TNOTE>
                            <SU>a</SU>
                             This North American Industry Classification System (NAICS) category includes clearinghouses and is titled “Third Party Administration of Insurance and Pension Funds.” The number of clearinghouses is based on the Department's research.
                        </TNOTE>
                        <TNOTE>
                            <SU>b</SU>
                             Number of pharmacies is taken from industry statistics.
                        </TNOTE>
                        <TNOTE>
                            <SU>c</SU>
                             
                            <E T="03">See</E>
                             “Table of Small Business Size Standards,” U.S. Small Business Administration (Mar. 17, 2023), 
                            <E T="03">https://www.sba.gov/sites/sbagov/files/2023-06/Table%20of%20Size%20Standards_Effective%20March%2017%2C%202023%20%282%29.pdf.</E>
                             The SBA size thresholds are discussed in Section V.C. Regulatory Flexibility Act—Small Entity Analysis of this NPRM.
                        </TNOTE>
                    </GPOTABLE>
                    <P>
                        The Department also estimated the percentage of rural and urban health care providers by matching health care provider data from CMS,
                        <SU>951</SU>
                        <FTREF/>
                         Health Resources &amp; Services Administration,
                        <SU>952</SU>
                        <FTREF/>
                         and the Statistics of U.S. Businesses (SUSB) 
                        <SU>953</SU>
                        <FTREF/>
                         with county population data from the U.S. Census Bureau.
                        <SU>954</SU>
                        <FTREF/>
                         We determined whether a health care provider was rural or urban based on OMB's standards for delineating metropolitan and micropolitan statistical areas.
                        <SU>955</SU>
                        <FTREF/>
                         Consistent with OMB's standard, we considered a county to be rural if it has fewer than 50,000 inhabitants.
                        <SU>956</SU>
                        <FTREF/>
                         This includes micropolitan areas (towns and cities between 10,000 and 49,999) and counties outside of metropolitan statistical areas and micropolitan areas. Based on this analysis, we estimate that 7-8 percent of health care providers operate in rural areas.
                    </P>
                    <FTNT>
                        <P>
                            <SU>951</SU>
                             
                            <E T="03">See</E>
                             “Provider of Services File—Internet Quality Improvement and Evaluation System—Home Health Agency, Ambulatory Surgical Center, and Hospice Providers,” Centers for Medicare &amp; Medicaid Services (2024), 
                            <E T="03">https://data.cms.gov/provider-characteristics/hospitals-and-other-facilities/provider-of-services-file-internet-quality-improvement-and-evaluation-system-home-health-agency-ambulatory-surgical-center-and-hospice-providers;</E>
                             “Provider of Services File—Hospital &amp; Non-Hospital Facilities,” Centers for Medicare &amp; Medicaid Services (2024), 
                            <E T="03">https://data.cms.gov/provider-characteristics/hospitals-and-other-facilities/provider-of-services-file-hospital-non-hospital-facilities.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>952</SU>
                             
                            <E T="03">See</E>
                             “Area Health Resources Files,” Health Resources &amp; Services Administration, U.S. Department of Health and Human Services (2022-2023 County Level Data), 
                            <E T="03">https://data.hrsa.gov/data/download?data=AHRF#AHRF.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>953</SU>
                             
                            <E T="03">See</E>
                             “2021 [Statistics of U.S. Businesses] SUSB Annual Data Tables by Establishment Industry,” 
                            <E T="03">supra</E>
                             note 947.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>954</SU>
                             
                            <E T="03">See</E>
                             “Delineation Files,” U.S. Census Bureau, U.S. Department of Commerce (2023), 
                            <E T="03">https://www.census.gov/geographies/reference-files/time-series/demo/metro-micro/delineation-files.html.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>955</SU>
                             
                            <E T="03">See generally</E>
                             86 FR 37770 (July 16, 2021).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>956</SU>
                             
                            <E T="03">See</E>
                             86 FR 37770, 37778 (July 16, 2021).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">Estimated Number and Type of Business Associates</HD>
                    <P>
                        The Department adopts the estimate of approximately 1,000,000 business associates (including subcontractors) as stated in the 2024 ICR and the 2013 “Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the Health Information Technology for Economic and Clinical Health [HITECH] Act and the Genetic Information Nondiscrimination Act, and Other Modifications to the HIPAA Rules” final rule.
                        <SU>957</SU>
                        <FTREF/>
                         We considered whether to increase this figure in our updates but did not do so because many business associates serve multiple covered entities. We lack sufficient data to estimate the number of such businesses more precisely, but we believe that the number of business associates is highly dynamic and dependent on multiple market factors, including expansion and consolidation among various lines of business, changing laws and legal interpretations, and emerging technologies. We include subcontractors of business associates within our estimate because they are business associates of business associates.
                    </P>
                    <FTNT>
                        <P>
                            <SU>957</SU>
                             78 FR 5565 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <P>The Department welcomes comments on the number or type(s) of regulated entities that would be affected by the proposals in this proposed rule and the extent to which they may experience costs or other burdens not already accounted for in the cost estimates. The Department also requests comment on the number of health plan documents that would need to be revised, if any. The Department additionally requests detailed comment on any situations, other than those identified here, in which covered entities or business associates would be affected by the proposals in this rulemaking.</P>
                    <HD SOURCE="HD3">Health Plan Sponsors</HD>
                    <P>
                        Within this NPRM, the Department is for the first time including estimates of health plan sponsors' potential costs of compliance with specific 
                        <PRTPAGE P="997"/>
                        administrative, physical, and technical safeguards of the Security Rule. The Department relied on data from AHRQ and the U.S. Census to estimate the number of firms offering group health plans (1.9 million),
                        <SU>958</SU>
                        <FTREF/>
                         and multiplied that by the percentage that offer at least one self-insured plan to calculate the number of plan sponsors that would be likely to receive ePHI and be subject to the requirements of 45 CFR 164.314(b) [1,943,484 × .382 = 742,411]. We solicit comments on whether group health plans or third-party administrators address any Security Rule requirements for plan sponsors, so the plan sponsors would not have an additional burden or would have a smaller burden than estimated below.
                    </P>
                    <FTNT>
                        <P>
                            <SU>958</SU>
                             
                            <E T="03">See</E>
                             “Medical Expenditure Panel Survey—Insurance Component,” Tables I.A.1 and I.A.2, Agency for Healthcare Research and Quality (2023), 
                            <E T="03">https://meps.ahrq.gov/data_stats/summ_tables/insr/national/series_1/2023/ic23_ia_g.pdf?_gl=1*16xft35*_ga*MTE0MDI5NzI0LjE3MDk2NjQ0NDM.*_ga_45NDTD15CJ*MTczMTEwMzQ4OS4yLjEuMTczMTEwMzUzNS4xNC4wLjA</E>
                             (showing the number of establishments and percent offering health plans) and “County Business Patterns: 2021,” United States Census Bureau (April 27, 2023), 
                            <E T="03">https://www.census.gov/data/datasets/2021/econ/cbp/2021-cbp.html</E>
                             (providing the ratio of firms to establishments). We assume one health plan sponsor per firm that offers a self-insured group health plan.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">Individuals Affected</HD>
                    <P>
                        The number of individuals potentially affected by the proposed changes to the Security Rule includes most of the United States population (approximately 337 million), specifically those who have received any health care in the past seven years and whose ePHI is likely created, received, maintained, or transmitted by a regulated entity. Statistics about the number of individuals affected by breaches of PHI provide insight into known instances where safeguards were breached, although the effects of the Security Rule extend farther than that, to all ePHI. Data from the 2022 Annual Report to Congress on Breaches of Unsecured Protected Health Information for Calendar Year 2022 
                        <SU>959</SU>
                        <FTREF/>
                         revealed nearly 42 million individuals affected by breaches of PHI in that year. Third-party sources reported approximately 133 million individuals affected by health care breaches in 2023.
                        <SU>960</SU>
                        <FTREF/>
                         According to UnitedHealth Group, the 2024 breach of its clearinghouse subsidiary Change Healthcare may have affected approximately one-third of the U.S. population, or 112 million individuals.
                        <SU>961</SU>
                        <FTREF/>
                         The Department believes that the range of individuals potentially affected by the proposed regulatory changes would be from 42 million to 337 million.
                    </P>
                    <FTNT>
                        <P>
                            <SU>959</SU>
                             
                            <E T="03">See</E>
                             “Annual Report to Congress on Breaches of Unsecured Protected Health Information for Calendar Year 2022,” 
                            <E T="03">supra</E>
                             note 213, p. 9 (2023).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>960</SU>
                             
                            <E T="03">See</E>
                             Steve Alder, “December 2023 Healthcare Data Breach Report,” The HIPAA Journal (Jan. 18, 2024), 
                            <E T="03">https://www.hipaajournal.com/december-2023-healthcare-data-breach-report/.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>961</SU>
                             
                            <E T="03">See</E>
                             “What We Learned: Change Healthcare Cyber Attack,” U.S. House of Representatives Committee on Energy &amp; Commerce (May 3, 2024), 
                            <E T="03">https://energycommerce.house.gov/posts/what-we-learned-change-healthcare-cyber-attack.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">HIPAA Breach Data</HD>
                    <P>The Department has reported HIPAA/HITECH breach data annually since 2009. Table 5 shows the data as reported to Congress for the past five years. We relied on this data, combined with breach cost data from industry sources, to analyze the potential savings of the NPRM.</P>
                    <GPOTABLE COLS="7" OPTS="L2,i1" CDEF="s25,12,12,12,12,12,12">
                        <TTITLE>Table 5—Breaches of PHI</TTITLE>
                        <BOXHD>
                            <CHED H="1">Year</CHED>
                            <CHED H="1">
                                Small breaches
                                <LI>(fewer than 500 affected</LI>
                                <LI>individuals)</LI>
                            </CHED>
                            <CHED H="2">Breach count</CHED>
                            <CHED H="2">
                                Affected
                                <LI>individuals</LI>
                            </CHED>
                            <CHED H="1">
                                Large breaches
                                <LI>(500+ affected</LI>
                                <LI>individuals)</LI>
                            </CHED>
                            <CHED H="2">Breach count</CHED>
                            <CHED H="2">
                                Affected
                                <LI>individuals</LI>
                            </CHED>
                            <CHED H="1">Total</CHED>
                            <CHED H="2">Breach count</CHED>
                            <CHED H="2">
                                Affected
                                <LI>individuals</LI>
                            </CHED>
                        </BOXHD>
                        <ROW>
                            <ENT I="01">2018</ENT>
                            <ENT>63,098</ENT>
                            <ENT>296,948</ENT>
                            <ENT>302</ENT>
                            <ENT>12,196,601</ENT>
                            <ENT>63,400</ENT>
                            <ENT>12,493,549</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">2019</ENT>
                            <ENT>62,771</ENT>
                            <ENT>284,812</ENT>
                            <ENT>408</ENT>
                            <ENT>38,732,966</ENT>
                            <ENT>63,179</ENT>
                            <ENT>39,017,778</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">2020</ENT>
                            <ENT>66,509</ENT>
                            <ENT>312,723</ENT>
                            <ENT>656</ENT>
                            <ENT>37,641,403</ENT>
                            <ENT>67,165</ENT>
                            <ENT>37,954,126</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">2021</ENT>
                            <ENT>63,571</ENT>
                            <ENT>319,215</ENT>
                            <ENT>609</ENT>
                            <ENT>37,182,558</ENT>
                            <ENT>64,180</ENT>
                            <ENT>37,501,773</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">2022</ENT>
                            <ENT>63,966</ENT>
                            <ENT>257,105</ENT>
                            <ENT>626</ENT>
                            <ENT>41,747,613</ENT>
                            <ENT>64,592</ENT>
                            <ENT>42,004,718</ENT>
                        </ROW>
                    </GPOTABLE>
                    <HD SOURCE="HD3">3. Costs of the Proposed Rule</HD>
                    <P>Below, the Department provides the basis for its estimated quantifiable costs resulting from the proposed changes to specific provisions of the Security Rule. Many of the estimates are based on assumptions formed through OCR's experience with compliance and enforcement and accounts from stakeholders. For each cost, the Department provides its main estimate, as well as additional high and low estimates for some costs to account for any uncertainty in the compliance approach of regulated entities.</P>
                    <P>All estimates in this section are based on subject matter expertise. The Department requests information or data points from commenters to further refine its estimates and assumptions.</P>
                    <HD SOURCE="HD3">a. Costs Associated With Conducting a Security Rule Compliance Audit</HD>
                    <P>
                        The Department estimates that all regulated entities would need to conduct a Security Rule Compliance Audit because this would be a new requirement under proposed 45 CFR 164.308(a)(14). Although some regulated entities have mistakenly conducted such an audit in lieu of a risk analysis, the Department believes that costs for the compliance audit as a separate requirement should be attributed to the proposed changes in the NPRM. Further, because this would be an annual requirement, the Department is including this as a recurring cost. The Department estimates that regulated entities would need an average of 2 hours of labor by an information systems analyst to conduct the compliance audit, based on the assumption that regulated entities have already documented Security Rule compliance activities as currently required. This would result in total estimated costs of $437,205,288 [= 1,822,600 regulated entities × 2 hours × $119.94]. The respective low and high estimates would be 0.25 and 2.5 hours of information systems analyst labor, resulting in respective total estimated costs of $54,650,6611 [= 1,822,600 regulated entities × 0.25 hours × $119.94] and $546,506,610 [= 1,822,600 regulated entities × 2.5 hours × $119.94].
                        <PRTPAGE P="998"/>
                    </P>
                    <HD SOURCE="HD3">b. Estimated Costs From Adding a Requirement for Business Associates to Analyze Compliance With Technical Safeguards</HD>
                    <P>For proposed 45 CFR 164.308(b), the Department estimates that business associates that handle ePHI would need to spend an average of 2 hours (with a low estimate of 0.25 hours and high estimate of 2.5 hours) analyzing how their cybersecurity measures comply with the proposed requirements for technical safeguards and producing a verification report for covered entities at the hourly wage rate of an information security analyst. This estimate assumes that business associates have already documented existing safeguards, policies, and procedures, so that the costs attributable to the new requirement are incremental and would total approximately $239,880,000 [1 million business associates × 2 hours × $119.94], with a low estimate of $29,985,000 [1 million business associates × 0.25 hours × $119.94] and high estimate of $299,850,000 [1 million business associates × 2.5 hours × $119.94].</P>
                    <HD SOURCE="HD3">c. Costs Arising From Covered Entities and Business Associates Obtaining Verification From Business Associates of Compliance With Technical Safeguards</HD>
                    <P>Under 45 CFR 164.308(b), the Department further estimates that each covered entity would need to spend an average of 30 minutes (with 15 minutes as a low estimate and 90 minutes as a high estimate) requesting and obtaining compliance reports from its business associates about their deployment of technical safeguards required by the Security Rule at the hourly wage of an information security analyst. This assumes that in most instances, business associates would produce the required verification for covered entities without being prompted by a request because they would be required to do so by the Security Rule, as proposed in the NPRM. It further assumes that covered entities have readily available means of contacting business associates, such as via email, and that the contact could be a single email draft sent in a batch. The average time burden per entity depends on verification frequency, likely influenced by entities' average number of business associates and how frequently entities change business associates. The low estimate assumes that entities verify less frequently, whereas the high estimate assumes entities verify more frequently. At the wage rate of an information security analyst, this would result in estimated total costs for covered entities of $49,331,322 [= 822,600 covered entities × 0.5 hours × $119.94], with a low estimate of $24,665,661 [= 822,600 covered entities × 0.25 hours × $119.94] and high estimate of $147,993,966 [= 822,600 covered entities × 1.5 hours × $119.94].</P>
                    <P>The proposed requirement to obtain verification of compliance with technical safeguards also would apply to business associates with respect to their subcontractors. However, we believe that a much smaller number of business associates rely on subcontractors compared to the number of covered entities that rely on business associates to conduct activities on their behalf. Thus, we estimate that, on average, business associates would need 5 minutes annually to obtain verification from their subcontractors that the subcontractors have complied with technical safeguards as required by the Security Rule. The estimate includes only the time needed for business associates to send a mass email to subcontractors because we have already addressed the burden on business associates of producing the verification in the previous section and that estimate includes burdens on subcontractors. The high estimate for this activity would be an average of 15 minutes per business associate, and a low estimate would be for business associates to 2 minutes on this activity. At the wage rate of an information security analyst, this would add estimated total costs for business associates of $9,995,000 [= 1,000,000 business associates × 0.083 hours × $119.94], with a high estimate of $29,985,000 [= 1,000,000 business associates × .25 hours × $119.94].</P>
                    <HD SOURCE="HD3">d. Cost Related to Notification of Termination or Change of Workforce Members' Access to ePHI</HD>
                    <P>
                        The Department estimates that regulated entities are likely to incur additional costs to implement a process to notify other regulated entities when a workforce member's access to ePHI is terminated or changed under proposed 45 CFR 164.308(a)(9)(ii). This estimate assumes that notifications will take an average of 1 hour annually per regulated entity. This results in new estimated costs totaling $84,021,860 [= 1,822,600 regulated entities × 1 hour × $46.10].
                        <SU>962</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>962</SU>
                             
                            <E T="03">See</E>
                             table 3, wage rate for Office and Administrative Support Occupations.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">e. Cost Related to Regulated Entities Deploying Multi-Factor Authentication</HD>
                    <P>The Department estimates that, on average, regulated entities would have an information security analyst spend 1.5 hours deploying MFA, as specifically required under proposed 45 CFR 164.312(f)(2)(ii). This would be a one-time, first-year burden that includes an average of 30 minutes for a regulated entity to select an MFA solution that allows them to meet the requirements of the proposal without creating workflow disruptions or delays. This estimate would vary depending on how prevalent MFA is in the industry when and if the requirements of the NPRM are finalized. As a widely accepted information security practice, the Department believes that many large entities have already deployed MFA and the costs range from zero to only a few dollars per user. The low estimate would be 01 hours on average (assuming that many entities already have some form of MFA), and the high estimate would be 1.75 hours (assuming that few entities have MFA). At the loaded wage rate of an information security analyst, the total estimated cost would be $327,903,966 [= 1,822,600 regulated entities × 1.5 hours × $119.94], with a low estimated total of $218,602,644 [= 1,822,600 regulated entities × 1 hour × $119.94] and a high estimated total of $382,554,627 [= 1,822,600 regulated entities × 1.75 hours × $119.94]. The Department applies this cost in the first year only because minimal additional labor is needed to maintain this safeguard once it has been deployed.</P>
                    <HD SOURCE="HD3">f. Costs Related to Network Segmentation</HD>
                    <P>
                        The Department believes that most large regulated entities and many medium-sized regulated entities have segmented their information networks to some degree; however, additional actions may be needed to more fully protect ePHI as required under proposed 45 CFR 164.312(a)(2)(vi). Further, small entities may not have been aware of the importance of segmenting networks or taken steps to segment their networks. The Department estimates that each regulated entity would spend an average of 4.5 hours to set up network segmentation in the first year of compliance with a final rule (with a low estimate of 4 hours and a high estimate of 5 hours) at the hourly wage of an information security analyst. The Department further assumes that in the following years, the burden to maintain the segmented network would be minimal and incorporated into the maintenance requirements. The total first year estimated cost of the network segmentation requirement would be $983,711,898 [= 1,822,600 regulated entities × 4.5 hours × $119.94] with a low estimated total of $874,410,576 [= 1,822,600 regulated entities × 4 hours × 
                        <PRTPAGE P="999"/>
                        $119.94] and a high estimate of $1,093,013,220 [= 1,822,600 regulated entities × 5 hours × $119.94].
                    </P>
                    <HD SOURCE="HD3">g. Cost Related to Disabling Ports and Removing Extraneous Software</HD>
                    <P>
                        The Department believes that large regulated entities have already disabled unused network ports and removed extraneous software as part of existing configuration requirements. However, the Department believes that small and medium-sized regulated entities are less likely to have performed these actions and thus would incur a new burden to implement these aspects of configuration management proposed at 45 CFR 164.312(c)(2)(ii) and (iv). The Department estimates that 629,796 establishments are owned by small and medium-sized covered entities,
                        <SU>963</SU>
                        <FTREF/>
                         which is approximately 76.56 percent of all covered entities [= 629,796/822,600]. The Department applies that percentage to the estimated number of business associates [= 0.7656 × 1,000,000] to arrive at the estimated number of regulated entities with quantifiably increased burdens from these proposed requirements to disable unused ports and remove extraneous software. We estimate that for these 1,395,396 regulated entities [= 629,796 covered entities + 765,600 business associates], an average annual burden of 30 minutes would be needed at the wage rate of an information security analyst to make needed changes to configuration management, specifically disabling unused ports and removing extraneous software. This would result in estimated total cost increases of $83,681,898 [= 1,395,3960 regulated entities × 0.5 hours × $119.94], with a low estimate of $41,840,949 [= 1,395,396 regulated entities × 0.25 hours × $119.94] based on an estimated annual burden of 15 minutes per affected entity and a high estimate of $109,301,322 [= 1,822,600 regulated entities × 0.50 hours × $119.94] based on an estimated annual burden of 30 minutes for all regulated entities.
                    </P>
                    <FTNT>
                        <P>
                            <SU>963</SU>
                             As defined by having 500 or fewer employees. 
                            <E T="03">See</E>
                             “2021 [Statistics of U.S. Businesses] SUSB Annual Data Tables by Establishment Industry,” 
                            <E T="03">supra,</E>
                             note 947.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">h. Costs Related to Regulated Entities Conducting Penetration Testing</HD>
                    <P>The Department estimates that each regulated entity would spend an average of 3 hours conducting penetration testing (with a low estimate of 2 hours and a high estimate of 10 hours) at the hourly wage of an information security analyst. The Department expects that there might be a high degree of variability between entities depending on their size and technological sophistication. Large entities have more endpoints to test, and thus have greater exposure. The Department also believes there is room for significant variability in the effort that regulated entities may apply to this activity. At the wage rate of an information security analyst, this would result in estimated total annual costs for regulated entities of $655,807,932 [= 1,822,600 regulated entities × 3 hours × $119.94], with a low estimated total of $437,205,288 [= 1,822,600 regulated entities × 2 hours × $119.94] and high estimated total of $2,186,026,440 [= 1,822,600 regulated entities × 10 hours × $119.94].</P>
                    <HD SOURCE="HD3">i. Costs Arising From Reporting Contingency Plan Activation</HD>
                    <P>The Department estimates that business associates would need to notify other regulated entities in the event that they activate their contingency plan once business associate agreements are revised according to proposed 45 CFR 164.314(a)(2)(i)(D). The Department believes this is unlikely to occur more frequently than once per year and that the time to do so would be minimal because the proposed requirement does not specify the means or scope of such notification. The Department estimates that business associates would need an average of 30 minutes (with 15 minutes as a low estimate and 45 minutes as a high estimate) to report to other regulated entities, as applicable, when their contingency plan is activated at the wage rate of an information security analyst for a total annual cost of $59,970,000 [= 1,000,000 business associates × 0.5 hours × $119.94], with a low estimated total of $29,985,000[= 1,000,000 business associates × 0.25 hours × $119.94] and high estimated total of $89,955,000 [= 1,000,000 business associates × 0.75 hours × $119.94].</P>
                    <HD SOURCE="HD3">j. Revised Health Plan Documents</HD>
                    <P>The Department estimates that health care insurers and third-party administrators would need to revise health plan documents to reflect that health plan sponsors that receive ePHI (that is not limited to summary health information or disenrollment information) are protecting ePHI with the administrative, physical, and technical safeguards detailed in the Security Rule, as proposed. These 6,162 entities collectively would be responsible for updating approximately 742,411 health plan documents at the wage rate of a compensation and benefits manager. The Department's estimate assumes that on average each plan document requires 30 minutes to update for a total estimated cost of $53,876,766 [1742,411 × 0.5 hours × $145.14]. The Department has attributed these costs solely to health plans and not health plan sponsors because the health plan is the regulated entity.</P>
                    <HD SOURCE="HD3">k. Estimated Costs for Developing New or Modified Policies and Procedures</HD>
                    <P>The Department anticipates that regulated entities would need to develop new or modified policies and procedures for the proposed new requirements to obtain or provide verification of business associates' compliance with the Security Rule's requirements for technical safeguards, conducting a Security Rule compliance audit, and reporting the activation of a contingency plan, as well as other proposed changes, depending on the regulated entities' existing policies and procedures. The Department estimates that the costs associated with developing such policies and procedures would be the labor of a computer and information systems manager for an average of 3.5 hours (with 2.5 hours as a low estimate and 6 hours as a high estimate, depending on the number of entities with written policies and procedures, and their degree of specificity). This would result in total annual costs of $1,108,432,416 [= 1,822,600 regulated entities × 3.5 hours × $173.76], with a low estimated total of $791,737,440 [= 1,822,600 regulated entities × 2.5 hours × $173.76] and high estimated total of $1,900,169,856 [= 1,822,600 regulated entities × 6 hours × $173.76]. The existing rule requires updates to policies and procedures in response to environmental or operational changes affecting the security of the ePHI, and as a result, the Department is estimating additional costs for new policies related to this proposed rule as an incremental increase.</P>
                    <HD SOURCE="HD3">l. Costs Associated With Training Workforce Members</HD>
                    <P>
                        The Department anticipates that regulated entities would be able to incorporate new content into existing Security Rule training programs and that the costs associated with doing so would be attributed to the labor of a training specialist for an estimated 2 hours for total annual costs of $252,247,840 [= 1,822,600 regulated entities × 2 hours × $69.20]. The low estimate for this activity is $126,123,920 [= 1,822,600 regulated entities × 1 hour × $69.20], and the high estimate is $378,371,760 [= 1,822,600 regulated entities × 3 hours × $69.20]. Many of the changes in the NPRM require the 
                        <PRTPAGE P="1000"/>
                        adoption of standard cybersecurity practices as applied specifically to address the confidentiality, integrity, and availability of ePHI, so we expect that an information security analyst would be familiar with this content. These estimated costs would address any required revisions to training for workforce members within the first year of compliance with a final rule. Any further recurring component is likely to be implemented into regularly scheduled employee training and thus would not be directly attributable to the proposals in this NPRM.
                    </P>
                    <HD SOURCE="HD3">m. Revising Business Associate Agreements</HD>
                    <P>
                        The NPRM proposes to provide a transition period in proposed 45 CFR 164.318 for regulated entities to revise business associate agreements to comply with the proposed changes to the requirements of the Security Rule. The proposed transition period would allow regulated entities to revise existing agreements by the earlier of the contract renewal date that falls after the compliance date of a final rule, or within one year of the rule's effective date. For a large share of existing agreements, this would allow regulated entities to complete the revisions on a rolling basis according to the dates they are renewed. The Department estimates that 1,822,600 
                        <SU>964</SU>
                        <FTREF/>
                         business associate agreements would need to be revised if this NPRM is adopted and that, on average, the portion of this activity that results from the rule's modifications would take an hour of a lawyer's time for each regulated entity. This would result in annual costs of $309,258,768 [= 1,822,600 regulated entities × 1 hour × $169.68]. The Department recognizes that this estimate may not fully account for all revised business associate agreements. However, the Department believes that in some instances, one hour of time is more than would be needed. We also believe it is likely that, for some regulated entities, a professional other than a lawyer would be responsible for the revised agreements at a lower hourly wage. For some large business associates, the Department believes that a single agreement is used for most of its customers. The Department's estimates assume that most agreements would be revised within the first year and accounts for all of them within that time period. This would be considered a one-time cost; in other words, it is not carried over into future years. As with all the estimates in this NPRM, the Department invites comments about the assumptions underlying the proposed cost projections.
                    </P>
                    <FTNT>
                        <P>
                            <SU>964</SU>
                             This is the estimated total number of covered entities and business associates.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">n. Plan Sponsors' Obligations</HD>
                    <P>
                        Proposed 45 CFR 164.314(b)(2) would mandate that group health plan documents require their health plan sponsors who receive ePHI that is not limited to summary health information or enrollment or disenrollment information to deploy the administrative, physical, and technical safeguards for ePHI required by the Security Rule and notify their group health plans upon activation of the plan sponsors' contingency plan. Currently, plan documents must require such health plan sponsors to have safeguards in place, but not necessarily the safeguards specified in the Security Rule.
                        <SU>965</SU>
                        <FTREF/>
                         The Department estimates that an additional 52.42 hours of labor would be needed for each affected health plan sponsor to bring its security safeguards for ePHI into compliance with the Security Rule standards and to notify group health plans when its contingency plan is activated, over and above the actions attributable to safeguards already in place for ePHI and for sponsors' electronic information systems generally. The Security Rule compliance activities attributed to group health plan sponsors are shown in table 7, below.
                    </P>
                    <FTNT>
                        <P>
                            <SU>965</SU>
                             
