<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Referred-in-Senate" bill-type="olc" dms-id="H855F4F3E34DE4114BF00B4052BEFBD6F" key="H" public-private="public">
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>109 HR 5835 : Veterans Identity and Credit Security
</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2006-11-13</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
	<form>
		<distribution-code display="yes">IIB</distribution-code>
		<congress>109th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>H. R. 5835</legis-num>
		<current-chamber display="yes">IN THE SENATE OF THE UNITED
		  STATES</current-chamber>
		<action>
			<action-date>September 27, 2006</action-date>
			<action-desc>Received</action-desc>
		</action>
		<action>
			<action-date date="20061113">November 13, 2006</action-date>
			<action-desc> Read twice and referred to the
			 <committee-name committee-id="SSVA00">Committee on Veterans'
			 Affairs</committee-name></action-desc>
		</action>
		<legis-type>AN ACT</legis-type>
		<official-title display="yes">To amend title 38, United States Code, to
		  improve information management within the Department of Veterans Affairs, and
		  for other purposes. </official-title>
	</form>
	<legis-body id="H1ED054D2DA014F5E82686EEE259804DF" style="OLC">
		<section display-inline="no-display-inline" id="H7D9335F5893846CDBF7EA4E79EADAD7F" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Veterans Identity and Credit Security
			 Act of 2006</short-title></quote>.</text>
		</section><section display-inline="no-display-inline" id="HB8E96AE84E9442E1ACE4DF0F07DDE15"><enum>2.</enum><header>Federal agency
			 data breach notification requirements</header>
			<subsection id="HA077FB5E512A447EA4B7ACB72C844486"><enum>(a)</enum><header>Authority of
			 director of Office of Management and Budget to establish data breach
			 policies</header><text><external-xref legal-doc="usc" parsable-cite="usc/44/3543">Section 3543(a)</external-xref> of title 44, United
			 States Code, is amended—</text>
				<paragraph id="H66ABE57354154F0395E15D2E247CDF04"><enum>(1)</enum><text>by striking
			 <quote>and</quote> at the end of paragraph (7);</text>
				</paragraph><paragraph id="H28B74A624F464387B98796BDFC9504D6"><enum>(2)</enum><text>by striking the
			 period and inserting <quote>; and</quote> at the end of paragraph (8);
			 and</text>
				</paragraph><paragraph id="H00C75D13E748460496C76800D4F0AEC"><enum>(3)</enum><text>by
			 adding at the end the following:</text>
					<quoted-block id="HDD5AA6F02F014155BE049056FEDFA400" style="OLC">
						<paragraph id="H4B5AC25C13FF402593D4B0434CCF2299"><enum>(9)</enum><text display-inline="yes-display-inline">establishing policies, procedures, and
				standards for agencies to follow in the event of a breach of data security
				involving the disclosure of sensitive personal information and for which harm
				to an individual could reasonably be expected to result, specifically
				including—</text>
							<subparagraph id="H6B7E4AB8BE79491EA6341D3DA36F16B"><enum>(A)</enum><text>a requirement for
				timely notice to be provided to those individuals whose sensitive personal
				information could be compromised as a result of such breach, except no notice
				shall be required if the breach does not create a reasonable risk of identity
				theft, fraud, or other unlawful conduct regarding such individual;</text>
							</subparagraph><subparagraph id="HD93AFF0161BB49058F0002044D8EEB1F"><enum>(B)</enum><text>guidance on
				determining how timely notice is to be provided; and</text>
							</subparagraph><subparagraph id="HE1C902ADB60E4A0DACCFA6A5893DEDE1"><enum>(C)</enum><text>guidance regarding
				whether additional special actions are necessary and appropriate, including
				data breach analysis, fraud resolution services, identity theft insurance, and
				credit protection or monitoring
				services.</text>
							</subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection id="H4EADF80516564280BB2DF5B1D3C981B7"><enum>(b)</enum><header>Authority of
			 chief information officer to enforce data breach policies and develop and
			 maintain inventories</header><text>Section 3544(a)(3)
			 of title 44, United States Code, is amended—</text>
				<paragraph id="H866941541DBE485A8F4700DA116FAA91"><enum>(1)</enum><text>by inserting after
			 <quote>authority to ensure compliance with</quote> the following: <quote>and,
			 to the extent determined necessary and explicitly authorized by the head of the
			 agency, to enforce</quote>;</text>
				</paragraph><paragraph id="H2316E91E147C4EA792DF6537D57E5F35"><enum>(2)</enum><text>by striking
			 <quote>and</quote> at the end of subparagraph (D);</text>
				</paragraph><paragraph id="HB8F36C37204547C7A40798D4F561D89C"><enum>(3)</enum><text>by inserting
			 <quote>and</quote> at the end of subparagraph (E); and</text>
				</paragraph><paragraph id="HDE36E26FBF564B7C0099D65E7E37E4F"><enum>(4)</enum><text>by
			 adding at the end the following:</text>
					<quoted-block id="H1729AAB9BB8A4FE1A3A65F5E9EFB407C" style="OLC">
						<subparagraph id="H8DFA7BB360074EC98B63E3C22CDADD26"><enum>(F)</enum><text>developing and
				maintaining an inventory of all personal computers, laptops, or any other
				hardware containing sensitive personal
				information;</text>
						</subparagraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection id="H11EDB857629242BE9F05DC5F23EA51C7"><enum>(c)</enum><header>Inclusion of
			 data breach notification in agency information security
			 programs</header><text><external-xref legal-doc="usc" parsable-cite="usc/44/3544">Section 3544(b)</external-xref> of title 44, United
			 States Code, is amended—</text>
				<paragraph id="H3C4133DC513848B4BF7F55D1FF24E00"><enum>(1)</enum><text>by
			 striking <quote>and</quote> at the end of paragraph (7);</text>
				</paragraph><paragraph id="HDF29973EAAB84EB5BDD18740A5BE71E2"><enum>(2)</enum><text>by striking the
			 period and inserting <quote>; and</quote> at the end of paragraph (8);
			 and</text>
				</paragraph><paragraph id="HC83856CC24BD4F46A21BCECA8775D291"><enum>(3)</enum><text>by adding at the
			 end the following:</text>
					<quoted-block id="HB7F048D50425464992E95E8E70AB3BE4" style="OLC">
						<paragraph id="H87C3596F620546769887788E22623165"><enum>(9)</enum><text>procedures for
				notifying individuals whose sensitive personal information is compromised
				consistent with policies, procedures, and standards established under section
				3543(a)(9) of this
				title.</text>
						</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection id="HA14BFD99E98541C3A44FA64913EDA062"><enum>(d)</enum><header>Authority of
			 agency chief human capital officers to assess federal personal
			 property</header><text><external-xref legal-doc="usc" parsable-cite="usc/5/1402">Section 1402(a)</external-xref> of title 5, United
			 States Code, is amended—</text>
				<paragraph id="H1CBFFE87F5934435B93F85E8FA91F43"><enum>(1)</enum><text>by
			 striking <quote>, and</quote> at the end of paragraph (5) and inserting a
			 semicolon;</text>
				</paragraph><paragraph id="H952BF7F5349E488CA100DB2E3DAA72E5"><enum>(2)</enum><text>by striking the
			 period and inserting <quote>; and</quote> at the end of paragraph (6);
			 and</text>
				</paragraph><paragraph id="H3CBC2B45F3154FBF9324D2AB1E3CAADC"><enum>(3)</enum><text>by adding at the
			 end the following:</text>
					<quoted-block id="H279DDB249E30425591898EEBFDB86623" style="OLC">
						<paragraph id="HF227A0D42D8C431387FF9462FF212900"><enum>(7)</enum><text>prescribing
				policies and procedures for exit interviews of employees, including a full
				accounting of all Federal personal property that was assigned to the employee
				during the course of
				employment.</text>
						</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection id="H4B1C62A9CCB24DE08CB16444B2DEDF23"><enum>(e)</enum><header>Sensitive
			 personal information definition</header><text><external-xref legal-doc="usc" parsable-cite="usc/44/3542">Section 3542(b)</external-xref> of title 44, United
			 States Code, is amended by adding at the end the following new
			 paragraph:</text>
				<quoted-block id="H48D2E1BD8D504644B339D7DFF2A0CDD1" style="OLC">
					<paragraph id="H8A2DD5FA5BE3486593E7A100536EF306"><enum>(4)</enum><text>The term
				<quote>sensitive personal information</quote>, with respect to an individual,
				means any information about the individual maintained by an agency,
				including—</text>
						<subparagraph id="H8FD2CAF29BCE44A0B9C40598E245994E"><enum>(A)</enum><text>education,
				financial transactions, medical history, and criminal or employment
				history;</text>
						</subparagraph><subparagraph id="H8E828CA765C746E0AB98209FF36F1323"><enum>(B)</enum><text>information that
				can be used to distinguish or trace the individual’s identity, including name,
				social security number, date and place of birth, mother’s maiden name, or
				biometric records; or</text>
