<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="HA1A6E00D8B794772A3E16DD6DCB1CC32" public-private="public">
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>109 HR 5588 IH: To require the Secretary of Veterans Affairs to protect
</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2006-06-12</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
	<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>109th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>H. R. 5588</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20060612">June 12, 2006</action-date>
			<action-desc><sponsor name-id="S001158">Mr. Salazar</sponsor> (for
			 himself and <cosponsor name-id="E000250">Mr. Evans</cosponsor>) introduced the
			 following bill; which was referred to the <committee-name committee-id="HVR00">Committee on Veterans’
			 Affairs</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To require the Secretary of Veterans Affairs to protect
		  sensitive personal information of veterans, to ensure that veterans are
		  appropriately notified of any breach of data security with respect to such
		  information, to provide free credit monitoring and credit reports for veterans
		  and others affected by any such breach of data security, and for other
		  purposes.</official-title>
	</form>
	<legis-body id="HDA35B8E412574EC18500C7B8F4D85C62" style="OLC">
		<section id="H9C9BA7D2C29D459CB1C34D98B25B98DD" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote>Comprehensive Veterans' Data Protection and Identity Theft Prevention
			 Act of 2006</quote>.</text>
		</section><section id="H91D4415BDC2446BC9939EF63B97D7B89"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">For purposes of this Act, the following
			 definitions shall apply:</text>
			<paragraph id="HE5C09334DCA14B469D25D7C226F0A02B"><enum>(1)</enum><header>Data
			 breach</header><text>The term <quote>data breach</quote> means the unauthorized
			 acquisition or use of data in electronic or printed form containing sensitive
			 personal information, including information compromised with respect to the
			 theft of data first publicly reported on May 22, 2006.</text>
			</paragraph><paragraph id="H71DC304BEEA1485597325E8CD51F9962"><enum>(2)</enum><header>Data in
			 electronic form</header><text>The term <quote>data in electronic form</quote>
			 means any data stored electronically or digitally on any computer system or
			 database and includes recordable tapes and other mass storage devices.</text>
			</paragraph><paragraph id="HED8643CA7EB24C4AB760CA4695FD60AD"><enum>(3)</enum><header>Department</header><text display-inline="yes-display-inline">The term <quote>Department</quote> means
			 the Department of Veterans Affairs.</text>
			</paragraph><paragraph id="H156DDBF6B69841749B82F9987B7DFC48"><enum>(4)</enum><header>Encryption</header><text>The
			 term <quote>encryption</quote> means the protection of data in electronic form
			 in storage or transit using an encryption technology that has been adopted by
			 an established standards setting body which renders such data indecipherable in
			 the absence of associated cryptographic keys necessary to enable decryption of
			 such data, together with appropriate management and safeguards of such keys to
			 protect the integrity of the encryption.</text>
			</paragraph><paragraph id="H8292BFBD84A8490982B6B546D969B9B4"><enum>(5)</enum><header>Nationwide
			 consumer reporting agency</header><text>The term <quote>nationwide consumer
			 reporting agency</quote> means a consumer reporting agency described in section
			 603(p) of the Fair Credit Reporting Act.</text>
			</paragraph><paragraph id="HB39172BAFFCB48BD9461A40090419445"><enum>(6)</enum><header>Secretary</header><text>The
			 term <quote>Secretary</quote> means the Secretary of Veterans Affairs.</text>
			</paragraph><paragraph id="H3FC54899F20D49BAA001F8408C40FECE"><enum>(7)</enum><header>Sensitive
			 personal information</header><text display-inline="yes-display-inline">The term
			 <quote>sensitive personal information</quote> means the name, address, or
			 telephone number of a veteran or other individual, in combination with any of
			 the following:</text>
				<subparagraph id="HA4ACB1C8A8754284B972F5EF000F94D"><enum>(A)</enum><text>Social Security
			 number.</text>
				</subparagraph><subparagraph id="H76F77A4304694075AB8BA7F531C875FE"><enum>(B)</enum><text>Any information
			 not available as part of the public record regarding the veteran or other