                            <E T="03">See</E>
                             45 CFR 164.314(b) (requiring that a group health plan ensure that its plan documents provide that the plan sponsor will reasonably and appropriately safeguard electronic protected health information created, received, maintained, or transmitted to or by the plan sponsor on behalf of the group health plan).
                        </P>
                    </FTNT>
                    <P>Most compliance activities would be performed by a workforce member at the hourly wage rate of an information security analyst ($119.94), while documentation of maintenance would be performed at the rate of a management analyst ($111.08) and notification of termination or change of workforce members' access to ePHI would be performed by an office administrative assistant ($46.10). This would result in estimated total first year costs for health plan sponsors of $4,658,781,219 as shown in detail in table 7.</P>
                    <HD SOURCE="HD3">o. Total Quantifiable Costs</HD>
                    <P>The Department summarizes in tables 6 and 7 the estimated costs that regulated entities (approximately $4,655 million) and plan sponsors (approximately $4,659 million), respectively, would experience in the first year of implementing the proposed regulatory changes. The Department anticipates that these costs would be for the following activities: conducting a Security Rule compliance audit; obtaining verification of business associates' and subcontractors' compliance with technical safeguards; providing verification of business associates' compliance with technical safeguards; providing notification of termination or change of workforce members' access to ePHI; deploying MFA and penetration testing; segmenting networks; disabling unused ports; removing extraneous software; notifying covered entities or business associates, as applicable, upon activation of a contingency plan; and updating health plan documents, policies and procedures, workforce training, and business associate agreements. These costs would also include health plan sponsors deploying safeguards for their relevant electronic information systems to meet Security Rule standards and notifying group health plans upon activation of a plan sponsor's contingency plan.</P>
                    <GPOTABLE COLS="5" OPTS="L2,i1" CDEF="s50,12,r50,12,12">
                        <TTITLE>
                            Table 6—First Year Cost Estimates for Regulated Entities' Proposed Compliance Obligations 
                            <E T="01">
                                <SU>a</SU>
                            </E>
                        </TTITLE>
                        <BOXHD>
                            <CHED H="1">Compliance activities</CHED>
                            <CHED H="1">
                                Burden hours
                                <LI>× frequency</LI>
                            </CHED>
                            <CHED H="1">Respondents</CHED>
                            <CHED H="1">Wage rate</CHED>
                            <CHED H="1">
                                Total annual
                                <LI>cost</LI>
                                <LI>(millions)</LI>
                            </CHED>
                        </BOXHD>
                        <ROW>
                            <ENT I="01">Security Rule Compliance Audit</ENT>
                            <ENT>2 × 1</ENT>
                            <ENT>1,822,600 Regulated Entities</ENT>
                            <ENT>$119.94</ENT>
                            <ENT>$437</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">BA Verification of Technical Safeguards</ENT>
                            <ENT>2 × 1</ENT>
                            <ENT>1,000,000 Business Associates</ENT>
                            <ENT>119.94</ENT>
                            <ENT>240</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Obtain BA Compliance Verification</ENT>
                            <ENT>.5 × 1</ENT>
                            <ENT>822,600 Covered Entities</ENT>
                            <ENT>119.94</ENT>
                            <ENT>49</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Obtain Subcontractors' Compliance Verification</ENT>
                            <ENT>.083 × 1</ENT>
                            <ENT>1,000,000 Business Associates</ENT>
                            <ENT>119.94</ENT>
                            <ENT>10</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Notification of Workforce Members' Termination of access to ePHI</ENT>
                            <ENT>1 × 1</ENT>
                            <ENT>1,822,600 Regulated Entities</ENT>
                            <ENT>46.10</ENT>
                            <ENT>84</ENT>
                        </ROW>
                        <ROW>
                            <PRTPAGE P="1001"/>
                            <ENT I="01">Multi-factor Authentication</ENT>
                            <ENT>1.5 × 1</ENT>
                            <ENT>1,822,600 Regulated Entities</ENT>
                            <ENT>$119.94</ENT>
                            <ENT>$328</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Network Segmentation</ENT>
                            <ENT>4.5 × 1</ENT>
                            <ENT>1,822,600 Regulated Entities</ENT>
                            <ENT>119.94</ENT>
                            <ENT>984</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Configuration Management</ENT>
                            <ENT>.5 × 1</ENT>
                            <ENT>1,395,396 Regulated Entities</ENT>
                            <ENT>119.94</ENT>
                            <ENT>84</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Penetration Testing</ENT>
                            <ENT>3 × 1</ENT>
                            <ENT>1,822,600 Regulated Entities</ENT>
                            <ENT>119.94</ENT>
                            <ENT>656</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Notification of Contingency Plan Activation</ENT>
                            <ENT>.5 × 1</ENT>
                            <ENT>1,000,000 Business Associates</ENT>
                            <ENT>119.94</ENT>
                            <ENT>60</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Update Health Plan Documents</ENT>
                            <ENT>.5 × 120</ENT>
                            <ENT>3,102,851 Health Plan Documents</ENT>
                            <ENT>145.14</ENT>
                            <ENT>54</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Update Policies and Procedures</ENT>
                            <ENT>3.5 × 1</ENT>
                            <ENT>1,822,600 Regulated Entities</ENT>
                            <ENT>173.76</ENT>
                            <ENT>1,108</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Update Workforce Training</ENT>
                            <ENT>2 × 1</ENT>
                            <ENT>1,822,600 Regulated Entities</ENT>
                            <ENT>69.20</ENT>
                            <ENT>252</ENT>
                        </ROW>
                        <ROW RUL="n,s">
                            <ENT I="01">Revise Business Associate Agreements</ENT>
                            <ENT>1 × 1</ENT>
                            <ENT>1,822,600 Regulated Entities</ENT>
                            <ENT>169.68</ENT>
                            <ENT>309</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="03">Total Annual Cost Burden</ENT>
                            <ENT/>
                            <ENT/>
                            <ENT/>
                            <ENT>4,655</ENT>
                        </ROW>
                        <TNOTE>
                            <SU>a</SU>
                             These represent first year estimated costs and are rounded.
                        </TNOTE>
                    </GPOTABLE>
                    <P>The Department presents the estimated cost of health plan sponsors' compliance with the proposed new requirements in table 7 below.</P>
                    <GPOTABLE COLS="5" OPTS="L2,i1" CDEF="s50,12,r50,12,12">
                        <TTITLE>
                            Table 7—First Year Cost Estimates of Health Plan Sponsors' Proposed Compliance Obligations 
                            <E T="01">
                                <SU>a</SU>
                            </E>
                        </TTITLE>
                        <BOXHD>
                            <CHED H="1">Compliance activities</CHED>
                            <CHED H="1">Burden hours × frequency</CHED>
                            <CHED H="1">Respondents</CHED>
                            <CHED H="1">Wage rate</CHED>
                            <CHED H="1">
                                Total annual cost
                                <LI>(millions)</LI>
                            </CHED>
                        </BOXHD>
                        <ROW>
                            <ENT I="01">Risk Analysis—Documentation</ENT>
                            <ENT>5 × 1</ENT>
                            <ENT>742,411 Plan Sponsors</ENT>
                            <ENT>$119.94</ENT>
                            <ENT>$445</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Information System Activity Review—Documentation</ENT>
                            <ENT>.75 × 12</ENT>
                            <ENT>742,411 Plan Sponsors</ENT>
                            <ENT>119.94</ENT>
                            <ENT>801</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Ongoing Education</ENT>
                            <ENT>.17 × 12</ENT>
                            <ENT>742,411 Plan Sponsors</ENT>
                            <ENT>119.94</ENT>
                            <ENT>178</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Security Incidents (other than breaches)—Documentation</ENT>
                            <ENT>2 × 12</ENT>
                            <ENT>742,411 Plan Sponsors</ENT>
                            <ENT>119.94</ENT>
                            <ENT>2,137</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Contingency Plan—Testing and Revision</ENT>
                            <ENT>2 × 1</ENT>
                            <ENT>742,411 Plan Sponsors</ENT>
                            <ENT>119.94</ENT>
                            <ENT>178</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Contingency Plan—Criticality Analysis</ENT>
                            <ENT>.5 × 1</ENT>
                            <ENT>742,411 Plan Sponsors</ENT>
                            <ENT>119.94</ENT>
                            <ENT>45</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Notification of Workforce Members' Termination of ePHI Access</ENT>
                            <ENT>.25 × 1</ENT>
                            <ENT>742,411 Plan Sponsors</ENT>
                            <ENT>46.10</ENT>
                            <ENT>9</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Maintenance Records</ENT>
                            <ENT>.5 × 12</ENT>
                            <ENT>742,411 Plan Sponsors</ENT>
                            <ENT>111.08</ENT>
                            <ENT>495</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Multi-factor Authentication</ENT>
                            <ENT>1.5 × 1</ENT>
                            <ENT>742,411 Plan Sponsors</ENT>
                            <ENT>119.94</ENT>
                            <ENT>133</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Configuration Management</ENT>
                            <ENT>.5 × 1</ENT>
                            <ENT>742,411 Plan Sponsors</ENT>
                            <ENT>119.94</ENT>
                            <ENT>45</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Penetration Testing</ENT>
                            <ENT>2 × 1</ENT>
                            <ENT>742,411 Plan Sponsors</ENT>
                            <ENT>119.94</ENT>
                            <ENT>178</ENT>
                        </ROW>
                        <ROW RUL="n,s">
                            <ENT I="01">Notification of Contingency Plan Activation</ENT>
                            <ENT>.17 × 1</ENT>
                            <ENT>742,411 Plan Sponsors</ENT>
                            <ENT>119.94</ENT>
                            <ENT>15</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="03">Total Annual Cost Burden</ENT>
                            <ENT/>
                            <ENT/>
                            <ENT/>
                            <ENT>4,659</ENT>
                        </ROW>
                        <TNOTE>
                            <SU>a</SU>
                             These represent first year estimated costs and are rounded.
                        </TNOTE>
                    </GPOTABLE>
                    <P>Together, regulated entities' and affected health plan sponsors' estimated first year costs of compliance with the proposals in the NPRM would be approximately 9,314 million (or $9 billion).</P>
                    <HD SOURCE="HD3">p. Costs Borne by the Department</HD>
                    <P>The covered entities that are operated by the Department would be affected by the changes in a similar manner to other covered entities, and such costs have been factored into the estimates above. The Department has not identified other costs to the Department related to the changes in the NPRM. A reduction in the number of large breaches (affecting 500 or more individuals per incident) would benefit the Department by enabling it to focus its resources on a smaller number of breach investigations, and potentially resolve such investigations more quickly.</P>
                    <HD SOURCE="HD3">4. Benefits of the Proposed Rule</HD>
                    <HD SOURCE="HD3">a. Quantitative Analysis of Benefits</HD>
                    <P>
                        A key goal of strengthening the cybersecurity posture of regulated entities is to reduce the number and severity of security incidents, including breaches of ePHI. The Department believes that compliance with the proposed changes, which align with industry guidelines and best practices, would benefit regulated entities by reducing the cost of breaches. Although the costs of implementing the proposed cybersecurity measures would be significant, the costs of responding to breaches of ePHI are much higher. According to industry data, the average cost of a health care breach in 2023 rose to $10.93 million, the highest among all industries studied,
                        <SU>966</SU>
                        <FTREF/>
                         and the per record cost of a breach involving personally identifiable information (across all industries) was $183.
                        <SU>967</SU>
                        <FTREF/>
                         These costs include detection and investigation activities, notification activities, post-breach response activities, and activities attempting to minimize the loss of business. Thus, the benefits of the proposed rule would be to reduce the harms of health care breaches described in the preamble. The Department believes that implementing the changes in the NPRM would reduce both the incidence of breaches in health care and the costs of mitigating breaches when they occur.
                    </P>
                    <FTNT>
                        <P>
                            <SU>966</SU>
                             
                            <E T="03">See</E>
                             “Cost of a Data Breach Report 2023,” 
                            <E T="03">supra</E>
                             note 131, p. 13.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>967</SU>
                             
                            <E T="03">Id.</E>
                             at 18.
                        </P>
                    </FTNT>
                    <P>
                        The Department also analyzed the potential cost savings of proposals that 
                        <PRTPAGE P="1002"/>
                        correspond to major factors affecting the costs of large breaches as identified in published reports.
                        <SU>968</SU>
                        <FTREF/>
                         The Department estimates that, at a minimum, performing the following actions would quantifiably reduce costs: (1) encryption; (2) penetration testing; (3) requiring MFA and notification of termination of access to ePHI; (4) increasing employee training; and (5) reducing noncompliance with regulations. These factors would account for an estimated 23.6 percent decrease in large breach costs.
                        <SU>969</SU>
                        <FTREF/>
                         For health care breaches, this corresponds to an estimated cost savings of $2.6 million per large breach in high incidence years, and $2.1 million per large breach in low incidence years.
                    </P>
                    <FTNT>
                        <P>
                            <SU>968</SU>
                             The impact factor costs and cost savings are based on estimates for all breaches from the annual IBM Security and Ponemon Institute Costs of a Data Breach Reports for years 2018-2023. 
                            <E T="03">See id.</E>
                             at p. 28.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>969</SU>
                             The Department calculated the percentage decrease as a share of the sum of factor costs from the average breach cost: ($218,915 + $180,358 + $187,703 + $221,593 + $232,867)/$4,450,000 = 0.236.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">Non-Quantitative Analysis of Benefits</HD>
                    <P>
                        A fundamental benefit of the proposed rule would be to decrease the effects of breaches on individuals who are the subjects of ePHI, namely patients and health plan members. Breaches of ePHI may cause harm to individuals in many ways, including loss of reputation and personal dignity and financial and medical fraud, which may result in false debts, impaired credit, and even health threats from misuse of health insurance credentials by another individual. “[H]ealthcare data, which includes medical histories and personal identification, can last a lifetime. The information collected can be used for ransom, to commit tax frauds, to provide supporting disability documentation, to send fake bills to insurance providers, to obtain healthcare, prescription drugs, medical treatment, and to obtain government benefits like Medicare and Medicaid.” 
                        <SU>970</SU>
                        <FTREF/>
                         Hackers can use stolen personal, medical, and financial data to take out a bank loan in the victim's name and change direct deposit information in payroll systems, allowing them to steal wages as well.
                        <SU>971</SU>
                        <FTREF/>
                         In addition, medical identity fraud can impact the victim's credit score and health insurance premiums, and may result in unexpected legal fees.
                        <SU>972</SU>
                        <FTREF/>
                         Medical identity fraud also enables thieves to obtain medical treatment using the victim's stolen ePHI. This can lead to the thief's medical conditions being incorporated into the victim's medical records and impacting the victim's ability to receive appropriate medical treatment based on accurate records in the future, or any care at all depending on whether the thief has exhausted the victim's insurance benefits.
                        <SU>973</SU>
                        <FTREF/>
                         Overall, recovering compromised ePHI and addressing the consequences of breached information can be a long and arduous process that can cost victims large amounts of time, energy, and money.
                        <SU>974</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>970</SU>
                             
                            <E T="03">See</E>
                             “New Dangers in the New World: Cyber Attacks in the Healthcare Industry,” 
                            <E T="03">supra</E>
                             note 135, p. 3.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>971</SU>
                             
                            <E T="03">See</E>
                             “Is the HIPAA Security Rule Enough to Protect Electronic Personal Health Information (PHI) in the Cyber Age? ” 
                            <E T="03">supra</E>
                             note 207; 
                            <E T="03">see also</E>
                             Adam Wright, et al., “The Big Phish: Cyberattacks Against U.S. Healthcare Systems,” Journal of General Internal Medicine, Volume 31, p. 1115-1118 (May 13, 2016), 
                            <E T="03">https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5023604/.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>972</SU>
                             
                            <E T="03">See</E>
                             Thomas Clifford, “Provider Liability and Medical Identity Theft: Can I Get Your (Insurance) Number?,” Northwestern Journal of Law &amp; Social Policy, Volume 12, p. 45 (2016), 
                            <E T="03">https://scholarlycommons.law.northwestern.edu/njlsp/vol12/iss1/2/.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>973</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>974</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        Breaches of ePHI maintained by health care systems can also pose a threat to the medical well-being of affected individuals. Cyberattacks on health care organizations can include the deployment of malware that compromises the function of both internal and external medical devices. Such software can alter the dosages of sensitive medicines or shut down devices while they are in use, thus affecting patient care.
                        <SU>975</SU>
                        <FTREF/>
                         Some of the medical devices that are vulnerable to malicious software attacks include insulin pumps and cardiac implant devices.
                        <SU>976</SU>
                        <FTREF/>
                         The consequences of a cyberattack on such a medical device can be fatal.
                    </P>
                    <FTNT>
                        <P>
                            <SU>975</SU>
                             
                            <E T="03">See</E>
                             “Assessing resilience of hospitals to cyberattack,” 
                            <E T="03">supra</E>
                             note 130; 
                            <E T="03">see also</E>
                             Ashley Carman, “ `MEDJACK' tactic allows cyber criminals to enter healthcare networks undetected,” SC Media (June 4, 2015) (“Medjack” means a medical device hijack that attackers use to exploit outdated and unpatched medical devices), 
                            <E T="03">https://www.scmagazine.com/news/medjack-tactic-allows-cyber-criminals-to-enter-healthcare-networks-undetected.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>976</SU>
                             
                            <E T="03">See</E>
                             “New Dangers in the New World: Cyber Attacks in the Healthcare Industry,” 
                            <E T="03">supra</E>
                             note 135.
                        </P>
                    </FTNT>
                    <P>
                        Cyberattacks on relevant electronic information systems also hinder the efficiency of hospitals and limit the quality of care provided to patients. Breaches of relevant electronic information systems negatively affect the routine functions of health care organizations. They can affect the availability of ePHI and relevant electronic information systems and redirect critical resources from patient care to addressing the cybersecurity attack. A 2020 cyberattack on a large covered entity disrupted communication and clinician access to medical records, including to individualized chemotherapy plan templates and tools for communicating during treatment preparation and delivery.
                        <SU>977</SU>
                        <FTREF/>
                         In the first week following the attack, the hospital's ability to provide critical outpatient care was reduced by 40 percent and infusion visit volume decreased by 52 percent. Many patients had to be transferred to other sites to minimize delays in receiving critical medications. The effects of this data breach are not unique to this provider. There is evidence that cyberattacks on health care organizations decrease the number of patients they are able to treat in a given day and staff utilization.
                        <SU>978</SU>
                        <FTREF/>
                         Decreases in efficiency and number of treated patients also cause health care facilities to lose revenue because of their inability to provide care during a cybersecurity event.
                    </P>
                    <FTNT>
                        <P>
                            <SU>977</SU>
                             