						</subparagraph><subparagraph id="HF7888D29EDCA4BA6B13CCD61124B8014"><enum>(C)</enum><text>any other personal
				information that is linked or linkable to the
				individual.</text>
						</subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection></section><section id="HFB7F0B21C9974DDAB1C575C5B0A79900"><enum>3.</enum><header>Under Secretary
			 for Information Services</header>
			<subsection id="H8E90AF3B148948338D16488959E1C1F"><enum>(a)</enum><header>Under
			 Secretary</header><text><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/38/3">Chapter 3</external-xref> of title 38, United
			 States Code, is amended by inserting after
			 section
			 307 the following new section:</text>
				<quoted-block display-inline="no-display-inline" id="HA86A5DDCFC264105A3CB40C1DD50EB91" style="USC">
					<section id="H0A36186538EB4FFF82A55DD421DE4BD1"><enum>307A.</enum><header>Under
				Secretary for Information Services</header>
						<subsection id="HC920885D13104712AF292982D184EB04"><enum>(a)</enum><header>Under
				Secretary</header><text display-inline="yes-display-inline">There is in the
				Department an Under Secretary for Information Services, who is appointed by the
				President, by and with the advice and consent of the Senate. The Under
				Secretary shall be the head of the Office of Information Services and shall
				perform such functions as the Secretary shall prescribe.</text>
						</subsection><subsection id="HF48A39F3C1DD435EBDB192045DB0C4F6"><enum>(b)</enum><header>Service as Chief
				Information Officer</header><text>Notwithstanding any other provision of law,
				the Under Secretary for Information Services shall serve as the Chief
				Information Officer of the Department under section 310 of this
				title.</text>
						</subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="H9F13AD234EC349109DFB74B44ED84BD5"><enum>(b)</enum><header>Clerical
			 amendment</header><text>The table of sections at the beginning of such chapter
			 is amended by inserting after the item relating to section 307 the following
			 new item:</text>
				<quoted-block display-inline="no-display-inline" id="H747A69484C22465F96ECB724CC5B97CD" style="USC">
					<toc regeneration="no-regeneration">
						<toc-entry level="section">307A. Under Secretary for Information
				Services.</toc-entry>
					</toc>
					<after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="H83269523E5204F6E87C2CECDD57B31CA"><enum>(c)</enum><header>Conforming
			 amendment</header><text>Section 308(b) of such title is amended by striking
			 paragraph (5) and redesignating paragraphs (6) through (11) as paragraphs (5)
			 through (10), respectively.</text>
			</subsection></section><section id="HE98FE2DC2F884E74A5C8330593D91CA1"><enum>4.</enum><header>Department of
			 Veterans Affairs information security</header>
			<subsection id="H469205FF9F634EA98331AA636198B2D7"><enum>(a)</enum><header>Information
			 security</header><text><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/38/57">Chapter 57</external-xref> of title 38,
			 United States Code, is amended by adding at the end the following new
			 subchapter:</text>
				<quoted-block display-inline="no-display-inline" id="H19D082FF5CBD4E209EE600721EB0F7BF" style="USC">
					<subchapter id="HEB7E70F98632435A8D81A31281DB871C"><enum>III</enum><header>Information
				Security</header>
						<section id="H0D8FF65AE36F42DD9C9083A3468500B6"><enum>5721.</enum><header>Definitions</header><text display-inline="no-display-inline">For the purposes of this subchapter:</text>
							<paragraph id="HCD655426E2A043E59EB7D845DDD92CD4"><enum>(1)</enum><text>The term
				<quote>sensitive personal information</quote>, with respect to an individual,
				means any information about the individual maintained by an agency,
				including—</text>
								<subparagraph id="H4083A74B9FE94145BBF34D7E00989F13"><enum>(A)</enum><text>education,
				financial transactions, medical history, and criminal or employment
				history;</text>
								</subparagraph><subparagraph id="H21BC9C07C22D42A297429BA446EB4E78"><enum>(B)</enum><text>information that
				can be used to distinguish or trace the individual’s identity, including name,
				social security number, date and place of birth, mother’s maiden name, or
				biometric records; or</text>
								</subparagraph><subparagraph id="HCF0AD778D07B498984F2C00E9CF00C2"><enum>(C)</enum><text>any other personal
				information that is linked or linkable to the individual.</text>
								</subparagraph></paragraph><paragraph id="H1597D4BF39034582A2C899A424EB796"><enum>(2)</enum><text>The term
				<quote>data breach</quote> means the loss, theft, or other unauthorized access
				to data containing sensitive personal information, in electronic or printed
				form, that results in the potential compromise of the confidentiality or
				integrity of the data.</text>
							</paragraph><paragraph id="H07B55485000548429D0043AFDD931B8"><enum>(3)</enum><text>The term
				<quote>data breach analysis</quote> means the identification of any misuse of
				sensitive personal information involved in a data breach.</text>
							</paragraph><paragraph id="H5F0CAFA85D4F43C692285FCCA3959910"><enum>(4)</enum><text>The term
				<quote>fraud resolution services</quote> means services to assist an individual
				in the process of recovering and rehabilitating the credit of the individual
				after the individual experiences identity theft.</text>
							</paragraph><paragraph id="HA23A40543C0B4D0EABE4174682DE5507"><enum>(5)</enum><text>The term
				<quote>identity theft</quote> has the meaning given such term under section 603
				of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681a">15 U.S.C. 1681a</external-xref>).</text>
							</paragraph><paragraph id="H8F04777BF5164128B821F7F4EF00E52B"><enum>(6)</enum><text>The term
				<quote>identity theft insurance</quote> means any insurance policy that pays
				benefits for costs, including travel costs, notary fees, and postage costs,
				lost wages, and legal fees and expenses associated with the identity theft of
				the insured individual.</text>
							</paragraph><paragraph id="HEE1E8791B8F4459E8BE7F600D3D2BC8F"><enum>(7)</enum><text display-inline="yes-display-inline">The term <quote>principal credit reporting
				agency</quote> means a consumer reporting agency as described in section 603(p)
				of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681a">15 U.S.C. 1681a(p)</external-xref>).</text>
							</paragraph></section><section id="HEDBCDE8C7840495C8B2800A3D38BFA4"><enum>5722.</enum><header>Office of the
				Under Secretary for Information Services</header>
							<subsection id="H49433F7F09384909881CF6739D1300E8"><enum>(a)</enum><header>Deputy Under
				Secretaries</header><text>The Office of the Under Secretary for Information
				Services shall consist of the following:</text>
								<paragraph id="H678CFA1BF4784E75ABECA35100E2CE19"><enum>(1)</enum><text>The Deputy Under
				Secretary for Information Services for Security, who shall serve as the Senior
				Information Security Officer of the Department.</text>
								</paragraph><paragraph id="H905DA0191C5741189E458BCAB5106291"><enum>(2)</enum><text>The Deputy Under
				Secretary for Information Services for Operations and Management.</text>
								</paragraph><paragraph id="HC3A4F012DA284929A52032B4FE4FC0C6"><enum>(3)</enum><text>The Deputy Under
				Secretary for Information Services for Policy and Planning.</text>
								</paragraph></subsection><subsection id="HED8908A176274091AD3BE4F0FB8C0033"><enum>(b)</enum><header>Appointments</header><text>Appointments
				under subsection (a) shall be made by the Secretary, notwithstanding the
				limitations of section 709 of this title.</text>
							</subsection><subsection id="H09DA8A0531A647F2A4939DD1E39BDA34"><enum>(c)</enum><header>Qualifications</header><text display-inline="yes-display-inline">At least one of positions established and
				filled under subsection (a) shall be filled by an individual who has at least
				five years of continuous service in the Federal civil service in the executive
				branch immediately preceding the appointment of the individual as a Deputy
				Under Secretary. For purposes of determining such continuous service of an
				individual, there shall be excluded any service by such individual in a
				position—</text>
								<paragraph id="H492DB06880424AAC8B96ADBBBD00F900"><enum>(1)</enum><text>of a confidential,
				policy-determining, policy-making, or policy-advocating character;</text>
								</paragraph><paragraph id="H0DBF84DE720747B4AEB6C90086F8B170"><enum>(2)</enum><text>in which such
				individual served as a noncareer appointee in the Senior Executive Service, as
				such term is defined in
				section
				3132(a)(7) of title 5; or</text>
								</paragraph><paragraph id="H26AD9D58281343FA839571BACC5400F0"><enum>(3)</enum><text>to which such
				individual was appointed by the President.</text>
								</paragraph></subsection></section><section id="H09E9256B770E41A18FCEABBB0073AEE4"><enum>5723.</enum><header>Information