			 individual’s military service or health.</text>
				</subparagraph><subparagraph id="H55B6B8E9B0CC4158B622DCCC8CC5A638"><enum>(C)</enum><text>Any financial
			 account or other financial information relating to the veteran or other
			 person.</text>
				</subparagraph></paragraph></section><section id="H1A8E5EF822254865A78300ACC7B5FC5"><enum>3.</enum><header>
			 Protection of sensitive personal information of veterans</header>
			<subsection id="HF473AE2B53C84C2BB314426BFF3B1191"><enum>(a)</enum><header>Affirmative
			 obligation</header><text>The Secretary shall have an affirmative obligation to
			 protect from any data breach the sensitive personal information of veterans and
			 any other individuals that the Department (or any third-party entity acting on
			 behalf of the Department) possesses, creates, or maintains as well as any
			 information or tools, including passwords or cryptographic keys used to protect
			 the integrity of encrypted data, used to access sensitive personal information
			 maintained independently by others.</text>
			</subsection><subsection id="H118017FF6FEE488A926F444BA92B2E13"><enum>(b)</enum><header>Security
			 policies and procedures</header><text display-inline="yes-display-inline">The
			 Secretary shall implement and maintain reasonable policies and procedures to
			 protect the security and confidentiality of sensitive personal information
			 relating to any veteran or other individual that is maintained, serviced, or
			 communicated by or on behalf of the Department against any unauthorized
			 access.</text>
			</subsection><subsection id="H1E0678B0B550419191FB4F430BAB195"><enum>(c)</enum><header>Policies and
			 procedures regarding access and use</header><text>The Secretary, by regulation,
			 shall prescribe policies and procedures regarding employee and third party
			 access to, and use of, sensitive personal information as well as the protection
			 of such sensitive personal information, which the Department receives,
			 maintains, or transmits. Such policies and procedures shall be issued before
			 the end of the 90-day period beginning on the date of the enactment of this
			 Act.</text>
			</subsection><subsection id="H35820986BE3A415C85053D29DB4D46C0"><enum>(d)</enum><header>System
			 restoration requirements</header><text display-inline="yes-display-inline">If
			 the Secretary determines that a data breach has occurred, is likely to have
			 occurred, or is unavoidable, the Secretary shall take prompt and reasonable
			 measures to—</text>
				<paragraph id="H3552AE38B5AD4B6F9143765E4C9134BE"><enum>(1)</enum><text>repair the breach
			 and restore the security and confidentiality of the sensitive personal
			 information involved to limit further unauthorized misuse of such information;
			 and</text>
				</paragraph><paragraph id="H475540BE7D1D4C79B800CD8D0051EBCE"><enum>(2)</enum><text display-inline="yes-display-inline">restore the integrity of the data security
			 safeguards of the Department and make appropriate improvements to the data
			 security, and the access and use, policies and procedures issued under
			 subsections (b) and (c).</text>
				</paragraph></subsection><subsection id="H3F39DA7631774285ABFD2626DEE8513"><enum>(e)</enum><header>Third party
			 duties</header>
				<paragraph id="HB9FA244E928C41178231D4F194452BEF"><enum>(1)</enum><header>Coordinated
			 investigation</header><text display-inline="yes-display-inline">Whenever any
			 third party handling sensitive personal information for or on behalf of the
			 Department determines that a data breach has occurred, is likely to have
			 occurred, or is unavoidable, with respect to such information, the third party
			 shall—</text>
					<subparagraph id="H60009C6AFE3A42848FDB505E5078F000"><enum>(A)</enum><text>promptly notify
			 the Department of such determination;</text>
					</subparagraph><subparagraph id="H14C6C1F1864C4527A5C99FA61D5EE7CE"><enum>(B)</enum><text>conduct a
			 coordinated investigation with the Department to determine the full scope of
			 any such data breach; and</text>
					</subparagraph><subparagraph id="H537C127157044B32B49B7E3E8686F7C2"><enum>(C)</enum><text>ensure that the
			 appropriate notices are provided as required under section 4 of this
			 Act.</text>
					</subparagraph></paragraph><paragraph id="H94411BEAFE904F8CB0A6B028AE12A5FF"><enum>(2)</enum><header>Contractual