                            <E T="03">See</E>
                             Steven Ades, et al., “Cancer Care in the Wake of a Cyberattack: How to Prepare and What to Expect,” JCO Oncology Practice, Volume 18, p. 23-24 (Aug. 2, 2021), 
                            <E T="03">https://pubmed.ncbi.nlm.nih.gov/34339260/.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>978</SU>
                             
                            <E T="03">See</E>
                             “Assessing resilience of hospitals to cyberattack,” 
                            <E T="03">supra</E>
                             note 130.
                        </P>
                    </FTNT>
                    <P>
                        Similar to the effects of breaches of ePHI on individuals, health care organizations and facilities also experience reputational and financial impacts because of cybersecurity attacks. Hospitals can lose the community's trust and be subject to lawsuits from individuals whose data was compromised.
                        <SU>979</SU>
                        <FTREF/>
                         Organizations that experience cybersecurity attacks can experience reputational harm and other monetary costs, such as those associated with providing breach notifications, paying fines to regulators and damages to individuals, and providing credit monitoring and identity theft-related services.
                        <SU>980</SU>
                        <FTREF/>
                         The harm to an organization's reputation is difficult to quantify, but it can also affect the quality of care administered to individuals.
                        <SU>981</SU>
                        <FTREF/>
                         Privacy and security of ePHI are paramount to individuals feeling safe and at ease sharing their IIHI with clinicians. Security breaches can negatively impact a patient's confidence in a health care organization if they believe their information and privacy may be compromised. This can cause them to delay seeking treatment or 
                        <PRTPAGE P="1003"/>
                        withhold information from health care practitioners, ultimately compromising the decision-making capacity of their health care provider to administer the best quality of care.
                        <SU>982</SU>
                        <FTREF/>
                         Decreasing the number and scope of health care breaches would reduce the harms of such breaches and would be a significant benefit of the proposals in the NPRM.
                    </P>
                    <FTNT>
                        <P>
                            <SU>979</SU>
                             
                            <E T="03">See</E>
                             Mohammed Alkinoon, et al., “Measuring Health Care Data Breaches,” Information Security Applications, Volume 13009, p. 265-277 (Aug. 11, 2021), 
                            <E T="03">https://dl.acm.org/doi/10.1007/978-3-030-89432-0_22.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>980</SU>
                             
                            <E T="03">See</E>
                             “The Big Phish: Cyberattacks Against U.S. Healthcare Systems,” 
                            <E T="03">supra</E>
                             note 971, p. 1115-1118.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>981</SU>
                             
                            <E T="03">See</E>
                             “Health Records Database and Inherent Security Concerns: A Review of the Literature,” 
                            <E T="03">supra</E>
                             note 177.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>982</SU>
                             
                            <E T="03">Id.; see also</E>
                             Victoria Kisekka, et al., “The Effectiveness of Health Care Information Technologies: Evaluation of Trust, Security Beliefs, and Privacy as Determinants of Health Care Outcomes,” Journal of Medical Internet Research, Volume 20 (Apr. 11, 2018), 
                            <E T="03">https://pubmed.ncbi.nlm.nih.gov/29643052/.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">5. Comparison of Benefits and Costs</HD>
                    <P>Key inputs to the estimation of costs of this proposed rule include the numbers of regulated entities and health plan sponsors. The Department has not previously quantified the costs of Security Rule compliance for health plan sponsors because the existing requirements are for plan documents to require such sponsors to implement administrative, physical, and technical safeguards, but not necessarily to comply with the specific requirements of the Security Rule. Therefore, the proposed requirement to comply with the proposed changes to the Security Rule, along with the number of affected plan sponsors (approximately 740,000), results in a significant increase in overall cost estimates compared to the existing rule. The benefits of improved security for ePHI accrue to individuals, regulated entities, and health plan sponsors and are significant. The Department has discussed the benefits above.</P>
                    <P>The Department seeks to reduce the risk and mitigate the effects of breaches of ePHI and related information systems through the proposals included in this NPRM. Because the frequency and magnitude of cybersecurity events are inherently difficult to predict, we chose to conduct a break-even analysis in lieu of a cost savings analysis. The Department solicits comments with any information and data on the incidence and negative consequences of cybersecurity breaches.</P>
                    <P>
                        The
                        <FTREF/>
                         Department examined two different data points: the annual number of individuals affected by health care breaches, and the annual number of large breaches. Additionally, the Department considered a high and a low baseline based on the number of breaches and affected individuals per year. The Department calculated the high baseline as the average of the three highest values in the 6 years of available data (2018 to 2023, shown in table 8), and the low baseline as the average of the three lowest values.
                    </P>
                    <FTNT>
                        <P>
                            <SU>983</SU>
                             For this analysis, a record is the ePHI of one individual.
                        </P>
                    </FTNT>
                    <GPOTABLE COLS="3" OPTS="L2,i1" CDEF="s25,24,20">
                        <TTITLE>
                            Table 8—Data on Breaches of 
                            <E T="01">e</E>
                            PHI
                        </TTITLE>
                        <BOXHD>
                            <CHED H="1">Breach years</CHED>
                            <CHED H="1">
                                Affected individuals
                                <LI>
                                    for large breaches 
                                    <SU>a</SU>
                                </LI>
                            </CHED>
                            <CHED H="1">
                                Cost 
                                <SU>b</SU>
                                 per record 
                                <SU>983</SU>
                            </CHED>
                        </BOXHD>
                        <ROW>
                            <ENT I="01">2018</ENT>
                            <ENT>12,493,549</ENT>
                            <ENT>$488</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">2019</ENT>
                            <ENT>38,732,966</ENT>
                            <ENT>504</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">2020</ENT>
                            <ENT>37,641,403</ENT>
                            <ENT>476</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">2021</ENT>
                            <ENT>37,182,558</ENT>
                            <ENT>502</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">2022</ENT>
                            <ENT>41,747,613</ENT>
                            <ENT>477</ENT>
                        </ROW>
                        <ROW RUL="s">
                            <ENT I="01">2023</ENT>
                            <ENT>113,173,613</ENT>
                            <ENT>463</ENT>
                        </ROW>
                        <ROW RUL="s">
                            <ENT I="25"> </ENT>
                            <ENT>
                                Number of large breaches
                                <LI>(500+ individuals)</LI>
                            </ENT>
                            <ENT>Cost per breach</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">2018</ENT>
                            <ENT>302</ENT>
                            <ENT>12,012,809</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">2019</ENT>
                            <ENT>408</ENT>
                            <ENT>7,582,508</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">2020</ENT>
                            <ENT>656</ENT>
                            <ENT>8,273,537</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">2021</ENT>
                            <ENT>609</ENT>
                            <ENT>10,241,897</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">2022</ENT>
                            <ENT>626</ENT>
                            <ENT>10,468,138</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">2023</ENT>
                            <ENT>725</ENT>
                            <ENT>10,930,000</ENT>
                        </ROW>
                        <TNOTE>
                            <SU>a</SU>
                             The numbers of affected individuals and numbers of large breaches are contained in the Reports to Congress on Breaches of Unsecured Protected Health Information for years 2018-2022, 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/reports-congress/index.html.</E>
                             Data for 2023 is contained in OCR's breach portal, “Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information,” Office for Civil Rights, U.S. Department of Health and Human Services, 
                            <E T="03">https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf.</E>
                        </TNOTE>
                        <TNOTE>
                            <SU>b</SU>
                             The cost per record and cost per breach are based on estimates for health care breaches from the annual IBM Security and Ponemon Institute Costs of a Data Breach Reports for years 2018-2023. 
                            <E T="03">See</E>
                             “Cost of a Data Breach Report 2023,” IBM Security, p. 10, 13 (July 24, 2023), 
                            <E T="03">available at https://www.ibm.com/reports/data-breach.</E>
                             Because only general breach costs were available for the 2020-2023 period, the Department adjusted those by multiplying them by the average of the ratios of health care-specific to overall breach costs for the years for which both data points were available (2018, $408/$148 and 2019, $429/$150). All dollar values were converted to 2023 dollars using the seasonally adjusted GDP Implicit Price Deflator, 
                            <E T="03">https://fred.stlouisfed.org/series/GDPDEF/.</E>
                        </TNOTE>
                    </GPOTABLE>
                    <P>
                        The high baseline used 669 breaches and a total of 71 million individuals affected, and the low baseline used 440 breaches and 29 million individuals affected.
                        <SU>984</SU>
                        <FTREF/>
                         The high baseline represents years with higher incidence of breaches, whereas the low baseline represents years with lower incidence.
                    </P>
                    <FTNT>
                        <P>
                            <SU>984</SU>
                             
                            <E T="03">See</E>
                             “Annual Report to Congress on Breaches of Unsecured Protected Health Information for Calendar Year 2022,” 
                            <E T="03">supra</E>
                             note 213, p. 9 (2023); “December 2023 Healthcare Data Breach Report,” 
                            <E T="03">supra</E>
                             note 960
                            <E T="03">.</E>
                        </P>
                    </FTNT>
                    <P>
                        For each data point, the Department calculated the number of breaches or affected individuals by which the affected universe would have to decrease for the proposed rule to fully offset the annualized costs of regulated entities.
                        <SU>985</SU>
                        <FTREF/>
                         Table 9 and the discussion that follows analyses the costs and cost savings based on the number of individuals affected by breaches in a year and the cost per individual's ePHI or medical record.
                    </P>
                    <FTNT>
                        <P>
                            <SU>985</SU>
                             The break-even calculations presented here only include regulated entities because breach data is not available for health plan sponsors. Including sponsors and assuming they have the same rate of breaches would result in a similar break-even point in terms of percent decrease from baseline.
                        </P>
                    </FTNT>
                    <PRTPAGE P="1004"/>
                    <GPOTABLE COLS="6" OPTS="L2,i1" CDEF="s25,12,16,12,12,15">
                        <TTITLE>Table 9—Break-Even Thresholds by Number of Affected Individuals</TTITLE>
                        <BOXHD>
                            <CHED H="1">Baseline</CHED>
                            <CHED H="1">
                                Affected
                                <LI>individuals</LI>
                            </CHED>
                            <CHED H="1">
                                Regulated
                                <LI>entities NPRM</LI>
                                <LI>costs</LI>
                            </CHED>
                            <CHED H="1">
                                Unit cost
                                <LI>(per individual</LI>
                                <LI>record)</LI>
                            </CHED>
                            <CHED H="1">
                                Break-even
                                <LI>threshold</LI>
                                <LI>(NPRM cost ÷</LI>
                                <LI>unit cost)</LI>
                            </CHED>
                            <CHED H="1">
                                Percent
                                <LI>decrease</LI>
                                <LI>(threshold ÷</LI>
                                <LI>affected) × 100</LI>
                            </CHED>
                        </BOXHD>
                        <ROW>
                            <ENT I="01">High</ENT>
                            <ENT>64,551,397</ENT>
                            <ENT>$2,251,258,305</ENT>
                            <ENT>$498</ENT>
                            <ENT>4,521,423</ENT>
                            <ENT>7</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Low</ENT>
                            <ENT>29,006,854</ENT>
                            <ENT O="xl"/>
                            <ENT O="xl"/>
                            <ENT O="xl"/>
                            <ENT>16.4</ENT>
                        </ROW>
                    </GPOTABLE>
                    <P>The analysis in table 9 suggests that this NPRM would break even (cost savings would match monetized costs incurred) if the number of affected individuals is reduced by approximately 4.5 million. In years with a high incidence of breaches, this would be a reduction of approximately 7 percent, and in low-incidence years this would be a decrease of 16.4 percent. Thus, if the proposed changes in the NPRM reduce the number of affected individuals by 7 to 16 percent, the rule would pay for itself. Alternatively, the same cost savings may be achieved by lowering the cost per affected individual's ePHI by 7 percent ($35) and 16 percent ($82), respectively.</P>
                    <P>Table 10 analyzes the potential cost savings for regulated entities based on the annual number of large breaches of ePHI and the cost per breach, as shown below.</P>
                    <GPOTABLE COLS="6" OPTS="L2,i1" CDEF="s25,12,16,12,12,15">
                        <TTITLE>Table 10—Break-Even Thresholds by Number of Large Breaches</TTITLE>
                        <BOXHD>
                            <CHED H="1">Baseline</CHED>
                            <CHED H="1">Breaches</CHED>
                            <CHED H="1">
                                NPRM cost for
                                <LI>regulated</LI>
                                <LI>entities</LI>
                            </CHED>
                            <CHED H="1">
                                Unit cost
                                <LI>(per breach)</LI>
                            </CHED>
                            <CHED H="1">
                                Break-even
                                <LI>threshold</LI>
                                <LI>(NPRM cost ÷</LI>
                                <LI>unit cost)</LI>
                            </CHED>
                            <CHED H="1">
                                Percent
                                <LI>decrease</LI>
                                <LI>(threshold ÷</LI>
                                <LI>breaches) × 100</LI>
                            </CHED>
                        </BOXHD>
                        <ROW>
                            <ENT I="01">High</ENT>
                            <ENT>669</ENT>
                            <ENT>$2,251,258,305</ENT>
                            <ENT>$11,136,982</ENT>
                            <ENT>202</ENT>
                            <ENT>30.1</ENT>
                        </ROW>
                        <ROW>
                            <ENT I="01">Low</ENT>
                            <ENT>440</ENT>
                            <ENT O="xl"/>
                            <ENT O="xl"/>
                            <ENT O="xl"/>
                            <ENT>58.9</ENT>
                        </ROW>
                    </GPOTABLE>
                    <P>In table 10, the Department assumes that the average cost per breach in industry reports ($11.1 million, calculated as the average of the three highest values in table 9, adjusted for inflation) refers to large breaches of ePHI . The analysis in table 10 suggests that the NPRM would break even if the annual number of large breaches is reduced by approximately 202. In high-incidence years, this would be a reduction of approximately 30 percent, and in low-incidence years, this would be a decrease of 59 percent. Alternatively, the same cost savings may be achieved by lowering the cost per breach by 30 percent ($3.4 million) and 9 percent ($6.6 million), respectively.</P>
                    <HD SOURCE="HD2">B. Regulatory Alternatives to the Proposed Rule</HD>
                    <P>The Department welcomes public comment on any benefits or drawbacks of the following alternatives it considered, but did not propose, while developing this proposed rule. We also request comment on whether the Department should reconsider any of the alternatives considered, and if so, why.</P>
                    <HD SOURCE="HD3">No Changes to the Security Rule</HD>
                    <P>We considered not proposing revisions to the Security Rule. However, the Department believes that not revising the Security Rule would result in continued increases in both the number and size of breaches. Such increases would result in an exponential increase in costs as shown in table 8 above. If the modifications to the Security Rule result in even modest improvements to the security of ePHI, the reduction in the number and/or size of breaches would reduce the overall costs associated with breaches, including the costs of mitigating harm resulting from such breaches.</P>
                    <HD SOURCE="HD3">Email Security</HD>
                    <P>
                        The Department considered proposing a separate standard for regulated entities to secure email transmissions. In the Department's Cybersecurity Performance Goals,
                        <SU>986</SU>
                        <FTREF/>
                         the Department identifies email security as an essential goal for reducing risk from common email-based threats such as email spoofing, phishing, and fraud. Therein, the Department points to basic email protection controls identified in the Health Industry Cybersecurity Practices, such as spam/virus checking and real-time deny lists, as well as strategies that may be deployed across small, medium, and large organizations, including MFA for email access, email encryption, workforce education, and advance tooling (
                        <E T="03">e.g.,</E>
                         URL click protection via analytics, attachment sandboxing).
                        <SU>987</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>986</SU>
                             “Cybersecurity Performance Goals,” 
                            <E T="03">supra</E>
                             note 18.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>987</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>
                        The Department is aware of the threat that email poses to the information systems of regulated entities and to the confidentiality, integrity, and availability of ePHI.
                        <SU>988</SU>
                        <FTREF/>
                         However, the Department believes that it is important that the Security Rule remain technology-neutral and that the security measures we propose in this NPRM apply to a regulated entity's information systems broadly, including email programs. For example, in this NPRM, the Department proposes to require regulated entities to encrypt all ePHI at rest and in transit and proposes a transmission security standard in which regulated entities would be required to deploy technical controls to guard against unauthorized access to ePHI that is being transmitted over an electronic communications network.
                        <SU>989</SU>
                        <FTREF/>
                         Therefore, the Department believes it is unnecessary to promulgate a separate standard for email security. Because the other technical controls, such as encryption and MFA, are already incorporated into the requirements that would protect relevant electronic information systems, the Department believes that adopting a separate secure email standard would duplicate costs without creating a net benefit.
                    </P>
                    <FTNT>
                        <P>
                            <SU>988</SU>
                             According to the 2021 Verizon Data Breach Investigations Report, “phishing was `present in 36% of breaches (up from 25% last year);' [and] 23% of malware was delivered through email.” 
                            <E T="03">See</E>
                             “Technical Volume 2: Cybersecurity Practices for Medium and Large Healthcare Organizations,” Cybersecurity Practice #1: Email Protection Systems, HHS Healthcare &amp; Public Health Sector Coordinating Council, p. 13 (2023), 
                            <E T="03">https://405d.hhs.gov/Documents/tech-vol2-508.pdf</E>
                             (citing a 2021 Verizon Data Breach Investigations Report).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>989</SU>
                             
                            <E T="03">See</E>
                             proposed 45 CFR 164.312(b)(2) and (g).
                        </P>
                    </FTNT>
                    <PRTPAGE P="1005"/>
                    <P>
                        Additionally, the Department considered whether to heighten the existing expectation 
                        <SU>990</SU>
                        <FTREF/>
                         for regulated entities to inform individuals before transmitting ePHI to the individual via unencrypted email in response to a request for access under 45 CFR 164.524 by this means. We considered whether to require such notification for different types of requests, such as different categories of PHI (
                        <E T="03">e.g.,</E>
                         billing, lab results, etc.), determining whether the individual had already received such notice, or providing notification upon each disclosure. Instead, the Department has proposed to clarify that notification must be provided for each request made by the individual under the individual right of access at 45 CFR 164.524 for their ePHI to be transmitted via unsecure email. We believe that requiring a regulated entity to determine whether the individual had already received such notification would be more burdensome than incorporating the notification into the access request process, and instead, have proposed. We estimate that this could increase burdens for providing access via unsecure means by approximately one minute per request of this type. We lack data to estimate the number of requests for access via unsecure means.
                    </P>
                    <FTNT>
                        <P>
                            <SU>990</SU>
                             