				security management</header>
							<subsection id="H5568747AA76C4C1C869D14AAAA8407"><enum>(a)</enum><header>Responsibilities
				of Chief Information Officer</header><text display-inline="yes-display-inline">To support the economical, efficient, and
				effective execution of subtitle III of
				<external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, and
				policies and plans of the Department, the Secretary shall ensure that the Chief
				Information Officer of the Department has the authority and control necessary
				to develop, approve, implement, integrate, and oversee the policies,
				procedures, processes, activities, and systems of the Department relating to
				that subtitle, including the management of all related mission applications,
				information resources, personnel, and infrastructure.</text>
							</subsection><subsection id="HF6DF6CA18EAB441BBABF91A3C19549F1"><enum>(b)</enum><header>Annual compliance
				report</header><text display-inline="yes-display-inline">Not later than March 1
				of each year, the Secretary shall submit to the Committees on Veterans’ Affairs
				of the Senate and House of Representatives, the Committee on Government Reform
				of the House of Representatives, and the Committee on Homeland Security and
				Governmental Affairs of the Senate, a report on the Department’s compliance
				with subtitle III of
				<external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44. The
				information in such report shall be displayed in the aggregate and separately
				for each Administration, office, and facility of the Department.</text>
							</subsection><subsection id="H698B5A8E9840429BAF2690FD00768993"><enum>(c)</enum><header>Reports to
				Secretary of compliance deficiencies</header><paragraph commented="no" display-inline="yes-display-inline" id="HDBDE8D89B6EA4EDA9800CC6052006350"><enum>(1)</enum><text>At least once every
				month, the Chief Information Officer shall report to the Secretary any
				deficiency in the compliance with subtitle III of
				<external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44 of the
				Department or any Administration, office, or facility of the Department.</text>
								</paragraph><paragraph id="HFD5550CACA934147977F7B35F07CF561" indent="up1"><enum>(2)</enum><text>The Chief Information Officer shall
				immediately report to the Secretary any significant deficiency in such
				compliance.</text>
								</paragraph></subsection><subsection display-inline="no-display-inline" id="H0B5099B3AE2A4FBF846EBD4EC2035789"><enum>(d)</enum><header>Data
				breaches</header><paragraph commented="no" display-inline="yes-display-inline" id="H2780926E7EA54ED6A9CCC7980045B873"><enum>(1)</enum><text>The Chief Information
				Officer shall immediately provide notice to the Secretary of any data
				breach.</text>
								</paragraph><paragraph id="H730C1C60E0F848A69116F36DF53CE3B" indent="up1"><enum>(2)</enum><text>Immediately after receiving notice of
				a data breach under paragraph (1), the Secretary shall provide notice of such
				breach to the Director of the Office of Management and Budget, the Inspector
				General of the Department, and, if appropriate, the Federal Trade Commission
				and the United States Secret Service.</text>
								</paragraph></subsection><subsection id="H9F00802F19DE449FA2498B41ED8C5135"><enum>(e)</enum><header>Budgetary
				matters</header><text>When the budget for any fiscal year is submitted by the
				President to Congress under
				section
				1105 of title 31, the Secretary shall submit to Congress a
				report that identifies amounts requested for Department implementation and
				remediation of and compliance with this subchapter and subtitle III of
				<external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44. The
				report shall set forth those amounts both for each Administration within the
				Department and for the Department in the aggregate and shall identify, for each
				such amount, how that amount is aligned with and supports such implementation
				and compliance.</text>
							</subsection></section><section id="H9AC110AAB5344A56A5D288C1FF363D8B"><enum>5724.</enum><header>Congressional
				reporting and notification of data breaches</header>
							<subsection id="H320C55962D9D44BAB1EF23214100E446"><enum>(a)</enum><header>Quarterly
				reports</header><paragraph commented="no" display-inline="yes-display-inline" id="H594E45553F7D44E1B085471591886FF1"><enum>(1)</enum><text>Not later than 30 days
				after the last day of a fiscal quarter, the Secretary shall submit to the
				Committees on Veterans’ Affairs of the Senate and House of Representatives a
				report on any data breach with respect to sensitive personal information
				processed or maintained by the Department that occurred during that
				quarter.</text>
								</paragraph><paragraph id="HCCE3D4A07BD34F40AF48E98349F83DFB" indent="up1"><enum>(2)</enum><text>Each report submitted under paragraph
				(1) shall identify, for each data breach covered by the report, the
				Administration and facility of the Department responsible for processing or
				maintaining the sensitive personal information involved in the data
				breach.</text>
								</paragraph></subsection><subsection id="H960DC0184AD347CA894604CB447265DA"><enum>(b)</enum><header>Notification of
				significant data breaches</header><paragraph commented="no" display-inline="yes-display-inline" id="H8738E9F89C594D64BCCE004B1E655ED"><enum>(1)</enum><text>In the event of a data
				breach with respect to sensitive personal information processed or maintained
				by the Secretary that the Secretary determines is significant, the Secretary
				shall provide notice of such breach to the Committees on Veterans’ Affairs of
				the Senate and House of Representatives.</text>
								</paragraph><paragraph id="H0005847613C04E46AA676D28432D4531" indent="up1"><enum>(2)</enum><text display-inline="yes-display-inline">Notice under paragraph (1) shall be
				provided promptly following the discovery of such a data breach and the
				implementation of any measures necessary to determine the scope of the breach,
				prevent any further breach or unauthorized disclosures, and reasonably restore
				the integrity of the data system.</text>
								</paragraph></subsection></section><section id="H1F1729FB2BDC40E1AF4F697E13A25BD3"><enum>5725.</enum><header>Data
				breaches</header>
							<subsection id="H236F8059DE9B472894C3569E0000D235"><enum>(a)</enum><header>Independent risk
				analysis</header><paragraph commented="no" display-inline="yes-display-inline" id="H29284137914B474784B295CC549F2F36"><enum>(1)</enum><text>In the event of a data
				breach with respect to sensitive personal information that is processed or
				maintained by the Secretary, the Secretary shall ensure that, as soon as
				possible after the data breach, a non-Department entity conducts an independent
				risk analysis of the data breach to determine the level of risk associated with
				the data breach for the potential misuse of any sensitive personal information
				involved in the data breach.</text>
								</paragraph><paragraph id="HA1E1CA29C49A43C09E183F1874967462" indent="up1"><enum>(2)</enum><text display-inline="yes-display-inline">If the Secretary determines, based on the
				findings of a risk analysis conducted under paragraph (1), that a reasonable
				risk exists for the potential misuse of sensitive information involved in a
				data breach, the Secretary shall provide credit protection services in
				accordance with section 5726 of this title.</text>
								</paragraph></subsection><subsection id="H9AADDEBCEFFB4F1D8E76894B773C2784"><enum>(b)</enum><header>Notification</header><paragraph commented="no" display-inline="yes-display-inline" id="HD8CFFB98FD544C03B7ECC3C32CE81E85"><enum>(1)</enum><text display-inline="yes-display-inline">In the event of a data breach with respect
				to sensitive personal information that is processed or maintained by the
				Secretary, the Secretary shall provide to an individual whose sensitive
				personal information is involved in that breach notice of the data
				breach—</text>
									<subparagraph id="H59B6071FFD8D4B4EBA478944669C4B3D" indent="up1"><enum>(A)</enum><text>in writing; or</text>
									</subparagraph><subparagraph id="HECA7E71365E7499F81EFD4D9F536EA07" indent="up1"><enum>(B)</enum><text>by email, if—</text>
										<clause id="H2CC74E8D4D2E4D8A95AA4F00D844F84F"><enum>(i)</enum><text>the Department's primary method of
				communication with the individual is by email; and</text>
										</clause><clause id="HA48B2A2E752A4E059297AE7900F8D2D3"><enum>(ii)</enum><text>the individual has consented to
				receive such notification.</text>
										</clause></subparagraph></paragraph><paragraph id="H9539C515027C42D780ED39AF7600E175" indent="up1"><enum>(2)</enum><text>Notice provided under paragraph (1)
				shall—</text>