			 obligation required</header><text>The Secretary shall not provide sensitive
			 personal information to a third party unless such third party agrees to fulfill
			 the obligations imposed by sections 4, 5, and 6 of this Act.</text>
				</paragraph><paragraph id="H5F170C272AAE40420000004CE9902389"><enum>(3)</enum><header>Liability for
			 costs</header><text display-inline="yes-display-inline">Except as otherwise
			 established by written agreements between the Department and any third party, a
			 third party that suffers a data breach shall be responsible for all costs
			 associated with complying with this Act, as well as other costs related to such
			 a breach, including any damages relating to such a breach.</text>
				</paragraph></subsection></section><section id="H5430528FB5754C549CF1C4FA8368B449"><enum>4.</enum><header>Notification of
			 data breach</header>
			<subsection id="H08292FA8AC6E4F46B1AC50073E69DF0"><enum>(a)</enum><header>Notification</header><text>Upon
			 discovery of a data breach, the Secretary shall—</text>
				<paragraph id="HFF873210FB1040568E52D8637DB2C8C5"><enum>(1)</enum><text>notify the United
			 States Secret Service, the Inspector General for the Department of Veterans
			 Affairs, the Committees on Veterans’ Affairs of the Senate and the House of
			 Representatives, and the Federal Trade Commission that a data breach has
			 occurred and the extent of such a breach;</text>
				</paragraph><paragraph id="HB6F3B98536B04F85BDF10BD62429FB7"><enum>(2)</enum><text>notify each
			 individual whose personal information was acquired or accessed by an
			 unauthorized person as a result of such a data breach; and</text>
				</paragraph><paragraph id="H4650E247B4B7407EB7C7D4AF8B3CBDA6"><enum>(3)</enum><text>place a
			 conspicuous notice on the Department’s Internet website, which shall include a
			 telephone number that the individual may use, at no cost to such individual, to
			 contact the Department to inquire about the data breach or the information the
			 Department maintained about that individual.</text>
				</paragraph></subsection><subsection id="H1D763C32AA684B2BB5DFDA311592CAA"><enum>(b)</enum><header>Timeliness of
			 notification</header><text>All notifications required under subsection (a)
			 shall be made as promptly as possible and without unreasonable delay following
			 the discovery of a data breach and the implementation of any measures necessary
			 to determine the scope of the breach, prevent any further breach or
			 unauthorized disclosures, and reasonably restore the integrity of the data
			 system.</text>
			</subsection><subsection id="H746E785DF2D641B88EF28FDBA92A738"><enum>(c)</enum><header>Method and
			 content of notification</header>
				<paragraph display-inline="no-display-inline" id="H1DAEDF944CB846A9A03FAE7C533713FE"><enum>(1)</enum><header>Method of
			 notification</header><text>The Secretary shall provide written notification to
			 individuals under subsection (a)(2).</text>
				</paragraph><paragraph id="H0FFC16A72F4E46F3A6FA65009E859794"><enum>(2)</enum><header>Content of
			 notification</header><text>Such written notification provided to an individual
			 under paragraph (1) shall include—</text>
					<subparagraph id="H7FDF3030869F4A268F19434FBE9D9E54"><enum>(A)</enum><text>a description of
			 the personal information that was acquired by an unauthorized person;</text>
					</subparagraph><subparagraph id="H1D2C8A423A994996A462EF24E754941"><enum>(B)</enum><text display-inline="yes-display-inline">a telephone number that the individual may
			 use, at no cost to such individual, to contact the Ombudsman for Data Security
			 in the Department to inquire about the security breach or the information about
			 that individual that the person acquired or accessed, as well as to obtain
			 assistance in addressing identity theft issues;</text>
					</subparagraph><subparagraph id="H623C11577F03425A9DBEBB67D5E2906B"><enum>(C)</enum><text>the toll-free
			 contact telephone numbers and addresses for the major credit reporting
			 agencies;</text>
					</subparagraph><subparagraph id="H1F01E18CDC814354AEE44BF11B9E2E4"><enum>(D)</enum><text>a toll-free
			 telephone number and Internet website address for the Federal Trade Commission
			 whereby the individual may obtain information regarding identity theft;
			 and</text>
					</subparagraph><subparagraph id="H1A497678A0A341C0B1310600D200B992"><enum>(E)</enum><text>information