                            <E T="03">See</E>
                             “Individuals' Right under HIPAA to Access their Health Information 45 CFR 164.524,” What is the liability of a covered entity in responding to an individual's access request to send the individual's PHI to a third party?, Office for Civil Rights, U.S. Department of Health and Human Services, 
                            <E T="03">https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/access/index.html.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">Small and Rural Health Care Providers</HD>
                    <P>
                        Consistent with the requirement that the Secretary adopt security standards that take into account the needs and capabilities of small health care providers and rural health care providers,
                        <SU>991</SU>
                        <FTREF/>
                         the Department considered excepting small and rural health care providers from the requirement to perform penetration testing at proposed 45 CFR 164.308(h)(2)(iii) to lower anticipated costs of the rule for such providers. The Department estimates that approximately 90 percent of providers are small (based on revenue). Thus, the estimated cost reduction from this exemption (as compared to the proposed requirement for all regulated entities), would be approximately $266,389,139 [822,600 × .9 × 3 hours × $119.94 wage of an information security analyst] annually. While the Department is aware of the cost implications of this requirement for small and rural health care providers, we also believe that penetration testing is a critical component of managing vulnerability to cyberthreats across the health care sector. Additionally, we believe that setting different requirements for cybersecurity for small and rural health care providers would lead such health care providers to believe that they can limit their investment in cybersecurity. Given that a significant amount of health care is provided by small and rural health care providers, limiting their investment in cybersecurity would create a sizable gap in security protections. Such a gap has the potential to increase such providers' attractiveness to cybercriminals.
                    </P>
                    <FTNT>
                        <P>
                            <SU>991</SU>
                             42 U.S.C. 1320d-2(d)(1)(A)(v).
                        </P>
                    </FTNT>
                    <P>The Department also considered proposing to permit small and rural health care providers to adopt alternate compensating controls, in lieu of the specified implementation specifications, to meet certain standards. After careful consideration, the Department concluded that it potentially could be just as costly to identify and adopt compensating controls that are reasonable and appropriate for small and rural health care practices. Small and rural health care providers would likely need to either hire personnel or contract with cybersecurity experts to identify potential compensating controls that would meet the relevant standard and provide implementation support. Accordingly, the Department declines to put forward such proposals at this time.</P>
                    <HD SOURCE="HD3">The Federal Information Security Modernization Act</HD>
                    <P>
                        The Department considered the requirements of the Federal Information Security Modernization Act (FISMA) 
                        <SU>992</SU>
                        <FTREF/>
                         and whether compliance with FISMA by Federal agencies that are also regulated entities would be comparable to meeting the proposals in this NPRM. FISMA requires each Federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source.
                        <SU>993</SU>
                        <FTREF/>
                         After careful consideration, the Department does not believe that a regulated entity's compliance with FISMA would necessarily ensure compliance with all applicable proposed requirements in this NPRM because FISMA's requirements and the Security Rule's requirements are designed to serve different purposes. FISMA primarily focuses on securing Federal information systems, while the Security Rule applies specifically to ePHI. This NPRM contains specific proposed requirements, not found in FISMA, which are tailored to ensure the confidentiality, integrity, and availability of ePHI. Therefore, although the Department believes that FISMA requirements are consistent with those in the Security Rule and the proposals in this NPRM, we decline to propose that compliance with FISMA requirements would be a comparable alternative to compliance with the proposals in this NPRM. Instead, we believe that FISMA requirements complement the Security Rule and the proposed requirements and will facilitate the ability of regulated entities that are also subject to FISMA to fulfill their compliance with the HIPAA Rules.
                    </P>
                    <FTNT>
                        <P>
                            <SU>992</SU>
                             Public Law 113-283 (Dec. 18, 2014) (codified at 44 U.S.C. 3551 
                            <E T="03">et seq.</E>
                            ).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>993</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <HD SOURCE="HD3">Modifications to the Definition of “Information System”</HD>
                    <P>
                        The Department considered proposing additional modifications to the definition of “information system.” The Security Rule currently defines the term “information system” as an interconnected set of information resources under the same direct management control that shares common functionality and includes hardware, software, information, data, applications, communications, and people.
                        <SU>994</SU>
                        <FTREF/>
                         This definition is based on the definition of “general support system” or “system” in the appendix to the 1996 version of OMB Circular A-130, Security of Federal Automated Information Systems.
                        <SU>995</SU>
                        <FTREF/>
                         We considered proposing to remove the phrase “under the same direct management control” as a potential way to clarify the application of the definition to cloud-based computing. Cloud computing applications play an important role in health care today. For example, many health care providers have implemented cloud-based electronic health records (EHRs) and practice management systems. These applications are used to create, receive, maintain, and transmit ePHI, and as such, should be included as components of a covered entity's relevant electronic information system, a term which is based upon the term “information system.” After careful consideration, we have decided to retain the phrase “under the same direct 
                        <PRTPAGE P="1006"/>
                        management control” and instead clarify in the preamble how the definition of “information system” applies in cloud computing environments. The Department also requests comment on the definition of “information system” and the extent of control a regulated entity has with respect to applications in cloud computing environments.
                    </P>
                    <FTNT>
                        <P>
                            <SU>994</SU>
                             45 CFR 164.304 (definition of “Information system”).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>995</SU>
                             “Managing Information as a Strategic Resource,” Circular No. A-130, Management of Federal Information Resources, Appendix III, Security of Federal Automated Information Resources, Office of Management and Budget, Executive Office of the President (Feb. 8, 1996), 
                            <E T="03">https://georgewbush-whitehouse.archives.gov/omb/circulars/a130/a130.html.</E>
                        </P>
                    </FTNT>
                    <P>
                        We also considered proposing to adopt the definition of “information system” in the Paperwork Reduction Act of 1995 (PRA) and the current operative version of OMB Circular A-130.
                        <SU>996</SU>
                        <FTREF/>
                         The PRA and OMB Circular A-130 define “information system” as “a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.” The Department declined to adopt this definition because the existing definition in the Security Rule based on the definition of “system” in the 1996 version of OMB Circular A-130 more accurately reflects the typical components of an information system and the full extent of resources that are addressed by the Security Rule. Additionally, the definition of “information system” in the PRA and current operative version of OMB Circular A-130 contains some terms that are defined by the HIPAA Rules and some that are not. As a result, adopting this definition would require the Department to propose definitions to such additional terms and to ensure that the manner in which the terms with existing definitions are used is consistent with those existing definitions, and we are concerned that such change could cause significant confusion for regulated entities.
                    </P>
                    <FTNT>
                        <P>
                            <SU>996</SU>
                             Public Law 104-13, 109 Stat. 166 (May 22, 1995) (codified at 44 U.S.C. 3502(8)) (definition of “information system”); 
                            <E T="03">see also</E>
                             “Managing Information as a Strategic Resource,” Circular No. A-130, Office of Management and Budget, Executive Office of the President, p. 31 (Jul. 28, 2016), (definition of “information system”) 
                            <E T="03">https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/circulars/A130/a130revised.pdf.</E>
                        </P>
                    </FTNT>
                    <P>We do not believe that either of the alternative definitions considered would have generated a quantifiable change in costs because the alternatives would be clarifications to existing requirements and would not have changed the scope of the Security Rule's applicability.</P>
                    <HD SOURCE="HD3">Exception From Multi-Factor Authentication (MFA) Requirement</HD>
                    <P>
                        The Department considered proposing an exception to the MFA authentication requirement that would permit regulated entities in the future to adopt other technologies, in lieu of MFA, that might offer a more secure method of authenticating user identity.
                        <SU>997</SU>
                        <FTREF/>
                         Based on discussions with cybersecurity experts, the Department believes that MFA is likely to remain the most secure method for authenticating user identity in future years. It may take different forms, but it will still, at its core, meet the definition of MFA proposed in this NPRM for the foreseeable future.
                        <SU>998</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>997</SU>
                             Proposed 45 CFR 164.312(f)(2)(ii).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>998</SU>
                             45 CFR 164.304 (proposed definition of “Multi-factor authentication”).
                        </P>
                    </FTNT>
                    <P>While the Department acknowledges that technology will continue to evolve, we are unable to predict when and whether future technology will address identity verification and exceed the level of protection offered by MFA. This uncertainty renders us unable to articulate requirements specific enough to justify a purposeful exception. Because of the uncertainty surrounding new technologies, we are also unable to estimate costs of adopting this alternative. Our current view is that proposing and codifying such an exception would be premature, but we will revisit the proposed specific requirement for MFA, if adopted, and reconsider the need for an exception should a more secure technology emerge.</P>
                    <HD SOURCE="HD3">Transition for Business Associates and Group Health Plans</HD>
                    <P>The Department considered requiring regulated entities to comply with all of the proposals in this NPRM by the compliance date, rather than proposing transition provisions for existing business associate agreements or other contractual arrangements. Had the Department taken that approach, we would have proposed that regulated entities update all existing business associate agreements by the proposed compliance date to comply with all applicable proposed requirements in this NPRM. While the Department believes that many of the proposals in this NPRM are consistent with the Security Rule as it currently exists, we are also concerned that too many regulated entities are not currently compliant with the Security Rule. Given the demonstrable increase in breaches, we believe that it is more important for regulated entities to first improve their cybersecurity posture by coming into compliance with all applicable proposed requirements in this NPRM, if adopted. Upon doing so, the Department anticipates that regulated entities will be better positioned to evaluate their contractual needs and to modify existing business associate agreements. For this reason, the Department has proposed the transition provisions in proposed 45 CFR 164.318. Not allowing for a transition period could have an opportunity cost whereby regulated entities spend their limited time revising business associate agreements instead of enhancing their cybersecurity posture. The Department believes that this could result in duplicative costs because some regulated entities may identify the need for additional changes to business associate agreements after they have fully evaluated their changed cybersecurity needs. The Department estimates that small regulated entities may be more likely to experience that outcome without a transition period, and thus the alternative of no transition period would cause a potential one-time increase in costs of $278,332,891 [(1,822,600 regulated entities × .9) × 1 hour × $169.68 lawyer hourly wage].</P>
                    <P>Relatedly, the Department considered proposing similar transition provisions for group health plans and plan sponsors that would provide these entities with additional time to update plan documents to align with new proposed requirements in this NPRM, if adopted. However, the Department believes that affected plans and plan sponsors would be able to complete any necessary updates by the proposed compliance date. The Department believes that updating plan documents is not as complex a task as evaluating potential new contractual needs to meet business associate obligations. Additionally, plan sponsors do not have Security Rule obligations independent of plan documents, and thus would not be obligated to implement the requirements proposed in this NPRM absent updates to the plan documents. The result of a transition period for updating plan documents would be merely to delay compliance with the changed Security Rule requirements, and therefore, delay improvements to their cybersecurity posture, not to reduce costs. Accordingly, we are not proposing such transition provisions in this NPRM.</P>
                    <HD SOURCE="HD2">C. Regulatory Flexibility Act—Small Entity Analysis</HD>
                    <P>
                        The Department has examined the economic implications of this proposed rule as required by the RFA. If a rule has a significant economic impact on a substantial number of small entities, the RFA requires agencies to analyze regulatory options that would reduce the economic effect of the rule on small entities. As discussed in greater detail below, this analysis concludes, and the Secretary proposes to certify, that the proposed rule, if finalized, would not 
                        <PRTPAGE P="1007"/>
                        result in a significant economic effect on a substantial number of small entities.
                    </P>
                    <P>
                        For purposes of the RFA, small entities include small businesses, nonprofit organizations, and small governmental jurisdictions. The Act defines “small entities” as (1) a proprietary firm meeting the size standards of the SBA, (2) a nonprofit organization that is not dominant in its field, and (3) a small government jurisdiction of less than 50,000 population. The Department has determined that roughly 90 percent or more of all health care providers meet the SBA size standard for a small business as shown in table 4 or are a nonprofit organization. Therefore, the Department estimates that there would be 740,348 small entities affected by the proposals in this proposed rule.
                        <SU>999</SU>
                        <FTREF/>
                         The SBA size standard for health care providers ranges between a maximum of $9 million and $47 million in annual receipts, depending upon the type of entity, as shown in table 4, above.
                        <SU>1000</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>999</SU>
                             740,348 = 822,609 covered entities × .90.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1000</SU>
                             
                            <E T="03">See</E>
                             “Table of Small Business Size Standards,” U.S. Small Business Administration (Mar. 17, 2023), 
                            <E T="03">https://www.sba.gov/sites/sbagov/files/2023-06/Table%20of%20Size%20Standards_Effective%20March%2017%2C%202023%20%282%29.pdf.</E>
                        </P>
                    </FTNT>
                    <P>
                        With respect to health insurers, the SBA size standard is a maximum of $47 million in annual receipts, and for pharmacy benefits and clearinghouses it is $45.5 million.
                        <SU>1001</SU>
                        <FTREF/>
                         While some insurers are classified as nonprofit, it is possible they are dominant in their market. For example, a number of Blue Cross/Blue Shield insurers are organized as nonprofit entities; and yet, they dominate the health insurance market in the States where they are licensed.
                        <SU>1002</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>1001</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1002</SU>
                             “Market Share and Enrollment of Largest Three Insurers—Large Group Market,” Kaiser Family Foundation (2019), 
                            <E T="03">https://www.kff.org/other/state-indicator/market-share-and-enrollment-of-largest-three-insurers-large-group-market/?currentTimeframe=0&amp;sortModel=%7B%22colId%22:%22Location%22,%22sort%22:%22asc%22%7D.</E>
                        </P>
                    </FTNT>
                    <P>
                        With respect to business associates, they provide a wide range of services for covered entities, including computer infrastructure, clearinghouse activities, leased office equipment, and professional services, such as legal, accounting, business planning, and marketing. The SBA size thresholds for these industries ranges from $15.5 million for lawyers to $47 million for clearinghouses.
                        <SU>1003</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>1003</SU>
                             
                            <E T="03">See</E>
                             “Table of Small Business Size Standards,” 
                            <E T="03">supra</E>
                             note 1000.
                        </P>
                    </FTNT>
                    <P>
                        For the reasons stated below, the Department does not expect that the cost of compliance would be significant for small entities. Nor does the Department expect that the cost of compliance would fall disproportionately on small entities. Although many of the regulated entities affected by the proposals in this proposed rule are small entities, they would not bear a disproportionate cost burden compared to the other entities subject to the rule. The projected total costs are discussed in detail in the RIA. The Department does not view this as a substantial burden because the result of the changes would be annualized costs per regulated entity of approximately $1,235 [= $2.3 billion 
                        <SU>1004</SU>
                        <FTREF/>
                        /1,822,600 regulated entities]. The per-entity costs represent the costs per establishment. As a result, smaller entities' costs are lower because they have fewer establishments. Larger regulated entities (
                        <E T="03">i.e.,</E>
                         firms) that have multiple facilities (
                        <E T="03">i.e.,</E>
                         establishments) would experience higher costs than the average cost per establishment because each firm would need to apply the proposals to all of their establishments. In the context of the RFA, HHS generally considers an economic impact exceeding 3 percent of annual revenue to be significant, and 5 percent or more of the affected small entities within an identified industry to represent a substantial number.
                    </P>
                    <FTNT>
                        <P>
                            <SU>1004</SU>
                             This figure is rounded and represents annualized costs discounted at a 2 percent rate. The actual figure is $2,251,258,305.
                        </P>
                    </FTNT>
                    <P>
                        More than 5 percent of the small covered entities listed under the NAICS codes in table 4 are one-establishment firms with fewer than five employees,
                        <SU>1005</SU>
                        <FTREF/>
                         so the analysis must determine how the effects of the quantified costs on one-establishment firms compare to their revenues. As explained above, the cost for a one-establishment firm is $1,235, so only small firms whose revenues are below $41,167 [=$1,235/0.03] would experience an effect exceeding 3 percent.
                    </P>
                    <FTNT>
                        <P>
                            <SU>1005</SU>
                             SUSB 2017 reports average revenue per firm by employment size. The size categories begin with less than 5 employees followed by 5 to 10 employees, and so on, with the largest categories representing firms with 2,500 to 4,999 employees and 5,000 or more employees). “2017 [Statistics of U.S. Businesses] Annual Data Tables by Establishment Industry,” (May 2021), 
                            <E T="03">https://www.census.gov/data/tables/2017/econ/susb/2017-susb-annual.html.</E>
                             We inflated these revenues to 2021 dollars using the GDP deflator to estimate average revenues in each employment class in 2021 because that is the latest year for which data is reported. 
                            <E T="03">See</E>
                             “2021 [Statistics of U.S. Businesses] SUSB Annual Data Tables by Establishment Industry,” 
                            <E T="03">supra</E>
                             note 947. We then concluded that more than 5 percent of the firms whose revenues fall below the SBA thresholds (see table 4) belong to the “fewer than 5 employees” category and operate a single establishment.
                        </P>
                    </FTNT>
                    <P>Among the NAICS codes for health care providers, the small firms with the lowest revenues are one-establishment HMO [Health Maintenance Organization] Medical Centers (NAICS 621491) with fewer than five employees, which had an estimated average yearly revenue in 2021 of $108,000. Residential Intellectual and Developmental Disability Facilities (NAICS 623210) had the second lowest revenues for one-establishment firms with fewer than five employees, with $180,000. Offices of Mental Health Practitioners (NAICS 621330) have the third lowest revenues for one-establishment firms with fewer than five employees, with $189,000. Thus, the Department believes that almost all regulated entities have annual revenues that exceed these amounts.</P>
                    <P>The Department acknowledges that there may be very small firms—namely firms without employees—whose revenues are below $41,167. We believe that such firms would comply with the regulation by purchasing services from software and web-hosting companies whose costs may increase as a result of the proposed changes. Such software and web-hosting companies would be business associates, and thus costs to them are already accounted for. We believe that, to the extent that these business associates decide to recover their minor cost increases by raising the prices of the services sold to non-employer firms, these incremental costs passed through to their small-firm customers would be negligible because they will be spread among many non-employer firms.</P>
                    <P>
                        The Department has separately analyzed the effects of the NPRM on health plan sponsors and does not view the projected costs as a significant burden because the proposed changes would result in annualized costs per plan sponsor of approximately $6,133 [=$4,552,995,816/742,411 health plan sponsors]. The quantified impact of $6,133 per health plan sponsor would only apply to those sponsors whose annual revenue is $204,433 or less.
                        <SU>1006</SU>
                        <FTREF/>
                         The Department believes there are few, if any, group health plan sponsors with annual revenues below this amount because the average revenue of a U.S. business with 1-4 employees is $387,000 
                        <SU>1007</SU>
                        <FTREF/>
                         and employers with 0-1 employees are unlikely to sponsor a group health plan.
                    </P>
                    <FTNT>
                        <P>
                            <SU>1006</SU>
                             $6,133 is 3 percent of $204,433.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1007</SU>
                             “Average Small Business Revenue: What To Know,” Fora Financial (Jan. 11, 2023), 
                            <E T="03">https://www.forafinancial.com/blog/small-business/average-small-business-revenue/.</E>
                        </P>
                    </FTNT>
                    <P>
                        Accordingly, the Department believes that this proposed rule, if adopted, would be unlikely to affect a substantial 
                        <PRTPAGE P="1008"/>
                        number of small entities that meet the RFA threshold. Thus, this analysis concludes, and the Secretary proposes to certify, that the NPRM would not result in a significant economic effect on a substantial number of small entities.
                    </P>
                    <P>
                        HIPAA requires the Department to consider the needs and capabilities of small and rural health care providers.
                        <SU>1008</SU>
                        <FTREF/>
                         As we explained in our 2003 analysis of the effect of the Security Rule on small and rural health care providers, the scalability provisions preclude the need to precisely define those categories.
                        <SU>1009</SU>
                        <FTREF/>
                         We have long considered the effect of our rules on small businesses in the Small Entity Analysis discussed above. However, because of the breadth of changes proposed in this NPRM, the Department has considered more closely how it would affect rural health care providers. There are approximately 2,000 rural hospitals,
                        <SU>1010</SU>
                        <FTREF/>
                         comprising nearly 30 percent of all hospitals [= 2,057/7,465],
                        <SU>1011</SU>
                        <FTREF/>
                         and the Department estimates approximately 7 to 8 percent of all health care providers operate in rural areas (counties or micropolitan areas with fewer than 50,000 inhabitants). See Regulated Entities Affected in Section V.A.2. Baseline Conditions, above.
                    </P>
                    <FTNT>
                        <P>
                            <SU>1008</SU>
                             42 U.S.C. 1320d-2(d).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1009</SU>
                             
                            <E T="03">See</E>
                             68 FR 8334, 8341 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1010</SU>
                             
                            <E T="03">See</E>
                             “Fact Sheet: Biden-Harris Administration Bolsters Protections for Americans' Access to Healthcare Through Strengthening Cybersecurity,” 
                            <E T="03">supra</E>
                             note 306. 
                            <E T="03">See also</E>
                             table 4 above, SBA size threshold for hospitals.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1011</SU>
                             
                            <E T="03">See</E>
                             “2021 [Statistics of U.S. Businesses] SUSB Annual Data Tables by Establishment Industry,” 
                            <E T="03">supra</E>
                             note 947 (count of hospitals).
                        </P>
                    </FTNT>
                    <P>
                        Because rural health care providers are more likely to be small businesses, they would be affected in a manner similar to small entities, as demonstrated in the Small Entity Analysis above. Likewise, to the extent that Tribal health care providers are in rural areas, which many are,
                        <SU>1012</SU>
                        <FTREF/>
                         our analysis of the effects on rural health care providers generally also applies. However, Tribal health providers have the benefit of access to centralized supportive services for health IT and EHR adoption, which other rural providers may lack.
                        <SU>1013</SU>
                        <FTREF/>
                         A primary barrier to both adoption of health information technology (health IT) and deployment of cybersecurity safeguards in rural communities is limited access to high-speed internet. Rural health care providers, such as hospitals, have adopted EHRs at a lower rate than non-rural hospitals,
                        <SU>1014</SU>
                        <FTREF/>
                         and thus may also have fewer electronic information systems that are subject to the Security Rule requirements, which could ease some burdens of compliance. However, as EHR adoption has increased in rural hospitals,
                        <SU>1015</SU>
                        <FTREF/>
                         so too have the risks of cybersecurity attacks.
                        <SU>1016</SU>
                        <FTREF/>
                         Rural health care providers are more likely to have limited resources to update legacy information technology (IT) systems, implement new or changed regulatory requirements, and respond to large breaches. Additionally, the health IT workforce is more limited in rural areas, which may affect the ability of rural health care providers to access in-person technical assistance. Because most rural hospitals are “located more than 35 miles from another hospital,” responding to cyberattacks may be more challenging.
                        <SU>1017</SU>
                        <FTREF/>
                         We request comment on the burdens these proposals would impose on rural health care providers, including rural hospitals.
                    </P>
                    <FTNT>
                        <P>
                            <SU>1012</SU>
                             The Indian Health Service funds a “network of over 600 hospitals, clinics, and health stations on or near Indian reservations in service areas that are rural, isolated, and underserved.” “Justification of Estimates for Appropriations Committees, Fiscal Year 2025” Indian Health Service, U.S. Department of Health and Human Services, p. CJ-39 (Mar. 5, 2024).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1013</SU>
                             
                            <E T="03">See id.</E>
                             at p. CJ-63-75.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1014</SU>
                             
                            <E T="03">See</E>
                             “Telehealth and Health Information Technology in Rural Healthcare,” Rural Health Information Hub, 
                            <E T="03">https://www.ruralhealthinfo.org/topics/telehealth-health-it#challenges-for-rural-communities.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1015</SU>
                             
                            <E T="03">See</E>
                             “Percent of Hospitals, By Type, that Possess Certified Health IT,” 
                            <E T="03">supra</E>
                             note 298.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1016</SU>
                             Kat Jercich, “Rural hospitals are more vulnerable to cyberattacks—here's how they can protect themselves,” 
                            <E T="03">supra</E>
                             note 295.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1017</SU>
                             
                            <E T="03">See</E>
                             “Fact Sheet: Biden-Harris Administration Bolsters Protections for Americans' Access to Healthcare Through Strengthening Cybersecurity,” s
                            <E T="03">upra</E>
                             note 306.
                        </P>
                    </FTNT>
                    <P>
                        Rural health care providers and other regulated entities can avail themselves of grants and incentives to improve broadband access and adoption of health IT.
                        <SU>1018</SU>
                        <FTREF/>
                         For cybersecurity in particular, the White House, in partnership with private companies, announced the availability of direct assistance to rural health care providers on cybersecurity in the form of grants, discounts, and technical advice.
                        <SU>1019</SU>
                        <FTREF/>
                         Additionally, CISA has compiled a list of free services and tools available to regulated entities from private and public sector entities. CISA also has published, in partnership with the Joint Cyber Defense Collaborative, a list of cybersecurity resources especially focused on high-risk communities.
                        <SU>1020</SU>
                        <FTREF/>
                         And the Advanced Research Projects Agency for Health announced plans to invest $50 million to develop an autonomous solution for addressing cyberthreats to assist hospitals in defending their information systems.
                        <SU>1021</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>1018</SU>
                             Hannah Neprash, et al., “What happens to rural hospitals during a ransomware attack? Evidence from Medicare data,” The Journal of Rural Health (Mar. 17, 2024), 
                            <E T="03">https://pubmed.ncbi.nlm.nih.gov/38494590/.</E>
                             For information about grants and incentives available for improving broadband access and adoption of health IT, 
                            <E T="03">see, e.g.,</E>
                             “Funding Programs,” BroadbandUSA, National Telecommunications and Information Administration, U.S. Department of Commerce, 
                            <E T="03">https://broadbandusa.ntia.doc.gov/funding-programs;</E>
                             “Rural Health Care Program,” Federal Communications Commission, 
                            <E T="03">https://www.fcc.gov/general/rural-health-care-program.</E>
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1019</SU>
                             
                            <E T="03">See</E>
                             “Fact Sheet: Biden-Harris Administration Bolsters Protections for Americans' Access to Healthcare Through Strengthening Cybersecurity,” s
                            <E T="03">upra</E>
                             note 306.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1020</SU>
                             
                            <E T="03">See, e.g.,</E>
                             “Free Cybersecurity Services and Tools,” 
                            <E T="03">supra</E>
                             note 313; “Cybersecurity Resources for High-Risk Communities,” 
                            <E T="03">supra</E>
                             note 313.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1021</SU>
                             