									<subparagraph id="HBD0A74F46F634773AF7DE64F3499A09B"><enum>(A)</enum><text display-inline="yes-display-inline">describe the circumstances of the data
				breach and the risk that the breach could lead to misuse, including identity
				theft, involving the sensitive personal information of the individual;</text>
									</subparagraph><subparagraph id="HFE2BDDADDD914BB3AC1FAB0063D46D1"><enum>(B)</enum><text>describe the specific types of
				sensitive personal information that was compromised as a part of the data
				breach;</text>
									</subparagraph><subparagraph id="HBC37B3395B1341B88283A848C4D8FBE4"><enum>(C)</enum><text>describe the actions the Department is
				taking to remedy the data breach;</text>
									</subparagraph><subparagraph display-inline="no-display-inline" id="H395B21F66DFC4A23B9471D6F89001915"><enum>(D)</enum><text>inform the individual that the
				individual may request a fraud alert and credit security freeze under this
				section;</text>
									</subparagraph><subparagraph id="HED5E3C790F3041C1BAAE4F00A3CC279F"><enum>(E)</enum><text display-inline="yes-display-inline">clearly explain the advantages and
				disadvantages to the individual of receiving fraud alerts and credit security
				freezes under this section; and</text>
									</subparagraph><subparagraph id="HFF677F15DB194D5F87E18EF4EF72C423"><enum>(F)</enum><text>includes such other information as the
				Secretary determines is appropriate.</text>
									</subparagraph></paragraph><paragraph id="H70FED4F664F2435DB7511707A651C51C" indent="up1"><enum>(3)</enum><text>The notice required under paragraph
				(1) shall be provided promptly following the discovery of a data breach and the
				implementation of any measures necessary to determine the scope of the breach,
				prevent any further breach or unauthorized disclosures, and reasonably restore
				the integrity of the data system.</text>
								</paragraph></subsection><subsection id="H15B39968D8D94D769766BEF2D2B0582"><enum>(c)</enum><header>Report</header><text>For
				each data breach with respect to sensitive personal information processed or
				maintained by the Secretary, the Secretary shall promptly submit to the
				Committees on Veterans’ Affairs of the Senate and House of Representatives a
				report containing the findings of any independent risk analysis conducted under
				subsection (a)(1), any determination of the Secretary under subsection (a)(2),
				and a description of any credit protection services provided under section 5726
				of this title.</text>
							</subsection><subsection id="H55AFE315D01A4973B8F0C600473D6C20"><enum>(d)</enum><header>Final
				determination</header><text display-inline="yes-display-inline">Notwithstanding
				sections 511 and 7104(a) of this title, any determination of the Secretary
				under subsection (a)(2) with respect to the reasonable risk for the potential
				misuse of sensitive information involved in a data breach is final and
				conclusive and may not be reviewed by any other official, administrative body,
				or court, whether by an action in the nature of mandamus or otherwise.</text>
							</subsection><subsection id="H72760B699FAF4AF7892237667BAA46D9"><enum>(e)</enum><header>Fraud
				alerts</header><paragraph commented="no" display-inline="yes-display-inline" id="H00D2FF379F1047038681721B1156B775"><enum>(1)</enum><text display-inline="yes-display-inline">In the event of a data breach with respect
				to sensitive personal information that is processed or maintained by the
				Secretary, the Secretary shall arrange, upon the request of an individual whose
				sensitive personal information is involved in the breach to a principal credit
				reporting agency with which the Secretary has entered into a contract under
				section 5726(d) and at no cost to the individual, for the principal credit
				reporting agency to provide fraud alert services for that individual for a
				period of not less than one year, beginning on the date of such request, unless
				the individual requests that such fraud alert be removed before the end of such
				period, and the agency receives appropriate proof of the identity of the
				individual for such purpose.</text>
								</paragraph><paragraph display-inline="no-display-inline" id="H28D79362EBFE421BB9D899996DA0064" indent="up1"><enum>(2)</enum><text>The Secretary shall arrange for each
				principal credit reporting agency referred to in paragraph (1) to provide any
				alert requested under such subsection in the file of the individual along with
				any credit score generated in using that file, for a period of not less than
				one year, beginning on the date of such request, unless the individual requests
				that such fraud alert be removed before the end of such period, and the agency
				receives appropriate proof of the identity of the individual for such
				purpose.</text>
								</paragraph></subsection><subsection id="H020833F5C3B441F281C82C1FF298E6B5"><enum>(f)</enum><header>Credit security
				freeze</header><text display-inline="yes-display-inline"></text><paragraph commented="no" display-inline="yes-display-inline" id="HE1482FC3FEC84CA0A7E758475830EA25"><enum>(1)</enum><text display-inline="yes-display-inline">In the event of a data breach with respect
				to sensitive personal information that is processed or maintained by the
				Secretary, the Secretary shall arrange, upon the request of an individual whose
				sensitive personal information is involved in the breach and at no cost to the
				individual, for each principal credit reporting agency to apply a security
				freeze to the file of that individual for a period of not less than one year,
				beginning on the date of such request, unless the individual requests that such
				security freeze be removed before the end of such period, and the agency
				receives appropriate proof of the identity of the individual for such purpose.</text>
								</paragraph><paragraph id="HF947E71608764FD78BA73DE97D22BEEA" indent="up1"><enum>(2)</enum><text>The Secretary shall arrange for a
				principal credit reporting agency applying a security freeze under paragraph
				(1)—</text>
									<subparagraph id="H0ABFED113CB0473E8BF25079063F132" indent="up1"><enum>(A)</enum><text>to send a written confirmation of the
				security freeze to the individual within five business days of applying the
				freeze;</text>
									</subparagraph><subparagraph id="H7F2BE0C54C8B479DAC4423AA6FEC1972" indent="up1"><enum>(B)</enum><text display-inline="yes-display-inline">to refer the information regarding the
				security freeze to other consumer reporting agencies;</text>
									</subparagraph><subparagraph id="HBD558F44AC424F13A0F88EA257832888" indent="up1"><enum>(C)</enum><text>to provide the individual with a
				unique personal identification number or password to be used by the individual
				when providing authorization for the release of the individual’s credit for a
				specific party or period of time; and</text>
									</subparagraph><subparagraph id="H6CD1C826EF2B4E04B5EBD519BB1399AB" indent="up1"><enum>(D)</enum><text>upon the request of the individual,
				to temporarily lift the freeze for a period of time specified by the
				individual, beginning not later than three business days after the date on
				which the agency receives the request.</text>
									</subparagraph></paragraph></subsection></section><section id="HF45E51B9BE3E41728239512C7F7DFF9C"><enum>5726.</enum><header>Provision of
				credit protection services</header>
							<subsection display-inline="no-display-inline" id="H0ED9252D9BAB47AB9CEEC500785B8972"><enum>(a)</enum><header>Covered
				individual</header><text>For purposes of this section, a covered individual is
				an individual whose sensitive personal information that is processed or
				maintained by the Department (or any third-party entity acting on behalf of the
				Department) is involved, on or after August 1, 2005, in a data breach for which
				the Secretary determines a reasonable risk exists for the potential misuse of
				sensitive personal information under section 5725(a)(2) of this title.</text>
							</subsection><subsection id="H5C426A57E4CE431890FFAC9F2E99F447"><enum>(b)</enum><header>Notification</header><paragraph commented="no" display-inline="yes-display-inline" id="HFF34DA66FE3841E5A5C0FB00196EE1E7"><enum>(1)</enum><text>In addition to any
				notice required under subsection 5725(b) of this title, the Secretary shall
				provide to a covered individual notice in writing that—</text>
									<subparagraph id="HC0EE55E0F3F14A2BAF062E1BD630B7B0" indent="up1"><enum>(A)</enum><text>the individual may request credit
				protection services under this section;</text>
									</subparagraph><subparagraph id="H1234330FCB3C429AA47E35C3E09879CB" indent="up1"><enum>(B)</enum><text>clearly explains the advantages and
				disadvantages to the individual of receiving credit protection services under
				this section;</text>