			 regarding the right of an individual, at no cost to that individual, to place a
			 fraud alert, obtain a security freeze, and receive credit monitoring where
			 applicable, including information clearly describing the advantages and
			 disadvantages of these actions.</text>
					</subparagraph></paragraph></subsection><subsection id="H0E8CFE7EE9F5421DBFCAC0D8859518A2"><enum>(d)</enum><header>Website notice
			 of Federal Trade Commission</header><text>The Federal Trade Commission shall
			 place, in a clear and conspicuous location on its Internet website, a notice of
			 any breach of security that is reported to the Commission under subsection
			 (a)(1).</text>
			</subsection></section><section id="H446E6A704B9748D4B7F3A6F8CF556D00"><enum>5.</enum><header>Fraud
			 alerts</header>
			<subsection id="H8CD860583F0946D1866409A0EB6FC500"><enum>(a)</enum><header>Inclusion in
			 consumer files</header><text>The Secretary shall arrange, upon the request of a
			 veteran or other individual affected by a data breach and at no cost to the
			 veteran or other individual, to include a fraud alert in the file of that
			 veteran or other individual with each nationwide consumer reporting agencies in
			 the manner provided under section 605A(a) for a period of not less than 1 year,
			 beginning on the date of such request, unless the veteran or other individual
			 requests that such fraud alert be removed before the end of such period, and
			 the agency has received appropriate proof of the identity of the requestor for
			 such purpose.</text>
			</subsection><subsection id="HB1257C46FA8247F8BF94C79273F72CE1"><enum>(b)</enum><header>Distribution</header><text>Each
			 nationwide consumer reporting agency referred to in subsection (a) shall also
			 provide the alert required under such subsection in the file of a veteran or
			 other individual along with any credit score generated in using that file, for
			 a period of not less than 1 year, beginning on the date of such request, unless
			 the veteran or other individual requests that such fraud alert be removed
			 before the end of such period, and the agency has received appropriate proof of
			 the identity of the requestor for such purpose.</text>
			</subsection></section><section id="HA072EDC18E65452DB365388E90A536A7"><enum>6.</enum><header>Credit security
			 freeze</header>
			<subsection id="H7D1A6EABA2144F1F9757936459F06192"><enum>(a)</enum><header>In
			 general</header><text>The Secretary shall arrange, upon the request of a
			 veteran or other individual affected by a data breach and at no cost to the
			 veteran or other individual, to apply a security freeze to the file of that
			 veteran or other individual with each nationwide consumer reporting agency for
			 a period of not less than 1 year, beginning on the date of such request, unless
			 the veteran or other individual requests that such security freeze be removed
			 before the end of such period, and the agency has received appropriate proof of
			 the identity of the requestor for such purpose.</text>
			</subsection><subsection id="H1BA67E95E2E14A299E1E366539AF43F"><enum>(b)</enum><header>Confirmation and
			 pin numbers</header><text>The agency shall send a written confirmation of the
			 security freeze to the veteran or other individual within 5 business days of
			 placing the freeze. The agency shall refer the information regarding the
			 security freeze to other consumer reporting agencies. The agency shall provide
			 the veteran or other individual with a unique personal identification number or
			 password to be used by the veteran or other individual when providing
			 authorization for the release of his or her credit for a specific party or
			 period of time.</text>
			</subsection><subsection id="HE6C81DD17B3C486EAA76398CA779A94"><enum>(c)</enum><header>Temporary lift of
			 freeze</header><text>The agency that receives a request from a veteran or other
			 individual to temporarily lift a freeze on a consumer report shall comply with
			 the request no later than 3 business days after receiving the request. Such
			 request shall be specific as to the period to which the temporary lift of a
			 freeze shall apply.</text>
			</subsection><subsection id="H1375AFCB47DB48389B37DA81C546776C"><enum>(d)</enum><header>Negotiating
			 authority</header><text>The Secretary shall have broad authority to negotiate
			 and secure the best possible price for services provided under this section.