                            <E T="03">See</E>
                             “Fact Sheet: Biden-Harris Administration Bolsters Protections for Americans' Access to Healthcare Through Strengthening Cybersecurity,” s
                            <E T="03">upra</E>
                             note 306; 
                            <E T="03">see also</E>
                             “UPGRADE, Universal Patching and Remediation for Autonomous Defense,” Advanced Research Projects Agency for Health (May 20, 2024), 
                            <E T="03">https://arpa-h.gov/research-and-funding/programs/upgrade.</E>
                        </P>
                    </FTNT>
                    <P>
                        Cybersecurity is as essential for small and rural health care providers and their business associates, as it is for large and urban regulated entities. The seamless flow of data and increased connectivity means that threats to one health care provider do not affect only that one health care provider, regardless of size or location. The effects on patient care may be greater in rural environments where fewer alternatives exist if care is delayed or denied as a result of a cyberattack or malfunction.
                        <SU>1022</SU>
                        <FTREF/>
                         As discussed in the preamble, the factors described at 45 CFR 164.306(b)(2) provide the flexibility for small and rural providers, in particular, to adopt security measures that are reasonable and appropriate for their circumstances.
                    </P>
                    <FTNT>
                        <P>
                            <SU>1022</SU>
                             “What happens to rural hospitals during a ransomware attack? Evidence from Medicare data,” s
                            <E T="03">upra</E>
                             note 1018.
                        </P>
                    </FTNT>
                    <HD SOURCE="HD2">D. Executive Order 13132—Federalism</HD>
                    <P>
                        As required by E.O. 13132 on Federalism,
                        <SU>1023</SU>
                        <FTREF/>
                         the Department has examined the provisions in the proposed regulation for their effects on the relationship between the Federal Government and the States. E.O. 13132 establishes certain requirements that an agency must meet when it promulgates a proposed rule (and subsequent final rule) that imposes substantial direct requirement costs on State and local governments, preempts State law, or otherwise has federalism implications. In the Department's view, the proposed rule would not have any federalism implications.
                    </P>
                    <FTNT>
                        <P>
                            <SU>1023</SU>
                             64 FR 43255 (Aug. 4, 1999).
                        </P>
                    </FTNT>
                    <P>
                        The federalism implications of the Security Rule were also assessed as required by E.O. 13132 and published as part of the preambles to the final rules on February 20, 2003 
                        <SU>1024</SU>
                        <FTREF/>
                         and January 
                        <PRTPAGE P="1009"/>
                        25, 2013.
                        <SU>1025</SU>
                        <FTREF/>
                         Regarding preemption, HIPAA dictates the relationship between State law and HIPAA regulatory requirements.
                        <SU>1026</SU>
                        <FTREF/>
                         The Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act) provides that the HIPAA preemption provisions shall apply to the HITECH Act provisions and requirements.
                        <SU>1027</SU>
                        <FTREF/>
                         As explained by the House report that accompanied the American Recovery and Reinvestment Act of 2009, the HITECH Act would not only apply HIPAA's preemption provisions to the HITECH Act requirements, but it would also “preserve the HIPAA privacy and security standards to the extent that they are consistent with” the HITECH Act.
                        <SU>1028</SU>
                        <FTREF/>
                    </P>
                    <FTNT>
                        <P>
                            <SU>1024</SU>
                             68 FR 8334, 8373 (Feb. 20, 2003).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1025</SU>
                             78 FR 5566, 5686 (Jan. 25, 2013).
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1026</SU>
                             42 U.S.C. 1320d-7.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1027</SU>
                             Sec. 13421(a) of the HITECH Act; 
                            <E T="03">see also</E>
                             45 CFR part 160, subpart B.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1028</SU>
                             
                            <E T="03">See</E>
                             “MAKING SUPPLEMENTAL APPROPRIATIONS FOR JOB PRESERVATION AND CREATION, INFRASTRUCTURE INVESTMENT, ENERGY EFFICIENCY AND SCIENCE, ASSISTANCE TO THE UNEMPLOYED, AND STATE AND LOCAL FISCAL STABILIZATION, FOR THE FISCAL YEAR ENDING SEPTEMBER 30, 2009, AND FOR OTHER PURPOSES,” Conf. Report to Accompany H.R. 1, p. 502 (Feb. 12, 2009).
                        </P>
                    </FTNT>
                    <P>
                        A requirement, standard, or implementation specification adopted in accordance with HIPAA and the HIPAA Rules supersedes any contrary provision of State law, subject to certain exceptions.
                        <SU>1029</SU>
                        <FTREF/>
                         Specifically, State law would be preempted under the Security Rule only when (1) a regulated entity finds it impossible to comply with both State and Federal requirements; or (2) the provision of State law stands as an obstacle to accomplishing and executing the purposes and objectives of the Administrative Simplification provisions or the HITECH Act.
                        <SU>1030</SU>
                        <FTREF/>
                         Although a few States (
                        <E T="03">e.g.,</E>
                         California and New York) have promulgated or are in the process of promulgating regulations pertaining to cybersecurity in health care that may be more stringent than the Security Rule, the Department believes that a regulated entity could comply with both sets of requirements by adhering to the more stringent standard. Thus, in such cases, the State law would not be an obstacle to the accomplishment and execution of HIPAA or the HITECH Act.
                    </P>
                    <FTNT>
                        <P>
                            <SU>1029</SU>
                             42 U.S.C. 1320d-7(a); 45 CFR 160.203.
                        </P>
                    </FTNT>
                    <FTNT>
                        <P>
                            <SU>1030</SU>
                             
                            <E T="03">See</E>
                             45 CFR 160.202 (definition of “Contrary”). Preemption also applies if the provision of State law stands as an obstacle to the accomplishment and execution of the full purposes and objectives and purposes of sec. 264 of HIPAA. Sec. 264 of HIPAA contains the provisions pertaining to the privacy of individually identifiable health information.
                        </P>
                    </FTNT>
                    <P>The proposed modifications to the Security Rule would further the Congressional intent to improve the Medicare and Medicaid programs by the development of health information systems that are private and secure. The Department's proposals promote the safety, efficiency, and effectiveness of the health care system by refining the security standards established by Congress and implemented in the 2003 and 2013 Final Rules. The statute contemplated that the security measures adopted by all regulated entities, including State and local governments, would evolve over time in accordance with the security risks they face, and the NPRM proposals are in the nature of enhancing these existing requirements. Thus, the Department does not believe that the rule would impose substantial direct compliance costs on State and local governments that are not required by statute.</P>
                    <P>The Department anticipates that the most significant direct costs on State and local governments would be for conducting a Security Rule compliance audit; notifying covered entities or business associates, as applicable, upon activation of a contingency plan; notifying covered entities of changes or termination of workforce members' access to ePHI; deploying MFA; removing extraneous software; and penetration testing; providing or obtaining verification of business associates' compliance with technical safeguards; updating health plan documents; updating policies and procedures; and updating workforce training. However, the costs involved can be attributed to the statutory requirements of the Administrative Simplification provisions of HIPAA and would be similar in kind to those borne by non-government-operated regulated entities, which the proposed RIA above addresses in detail.</P>
                    <P>In considering the principles in and requirements of E.O. 13132, the Department believes that these proposed modifications to the Security Rule would not significantly affect the rights, roles, and responsibilities of the States and requests comment on this analysis.</P>
                    <HD SOURCE="HD2">E. Assessment of Federal Regulation and Policies on Families</HD>
                    <P>
                        Section 654 of the Treasury and General Government Appropriations Act of 1999 
                        <SU>1031</SU>
                        <FTREF/>
                         requires Federal departments and agencies to determine whether a proposed policy or regulation could affect family well-being. If the determination is affirmative, then the Department or agency must prepare an impact assessment to address criteria specified in the law. This proposed rule is expected to strengthen family well-being because it would ensure a baseline of security measures for individuals' PHI, and medical information and decisions based on that information are at the heart of family decision making. If finalized, the provisions in this proposed rule may be carried out only by the Federal Government because it would modify Federal law on cybersecurity in health care, ensuring that American families have confidence that the privacy of their PHI is secured by consistent safeguards, regardless of the State where they are located when health care is provided. Such health care privacy and is vital for individuals who seek or access health care.
                    </P>
                    <FTNT>
                        <P>
                            <SU>1031</SU>
                             Public Law 105-277, 112 Stat. 2681-528 (Oct. 21, 1998) (codified at 5 U.S.C. 601 note).
                        </P>
                    </FTNT>
                    <HD SOURCE="HD2">F. Paperwork Reduction Act of 1995</HD>
                    <P>
                        Under the PRA,
                        <SU>1032</SU>
                        <FTREF/>
                         agencies are required to submit to OMB for review and approval any reporting or recordkeeping requirements inherent in a proposed or final rule and are required to publish such proposed requirements for public comment. To fairly evaluate whether an information collection should be approved by the OMB, section 3506(c)(2)(A) of the PRA requires that the Department solicit comment on the following issues:
                    </P>
                    <FTNT>
                        <P>
                            <SU>1032</SU>
                             Public Law 104-13, 109 Stat. 163 (May 22, 1995) (codified at 44 U.S.C. 101 note).
                        </P>
                    </FTNT>
                    <P>1. Whether the information collection is necessary and useful to carry out the proper functions of the agency.</P>
                    <P>2. The accuracy of the agency's estimate of the information collection burden.</P>
                    <P>3. The quality, utility, and clarity of the information to be collected.</P>
                    <P>4. Recommendations to minimize the information collection burden on the affected public, including automated collection techniques.</P>
                    <P>The PRA requires consideration of the time, effort, and financial resources necessary to meet the information collection requirements referenced in this section. The Department solicits public comments on its assumptions and burden estimates in this NPRM as summarized below.</P>
                    <P>
                        In this RIA, the Department proposes to revise certain information collection requirements associated with this NPRM and, as such, would revise the information collection last prepared in 2024 and approved under OMB control #0945-0003.
                        <SU>1033</SU>
                        <FTREF/>
                         The proposed revisions to the information collection describe all new and adjusted information 
                        <PRTPAGE P="1010"/>
                        collection requirements for regulated entities pursuant to the implementing regulation for HIPAA at 45 CFR parts 160 and 164, the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules (“HIPAA Rules”).
                    </P>
                    <FTNT>
                        <P>
                            <SU>1033</SU>
                             “View ICR,” 
                            <E T="03">supra</E>
                             note 940.
                        </P>
                    </FTNT>
                    <P>The estimated annual labor burden presented by the regulatory modifications is 77,067,552 burden hours at a first-year cost of $9,314,106,174. These figures, respectively, represent the sum of 37,781,637 new burden hours at a cost of $4,655,324,954 for compliance by regulated entities and 39,285,915 new burden hours at a cost of $4,658,781,219 for compliance by health plan sponsors.</P>
                    <P>
                        The overall total burden for respondents to comply with the information collection requirements of all of the HIPAA Privacy, Security, and Breach Notification Rules, including new burdens presented by proposed program changes, is estimated to be 925,144,023 burden hours at a cost of $109,085,104,674, plus $163,499,411 in capital costs for a total estimated annual burden of $109,248,604,085, after the effective date of the final rule. This estimate is based on a total of 1,202,562,864 responses for a total of 2,565,011 respondents. The total burden for the HIPAA Rules, including the changes proposed in this NPRM, would result in a decrease of 28,838,213 burden hours and a cost increase of $1,911,898,144, in comparison to the baseline in the ICR associated with the 2024 Privacy Rule to Support Reproductive Health Care Privacy.
                        <SU>1034</SU>
                        <FTREF/>
                         This is the result of multiples changes, such as decreasing burden hours for some existing requirements, increasing the estimated number of covered entities, adding new Security Rule requirements, and expanding the pool of respondents for the Security Rule by adding requirements for health plan sponsors.
                    </P>
                    <FTNT>
                        <P>
                            <SU>1034</SU>
                             