									</subparagraph><subparagraph id="H41FD62F5758C4CBEA127C4021D2C006E" indent="up1"><enum>(E)</enum><text>includes a notice of which principal
				credit reporting agency the Secretary has entered into a contract with under
				subsection (d), and information about requesting services through that
				agency;</text>
									</subparagraph><subparagraph id="H1A526B85732548EF98EF948C2569B3B" indent="up1"><enum>(C)</enum><text>describes actions the individual can
				or should take to reduce the risk of identity theft; and</text>
									</subparagraph><subparagraph id="HEEAABA22891A49188EFEBE7E543DCA79" indent="up1"><enum>(D)</enum><text>includes such other information as the
				Secretary determines is appropriate.</text>
									</subparagraph></paragraph><paragraph display-inline="no-display-inline" id="HD0889B0FC2CF479EB36EAAD3CE2E150" indent="up1"><enum>(2)</enum><text display-inline="yes-display-inline">The notice required under paragraph (1)
				shall be made as promptly as possible and without unreasonable delay following
				the discovery of a data breach for which the Secretary determines a reasonable
				risk exists for the potential misuse of sensitive personal information under
				section 5725(a)(2) of this title and the implementation of any measures
				necessary to determine the scope of the breach, prevent any further breach or
				unauthorized disclosures, and reasonably restore the integrity of the data
				system.</text>
								</paragraph><paragraph id="HB5E5254327714B23BA15EFDF27892E7D" indent="up1"><enum>(3)</enum><text display-inline="yes-display-inline">The Secretary shall ensure that each
				notification under paragraph (1) includes a form or other means for readily
				requesting the credit protection services under this section. Such form or
				other means may include a telephone number, email address, or Internet website
				address.</text>
								</paragraph></subsection><subsection id="HD15611CB7D3040F7A3F92547ECCE95E5"><enum>(c)</enum><header>Availability of
				services through other Government agencies</header><text>If a service required
				to be provided under this section is available to a covered individual through
				another department or agency of the Government, the Secretary and the head of
				that department or agency may enter into an agreement under which the head of
				that department or agency agrees to provide that service to the covered
				individual.</text>
							</subsection><subsection id="H079A33DC5BCD4D7B894D884B906C3792"><enum>(d)</enum><header>Contract with
				credit reporting agency</header><text>Subject to the availability of
				appropriations and notwithstanding any other provision of law, the Secretary
				shall enter into contracts or other agreements as necessary with one or more
				principal credit reporting agencies in order to ensure, in advance, the
				provision of credit protection services under this section and fraud alerts and
				security freezes under section 5725 of this title. Any such contract or
				agreement may include provisions for the Secretary to pay the expenses of such
				a credit reporting agency for the provision of such services.</text>
							</subsection><subsection display-inline="no-display-inline" id="HEF0572AA78E54C2600723CB91E208977"><enum>(e)</enum><header>Data breach
				analysis</header><text display-inline="yes-display-inline">The Secretary shall
				arrange, upon the request of a covered individual and at no cost to the
				individual, to provide data breach analysis for the individual for a period of
				not less than one year, beginning on the date of such request.</text>
							</subsection><subsection id="H6989DBB5C91B459195C400BCBF4A1FD"><enum>(f)</enum><header>Provision of
				credit monitoring services and identity theft insurance</header><text>During
				the one-year period beginning on the date on which the Secretary notifies a
				covered individual that the individual’s sensitive personal information is
				involved in a data breach, the Secretary shall arrange, upon the request of the
				individual and without charge to the individual, for the provision of credit
				monitoring services to the individual. Credit monitoring services under this
				subsection shall include each of the following:</text>
								<paragraph id="H0869359BCC534AD3A1598B222EBF13B4"><enum>(1)</enum><text>One copy of the
				credit report of the individual every three months.</text>
								</paragraph><paragraph id="H8C03A2D0836C4C99004700782E9C1D1D"><enum>(2)</enum><text>Fraud resolution
				services for the individual.</text>
								</paragraph><paragraph id="HA096BD19929F44EE9C7FD40001891511"><enum>(3)</enum><text>Identity theft
				insurance in a coverage amount that does not exceed $30,000 in aggregate
				liability for the insured.</text>
								</paragraph></subsection></section><section id="H5EB35473EC9A4DEFA59158A24E89DD9"><enum>5727.</enum><header>Contracts for
				data processing or maintenance</header>
							<subsection id="H937FDBD345494752A16DA317F3B4009B"><enum>(a)</enum><header>Contract
				requirements</header><text display-inline="yes-display-inline">If the Secretary
				enters into a contract for the performance of any Department function that
				requires access to sensitive personal information, the Secretary shall require
				as a condition of the contract that—</text>
								<paragraph id="H053F57E3506F48CA8E3DAA8E5089F6DF"><enum>(1)</enum><text>the contractor
				shall not, directly or through an affiliate of the contractor, disclose such
				information to any other person unless the disclosure is lawful and is
				expressly permitted under the contract;</text>
								</paragraph><paragraph id="H43725CC9E58A4D6BBA2E69831B82BAC8"><enum>(2)</enum><text>the contractor, or
				any subcontractor for a subcontract of the contract, shall promptly notify the
				Secretary of any data breach that occurs with respect to such
				information.</text>
								</paragraph></subsection><subsection id="H3C995D268E3844BAB0DB4E3D4B00BE4F"><enum>(b)</enum><header>Liquidated
				damages</header><text>Each contract subject to the requirements of subsection
				(a) shall provide for liquidated damages to be paid by the contractor to the
				Secretary in the event of a data breach with respect to any sensitive personal
				information processed or maintained by the contractor or any subcontractor
				under that contract.</text>
							</subsection><subsection id="H9AD5C456165B48640065D6BE88D0E86E"><enum>(c)</enum><header>Provision of
				credit protection services</header><text>Any amount collected by the Secretary
				under subsection (b) shall be deposited in or credited to the Department
				account from which the contractor was paid and shall remain available for
				obligation without fiscal year limitation exclusively for the purpose of
				providing credit protection services in accordance with section 5726 of this
				title.</text>
							</subsection></section><section id="H556A13FEEE7D4DC890EBDFFAF4D11274"><enum>5728.</enum><header>Authorization
				of appropriations</header><text display-inline="no-display-inline">There are
				authorized to be appropriated to carry out this subchapter such sums as may be
				necessary for each fiscal
				year.</text>
						</section></subchapter><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection display-inline="no-display-inline" id="H2E33D90D748E46069C61C8C499C5B41"><enum>(b)</enum><header>Clerical
			 amendment</header><text>The table of sections at the beginning of such chapter
			 is amended by adding at the end the following new items:</text>
				<quoted-block display-inline="no-display-inline" id="H03ACC7B51B6E4CC4A3EAABB3982341FF" style="USC">
					<toc regeneration="no-regeneration">
						<toc-entry level="subchapter">Subchapter III—Information
				Security</toc-entry>
						<toc-entry level="section">5721. Definitions.</toc-entry>
						<toc-entry level="section">5722. Office of the Under Secretary for
				Information Services.</toc-entry>
						<toc-entry level="section">5723. Information security
				management.</toc-entry>
						<toc-entry level="section">5724. Congressional reporting and
				notification of data breaches.</toc-entry>
						<toc-entry level="section">5725. Data breaches.</toc-entry>
						<toc-entry level="section">5726. Provision of credit protection
				services.</toc-entry>
						<toc-entry level="section">5727. Contracts for data processing or
				maintenance.</toc-entry>
						<toc-entry level="section">5728. Authorization of
				appropriations.</toc-entry>
					</toc>
					<after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection display-inline="no-display-inline" id="HBEB1C5CEE0EA41C1BB8E6C48A6BBFC39"><enum>(c)</enum><header>Deadline for
			 regulations</header><text>Not later than 60 days after the date of the
			 enactment of this Act, the Secretary of Veterans Affairs shall publish
			 regulations to carry out subchapter III of
			 <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/38/57">chapter 57</external-xref> of title 38,