			 All reasonable costs shall be borne by the Secretary.</text>
			</subsection></section><section id="H467AC94C1BBD47350000EB001C844B57"><enum>7.</enum><header>Authority to
			 provide mitigation services to victims of data security breaches</header>
			<subsection id="HC99E1F89D2394AE58BA038635D35E8D0"><enum>(a)</enum><header>In
			 general</header><text>The Secretary shall provide, free of charge, to each
			 individual whose personal information is (or was before the date of enactment
			 of this Act) compromised by a data breach at the Department of Veterans
			 Affairs—</text>
				<paragraph id="H46DC83BB134C42468DA2394B16DAD919"><enum>(1)</enum><text>credit monitoring
			 services, during a 1-year period beginning on the date of enactment of this
			 Act; and</text>
				</paragraph><paragraph id="HC9A7DC10B29E4F488B4DAC38A2DB4EB5"><enum>(2)</enum><text>a
			 copy of the consumer report (as defined in section 603 of the Fair Credit
			 Reporting Act) of the affected individual once annually during the 2-year
			 period beginning on the date on which the credit monitoring services required
			 by paragraph (1) terminate, which shall be in addition to any other consumer
			 report provided to the individual under otherwise applicable law, free of
			 charge or otherwise.</text>
				</paragraph></subsection><subsection id="HC0A4E5B6A1E34DC881A8571198E768FC"><enum>(b)</enum><header>Negotiating
			 authority</header><text>The Secretary of Veterans Affairs shall have broad
			 authority to negotiate and secure the best possible price for services provided
			 under this section.</text>
			</subsection></section><section id="HB11CADEE897B450DA9397FB982970317"><enum>8.</enum><header>Ombudsman</header>
			<subsection id="H701F28566EC246F28826DC69B19EF96"><enum>(a)</enum><header>Establishment</header><text display-inline="yes-display-inline">The Secretary shall establish the position
			 of an Ombudsman for Data Security within the Department.</text>
			</subsection><subsection id="HA7E898C6D13F4297A93F05BB42CAD700"><enum>(b)</enum><header>Duties</header><text>The
			 Ombudsman for Data Security shall—</text>
				<paragraph id="HDF70C835BC6842BB88024E58003F8F6B"><enum>(1)</enum><text>provide
			 information and assistance to veterans or other individuals affected by data
			 breaches, including providing information and assistance on identity theft and
			 issues relating to identity theft;</text>
				</paragraph><paragraph id="H11D4C8B9701C4A108B41643822E9A5E3"><enum>(2)</enum><text>assist veterans or
			 other individuals affected by a data breach with placing fraud alerts and
			 security freezes;</text>
				</paragraph><paragraph id="HDFCAC0710CDC4CAFA1E3248BC02DC800"><enum>(3)</enum><text>provide veterans
			 with ongoing education on general financial matters and identity theft in
			 particular; and</text>
				</paragraph><paragraph id="HC20A076A8B57442AB5393C002F14B400"><enum>(4)</enum><text>carry out such
			 other duties and responsibilities as the Secretary may designate to the
			 Ombudsman for Data Security.</text>
				</paragraph></subsection></section></legis-body>
</bill>