                            <E T="03">Id.</E>
                        </P>
                    </FTNT>
                    <P>Details describing the burden analysis for the proposals associated with this RIA are presented below and explained further in the ICR associated with the NPRM.</P>
                    <HD SOURCE="HD3">1. Explanation of Estimated Annualized Burden Hours</HD>
                    <P>Below is a summary of the significant program changes and adjustments proposed since the approved 2024 ICR; because the ICR addresses regulatory burdens associated with the full suite of HIPAA Rules, the changes and adjustments include updated data and estimates for some provisions of the HIPAA Rules that are not affected by this proposed rule. These program changes and adjustments form the bases for the burden estimates presented in the ICR associated with this NPRM.</P>
                    <HD SOURCE="HD3">Adjusted Estimated Annual Burdens of Compliance</HD>
                    <P>(1) Updating the number of covered entities.</P>
                    <P>(2) Updating hourly wage rates.</P>
                    <P>(3) Adjusting downward the number of estimated requests for an exception to Federal preemption of State law to the prior baseline of 1 request per year.</P>
                    <P>(4) Adjusting downward the estimated hourly burden for regulated entities to report security incidents (not breaches) from 20 hours per monthly report to 10 hours per monthly report.</P>
                    <P>(5) Updating the number of research disclosures.</P>
                    <HD SOURCE="HD3">New Burdens Resulting From Program Changes</HD>
                    <P>In addition to the adjustments above, the Department proposes to add new annual estimated burdens as a result of program changes, as follows:</P>
                    <P>(1) A burden of 2 hours for each regulated entity to conduct a Security Rule compliance audit.</P>
                    <P>(2) A burden of 2 hours for each business associate (including each subcontractor) to provide verification of compliance with technical safeguards.</P>
                    <P>(3) A burden of .5 hours for each covered entity to obtain verification of business associates' compliance with technical safeguards.</P>
                    <P>(4) A burden of .083 hours for each business associate to obtain verification of subcontractors' compliance with technical safeguards.</P>
                    <P>(5) A burden of 1 hour for each regulated entity to provide notification to other regulated entities of workforce members' termination of access to ePHI.</P>
                    <P>(6) A burden of 1.5 hours for each regulated entity to deploy MFA.</P>
                    <P>(7) A burden of 4.5 hours for each regulated entity to perform network segmentation.</P>
                    <P>(8) A burden of .5 hours for approximately 76.56 percent of regulated entities to disable unused ports and remove extraneous software.</P>
                    <P>(9) A burden of 3 hours for each regulated entity to conduct penetration testing.</P>
                    <P>(10) A burden of .5 hours for each regulated entity to notify covered entities or business associates, as applicable, upon activation of a contingency plan.</P>
                    <P>(11) A burden of .5 hours for each insurer and third-party administrator to update health plan documents.</P>
                    <P>(12) A burden of 2 hours for each regulated entity to update the content of its cybersecurity awareness and Security Rule training program.</P>
                    <P>(13) A burden of 3.5 hours for each regulated entity to update its policies and procedures.</P>
                    <P>(14) A burden of 1 hour for each regulated entity to update business associate agreements.</P>
                    <P>(15) A burden of 52.92 hours for each health plan sponsor to modify safeguards for its relevant electronic information systems to meet Security Rule standards.</P>
                    <LSTSUB>
                        <HD SOURCE="HED">List of Subjects</HD>
                        <CFR>45 CFR Part 160</CFR>
                        <P>Administrative practice and procedure, Computer technology, Electronic information system, Electronic transactions, Employer benefit plan, Group health plan, Health, Health care, Health facilities, Health insurance, Health professions, Health records, Hospitals, Investigations, Medicaid, Medical Research, Medicare, Penalties, Preemption, Privacy, Public health, Reporting and recordkeeping requirements, Security.</P>
                        <CFR>45 CFR Part 164</CFR>
                        <P>Administrative practice and procedure, Computer technology, Drug abuse, Electronic information system, Electronic transactions, Employer benefit plan, Group health plan, Health, Health care, Health facilities, Health insurance, Health professions, Health records, Hospitals, Medicaid, Medical research, Medicare, Privacy, Public health, Reporting and recordkeeping requirements, Security.</P>
                    </LSTSUB>
                    <HD SOURCE="HD1">Proposed Rule</HD>
                    <P>For the reasons stated in the preamble, the Department of Health and Human Services proposes to amend 45 CFR subtitle A, subchapter C, parts 160 and 164 as set forth below:</P>
                    <PART>
                        <HD SOURCE="HED">PART 160—GENERAL ADMINISTRATIVE REQUIREMENTS</HD>
                    </PART>
                    <AMDPAR>1. The authority citation for part 160 continues to read as follows:</AMDPAR>
                    <AUTH>
                        <HD SOURCE="HED">Authority:</HD>
                        <P> 42 U.S.C. 1302(a); 42 U.S.C. 1320d-1320d-9; sec. 264, Pub. L. 104-191, 110 Stat. 2033-2034 (42 U.S.C. 1320d-2 (note)); 5 U.S.C. 552; secs. 13400-13424, Pub. L. 111-5, 123 Stat. 258-279; and sec. 1104 of Pub. L. 111-148, 124 Stat. 146-154.</P>
                    </AUTH>
                    <AMDPAR>2. Amend § 160.103 by revising the definition of “Electronic media” to read as follows:</AMDPAR>
                    <SECTION>
                        <SECTNO>§ 160.103</SECTNO>
                        <SUBJECT>Definitions.</SUBJECT>
                        <STARS/>
                        <P>
                            <E T="03">Electronic media</E>
                             means:
                        </P>
                        <P>
                            (1) Electronic storage material on which data may be recorded, maintained, or processed. This includes, but is not limited to, hard drives, 
                            <PRTPAGE P="1011"/>
                            removable media, magnetic tape, optical disk, and any other form of digital memory or storage.
                        </P>
                        <P>(2) Transmission media used to exchange information already in electronic storage material. Transmission media includes, but is not limited to, the internet, extranet or intranet, leased lines, dial-up lines, private and public networks, and the physical movement of removable/transportable electronic storage material.</P>
                        <STARS/>
                    </SECTION>
                    <PART>
                        <HD SOURCE="HED">PART 164—SECURITY AND PRIVACY</HD>
                    </PART>
                    <AMDPAR>1. The authority citation for part 164 continues to read as follows:</AMDPAR>
                    <AUTH>
                        <HD SOURCE="HED">Authority: </HD>
                        <P>42 U.S.C. 1302(a); 42 U.S.C. 1320d-1320d-9; sec. 264, Pub. L. 104-191, 110 Stat. 2033-2034 (42 U.S.C. 1320d-2(note)); and secs. 13400-13424, Pub. L. 111-5, 123 Stat. 258-279.</P>
                    </AUTH>
                    <AMDPAR>2. Revise and republish subpart C to read as follows:</AMDPAR>
                    <SUBPART>
                        <HD SOURCE="HED">Subpart C—Security Standards for the Protection of Electronic Protected Health Information</HD>
                    </SUBPART>
                    <CONTENTS>
                        <SECHD>Sec.</SECHD>
                        <SECTNO>164.302</SECTNO>
                        <SUBJECT>Applicability.</SUBJECT>
                        <SECTNO>164.304</SECTNO>
                        <SUBJECT>Definitions.</SUBJECT>
                        <SECTNO>164.306</SECTNO>
                        <SUBJECT>Security standards: General rules.</SUBJECT>
                        <SECTNO>164.308</SECTNO>
                        <SUBJECT>Administrative safeguards.</SUBJECT>
                        <SECTNO>164.310</SECTNO>
                        <SUBJECT>Physical safeguards.</SUBJECT>
                        <SECTNO>164.312</SECTNO>
                        <SUBJECT>Technical safeguards.</SUBJECT>
                        <SECTNO>164.314</SECTNO>
                        <SUBJECT>Organizational requirements.</SUBJECT>
                        <SECTNO>164.316</SECTNO>
                        <SUBJECT>Documentation requirements.</SUBJECT>
                        <SECTNO>164.318</SECTNO>
                        <SUBJECT>Transition provisions.</SUBJECT>
                        <SECTNO>164.320</SECTNO>
                        <SUBJECT>Severability.</SUBJECT>
                        <FP SOURCE="FP-1">Appendix A to Subpart C of Part 164—Security Standards: Matrix</FP>
                    </CONTENTS>
                    <AUTH>
                        <HD SOURCE="HED">Authority: </HD>
                        <P>42 U.S.C. 1320d-2 and 1320d-4; 42 U.S.C. 17931.</P>
                    </AUTH>
                    <SECTION>
                        <SECTNO>§ 164.302</SECTNO>
                        <SUBJECT>Applicability.</SUBJECT>
                        <P>A covered entity or business associate must comply with the applicable standards, implementation specifications, and requirements of this subpart with respect to electronic protected health information of a covered entity.</P>
                    </SECTION>
                    <SECTION>
                        <SECTNO>§ 164.304</SECTNO>
                        <SUBJECT>Definitions.</SUBJECT>
                        <P>As used in this subpart, the following terms have the following meanings:</P>
                        <P>
                            <E T="03">Access</E>
                             means the ability or the means necessary to read, write, modify, delete, transmit, or communicate data/information or otherwise use any component of an information system. (This definition applies to “access” as used in this subpart, not as used in subpart D or E of this part.)
                        </P>
                        <P>
                            <E T="03">Administrative safeguards</E>
                             are administrative actions and related policies and procedures to manage the selection, development, implementation, and maintenance (including updating and modifying) of security measures to protect electronic protected health information, and to manage the conduct of the covered entity's or business associate's workforce in relation to the protection of that information.
                        </P>
                        <P>
                            <E T="03">Authentication</E>
                             means the corroboration that a person or technology asset is the one they are claiming to be.
                        </P>
                        <P>
                            <E T="03">Availability</E>
                             means the property that data or information is accessible and useable upon demand by an authorized person or technology asset.
                        </P>
                        <P>
                            <E T="03">Confidentiality</E>
                             means the property that data or information is not made available or disclosed to unauthorized persons, technology assets, or processes.
                        </P>
                        <P>
                            <E T="03">Deploy</E>
                             means to configure technology for use and implement such technology.
                        </P>
                        <P>
                            <E T="03">Electronic information system</E>
                             means interconnected set of electronic information resources under the same direct management control that shares common functionality. An electronic information system generally includes technology assets, such as hardware, software, electronic media, information, and data.
                        </P>
                        <P>
                            <E T="03">Encryption</E>
                             means the use of an algorithmic process to transform data into a form in which there is a low probability of assigning meaning without use of a confidential process or key.
                        </P>
                        <P>
                            <E T="03">Facility</E>
                             means the physical premises and the interior and exterior of a building(s).
                        </P>
                        <P>
                            <E T="03">Implement</E>
                             means to put into effect and be in use, operational, and function as expected throughout the covered entity or business associate.
                        </P>
                        <P>
                            <E T="03">Information system</E>
                             means an interconnected set of information resources under the same direct management control that shares common functionality. An information system generally includes hardware, software, information, data, communications, and people.
                        </P>
                        <P>
                            <E T="03">Integrity</E>
                             means the property that data or information have not been altered or destroyed in an unauthorized manner.
                        </P>
                        <P>
                            <E T="03">Malicious software</E>
                             means software or firmware intended to perform an unauthorized action or activity that will have adverse impact on an electronic information system and/or the confidentiality, integrity, or availability of electronic protected health information. Examples include but are not limited to viruses, worms, Trojan horses, spyware, and some forms of adware.
                        </P>
                        <P>
                            <E T="03">Multi-factor authentication</E>
                             means authentication of the user's identity through verification of at least two of the following three categories:
                        </P>
                        <P>(1) Information known by the user, including but not limited to a password or personal identification number (PIN).</P>
                        <P>(2) Item possessed by the user, including but not limited to a token or a smart identification card.</P>
                        <P>(3) Personal characteristic of the user, including but not limited to fingerprint, facial recognition, gait, typing cadence, or other biometric or behavioral characteristics.</P>
                        <P>
                            <E T="03">Password</E>
                             means confidential authentication information composed of a string of characters, such as letters, numbers, spaces, and other symbols.
                        </P>
                        <P>
                            <E T="03">Physical safeguards</E>
                             are physical measures and related policies and procedures to protect a covered entity's or business associate's relevant electronic information systems, and related facilities and equipment, from natural and environmental hazards and unauthorized intrusion.
                        </P>
                        <P>
                            <E T="03">Relevant electronic information system</E>
                             means an electronic information system that creates, receives, maintains, or transmits electronic protected health information or that otherwise affects the confidentiality, integrity, or availability of electronic protected health information.
                        </P>
                        <P>
                            <E T="03">Risk</E>
                             means the extent to which the confidentiality, integrity, or availability of electronic protected health information is threatened by a potential circumstance or event.
                        </P>
                        <P>
                            <E T="03">Security</E>
                             or 
                            <E T="03">security measures</E>
                             encompass all of the administrative, physical, and technical safeguards in or applied to an information system.
                        </P>
                        <P>
                            <E T="03">Security incident</E>
                             means any of the following:
                        </P>
                        <P>(1) The attempted or successful unauthorized access, use, disclosure, modification, or destruction of information in an information system.</P>
                        <P>(2) The attempted or successful unauthorized interference with system operations in an information system.</P>
                        <P>
                            <E T="03">Technical controls</E>
                             means the technical mechanisms contained in the hardware, software, or firmware components of an electronic information system that are primarily implemented and executed by the electronic information system to protect the information system and data therein.
                        </P>
                        <P>
                            <E T="03">Technical safeguards</E>
                             means the technology, technical controls, and related policies and procedures governing the use of the technology that protects and controls access to electronic protected health information.
                        </P>
                        <P>
                            <E T="03">Technology asset</E>
                             means the components of an electronic information system, including but not 
                            <PRTPAGE P="1012"/>
                            limited to hardware, software, electronic media, information, and data.
                        </P>
                        <P>
                            <E T="03">Threat</E>
                             means any circumstance or event with the potential to adversely affect the confidentiality, integrity, or availability of electronic protected health information.
                        </P>
                        <P>
                            <E T="03">User</E>
                             means a person with authorized access.
                        </P>
                        <P>
                            <E T="03">Vulnerability</E>
                             means a flaw or weakness in an information system, information system security procedures, design, implementation, or technical controls that could be intentionally exploited or accidentally triggered by a threat.
                        </P>
                        <P>
                            <E T="03">Workstation</E>
                             means an electronic computing device and electronic media stored in its immediate environment. Workstation includes but is not limited to the following types of devices: a server, desktop computer, laptop computer, virtual device, and mobile device such as a smart phone or tablet.
                        </P>
                    </SECTION>
                    <SECTION>
                        <SECTNO>§ 164.306</SECTNO>
                        <SUBJECT>Security standards: General rules.</SUBJECT>
                        <P>
                            (a) 
                            <E T="03">General requirements.</E>
                             Each covered entity and business associate must do the following with respect to all electronic protected health information it creates, receives, maintains, or transmits:
                        </P>
                        <P>(1) Ensure the confidentiality, integrity, and availability of the electronic protected health information.</P>
                        <P>(2) Protect against any reasonably anticipated threats or hazards to the confidentiality, integrity, or availability of the electronic protected health information.</P>
                        <P>(3) Protect against any reasonably anticipated uses or disclosures of the electronic protected health information that are not permitted or required under subpart E of this part.</P>
                        <P>(4) Ensure compliance by its workforce with this subpart and all administrative, physical, and technical safeguards implemented in accordance with this subpart.</P>
                        <P>
                            (b) 
                            <E T="03">Flexibility of approach.</E>
                             (1) Covered entities and business associates may use any reasonable and appropriate security measures that allow the covered entity or business associate to implement the standards and implementation specifications as specified in this subpart.
                        </P>
                        <P>(2) In deciding which security measures to use, a covered entity or business associate must take into account all of the following factors:</P>
                        <P>(i) The size, complexity, and capabilities of the covered entity or business associate.</P>
                        <P>(ii) The covered entity's or the business associate's technical infrastructure, hardware, and software security capabilities.</P>
                        <P>(iii) The costs of security measures.</P>
                        <P>(iv) The probability and criticality of potential risks to electronic protected health information.</P>
                        <P>(v) The effectiveness of the security measure in supporting the resiliency of the covered entity or business associate.</P>
                        <P>
                            (c) 
                            <E T="03">Standards and implementation specifications.</E>
                             A covered entity or business associate must comply with the applicable standards, including their implementation specifications, as provided in this subpart.
                        </P>
                    </SECTION>
                    <SECTION>
                        <SECTNO>§ 164.308</SECTNO>
                        <SUBJECT>Administrative safeguards.</SUBJECT>
                        <P>(a) A covered entity or business associate must, in accordance with §§ 164.306 and 164.316, implement all of the following administrative safeguards to protect the confidentiality, integrity, and availability of all electronic protected health information that it creates, receives, maintains, or transmits:</P>
                        <P>
                            (1) 
                            <E T="03">Standard: Technology asset inventory</E>
                            —(i) 
                            <E T="03">General.</E>
                             Conduct and maintain an accurate and thorough written inventory and a network map of the covered entity's or business associate's electronic information systems and all technology assets that may affect the confidentiality, integrity, or availability of electronic protected health information.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Implementation specifications</E>
                            —(A) 
                            <E T="03">Inventory.</E>
                             Develop a written inventory of the covered entity's or business associate's technology assets that contains the identification, version, person accountable, and location of each technology asset.
                        </P>
                        <P>
                            (B) 
                            <E T="03">Network map.</E>
                             Develop a network map that illustrates the movement of electronic protected health information throughout the covered entity's or business associate's electronic information systems, including but not limited to how electronic protected health information enters and exits such information systems, and is accessed from outside of such information systems.
                        </P>
                        <P>
                            (C) 
                            <E T="03">Maintenance.</E>
                             Review and update the written inventory of technology assets required by paragraph (a)(1)(ii)(A) of this section and the network map required by paragraph (a)(1)(ii)(B) of this section in the following circumstances:
                        </P>
                        <P>
                            (
                            <E T="03">1</E>
                            ) On an ongoing basis, but at least once every 12 months.
                        </P>
                        <P>
                            (
                            <E T="03">2</E>
                            ) When there is a change in the covered entity's or business associate's environment or operations that may affect electronic protected health information, including but not limited to the adoption of new technology assets; the upgrading, updating, or patching of technology assets; newly recognized threats to the confidentiality, integrity, or availability of electronic protected health information; a sale, transfer, merger, or consolidation of all or part of the covered entity or business associate with another person; a security incident that affects the confidentiality, integrity, and availability of electronic protected health information; and relevant changes in Federal, State, Tribal, or territorial law.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Standard: Risk analysis</E>
                            —(i) 
                            <E T="03">General.</E>
                             Conduct an accurate and comprehensive written assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all electronic protected health information created, received, maintained, or transmitted by the covered entity or business associate.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Implementation specifications</E>
                            —(A) 
                            <E T="03">Assessment.</E>
                             The written assessment must include, at a minimum, all of the following:
                        </P>
                        <P>
                            (
                            <E T="03">1</E>
                            ) A review of the technology asset inventory required by paragraph (a)(1)(ii)(A) of this section and the network map required by paragraph (a)(1)(ii)(B) of this section to identify where electronic protected health information may be created, received, maintained, or transmitted within the covered entity's or business associate's electronic information systems.
                        </P>
                        <P>
                            (
                            <E T="03">2</E>
                            ) Identification of all reasonably anticipated threats to the confidentiality, integrity, and availability of electronic protected health information that the covered entity or business associate creates, receives, maintains, or transmits.
                        </P>
                        <P>
                            (
                            <E T="03">3</E>
                            ) Identification of potential vulnerabilities and predisposing conditions to the covered entity's or business associate's relevant electronic information systems.
                        </P>
                        <P>
                            (
                            <E T="03">4</E>
                            ) An assessment and documentation of the security measures the covered entity or business associate uses to ensure the confidentiality, integrity, and availability of the electronic protected health information created, received, maintained, or transmitted by the covered entity or business associate.
                        </P>
                        <P>
                            (
                            <E T="03">5</E>
                            ) A reasonable determination of the likelihood that each threat identified in accordance with paragraph (a)(2)(ii)(A)(
                            <E T="03">2</E>
                            ) of this section will exploit the vulnerabilities identified in accordance with paragraph (a)(2)(ii)(A)(
                            <E T="03">3</E>
                            ) of this section.
                        </P>
                        <P>
                            (
                            <E T="03">6</E>
                            ) A reasonable determination of the potential impact of each threat identified in accordance with paragraph (a)(2)(ii)(A)(
                            <E T="03">2</E>
                            ) of this section successfully exploiting the vulnerabilities identified in accordance with paragraph (a)(2)(ii)(A)(
                            <E T="03">3</E>
                            ) of this section.
                            <PRTPAGE P="1013"/>
                        </P>
                        <P>
                            (
                            <E T="03">7</E>
                            ) An assessment of risk level for each threat identified in accordance with paragraph (a)(2)(ii)(A)(
                            <E T="03">2</E>
                            ) of this section and vulnerability identified in accordance with paragraph (a)(2)(ii)(A)(
                            <E T="03">3</E>
                            ) of this section, based on the determinations made in accordance with paragraphs (a)(2)(ii)(A)(
                            <E T="03">5</E>
                            ) and (
                            <E T="03">6</E>
                            ) of this section.
                        </P>
                        <P>
                            (
                            <E T="03">8</E>
                            ) An assessment of the risks to electronic protected health information posed by entering into or continuing a business associate contract or other written arrangement with any prospective or current business associate, respectively, based on the written verification obtained from the prospective or current business associate in accordance with paragraph (b)(1) of this section.
                        </P>
                        <P>
                            (B) 
                            <E T="03">Maintenance.</E>
                             Review, verify, and update the written assessment on an ongoing basis, but at least once every 12 months and, in accordance with paragraph (a)(1)(ii)(C)(
                            <E T="03">2</E>
                            ) of this section, in response to a change in the covered entity's or business associate's environment or operations that may affect electronic protected health information.
                        </P>
                        <P>
                            (3) 
                            <E T="03">Standard: Evaluation</E>
                            —(i) 
                            <E T="03">General.</E>
                             Perform a written technical and nontechnical evaluation to determine whether a change in the covered entity's or business associate's environment or operations may affect the confidentiality, integrity, or availability of electronic protected health information.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Implementation specifications</E>
                            —(A) 
                            <E T="03">Performance.</E>
                             Perform a written technical and nontechnical evaluation within a reasonable period of time before making a change in the covered entity's or business associate's environment or operations as described in paragraph (a)(1)(ii)(C)(
                            <E T="03">2</E>
                            ) of this section.
                        </P>
                        <P>
                            (B) 
                            <E T="03">Response.</E>
                             Respond to the written technical and nontechnical evaluation in accordance with the covered entity's or business associate's risk management plan required by paragraph (a)(5)(ii)(A) of this section.
                        </P>
                        <P>
                            (4) 
                            <E T="03">Standard: Patch management</E>
                            —(i) 
                            <E T="03">General.</E>
                             Implement written policies and procedures for applying patches and updating the configuration(s) of the covered entity's or business associate's relevant electronic information systems.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Implementation specifications</E>
                            —(A) 
                            <E T="03">Policies and procedures.</E>
                             Establish written policies and procedures for identifying, prioritizing, acquiring, installing, evaluating, and verifying the timely installation of patches, updates, and upgrades throughout the covered entity's or business associate's relevant electronic information systems.
                        </P>
                        <P>
                            (B) 
                            <E T="03">Maintenance.</E>
                             Review and test written policies and procedures required by paragraph (a)(4)(ii)(A) of this section at least once every 12 months, and modify such policies and procedures as reasonable and appropriate.
                        </P>
                        <P>
                            (C) 
                            <E T="03">Application.</E>
                             Patch, update, and upgrade the configurations of relevant electronic information systems in accordance with the written policies and procedures required by paragraph (a)(4)(ii)(A) of this section and based on the results of the covered entity's or business associate's risk analysis required by paragraph (a)(2) of this section, the vulnerability scans required by § 164.312(h)(2)(i), the monitoring of authoritative sources required by § 164.312(h)(2)(ii), and penetration tests required by § 164.312(h)(2)(iii), within a reasonable and appropriate period of time, as follows, except to the extent that an exception at paragraph (a)(4)(ii)(D) of this section applies:
                        </P>
                        <P>
                            (
                            <E T="03">1</E>
                            ) Within 15 calendar days of identifying the need to patch, update, or upgrade the configuration of a relevant electronic information system to address a critical risk in accordance with this paragraph (a)(4)(ii)(C), where a patch, update, or upgrade is available; or, where a patch, update, or upgrade is not available, within 15 calendar days of a patch, update, or upgrade becoming available.
                        </P>
                        <P>
                            (
                            <E T="03">2</E>
                            ) Within 30 calendar days of identifying the need to patch, update, or upgrade the configuration of a relevant electronic information system to address a high risk in accordance with this paragraph (a)(4)(ii)(C), where a patch, update, or upgrade is available; or, where a patch, update, or upgrade is not available, within 30 calendar days of a patch, update, or upgrade becoming available.
                        </P>
                        <P>
                            (
                            <E T="03">3</E>
                            ) As determined by and documented in the covered entity's or business associate's policies and procedures under paragraph (a)(4)(ii)(A) of this section for all other patches, updates, and upgrades to the configuration of a relevant electronic information system.
                        </P>
                        <P>
                            (D) 
                            <E T="03">Exceptions.</E>
                             This paragraph (a)(4)(ii)(D) applies only to the extent that a covered entity or business associate documents that an exception in this paragraph (a)(4)(ii)(D) applies and that all other applicable conditions are met.
                        </P>
                        <P>
                            (
                            <E T="03">1</E>
                            ) A patch, update, or upgrade to the configuration of a relevant electronic information system is not available to address a risk identified in the risk analysis under paragraph (a)(2) of this section.
                        </P>
                        <P>
                            (
                            <E T="03">2</E>
                            ) The only available patch, update, or upgrade would adversely affect the confidentiality, integrity, or availability of electronic protected health information.
                        </P>
                        <P>
                            (E) 
                            <E T="03">Alternative measures.</E>
                             Where an exception at paragraph (a)(4)(ii)(D) of this section applies, a covered entity or business associate must document in real-time the existence of an applicable exception and implement reasonable and appropriate compensating controls in accordance with paragraph (a)(4)(ii)(F) of this section.
                        </P>
                        <P>
                            (F) 
                            <E T="03">Compensating controls.</E>
                             To the extent that a covered entity or business associate determines that an exception at paragraph (a)(4)(ii)(D) of this section applies, a covered entity or business associate must implement reasonable and appropriate security measures to address the identified risk in a timely manner as required by paragraph (a)(5)(ii)(D) of this section until a patch, update, or upgrade that does not adversely affect the confidentiality, integrity, or availability of electronic protected health information becomes available.
                        </P>
                        <P>
                            (5) 
                            <E T="03">Standard: Risk management</E>
                            —(i) 
                            <E T="03">General.</E>
                             Implement security measures sufficient to reduce risks and vulnerabilities to all electronic protected health information to a reasonable and appropriate level.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Implementation specifications</E>
                            —(A) 
                            <E T="03">Planning.</E>
                             Establish and implement a written risk management plan for reducing risks to all electronic protected health information, including but not limited to those risks identified by the risk analysis under paragraph (a)(2)(ii)(A) of this section, to a reasonable and appropriate level.
                        </P>
                        <P>
                            (B) 
                            <E T="03">Maintenance.</E>
                             Review the written risk management plan required by paragraph (a)(5)(ii)(A) of this section at least once every 12 months and as reasonable and appropriate in response to changes in the risk analysis made in accordance with paragraph (a)(2)(ii)(B) of this section, and modify as reasonable and appropriate.
                        </P>
                        <P>
                            (C) 
                            <E T="03">Priorities.</E>
                             The written risk management plan must prioritize the risks identified in the risk analysis required by paragraph (a)(2)(ii)(A) of this section, based on the risk levels determined by such risk analysis.
                        </P>
                        <P>
                            (D) 
                            <E T="03">Implementation.</E>
                             Implement security measures in a timely manner to address the risks identified in the covered entity's or business associate's risk analysis in accordance with the priorities established under paragraph (a)(5)(ii)(C) of this section.
                        </P>
                        <P>
                            (6) 
                            <E T="03">Standard: Sanction policy</E>
                            —(i) 
                            <E T="03">General.</E>
                             Apply appropriate sanctions against workforce members who fail to comply with the security policies and 
                            <PRTPAGE P="1014"/>
                            procedures of the covered entity or business associate.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Implementation specifications</E>
                            —(A) 
                            <E T="03">Policies and procedures.</E>
                             Establish written policies and procedures for sanctioning workforce members who fail to comply with the security policies and procedures of the covered entity or business associate.
                        </P>
                        <P>
                            (B) 
                            <E T="03">Modifications.</E>
                             Review written sanctions policies and procedures at least once every 12 months, and modify as reasonable and appropriate.
                        </P>
                        <P>
                            (C) 
                            <E T="03">Application.</E>
                             Apply and document appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the covered entity or business associate in accordance with the written policies and procedures for sanctioning workforce members required by paragraph (a)(6)(ii)(A) of this section.
                        </P>
                        <P>
                            (7) 
                            <E T="03">Standard: Information system activity review</E>
                            —(i) 
                            <E T="03">General.</E>
                             Implement written policies and procedures for regularly reviewing records of activity in the covered entity's or business associate's relevant electronic information systems.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Implementation specifications</E>
                            —(A) 
                            <E T="03">Policies and procedures.</E>
                             Establish written policies and procedures for retaining and reviewing records of activity in the covered entity's or business associate's relevant electronic information systems by persons and technology assets, including the frequency for reviewing such records.
                        </P>
                        <P>
                            (B) 
                            <E T="03">Scope.</E>