			 United States Code, as added by subsection (a).</text>
			</subsection></section><section id="H2E59559BE30441108C08147742947666"><enum>5.</enum><header>Report on
			 feasibility of using personal identification numbers for
			 identification</header><text display-inline="no-display-inline">Not later than
			 180 days after the date of the enactment of this Act, the Secretary of Veterans
			 Affairs shall submit to Congress a report containing the assessment of the
			 Secretary with respect to the feasibility of using personal identification
			 numbers instead of Social Security numbers for the purpose of identifying
			 individuals whose sensitive personal information (as that term is defined in
			 section
			 5721 of title 38, United States Code, as added by section 4) is
			 processed or maintained by the Secretary.</text>
		</section><section id="H7BD5313C8423477E8E53E3D66189CB7E"><enum>6.</enum><header>Deadline for
			 appointments</header>
			<subsection id="H5136FEDA442C412FA56FF2237483C861"><enum>(a)</enum><header>Deadline</header><text>Not
			 later than 180 days after the date of the enactment of this Act—</text>
				<paragraph id="H20A4DE568C6F49AB86876B10806D81B8"><enum>(1)</enum><text>the President
			 shall nominate an individual to serve as the Under Secretary of Veterans
			 Affairs for Information Services under
			 section
			 307A of title 38, United States Code, as added by section 3;
			 and</text>
				</paragraph><paragraph id="H1196D9A4FE3949BD8276B375BDACEF50"><enum>(2)</enum><text>the Secretary of
			 Veterans Affairs shall appoint an individual to serve as each of the Deputy
			 Under Secretaries of Veterans Affairs for Information Services under section
			 5722 of such title, as added by section 4.</text>
				</paragraph></subsection><subsection id="HC0D9BBEA0F024E29BD11C41FD86461E"><enum>(b)</enum><header>Report</header><text>Not
			 later than 30 days after the date of the enactment of this Act, and every 30
			 days thereafter until the appointments described in subsection (a) are made,
			 the Secretary of Veterans Affairs shall submit to Congress a report describing
			 the progress of such appointments.</text>
			</subsection></section><section display-inline="no-display-inline" id="HC503DE28E47240F5A747A077CED2DB" section-type="subsequent-section"><enum>7.</enum><header>Information security
			 education assistance program</header>
			<subsection id="HA6D441013D0E4E98ABF1B046FD3AB9B"><enum>(a)</enum><header>Program
			 required</header><text>Title 38, United States Code, is amended by inserting
			 after chapter 78 the following new chapter:</text>
				<quoted-block display-inline="no-display-inline" id="H8E7FD29038A347098305E212085DACB5" style="USC">
					<chapter id="H550349765BA34FA79900F241C149F6D0"><enum>79</enum><header>Information
				Security Education Assistance Program</header>
						<toc container-level="chapter-container" idref="H550349765BA34FA79900F241C149F6D0" lowest-bolded-level="division-lowest-bolded" lowest-level="section" quoted-block="no-quoted-block" regeneration="yes-regeneration">
							<toc-entry idref="HFBD8ED0C46C242AB9EB314D692E9135" level="section">Sec.</toc-entry>
							<toc-entry level="section">7901.  Programs; purpose.</toc-entry>
							<toc-entry idref="HEC33983B551A490F80B16BE9535CC195" level="section">7902.  Scholarship program.</toc-entry>
							<toc-entry idref="H0DCAB72606F74F83B5C9C54E59423F81" level="section">7903.  Education debt reduction program.</toc-entry>
							<toc-entry idref="HB69CE3F131F241A797D3D7260083782E" level="section">7904.  Preferences in awarding financial
				  assistance.</toc-entry>
							<toc-entry idref="H7A2C72168546489F004CD04C800F1DF" level="section">7905.  Requirement of honorable discharge for veterans
				  receiving assistance.</toc-entry>
							<toc-entry idref="HDE0FCD263E074A35A498C94714849270" level="section">7906. Regulations.</toc-entry>
							<toc-entry idref="H842E92781530422DB019DB847F32308D" level="section">7907. Termination.</toc-entry>
						</toc>
						<section id="HFBD8ED0C46C242AB9EB314D692E9135"><enum>7901.</enum><header>Programs;
				purpose</header>
							<subsection id="HCE003CC631C646C7977C00FEF1489E32"><enum>(a)</enum><header>In
				General</header><text>To encourage the recruitment and retention of Department
				personnel who have the information security skills necessary to meet Department
				requirements, the Secretary shall carry out programs in accordance with this
				chapter to provide financial support for education in computer science and
				electrical and computer engineering at accredited institutions of higher
				education.</text>
							</subsection><subsection id="H4B306331E22F43168CA3D73814EF416F"><enum>(b)</enum><header>Types of
				Programs</header><text>The programs authorized under this chapter are as
				follows:</text>
								<paragraph id="H7390A20302B0471CA02E81209EF80094"><enum>(1)</enum><text display-inline="yes-display-inline">Scholarships for pursuit of doctoral
				degrees in computer science and electrical and computer engineering at
				accredited institutions of higher education.</text>
								</paragraph><paragraph id="H51825B7942044342B8CEDF27DBC1F8BB"><enum>(2)</enum><text display-inline="yes-display-inline">Education debt reduction for Department
				personnel who hold doctoral degrees in computer science and electrical and
				computer engineering at accredited institutions of higher education.</text>
								</paragraph></subsection></section><section id="HEC33983B551A490F80B16BE9535CC195"><enum>7902.</enum><header>Scholarship
				program</header>
							<subsection id="H7A4C29234EF74773898E324BBE148F69"><enum>(a)</enum><header>Authority</header><paragraph commented="no" display-inline="yes-display-inline" id="H5068CF7A76B845EC8C35C8009B91CF00"><enum>(1)</enum><text>Subject to the
				availability of appropriations, the Secretary shall establish a scholarship
				program under which the Secretary shall, subject to subsection (d), provide
				financial assistance in accordance with this section to a qualified
				person—</text>
									<subparagraph id="H11A9AEFB69204773893864446CED5354" indent="up1"><enum>(A)</enum><text display-inline="yes-display-inline">who is pursuing a doctoral degree in
				computer science or electrical or computer engineering at an accredited
				institution of higher education; and</text>
									</subparagraph><subparagraph id="H2E005CC472B541CF8069924D5D00D62F" indent="up1"><enum>(B)</enum><text>who enters into an agreement with the
				Secretary as described in subsection (b).</text>
									</subparagraph></paragraph><paragraph id="HBE6780FB744E4A2983EF6D7FDAFBCE00" indent="up1"><enum>(2)</enum><subparagraph commented="no" display-inline="yes-display-inline" id="HCA788879844D439D94937217B5DAF3C2"><enum>(A)</enum><text>Except as provided under
				subparagraph (B), the Secretary may provide financial assistance under this
				section to an individual for up to five years.</text>
									</subparagraph><subparagraph id="HB921A9428B974007B76B00FA71CD76A9" indent="up1"><enum>(B)</enum><text>The Secretary may waive the
				limitation under subparagraph (A) if the Secretary determines that such a
				waiver is appropriate.</text>
									</subparagraph></paragraph><paragraph id="H5DF30AF834EC4B0288ECA43D19877E7F" indent="up1"><enum>(3)</enum><subparagraph commented="no" display-inline="yes-display-inline" id="HB5BA657D5BD24173876D482DF26F7C9D"><enum>(A)</enum><text>The Secretary may award
				up to five scholarships for any academic year to individuals who did not
				receive assistance under this section for the preceding academic year.</text>
									</subparagraph><subparagraph id="HB5FE4CF971F247E7005F6156417C803E" indent="up1"><enum>(B)</enum><text>Not more than one scholarship awarded
				under subparagraph (A) may be awarded to an individual who is an employee of
				the Department when the scholarship is awarded.</text>
									</subparagraph></paragraph></subsection><subsection display-inline="no-display-inline" id="HB45EDC27129C41019D03DDD75C00BEE"><enum>(b)</enum><header>Service Agreement
				for Scholarship Recipients</header><paragraph commented="no" display-inline="yes-display-inline" id="H8522597C7F7044E393F19DBDC11CB6ED"><enum>(1)</enum><text>To receive financial
				assistance under this section an individual shall enter into an agreement to
				accept and continue employment in the Department for the period of obligated
				service determined under paragraph (2).</text>
								</paragraph><paragraph id="H943357D520BD47158B5B02AEEFB2AA5E" indent="up1"><enum>(2)</enum><text>For the purposes of this subsection,
				the period of obligated service for a recipient of financial assistance under
				this section shall be the period determined by the Secretary as being
				appropriate to obtain adequate service in exchange for the financial assistance
				and otherwise to achieve the goals set forth in section 7901(a) of this title.