                             Records of activity in the covered entity's or business associate's relevant electronic information systems by persons and/or technology assets include but are not limited to audit trails, event logs, firewall logs, system logs, data backup logs, access reports, anti-malware logs, and security incident tracking reports.
                        </P>
                        <P>
                            (C) 
                            <E T="03">Record review.</E>
                             Review records of activity in a covered entity's or business associate's relevant electronic information systems by persons and technology assets as often as reasonable and appropriate for the type of report or log and document such review.
                        </P>
                        <P>
                            (D) 
                            <E T="03">Record retention.</E>
                             Retain records of activity in the covered entity's or business associate's relevant electronic information systems by persons and technology assets for a period of time that is reasonable and appropriate for the type of report or log.
                        </P>
                        <P>
                            (E) 
                            <E T="03">Response.</E>
                             Where a suspected or known security incident is identified during the review required by paragraph (a)(7)(ii)(C) of this section, respond in accordance with the covered entity's or business associate's security incident response plan required by paragraph (a)(12)(ii)(A)(
                            <E T="03">1</E>
                            ) of this section.
                        </P>
                        <P>
                            (F) 
                            <E T="03">Maintenance.</E>
                             Review and test the written policies and procedures required by paragraph (a)(7)(ii)(A) of this section at least once every 12 months and modify as reasonable and appropriate.
                        </P>
                        <P>
                            (8) 
                            <E T="03">Standard: Assigned security responsibility.</E>
                             In writing, identify the security official who is responsible for the development and implementation of the policies and procedures, written or otherwise, and deployment of technical controls required by this subpart for the covered entity or business associate.
                        </P>
                        <P>
                            (9) 
                            <E T="03">Standard: Workforce security</E>
                            —(i) 
                            <E T="03">General.</E>
                             Implement written policies and procedures to ensure that all members of its workforce have appropriate access to electronic protected health information and relevant electronic information systems, and to prevent those workforce members who are not authorized to have access from obtaining access to electronic protected health information and relevant electronic information systems.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Implementation specifications</E>
                            —(A) 
                            <E T="03">Authorization and/or supervision.</E>
                             Establish and implement written procedures for the authorization and/or supervision of workforce members who access electronic protected health information or relevant electronic information systems, or who work in facilities where electronic protected health information or relevant electronic information systems might be accessed.
                        </P>
                        <P>
                            (B) 
                            <E T="03">Workforce clearance procedure.</E>
                             Establish and implement written procedures to determine that the access of a workforce member to electronic protected health information or relevant electronic information systems is appropriate in accordance with paragraph (a)(10)(ii)(B) of this section.
                        </P>
                        <P>
                            (C) 
                            <E T="03">Modification and termination procedures.</E>
                             (
                            <E T="03">1</E>
                            ) Establish and implement written procedures, in accordance with paragraph (a)(9)(ii)(C)(
                            <E T="03">2</E>
                            ) of this section, to terminate a workforce member's access to electronic protected health information and relevant electronic information systems, and to facilities where electronic protected health information or relevant electronic information systems might be accessed.
                        </P>
                        <P>
                            (
                            <E T="03">2</E>
                            ) A workforce member's access must be terminated as soon as possible but no later than one hour after the employment of, or other arrangement with, a workforce member ends.
                        </P>
                        <P>
                            (D) 
                            <E T="03">Notification.</E>
                             (
                            <E T="03">1</E>
                            ) Establish and implement written procedures, in accordance with paragraph (a)(9)(ii)(D)(
                            <E T="03">2</E>
                            ) of this section, to notify another covered entity or business associate of a change in or termination of access where the workforce member is or was authorized to access such electronic protected health information or relevant electronic information systems by the covered entity or business associate making the notification.
                        </P>
                        <P>
                            (
                            <E T="03">2</E>
                            ) Notification must occur as soon as possible but no later than 24 hours after a change in or termination of a workforce member's authorization to access electronic protected health information or relevant electronic information systems maintained by such other covered entity or business associate.
                        </P>
                        <P>
                            (E) 
                            <E T="03">Maintenance.</E>
                             Review and test written policies and procedures required under paragraph (a)(9)(ii)(A) through (D) of this section at least once every 12 months, and modify as reasonable and appropriate.
                        </P>
                        <P>
                            (10) 
                            <E T="03">Standard: Information access management</E>
                            —(i) 
                            <E T="03">General.</E>
                             Establish and implement written policies and procedures for authorizing access to electronic protected health information and relevant electronic information systems that are consistent with the applicable requirements of subpart E of this part.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Implementation specifications</E>
                            —(A) 
                            <E T="03">Isolating health care clearinghouse functions.</E>
                             If a health care clearinghouse is part of a larger organization, the clearinghouse must establish and implement written policies and procedures that protect the electronic protected health information and relevant electronic information systems of the clearinghouse from unauthorized access by the larger organization.
                        </P>
                        <P>
                            (B) 
                            <E T="03">Access authorization.</E>
                             Establish and implement written policies and procedures for granting and revising access to electronic protected health information and relevant electronic information systems as necessary and appropriate for each prospective user and technology asset to carry out their assigned function(s).
                        </P>
                        <P>
                            (C) 
                            <E T="03">Authentication management.</E>
                             Establish and implement written policies and procedures for verifying the identities of users and technology assets prior to accessing the covered entity's or business associate's relevant electronic information systems, including written policies and procedures for implementing multi-factor authentication technical controls required by § 164.312(f)(2)(ii) through (v).
                        </P>
                        <P>
                            (D) 
                            <E T="03">Access determination and modification.</E>
                             Establish and implement written policies and procedures that, based upon the covered entity's or the business associate's access authorization policies, determine, document, review, and modify the access of each user and technology asset to specific components 
                            <PRTPAGE P="1015"/>
                            of the covered entity's or business associate's relevant electronic information systems.
                        </P>
                        <P>
                            (E) 
                            <E T="03">Network segmentation.</E>
                             Establish and implement written policies and procedures that ensure that a covered entity's or business associate's relevant electronic information systems are segmented to limit access to electronic protected health information to authorized workstations.
                        </P>
                        <P>
                            (F) 
                            <E T="03">Maintenance.</E>
                             Review and test the written policies and procedures required by this paragraph (a)(10)(ii) at least once every 12 months, and modify as reasonable and appropriate.
                        </P>
                        <P>
                            (11) 
                            <E T="03">Standard: Security awareness training</E>
                            —(i) 
                            <E T="03">General.</E>
                             Implement security awareness training for all workforce members on protection of electronic protected health information and information systems as necessary and appropriate for the members of the workforce to carry out their assigned function(s).
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Implementation specifications</E>
                            —(A) 
                            <E T="03">Training.</E>
                             A covered entity or business associate must develop and implement security awareness training for all workforce members that addresses all of the following:
                        </P>
                        <P>
                            (
                            <E T="03">1</E>
                            ) The written policies and procedures with respect to electronic protected health information required by this subpart as necessary and appropriate for the workforce members to carry out their assigned functions.
                        </P>
                        <P>
                            (
                            <E T="03">2</E>
                            ) Guarding against, detecting, and reporting suspected or known security incidents, including but not limited to, malicious software and social engineering.
                        </P>
                        <P>
                            (
                            <E T="03">3</E>
                            ) The written policies and procedures for accessing the covered entity's or business associate's relevant electronic information systems, including but not limited to: safeguarding passwords; setting unique passwords of sufficient strength to ensure the confidentiality, integrity, and availability of electronic protected health information; and limitations on sharing passwords.
                        </P>
                        <P>
                            (B) 
                            <E T="03">Timing.</E>
                             A covered entity or business associate must provide security awareness training as follows:
                        </P>
                        <P>
                            (
                            <E T="03">1</E>
                            ) As required by paragraph (a)(11)(ii)(A) of this section, to each member of its workforce by no later than the compliance date, and at least once every 12 months thereafter.
                        </P>
                        <P>
                            (
                            <E T="03">2</E>
                            ) As required by paragraph (a)(11)(ii)(A) of this section, to each new member of its workforce within a reasonable period of time but no later than 30 days after the person first has access to the covered entity's or business associate's relevant electronic information systems.
                        </P>
                        <P>
                            (
                            <E T="03">3</E>
                            ) On a material change to the policies or procedures required by this subpart, to each member of its workforce whose functions are affected by such change, within a reasonable period of time but no later than 30 days after the material change occurs.
                        </P>
                        <P>
                            (C) 
                            <E T="03">Ongoing education.</E>
                             A covered entity or business associate must provide its workforce members ongoing reminders of their security responsibilities and notifications of relevant threats, including but not limited to new and emerging malicious software and social engineering.
                        </P>
                        <P>
                            (D) 
                            <E T="03">Documentation.</E>
                             A covered entity or business associate must document that the training required by paragraph (a)(11)(ii)(A) of this section and ongoing reminders required by paragraph (a)(11)(ii)(C) of this section have been provided.
                        </P>
                        <P>
                            (12) 
                            <E T="03">Standard: Security incident procedures</E>
                            —(i) 
                            <E T="03">General.</E>
                             Implement written policies and procedures to respond to security incidents.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Implementation specifications</E>
                            —(A) 
                            <E T="03">Planning and testing.</E>
                             (
                            <E T="03">1</E>
                            ) Establish written security incident response plan(s) and procedures documenting how workforce members are to report suspected or known security incidents and how the covered entity or business associate will respond to suspected or known security incidents in accordance with paragraph (a)(12)(ii)(B) of this section.
                        </P>
                        <P>
                            (
                            <E T="03">2</E>
                            ) Implement written procedures for testing and revising security incident response plan(s) required by paragraph (a)(12)(ii)(A)(
                            <E T="03">1</E>
                            ) of this section.
                        </P>
                        <P>
                            (
                            <E T="03">3</E>
                            ) Review and test security incident response plan(s) and procedures required by paragraph (a)(12)(ii)(A)(
                            <E T="03">1</E>
                            ) of this section at least once every 12 months, document the results of such tests, and modify security incident response plan(s) and procedures as reasonable and appropriate.
                        </P>
                        <P>
                            (B) 
                            <E T="03">Response.</E>
                             (
                            <E T="03">1</E>
                            ) Identify and respond to suspected or known security incidents.
                        </P>
                        <P>
                            (
                            <E T="03">2</E>
                            ) Mitigate, to the extent practicable, harmful effects of security incidents that are suspected or known to the covered entity or business associate.
                        </P>
                        <P>
                            (
                            <E T="03">3</E>
                            ) Identify and remediate, to the extent practicable, the root cause(s) of security incidents that are suspected or known to the covered entity or business associate.
                        </P>
                        <P>
                            (
                            <E T="03">4</E>
                            ) Eradicate the security incidents that are suspected or known to the covered entity or business associate.
                        </P>
                        <P>
                            (
                            <E T="03">5</E>
                            ) For suspected and known security incidents, develop and maintain documentation of investigations, analyses, mitigation, and remediation.
                        </P>
                        <P>
                            (13) 
                            <E T="03">Standard: Contingency plan</E>
                            —(i) 
                            <E T="03">General.</E>
                             Establish and implement as needed a written contingency plan, consisting of written policies and procedures for responding to an emergency or other occurrence—including but not limited to fire, vandalism, system failure, natural disaster, or security incident—that adversely affects relevant electronic information systems.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Implementation specifications</E>
                            —(A) 
                            <E T="03">Criticality analysis.</E>
                             Perform and document an assessment of the relative criticality of the covered entity's or business associate's relevant electronic information systems and technology assets in its relevant electronic information systems.
                        </P>
                        <P>
                            (B) 
                            <E T="03">Data backups.</E>
                             Establish and implement written procedures to create and maintain exact retrievable copies of electronic protected health information, including verification that the electronic protected health information has been copied accurately.
                        </P>
                        <P>
                            (C) 
                            <E T="03">Information systems backups.</E>
                             Establish and implement written procedures to create and maintain backups of the covered entity's or business associate's relevant electronic information systems, including verification of success of backups.
                        </P>
                        <P>
                            (D) 
                            <E T="03">Disaster recovery plan.</E>
                             (
                            <E T="03">1</E>
                            ) Establish (and implement as needed) written procedures to restore loss of the covered entity's or business associate's critical relevant electronic information systems and data within 72 hours of the loss.
                        </P>
                        <P>
                            (
                            <E T="03">2</E>
                            ) Establish (and implement as needed) written procedures to restore loss of the covered entity's or business associate's other relevant electronic information systems and data in accordance with the criticality analysis required by paragraph (a)(13)(ii)(A) of this section.
                        </P>
                        <P>
                            (E) 
                            <E T="03">Emergency mode operation plan.</E>
                             Establish (and implement as needed) written procedures to enable continuation of critical business processes for protection of the security of electronic protected health information while operating in emergency mode.
                        </P>
                        <P>
                            (F) 
                            <E T="03">Testing and revision procedures.</E>
                             (
                            <E T="03">1</E>
                            ) Establish written procedures for testing and revising contingency plans as required by this paragraph (a)(13) in accordance with paragraph (a)(13)(ii)(F)(
                            <E T="03">2</E>
                            ) of this section.
                        </P>
                        <P>
                            (
                            <E T="03">2</E>
                            ) Review and test contingency plans required by this paragraph (a)(13) at least once every 12 months, document the results of such tests, and modify such contingency plans as reasonable and appropriate in accordance with the results of those tests.
                            <PRTPAGE P="1016"/>
                        </P>
                        <P>
                            (14) 
                            <E T="03">Standard: Compliance audit.</E>
                             Perform and document an audit at least once every 12 months of the covered entity's or business associate's compliance with each standard and implementation specification in this subpart.
                        </P>
                        <P>
                            (b)(1) 
                            <E T="03">Standard: Business associate contracts and other arrangements.</E>
                             (i)(A) A covered entity may permit a business associate to create, receive, maintain, or transmit electronic protected health information on the covered entity's behalf only if the covered entity obtains satisfactory assurances, in accordance with § 164.314(a), that the business associate will comply with this subpart and verifies that the business associate has deployed technical safeguards in accordance with the requirements of § 164.312.
                        </P>
                        <P>(B) A covered entity is not required to obtain such satisfactory assurances or verification from a business associate that is a subcontractor.</P>
                        <P>(ii) A business associate may permit a business associate that is a subcontractor to create, receive, maintain, or transmit electronic protected health information on its behalf only if the business associate obtains satisfactory assurances, in accordance with § 164.314(a), that the subcontractor will comply with the requirements of this subpart and verifies that the business associate that is a subcontractor has deployed technical safeguards in accordance with the requirements of § 164.312.</P>
                        <P>
                            (2) 
                            <E T="03">Implementation specifications</E>
                            —(i) 
                            <E T="03">Written contract or other arrangement.</E>
                             Document the satisfactory assurances required by paragraph (b)(1)(i) or (ii) of this section through a written contract or other arrangement with the business associate that meets the applicable requirements of § 164.314(a).
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Written verification.</E>
                             Obtain written verification from the business associate at least once every 12 months that the business associate has deployed the technical safeguards as required by § 164.312 through both of the following:
                        </P>
                        <P>(A) A written analysis of the business associate's relevant electronic information systems by a person with appropriate knowledge of and experience with generally accepted cybersecurity principles and methods for ensuring the confidentiality, integrity, and availability of electronic protected health information to verify compliance with each standard and implementation specification in § 164.312.</P>
                        <P>(B) A written certification that the analysis has been performed and is accurate by a person who has the authority to act on behalf of the business associate.</P>
                        <P>
                            (3) 
                            <E T="03">Standard: Delegation to business associate.</E>
                             (i) A covered entity or business associate may permit a business associate to serve as their designated security official.
                        </P>
                        <P>(ii) A covered entity or business associate that delegates actions, activities, or assessments required by this subpart to a business associate remains liable for compliance with all applicable provisions of this subpart.</P>
                    </SECTION>
                    <SECTION>
                        <SECTNO>§ 164.310</SECTNO>
                        <SUBJECT>Physical safeguards.</SUBJECT>
                        <P>Each covered entity and business associate must, in accordance with §§ 164.306 and 164.316, implement all of the following physical safeguards to protect the confidentiality, integrity, and availability of all electronic protected health information that it creates, receives, maintains, or transmits:</P>
                        <P>
                            (a) 
                            <E T="03">Standard: Facility access controls</E>
                            —(1) 
                            <E T="03">General.</E>
                             Establish and implement written policies and procedures to limit physical access to all of its relevant electronic information systems and the facility or facilities in which they are housed, while ensuring that properly authorized access is allowed.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Implementation specifications</E>
                            —(i) 
                            <E T="03">Contingency operations.</E>
                             Establish (and implement as needed) written procedures that allow facility access in support of the covered entity's or business associate's contingency plan required by § 164.308(a)(13).
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Facility security plan.</E>
                             Establish and implement written policies and procedures to safeguard all facilities and the equipment therein from unauthorized physical access, tampering, and theft.
                        </P>
                        <P>
                            (iii) 
                            <E T="03">Access management and validation procedures.</E>
                             Establish and implement written procedures to authorize and manage a person's access to facilities based on their role or function, including visitor management.
                        </P>
                        <P>
                            (iv) 
                            <E T="03">Physical maintenance records.</E>
                             Establish and implement written policies and procedures to document repairs and modifications to the physical components of a facility that are related to security, including but not limited to hardware, walls, doors, locks, and security cameras.
                        </P>
                        <P>
                            (v) 
                            <E T="03">Maintenance.</E>
                             For each facility, review and test the written policies and procedures required by this paragraph (a)(2) at least once every 12 months, and modify such policies and procedures as reasonable and appropriate.
                        </P>
                        <P>
                            (b) 
                            <E T="03">Standard: Workstation use</E>
                            —(1) 
                            <E T="03">General.</E>
                             Establish and implement written policies and procedures that govern the use of workstations that access electronic protected health information or the covered entity's or business associate's relevant electronic information systems.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Implementation specifications</E>
                            —(i) 
                            <E T="03">Policies and procedures.</E>
                             The written policies and procedures must specify all of the following with respect to a workstation that accesses electronic protected health information or the covered entity's or business associate's relevant electronic information systems:
                        </P>
                        <P>(A) The functions for which a workstation may be used.</P>
                        <P>(B) The manner in which a workstation may be used to perform those functions.</P>
                        <P>(C) The physical attributes of the surroundings of a specific workstation or class of workstation that can access electronic protected health information, including the removal of such workstations from a facility and the movement of such workstations within and outside of a facility.</P>
                        <P>
                            (ii) 
                            <E T="03">Maintenance.</E>
                             Review and test written policies and procedures at least once every 12 months, and modify as reasonable and appropriate.
                        </P>
                        <P>
                            (c) 
                            <E T="03">Standard: Workstation security.</E>
                             Implement and modify physical safeguards for all workstations that access electronic protected health information or relevant electronic information systems, to address the written policies and procedures for workstation use required by paragraph (b) of this section and restrict access to authorized users.
                        </P>
                        <P>
                            (d) 
                            <E T="03">Standard: Technology asset controls</E>
                            —(1) 
                            <E T="03">General.</E>
                             Establish and implement written policies and procedures that govern the receipt and removal of technology assets that maintain electronic protected health information into and out of a facility, and the movement of these assets within the facility.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Implementation specifications</E>
                            —(i) 
                            <E T="03">Disposal.</E>
                             Establish and implement written policies and procedures for disposal of electronic protected health information and the technology assets on which it is maintained based on current standards for disposing of such technology assets.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Media sanitization.</E>
                             Establish and implement written procedures for removal of electronic protected health information from electronic media such that the electronic protected health information cannot be recovered, based on current standards for sanitizing electronic media before the media are made available for re-use.
                        </P>
                        <P>
                            (iii) 
                            <E T="03">Maintenance.</E>
                             Review and test the written policies and procedures required by paragraphs (d)(2)(i) and (ii) 
                            <PRTPAGE P="1017"/>
                            of this section at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate.
                        </P>
                    </SECTION>
                    <SECTION>
                        <SECTNO>§ 164.312</SECTNO>
                        <SUBJECT>Technical safeguards.</SUBJECT>
                        <P>Each covered entity or business associate must, in accordance with §§ 164.306 and 164.316, implement all of the following technical safeguards, including technical controls, to protect the confidentiality, integrity, and availability of all electronic protected health information that it creates, receives, maintains, or transmits:</P>
                        <P>
                            (a) 
                            <E T="03">Standard: Access control</E>
                            —(1) 
                            <E T="03">General.</E>
                             Deploy technical controls in relevant electronic information systems to allow access only to users and technology assets that have been granted access rights.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Implementation specifications</E>
                            —(i) 
                            <E T="03">Unique identification.</E>
                             Assign a unique name, number, and/or other identifier for tracking each user and technology asset in the covered entity or business associate's relevant electronic information systems.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Administrative and increased access privileges.</E>
                             Separate user identities from identities used for administrative and other increased access privileges.
                        </P>
                        <P>
                            (iii) 
                            <E T="03">Emergency access procedure.</E>
                             Establish (and implement as needed) written and technical procedures for obtaining necessary electronic protected health information during an emergency.
                        </P>
                        <P>
                            (iv) 
                            <E T="03">Automatic logoff.</E>
                             Deploy technical controls that terminate an electronic session after a predetermined time of inactivity that is reasonable and appropriate.
                        </P>
                        <P>
                            (v) 
                            <E T="03">Log-in attempts.</E>
                             Deploy technical controls that disable or suspend the access of a user or technology asset to relevant electronic information systems after a reasonable and appropriate predetermined number of unsuccessful authentication attempts.
                        </P>
                        <P>
                            (vi) 
                            <E T="03">Network segmentation.</E>
                             Deploy technical controls to ensure that the covered entity's or business associate's relevant electronic information systems are segmented in a reasonable and appropriate manner.
                        </P>
                        <P>
                            (vii) 
                            <E T="03">Data controls.</E>
                             Deploy technical controls to allow access to electronic protected health information only to those users and technology assets that have been granted access rights to the covered entity's or business associate's relevant electronic information systems as specified in § 164.308(a)(10).
                        </P>
                        <P>
                            (viii) 
                            <E T="03">Maintenance.</E>
                             Review and test the effectiveness of the procedures and technical controls required by this paragraph (a)(2) at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate.
                        </P>
                        <P>
                            (b) 
                            <E T="03">Standard: Encryption and decryption</E>
                            —(1) 
                            <E T="03">General.</E>
                             Deploy technical controls to encrypt and decrypt electronic protected health information using encryption that meets prevailing cryptographic standards.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Implementation specification.</E>
                             Encrypt all electronic protected health information at rest and in transit, except to the extent that an exception at paragraph (b)(3) of this section applies.
                        </P>
                        <P>
                            (3) 
                            <E T="03">Exceptions.</E>
                             This paragraph (b)(3) applies only to the electronic protected health information directly affected by one or more of the following exceptions and only to the extent that the covered entity or business associate documents that an exception applies and that all other applicable conditions are met.
                        </P>
                        <P>(i) The technology asset in use does not support encryption of the electronic protected health information consistent with prevailing cryptographic standards, and the covered entity or business associate establishes and implements a written plan to migrate electronic protected health information to a technology asset that supports encryption consistent with prevailing cryptographic standards within a reasonable and appropriate period of time.</P>
                        <P>(ii) An individual requests pursuant to § 164.524 to receive their electronic protected health information in an unencrypted manner and has been informed of the risks associated with the transmission, receipt, and storage of unencrypted electronic protected health information. This exception does not apply where such individual will receive their electronic protected health information pursuant to § 164.524 and the technology used by the individual to receive the electronic protected health information is controlled by the covered entity or its business associate.</P>
                        <P>(iii) During an emergency or other occurrence that adversely affects the covered entity's or business associate's relevant electronic information systems in which encryption is infeasible, and the covered entity or business associate implements reasonable and appropriate compensating controls in accordance with and determined by the covered entity's or business associate's contingency plan under § 164.308(a)(13).</P>
                        <P>(iv) The technology asset in use is a device under section 201(h) of the Food, Drug, and Cosmetic Act, 21 U.S.C. 321(h) that has been authorized for marketing by the Food and Drug Administration, as follows:</P>
                        <P>(A) Pursuant to a submission received before March 29, 2023, provided that the covered entity or business associate deploys in a timely manner any updates or patches required or recommended by the manufacturer of the device.</P>
                        <P>(B) Pursuant to a submission received on or after March 29, 2023, where the device is no longer supported by its manufacturer, provided that the covered entity or business associate has deployed any updates or patches required or recommended by the manufacturer of the device.</P>
                        <P>(C) Pursuant to a submission received on or after March 29, 2023, where the device is supported by its manufacturer.</P>
                        <P>
                            (4) 
                            <E T="03">Alternative measures</E>
                            —(i) 
                            <E T="03">Alternative measures.</E>
                             Where an exception at paragraph (b)(3) of this section applies, a covered entity or business associate must document in real-time the existence of an applicable exception and implement reasonable and appropriate compensating controls in accordance with paragraph (b)(4)(ii) of this section.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Compensating controls.</E>
                             (A) To the extent that a covered entity or business associate determines that an exception at paragraph (b)(3)(i), (ii), or (iii) or (b)(3)(iv)(A) or (B) of this section applies, the covered entity or business associate must secure such electronic protected health information by implementing reasonable and appropriate compensating controls reviewed and approved by the covered entity's or business associate's designated Security Official.
                        </P>
                        <P>(B) To the extent that a covered entity or business associate determines that an exception at paragraph (b)(3)(iv)(C) of this section applies, the covered entity or business associate shall be presumed to have implemented reasonable and appropriate compensating controls where the covered entity or business associate has deployed the security measures prescribed and as instructed by the authorized label for the device, including any updates or patches recommended or required by the manufacturer of the device.</P>
                        <P>
                            (C) To the extent that a covered entity or business associate is implementing compensating controls under this paragraph (b)(4)(ii), the implementation and effectiveness of compensating controls must be reviewed, documented, and signed by the designated Security Official at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, to continue securing electronic protected health information and relevant electronic information systems.
                            <PRTPAGE P="1018"/>
                        </P>
                        <P>
                            (5) 
                            <E T="03">Maintenance.</E>
                             Review and test the effectiveness of the technical controls required by this paragraph (b) at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate.
                        </P>
                        <P>
                            (c) 
                            <E T="03">Standard: Configuration management</E>
                            —(1) 
                            <E T="03">General.</E>
                             Establish and deploy technical controls for securing the covered entity's or business associate's relevant electronic information systems and technology assets in its relevant electronic information systems, including workstations, in a consistent manner, and maintain such electronic information systems and technology assets according to the covered entity's or business associate's established secure baselines.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Implementation specifications</E>
                            —(i) 
                            <E T="03">Anti-malware protection.</E>
                             Deploy technology assets and/or technical controls that protect all of the covered entity's or business associate's technology assets in its relevant electronic information systems against malicious software, including but not limited to viruses and ransomware.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Software removal.</E>
                             Remove extraneous software from the covered entity's or business associate's relevant electronic information systems.
                        </P>
                        <P>
                            (iii) 
                            <E T="03">Configuration.</E>
                             Configure and secure operating system(s) and software consistent with the covered entity's or business associate's risk analysis under § 164.308(a)(2).
                        </P>
                        <P>
                            (iv) 
                            <E T="03">Network ports.</E>
                             Disable network ports in accordance with the covered entity's or business associate's risk analysis under § 164.308(a)(2).
                        </P>
                        <P>
                            (v) 
                            <E T="03">Maintenance.</E>
                             Review and test the effectiveness of the technical controls required by this paragraph (c) at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate.
                        </P>
                        <P>
                            (d) 
                            <E T="03">Standard: Audit trail and system log controls</E>
                            —(1) 
                            <E T="03">General.</E>
                             Deploy technology assets and/or technical controls that record and identify activity in the covered entity's or business associate's relevant electronic information systems.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Implementation specifications</E>
                            —(i) 
                            <E T="03">Monitor and identify.</E>
                             The covered entity or business associate must deploy technology assets and/or technical controls that monitor in real-time all activity in its relevant electronic information systems, identify indications of unauthorized persons or unauthorized activity as determined by the covered entity's or business associate's risk analysis under § 164.308(a)(2), and alert workforce members of such indications in accordance with the policies and procedures required by § 164.308(a)(7).
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Record.</E>
                             The covered entity or business associate must deploy technology assets and/or technical controls that record in real-time all activity in its relevant electronic information systems.
                        </P>
                        <P>
                            (iii) 
                            <E T="03">Retain.</E>
                             The covered entity or business associate must deploy technology assets and/or technical controls to retain records of all activity in its relevant electronic information systems as determined by the covered entity's or business associate's policies and procedures for information system activity review at § 164.308(a)(7)(ii)(A).
                        </P>
                        <P>
                            (iv) 
                            <E T="03">Scope.</E>
                             Activity includes creating, accessing, receiving, transmitting, modifying, copying, or deleting any of the following:
                        </P>
                        <P>(A) Electronic protected health information.</P>
                        <P>(B) Relevant electronic information systems and the information therein.</P>
                        <P>
                            (v) 
                            <E T="03">Maintenance.</E>
                             Review and test the effectiveness of the technology assets and/or technical controls required by this paragraph (d) at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate.
                        </P>
                        <P>
                            (e) 
                            <E T="03">Standard: Integrity.</E>
                             Deploy technical controls to protect electronic protected health information from improper alteration or destruction, both at rest and in transit; and review and test the effectiveness of such technical controls at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate.
                        </P>
                        <P>
                            (f) 
                            <E T="03">Standard: Authentication</E>
                            —(1) 
                            <E T="03">General.</E>
                             Deploy technical controls to verify that a person or technology asset seeking access to electronic protected health information and/or the covered entity's or business associate's relevant electronic information systems is the one claimed.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Implementation specifications</E>
                            —(i) 
                            <E T="03">Information access management policies.</E>
                             Deploy technical controls in accordance with the covered entity's or business associate's information access management policies and procedures under § 164.308(a)(10), including technical controls that require users to adopt unique passwords that are consistent with the current recommendations of authoritative sources.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Multi-factor authentication.</E>
                             (A) Deploy multi-factor authentication to all technology assets in the covered entity's or business associate's relevant electronic information systems to verify that a person seeking access to the relevant electronic information system(s) is the user that the person claims to be.
                        </P>
                        <P>(B) Deploy multi-factor authentication for any action that would change a user's privileges to the covered entity's or business associate's relevant electronic information systems in a manner that would alter the user's ability to affect the confidentiality, integrity, or availability of electronic protected health information.</P>
                        <P>
                            (iii) 
                            <E T="03">Exceptions.</E>
                             Deployment of multi-factor authentication is not required in any of the following circumstances.
                        </P>
                        <P>(A) The technology asset in use does not support multi-factor authentication, and the covered entity or business associate establishes and implements a written plan to migrate electronic protected health information to a technology asset that supports multi-factor authentication within a reasonable and appropriate period of time.</P>
                        <P>(B) During an emergency or other occurrence that adversely affects the covered entity's or business associate's relevant electronic information systems or the confidentiality, integrity, or availability of electronic protected health information in which multi-factor authentication is infeasible and the covered entity or business associate implements reasonable and appropriate compensating controls in accordance with its emergency access procedures under paragraph (a)(2)(iii) of this section and the covered entity's or business associate's contingency plan under § 164.308(a)(13).</P>
                        <P>(C) The technology asset in use is a device under section 201(h) of the Food, Drug, and Cosmetic Act, 21 U.S.C. 321(h) that has been authorized for marketing by the Food and Drug Administration, as follows:</P>
                        <P>
                            (
                            <E T="03">1</E>
                            ) Pursuant to a submission received before March 29, 2023, provided that the covered entity or business associate has deployed any updates or patches required or recommended by the manufacturer of the device.
                        </P>
                        <P>
                            (
                            <E T="03">2</E>
                            ) Pursuant to a submission received on or after March 29, 2023, where the device is no longer supported by its manufacturer, provided that the covered entity or business associate has deployed any updates or patches required or recommended by the manufacturer of the device.
                        </P>
                        <P>
                            (
                            <E T="03">3</E>
                            ) Pursuant to a submission received on or after March 29, 2023, where the device is supported by its manufacturer.
                        </P>
                        <P>
                            (iv) 
                            <E T="03">Alternative measures</E>
                            —(A) 
                            <E T="03">Alternative measures.</E>
                             Where an exception at paragraph (f)(2)(iii) of this 
                            <PRTPAGE P="1019"/>
                            section applies, a covered entity or business associate must document in real-time the existence of an applicable exception and implement reasonable and appropriate compensating controls as required by paragraph (f)(2)(iv)(B) of this section.
                        </P>
                        <P>
                            (B) 
                            <E T="03">Compensating controls.</E>
                             (
                            <E T="03">1</E>
                            ) To the extent that a covered entity or business associate determines that an exception at paragraph (f)(2)(iii)(A) or (B) or (f)(2)(iii)(C)(
                            <E T="03">1</E>
                            ) or (
                            <E T="03">2</E>
                            ) of this section applies, the covered entity or business associate must secure its relevant electronic information systems by implementing reasonable and appropriate compensating controls reviewed, approved, and signed by the covered entity's or business associate's designated Security Official.
                        </P>
                        <P>
                            (
                            <E T="03">2</E>
                            ) To the extent that a covered entity or business associate determines that an exception at paragraph (f)(2)(iii)(C)(
                            <E T="03">3</E>
                            ) of this section applies, the covered entity or business associate shall be presumed to have implemented reasonable and appropriate compensating controls where the covered entity or business associate has deployed the security measures prescribed and as instructed by the authorized label for the device, including any updates or patches recommended or required by the manufacturer of the device.
                        </P>
                        <P>
                            (
                            <E T="03">3</E>
                            ) To the extent that a covered entity or business associate is implementing compensating controls under this paragraph (f)(2)(iv)(B), the effectiveness of compensating controls must be reviewed and documented by the designated Security Official at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, to continue securing electronic protected health information and its relevant electronic information systems.
                        </P>
                        <P>
                            (v) 
                            <E T="03">Maintenance.</E>
                             Review and test the effectiveness of the technical controls required by this paragraph (f) at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate.
                        </P>
                        <P>
                            (g) 
                            <E T="03">Standard: Transmission security.</E>
                             Deploy technical controls to guard against unauthorized access to electronic protected health information that is being transmitted over an electronic communications network; and review and test the effectiveness of such technical controls at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate.
                        </P>
                        <P>
                            (h) 
                            <E T="03">Standard: Vulnerability management</E>
                            —(1) 
                            <E T="03">General.</E>
                             Deploy technical controls in accordance with the covered entity's or business associate's patch management policies and procedures required by § 164.308(a)(4)(ii)(A) to identify and address technical vulnerabilities in the covered entity's or business associate's relevant electronic information systems.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Implementation specifications</E>
                            —(i) 
                            <E T="03">Vulnerability scanning.</E>
                             (A) Conduct automated vulnerability scans to identify technical vulnerabilities in the covered entity's or business associate's relevant electronic information systems in accordance with the covered entity's or business associate's risk analysis required by § 164.308(a)(2) or at least once every six months, whichever is more frequent.
                        </P>
                        <P>(B) Review and test the effectiveness of the technology asset(s) that conducts the automated vulnerability scans required by paragraph (h)(2)(i)(A) of this section at least once every 12 months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate.</P>
                        <P>
                            (ii) 
                            <E T="03">Monitoring.</E>
                             Monitor authoritative sources for known vulnerabilities on an ongoing basis and remediate such vulnerabilities in accordance with the covered entity's or business associate's patch management program under § 164.308(a)(4).
                        </P>
                        <P>
                            (iii) 
                            <E T="03">Penetration testing.</E>
                             Perform penetration testing of the covered entity's or business associate's relevant electronic information systems by a qualified person.
                        </P>
                        <P>(A) A qualified person is a person with appropriate knowledge of and experience with generally accepted cybersecurity principles and methods for ensuring the confidentiality, integrity, and availability of electronic protected health information.</P>
                        <P>(B) Penetration testing must be performed at least once every 12 months or in accordance with the covered entity's or business associate's risk analysis required by § 164.308(a)(2), whichever is more frequent.</P>
                        <P>
                            (iv) 
                            <E T="03">Patch and update installation.</E>
                             Deploy technical controls in accordance with the covered entity's or business associate's patch management program under § 164.308(a)(4) to ensure timely installation of software patches and critical updates as reasonable and appropriate.
                        </P>
                        <P>
                            (i) 
                            <E T="03">Standard: Data backup and recovery</E>
                            —(1) 
                            <E T="03">General.</E>
                             Deploy technical controls to create and maintain exact retrievable copies of electronic protected health information.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Implementation specifications</E>
                            —(i) 
                            <E T="03">Data backup.</E>
                             Create backups of electronic protected health information in accordance with the policies and procedures required by § 164.308(a)(13)(ii)(B) and with such frequency to ensure retrievable copies of electronic protected health information are no more than 48 hours older than the electronic protected health information maintained in the covered entity or business associate's relevant electronic information systems.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Monitor and identify.</E>
                             Deploy technical controls that, in real-time, monitor, and alert workforce members about, any failures and error conditions of the backups required by paragraph (i)(2)(i) of this section.
                        </P>
                        <P>
                            (iii) 
                            <E T="03">Record.</E>
                             Deploy technical controls that record the success, failure, and any error conditions of backups required by paragraph (i)(2)(i) of this section.
                        </P>
                        <P>
                            (iv) 
                            <E T="03">Testing.</E>
                             Restore a representative sample of electronic protected health information backed up as required by paragraph (i)(2)(i) of this section, and document the results of such test restorations at least monthly.
                        </P>
                        <P>
                            (j) 
                            <E T="03">Standard: Information systems backup and recovery.</E>
                             Deploy technical controls to create and maintain backups of relevant electronic information systems; and review and test the effectiveness of such technical controls at least once every six months or in response to environmental or operational changes, whichever is more frequent, and modify as reasonable and appropriate.
                        </P>
                    </SECTION>
                    <SECTION>
                        <SECTNO>§ 164.314</SECTNO>
                        <SUBJECT>Organizational requirements.</SUBJECT>
                        <P>
                            (a)(1) 
                            <E T="03">Standard: Business associate contracts or other arrangements.</E>
                             The contract or other arrangement required by § 164.308(b)(2) must meet the requirements of paragraph (a)(2)(i), (ii), or (iii) of this section, as applicable.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Implementation specifications</E>
                            —(i) 
                            <E T="03">Business associate contracts.</E>
                             The contract must provide that the business associate will do all of the following:
                        </P>
                        <P>(A) Comply with the applicable requirements of this subpart.</P>
                        <P>(B) In accordance with § 164.308(b)(1)(ii), ensure that any subcontractors that create, receive, maintain, or transmit electronic protected health information on behalf of the business associate agree to comply with the applicable requirements of this subpart by entering into a contract or other arrangement that complies with this section.</P>
                        <P>(C) Report to the covered entity any security incident of which it becomes aware, including breaches of unsecured electronic protected health information as required by § 164.410.</P>
                        <P>
                            (D) Report to the covered entity activation of its contingency plan under § 164.308(a)(13) without unreasonable 
                            <PRTPAGE P="1020"/>
                            delay, and in no case later than 24 hours after activation of the contingency plan.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Other arrangements.</E>
                             The covered entity is in compliance with paragraph (a)(1) of this section if it has another arrangement in place that meets the requirements of § 164.504(e)(3).
                        </P>
                        <P>
                            (iii) 
                            <E T="03">Business associate contracts with subcontractors.</E>
                             The requirements of paragraphs (a)(2)(i) and (ii) of this section apply to the contract or other arrangement between a business associate and a subcontractor required by § 164.308(b)(1)(ii) in the same manner as such requirements apply to contracts or other arrangements between a covered entity and business associate.
                        </P>
                        <P>
                            (b)(1) 
                            <E T="03">Standard: Requirements for group health plans.</E>
                             Except when the only electronic protected health information disclosed to a plan sponsor is disclosed pursuant to § 164.504(f)(1)(ii) or (iii), or as authorized under § 164.508, a group health plan must ensure that its plan documents provide that the plan sponsor will reasonably and appropriately safeguard electronic protected health information created, received, maintained, or transmitted to or by the plan sponsor on behalf of the group health plan.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Implementation specifications.</E>
                             The plan documents of the group health plan must be amended to incorporate provisions to require the plan sponsor to do all of the following:
                        </P>
                        <P>
                            (i) 
                            <E T="03">Safeguard implementation.</E>
                             Implement the administrative, physical, and technical safeguards that covered entities and business associates are required to implement under §§ 164.308(a), 164.310, and 164.312.
                        </P>
                        <P>
                            (ii) 
                            <E T="03">Separation.</E>
                             Ensure that the adequate separation required by § 164.504(f)(2)(iii) is supported by the administrative, physical, and technical safeguards implemented in accordance with paragraph (b)(2)(i) of this section.
                        </P>
                        <P>
                            (iii) 
                            <E T="03">Agents.</E>
                             Ensure that any agent to whom it provides this information agrees to implement the administrative, physical, and technical safeguards in accordance with paragraph (b)(2)(i) of this section.
                        </P>
                        <P>
                            (iv) 
                            <E T="03">Security incident awareness.</E>
                             Report to the group health plan any security incident of which it becomes aware.
                        </P>
                        <P>
                            (v) 
                            <E T="03">Contingency plan activation.</E>
                             Report to the group health plan activation of its contingency plan, adopted in accordance with § 164.308(a)(13) as required by paragraph (b)(2)(i) of this section, without unreasonable delay and in no case later than 24 hours after activation of the contingency plan.
                        </P>
                    </SECTION>
                    <SECTION>
                        <SECTNO>§ 164.316</SECTNO>
                        <SUBJECT>Documentation requirements.</SUBJECT>
                        <P>
                            (a) 
                            <E T="03">Standard: Documentation.</E>
                             A covered entity or business associate must do all of the following in written form, which may be electronic, taking into consideration the factors in § 164.306(b):
                        </P>
                        <P>(1) Document the policies and procedures required to comply with this subpart and how the covered entity or business associate considered the factors at § 164.306(b) in the development of such policies and procedures.</P>
                        <P>(2) Document each action, activity, or assessment required by this subpart.</P>
                        <P>
                            (b) 
                            <E T="03">Implementation specifications</E>
                            —(1) 
                            <E T="03">Time limit.</E>
                             Retain the documentation required by paragraph (a) of this section for 6 years from the date of its creation or the date when it last was in effect, whichever is later.
                        </P>
                        <P>
                            (2) 
                            <E T="03">Availability.</E>
                             Make documentation available to those persons responsible for implementing the procedures to which the documentation pertains.
                        </P>
                        <P>
                            (3) 
                            <E T="03">Updates.</E>
                             Review and update documentation at least once every 12 months and within a reasonable and appropriate period of time after a security measure is modified.
                        </P>
                    </SECTION>
                    <SECTION>
                        <SECTNO>§ 164.318</SECTNO>
                        <SUBJECT>Transition provisions.</SUBJECT>
                        <P>
                            (a) 
                            <E T="03">Standard: Effect of prior contracts or other arrangements with business associates.</E>
                             Notwithstanding any other provisions of this subpart, a covered entity, or business associate with respect to a subcontractor, may allow a business associate to create, receive, maintain, or transmit electronic protected health information pursuant to a written contract or other arrangement with such business associate that does not comply with §§ 164.308(b) and 164.314(a), only in accordance with paragraph (b) of this section.
                        </P>
                        <P>
                            (b) 
                            <E T="03">Implementation specification: Deemed compliance</E>
                            —(1) 
                            <E T="03">Qualification.</E>
                             Notwithstanding other sections of this subpart, a covered entity, or business associate with respect to a subcontractor, is deemed to be in compliance with the documentation and contract requirements of §§ 164.308(b) and 164.314(a), with respect to a particular business associate relationship for the time period set forth in paragraph (b)(2) of this section, if both of the following apply:
                        </P>
                        <P>
                            (i) Prior to [DATE OF PUBLICATION OF THE FINAL RULE IN THE 
                            <E T="04">Federal Register</E>
                            ], such covered entity, or business associate with respect to a subcontractor, has entered into and is operating pursuant to a written contract or other written arrangement with the business associate that complies with the applicable provisions of §§ 164.308(b) and 164.314(a) that were in effect on such date.
                        </P>
                        <P>
                            (ii) The contract or other arrangement is not renewed or modified from [DATE 60 DAYS AFTER DATE OF PUBLICATION OF THE FINAL RULE IN THE 
                            <E T="04">Federal Register</E>
                            ], until [DATE 240 DAYS AFTER DATE OF PUBLICATION OF THE FINAL RULE IN THE 
                            <E T="04">Federal Register</E>
                            ].
                        </P>
                        <P>
                            (2) 
                            <E T="03">Limited deemed compliance period.</E>
                             A prior contract or other arrangement that meets the qualification requirements at paragraph (b)(1) of this section shall be deemed compliant until the earlier of the following dates:
                        </P>
                        <P>
                            (i) The date such contract or other arrangement is renewed on or after [DATE 240 DAYS AFTER DATE OF PUBLICATION OF THE FINAL RULE IN THE 
                            <E T="04">Federal Register</E>
                            ].
                        </P>
                        <P>
                            (ii) [DATE 1 YEAR AND 60 DAYS AFTER DATE OF PUBLICATION OF THE FINAL RULE IN THE 
                            <E T="04">Federal Register</E>
                            ].
                        </P>
                        <P>
                            (c) 
                            <E T="03">Covered entity and business associate responsibilities.</E>
                             Nothing in this section shall alter the requirements of a covered entity or business associate to comply with applicable provisions of this part other than §§ 164.308(b) and 164.314(a).
                        </P>
                    </SECTION>
                    <SECTION>
                        <SECTNO>§ 164.320</SECTNO>
                        <SUBJECT>Severability.</SUBJECT>
                        <P>If any provision of this subpart is held to be invalid or unenforceable by its terms, or as applied to any person or circumstance, or stayed pending further agency action, it shall be construed so as to give it maximum effect permitted by law, unless such holding shall be one of utter invalidity or unenforceability, in which event such provision shall be severable from this subpart and shall not affect the remainder thereof or the application of such provision to other persons not similarly situated or to other dissimilar circumstances.</P>
                        <PRTPAGE P="1021"/>
                        <HD SOURCE="HD1">Appendix A to Subpart C of Part 164—Security Standards: Matrix</HD>
                        <EXTRACT>
                            <GPOTABLE COLS="3" OPTS="L2,tp0,i1" CDEF="s100,xls60,r100">
                                <TTITLE> </TTITLE>
                                <BOXHD>
                                    <CHED H="1">Standards</CHED>
                                    <CHED H="1">Sections</CHED>
                                    <CHED H="1">Implementation specifications</CHED>
                                </BOXHD>
                                <ROW EXPSTB="02" RUL="s">
                                    <ENT I="21">
                                        <E T="02">Administrative Safeguards</E>
                                    </ENT>
                                </ROW>
                                <ROW EXPSTB="00">
                                    <ENT I="01">Technology asset inventory</ENT>
                                    <ENT>164.308(a)(1)</ENT>
                                    <ENT>Inventory.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Network map.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Maintenance.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Risk analysis</ENT>
                                    <ENT>164.308(a)(2)</ENT>
                                    <ENT>Assessment</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Maintenance.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Evaluation</ENT>
                                    <ENT>164.308(a)(3)</ENT>
                                    <ENT>Performance</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Response.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Patch Management</ENT>
                                    <ENT>164.308(a)(4)</ENT>
                                    <ENT>Policies and procedures.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Maintenance.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Application.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Exceptions.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Alternative measures.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Compensating controls.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Risk management</ENT>
                                    <ENT>164.308(a)(5)</ENT>
                                    <ENT>Planning.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Maintenance.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Priorities.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Implementation.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Sanction policy</ENT>
                                    <ENT>164.308(a)(6)</ENT>
                                    <ENT>Policies and procedures.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Modifications.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Application.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Information system activity review</ENT>
                                    <ENT>164.308(a)(7)</ENT>
                                    <ENT>Policies and procedures.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Scope.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Record review.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Record retention.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Response.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Maintenance.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Assigned security responsibility</ENT>
                                    <ENT>164.308(a)(8)</ENT>
                                    <ENT/>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Workforce security</ENT>
                                    <ENT>164.308(a)(9)</ENT>
                                    <ENT>Authorization and/or supervision.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Workforce clearance procedure.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Modification and termination procedures.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Notification.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Maintenance.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Information access management</ENT>
                                    <ENT>164.308(a)(10)</ENT>
                                    <ENT>Isolating health care clearinghouse functions.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Access authorization.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Authentication management.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Access determination and modification.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Network segmentation.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Maintenance.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Security awareness training</ENT>
                                    <ENT>164.308(a)(11)</ENT>
                                    <ENT>Training.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Timing.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Ongoing education.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Documentation.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Security incident procedures</ENT>
                                    <ENT>163.308(a)(12)</ENT>
                                    <ENT>Planning and testing.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Response.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Contingency plan</ENT>
                                    <ENT>163.308(a)(13)</ENT>
                                    <ENT>Criticality analysis.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Data backups.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Information systems backups.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Disaster recovery plan.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Emergency mode operation plan.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Testing and revision procedures.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Compliance audit</ENT>
                                    <ENT>164.308(a)(14)</ENT>
                                    <ENT/>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Business associate contracts and other arrangements</ENT>
                                    <ENT>164.308(b)(1)</ENT>
                                    <ENT>Written contract or other arrangement.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Written verification.</ENT>
                                </ROW>
                                <ROW RUL="s">
                                    <ENT I="01">Delegation to business associate</ENT>
                                    <ENT>164.308(b)(3)</ENT>
                                    <ENT/>
                                </ROW>
                                <ROW EXPSTB="02" RUL="s">
                                    <ENT I="21">
                                        <E T="02">Physical Safeguards</E>
                                    </ENT>
                                </ROW>
                                <ROW EXPSTB="00">
                                    <ENT I="01">Facility access controls</ENT>
                                    <ENT>164.310(a)</ENT>
                                    <ENT>Contingency operations.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Facility security plan.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Access management and validation procedures.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Physical maintenance records.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Maintenance.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Workstation use</ENT>
                                    <ENT>164.310(b)</ENT>
                                    <ENT>Policies and procedures.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Maintenance.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Workstation security</ENT>
                                    <ENT>164.310(c)</ENT>
                                    <ENT/>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Technology asset controls</ENT>
                                    <ENT>164.310(d)</ENT>
                                    <ENT>Disposal.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Media sanitization.</ENT>
                                </ROW>
                                <ROW RUL="s">
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Maintenance.</ENT>
                                </ROW>
                                <ROW EXPSTB="02" RUL="s">
                                    <PRTPAGE P="1022"/>
                                    <ENT I="21">
                                        <E T="02">Technical Safeguards</E>
                                    </ENT>
                                </ROW>
                                <ROW EXPSTB="00">
                                    <ENT I="01">Access control</ENT>
                                    <ENT>164.312(a)</ENT>
                                    <ENT>Unique identification.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Administrative and increased access privileges.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Emergency access procedure.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Automatic logoff.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Log-in attempts.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Network segmentation.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Data controls.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Maintenance.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Encryption and decryption</ENT>
                                    <ENT>164.312(b)</ENT>
                                    <ENT>Implementation specification.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Exceptions.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Alternative measures.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Compensating controls.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Maintenance.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Configuration management</ENT>
                                    <ENT>164.312(c)</ENT>
                                    <ENT>Anti-malware protection.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Software removal.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Configuration.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Network ports.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Maintenance.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Audit trail and system log controls</ENT>
                                    <ENT>164.312(d)</ENT>
                                    <ENT>Monitor and identify.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Record.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Retain.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Scope.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Maintenance.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Integrity</ENT>
                                    <ENT>164.312(e)</ENT>
                                    <ENT/>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Authentication</ENT>
                                    <ENT>164.312(f)</ENT>
                                    <ENT>Information access management policies.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Multi-factor authentication.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Exceptions.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Alternative measures.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Compensating controls.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Maintenance.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Transmission security</ENT>
                                    <ENT>164.312(g)</ENT>
                                    <ENT/>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Vulnerability management</ENT>
                                    <ENT>164.312(h)</ENT>
                                    <ENT>Vulnerability scanning.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Monitoring.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Penetration testing.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Patch and update installation.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Data backup and recovery</ENT>
                                    <ENT>164.312(i)</ENT>
                                    <ENT>Data backup</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Monitor and identify.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Record.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="22"> </ENT>
                                    <ENT/>
                                    <ENT>Testing.</ENT>
                                </ROW>
                                <ROW>
                                    <ENT I="01">Information systems backup and recovery</ENT>
                                    <ENT>164.312(j)</ENT>
                                </ROW>
                            </GPOTABLE>
                        </EXTRACT>
                    </SECTION>
                    <SIG>
                        <DATED>Dated: December 20, 2024.</DATED>
                        <NAME>Xavier Becerra,</NAME>
                        <TITLE>Secretary, Department of Health and Human Services.</TITLE>
                    </SIG>
                </SUPLINF>
                <FRDOC>[FR Doc. 2024-30983 Filed 12-27-24; 4:15 pm]</FRDOC>
                <BILCOD>BILLING CODE 4153-01-P</BILCOD>
            </PRORULE>
        </PRORULES>
    </NEWPART>
</FEDREG>