				In no event may the period of service required of a recipient be less than the
				period equal to two times the total period of pursuit of a degree for which the
				Secretary agrees to provide the recipient with financial assistance under this
				section. The period of obligated service is in addition to any other period for
				which the recipient is obligated to serve on active duty or in the civil
				service, as the case may be.</text>
								</paragraph><paragraph id="H24E5EEBD0493449BBCCC27345731725D" indent="up1"><enum>(3)</enum><text>An agreement entered into under this
				section by a person pursuing an doctoral degree shall include terms that
				provide the following:</text>
									<subparagraph id="H25094727FCE0417895D3C1C435650837"><enum>(A)</enum><text>That the period of obligated service
				begins on a date after the award of the degree that is determined under the
				regulations prescribed under section 7906 of this title.</text>
									</subparagraph><subparagraph id="HCDCF5D2C6E7B42B39C228E53B47E769C"><enum>(B)</enum><text>That the individual will maintain
				satisfactory academic progress, as determined in accordance with those
				regulations, and that failure to maintain such progress constitutes grounds for
				termination of the financial assistance for the individual under this
				section.</text>
									</subparagraph><subparagraph id="H9731125D4D81488096D9C7DD88157638"><enum>(C)</enum><text>Any other terms and conditions that
				the Secretary determines appropriate for carrying out this section.</text>
									</subparagraph></paragraph></subsection><subsection display-inline="no-display-inline" id="H35851879612D4F8C8DCFAC9900FAA773"><enum>(c)</enum><header>Amount of
				Assistance</header><paragraph commented="no" display-inline="yes-display-inline" id="H7DEBE77528CF434F8B3F347BA91DA00"><enum>(1)</enum><text>The amount of the
				financial assistance provided for an individual under this section shall be the
				amount determined by the Secretary as being necessary to pay—</text>
									<subparagraph id="H55D1F34A607E42F09D0755B6BD26B00" indent="up1"><enum>(A)</enum><text>the tuition and fees of the
				individual; and</text>
									</subparagraph><subparagraph id="H85305622591E4C449EA6C55F0057A5" indent="up1"><enum>(B)</enum><text display-inline="yes-display-inline">$1500 to the individual each month
				(including a month between academic semesters or terms leading to the degree
				for which such assistance is provided or during which the individual is not
				enrolled in a course of education but is pursuing independent research leading
				to such degree) for books, laboratory expenses, and expenses of room and
				board.</text>
									</subparagraph></paragraph><paragraph id="H490ED9DFA4D645EBB19DCA4541C56742" indent="up1"><enum>(2)</enum><text>In no case may the amount of
				assistance provided for an individual under this section for an academic year
				exceed $50,000.</text>
								</paragraph><paragraph id="H527C17595D4C404BA8BF6700EE7FBA" indent="up1"><enum>(3)</enum><text>In no case may the total amount of
				assistance provided for an individual under this section exceed
				$200,000.</text>
								</paragraph><paragraph id="HE6BD8E2F46D44E3A9DE8001F622DB992" indent="up1"><enum>(4)</enum><text display-inline="yes-display-inline">Notwithstanding any other provision of law,
				financial assistance paid an individual under this section shall not be
				considered as income or resources in determining eligibility for, or the amount
				of benefits under, any Federal or federally assisted program.</text>
								</paragraph></subsection><subsection id="HFD41E5738A6045ECBB148FC65561CF16"><enum>(d)</enum><header>Repayment for Period of Unserved
				Obligated Service</header><paragraph commented="no" display-inline="yes-display-inline" id="H493314FA11F1469D8B8B241165B8CBBC"><enum>(1)</enum><text display-inline="yes-display-inline">An individual who receives financial
				assistance under this section shall repay to the Secretary an amount equal to
				the unearned portion of the financial assistance if the individual fails to
				satisfy the requirements of the service agreement entered into under subsection
				(b), except in certain circumstances authorized by the Secretary.</text>
								</paragraph><paragraph id="H2F9120F78706457AA9DDCF6396B6B8E" indent="up1"><enum>(2)</enum><text display-inline="yes-display-inline">The Secretary may establish, by
				regulations, procedures for determining the amount of the repayment required
				under this subsection and the circumstances under which an exception to the
				required repayment may be granted.</text>
								</paragraph><paragraph id="H2777C8CF6E584583A1083662CC26292" indent="up1"><enum>(3)</enum><text display-inline="yes-display-inline">An obligation to repay the Secretary under
				this subsection is, for all purposes, a debt owed the United States. A
				discharge in bankruptcy under title 11 does not discharge a person from such
				debt if the discharge order is entered less than five years after the date of
				the termination of the agreement or contract on which the debt is based.</text>
								</paragraph></subsection><subsection id="H95D05D4E48AB4AC28BFCC1EF1003C02"><enum>(e)</enum><header>Waiver or suspension of
				compliance</header><text display-inline="yes-display-inline">The Secretary
				shall prescribe regulations providing for the waiver or suspension of any
				obligation of a individual for service or payment under this section (or an
				agreement under this section) whenever noncompliance by the individual is due
				to circumstances beyond the control of the individual or whenever the Secretary
				determines that the waiver or suspension of compliance is in the best interest
				of the United States.</text>
							</subsection><subsection commented="no" id="H01785396518D4E948135327C8EAD4800"><enum>(f)</enum><header>Internships</header><paragraph commented="no" display-inline="yes-display-inline" id="H421494756C4F458FB508F799EA23C1D4"><enum>(1)</enum><text>The Secretary may offer
				a compensated internship to an individual for whom financial assistance is
				provided under this section during a period between academic semesters or terms
				leading to the degree for which such assistance is provided. Compensation
				provided for such an internship shall be in addition to the financial
				assistance provided under this section.</text>
								</paragraph><paragraph id="H407911D5BFC34ABB93FBF1C78500D789" indent="up1"><enum>(2)</enum><text>An internship under this subsection
				shall not be counted toward satisfying a period of obligated service under this
				section.</text>
								</paragraph></subsection><subsection id="H6B61B0BD73874B5093CBE092DB591AA"><enum>(g)</enum><header>Ineligibility of individuals
				receiving Montgomery GI Bill education assistance payments</header><text display-inline="yes-display-inline">An individual who receives a payment of
				educational assistance under chapter 30, 31, 32, 34, or 35 of this title or
				chapter 1606 or 1607 of title 10 for a month in which the individual is
				enrolled in a course of education leading to a doctoral degree in information
				security is not eligible to receive financial assistance under this section for
				that month.</text>
							</subsection></section><section id="H0DCAB72606F74F83B5C9C54E59423F81"><enum>7903.</enum><header>Education debt
				reduction program</header>
							<subsection id="HCA12CEFD967D40E2B4994E45CF7F28F0"><enum>(a)</enum><header>Authority</header><paragraph commented="no" display-inline="yes-display-inline" id="HDEE9FD56171A4281A418DB39BA754A7"><enum>(1)</enum><text>Subject to the
				availability of appropriations, the Secretary shall establish an education debt
				reduction program under which the Secretary shall make education debt reduction
				payments under this section to qualified individuals eligible under subsection
				(b) for the purpose of reimbursing such individuals for payments by such
				individuals of principal and interest on loans described in paragraph (2) of
				that subsection.</text>
								</paragraph><paragraph id="H35A31B46308C4E9D8511C64D3C009546" indent="up1"><enum>(2)</enum><subparagraph commented="no" display-inline="yes-display-inline" id="H5FD3C052C5FB4F41A23FC86083008D50"><enum>(A)</enum><text>For each fiscal year,
				the Secretary may accept up to five individuals into the program established
				under paragraph (1)who did not receive such a payment during the preceding
				fiscal year.</text>
									</subparagraph><subparagraph id="HEB89652ED42D4D6283EE3CF494566F65" indent="up1"><enum>(B)</enum><text>Not more than one individual accepted
				into the program for a fiscal year under subsection (A) shall be a Department
				employee as of the date on which the individual is accepted into the
				program.</text>
									</subparagraph></paragraph></subsection><subsection id="H6898087C88B0458794A6F96017D56BE4"><enum>(b)</enum><header>Eligibility</header><text display-inline="yes-display-inline">An individual is eligible to participate in
				the program under this section if the individual—</text>
								<paragraph id="H8420267FA27C4BF993CE6ED6F15E1672"><enum>(1)</enum><text display-inline="yes-display-inline">has completed a doctoral degree a doctoral
				degree in computer science or electrical or computer engineering at an
				accredited institution of higher education during the five-year period
				preceding the date on which the individual is hired;</text>
								</paragraph><paragraph id="H67AEE05EF5A44FD381003FB3FD00B66D"><enum>(2)</enum><text>is an employee of
				the Department who serves in a position related to information security (as
				determined by the Secretary); and</text>
								</paragraph><paragraph id="H8A589E9CB1E7444A9EFDD856B009800"><enum>(3)</enum><text display-inline="yes-display-inline">owes any amount of principal or interest
				under a loan, the proceeds of which were used by or on behalf of that
				individual to pay costs relating to a doctoral degree in computer science or
				electrical or computer engineering at an accredited institution of higher
				education.</text>
								</paragraph></subsection><subsection id="H5663FA8651AE497FBE312F44DECCF01D"><enum>(c)</enum><header>Amount of assistance</header><paragraph commented="no" display-inline="yes-display-inline" id="H6DF7187166814A67923FE87F875BB0EF"><enum>(1)</enum><text>Subject to paragraph
				(2), the amount of education debt reduction payments made to an individual
				under this section may not exceed $82,500 over a total of five years, of which
				not more than $16,500 of such payments may be made in each year.</text>
								</paragraph><paragraph id="HB377D7D19A9244D5B00978F7EE61358C" indent="up1"><enum>(2)</enum><text display-inline="yes-display-inline">The total amount payable to an individual
				under this section for any year may not exceed the amount of the principal and
				interest on loans referred to in subsection (b)(3) that is paid by the
				individual during such year.</text>
								</paragraph></subsection><subsection id="H1D8618C2144544A993BAC1177054E5E"><enum>(d)</enum><header>Payments</header><paragraph commented="no" display-inline="yes-display-inline" id="HE80EA26D675847FC841B00698B4F9585"><enum>(1)</enum><text>The Secretary shall make
				education debt reduction payments under this section on an annual basis.</text>
								</paragraph><paragraph id="HD84C62D434F343D08D0582277B05A723" indent="up1"><enum>(2)</enum><text>The Secretary shall make such a
				payment—</text>
									<subparagraph id="H160F706BA32849B29FA5BE85E2F336B6"><enum>(A)</enum><text>on the last day of the one-year period
				beginning on the date on which the individual is accepted into the program
				established under subsection (a); or</text>
									</subparagraph><subparagraph id="H732FA3A0780F4F82AB3CFAE42EF40D1"><enum>(B)</enum><text>in the case of an individual who
				received a payment under this section for the preceding fiscal year, on the
				last day of the one-year period beginning on the date on which the individual
				last received such a payment.</text>
									</subparagraph></paragraph><paragraph id="HC116B707E61E4335912350D9F6B13D16" indent="up1"><enum>(3)</enum><text>Notwithstanding any other provision
				of law, education debt reduction payments under this section shall not be
				considered as income or resources in determining eligibility for, or the amount
				of benefits under, any Federal or federally assisted program.</text>
								</paragraph></subsection><subsection id="H9CCC29378D2C4B39BE97003273256DEA"><enum>(e)</enum><header>Performance
				requirement</header><text display-inline="yes-display-inline">The Secretary may
				make education debt reduction payments to an individual under this section for
				a year only if the Secretary determines that the individual maintained an
				acceptable level of performance in the position or positions served by the
				individual during the year.</text>
							</subsection><subsection id="H4C5AF889DF6C497A9EE2805FE396202"><enum>(f)</enum><header>Notification of
				terms of provision of payments</header><text>The Secretary shall provide to an
				individual who receives a payment under this section notice in writing of the
				terms and conditions that apply to such a payment.</text>
							</subsection><subsection id="H4B79219EA93B452D9F55CAEDF833D762"><enum>(g)</enum><header>Covered
				costs</header><text>For purposes of subsection (b)(3), costs relating to a
				course of education or training include—</text>
								<paragraph id="H2B83B3B7FDBF4EFD9695BA002821D827"><enum>(1)</enum><text>tuition expenses;
				and</text>
								</paragraph><paragraph id="H1D5A0C165A21487C913834B67C64774C"><enum>(2)</enum><text>all other
				reasonable educational expenses, including fees, books, and laboratory
				expenses;</text>
								</paragraph></subsection></section><section id="HB69CE3F131F241A797D3D7260083782E"><enum>7904.</enum><header>Preferences in
				awarding financial assistance</header><text display-inline="no-display-inline">In awarding financial assistance under this
				chapter, the Secretary shall give a preference to qualified individuals who are
				otherwise eligible to receive the financial assistance in the following order
				of priority:</text>
							<paragraph id="HBF955961692F40769622CC4FF9277632"><enum>(1)</enum><text>Veterans with
				service-connected disabilities.</text>
							</paragraph><paragraph id="HEAC0B922ED0E4DFFB50814B6D8DEFDF"><enum>(2)</enum><text>Veterans.</text>
							</paragraph><paragraph id="HC95FC7795E5043FEA4D5CDB201A2DDEF"><enum>(3)</enum><text>Persons described
				in section 4215(a)(B) of this title.</text>
							</paragraph><paragraph id="H812A673F41644973B8B3FC300BE921E"><enum>(4)</enum><text display-inline="yes-display-inline">Individuals who received or are pursuing
				degrees at institutions designated by the National Security Agency as Centers
				of Academic Excellence in Information Assurance Education.</text>
							</paragraph><paragraph id="HAB6D3D571823434188F66FB38B21CDEA"><enum>(5)</enum><text>Citizens of the
				United States.</text>
							</paragraph></section><section id="H7A2C72168546489F004CD04C800F1DF"><enum>7905.</enum><header>Requirement of
				honorable discharge for veterans receiving assistance</header><text display-inline="no-display-inline">No veteran shall receive financial
				assistance under this chapter unless the veteran was discharged from the Armed
				Forces under honorable conditions.</text>
						</section><section id="HDE0FCD263E074A35A498C94714849270"><enum>7906.</enum><header>Regulations</header><text display-inline="no-display-inline">The Secretary shall prescribe regulations
				for the administration of this chapter.</text>
						</section><section id="H842E92781530422DB019DB847F32308D"><enum>7907.</enum><header>Termination</header><text display-inline="no-display-inline">The authority of the Secretary to make a
				payment under this chapter shall terminate on July 31,
				2017.</text>
						</section></chapter><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="H2C12221DB8734184A869C6E05CBEE2EA"><enum>(b)</enum><header>GAO
			 report</header><text>Not later than three years after the date of the enactment
			 of this Act, the Comptroller General shall submit to Congress a report on the
			 scholarship and education debt reduction programs under
			 <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/38/79">chapter 79</external-xref> of title 38,
			 United States Code, as added by subsection (a).</text>
			</subsection><subsection id="HA947442A746B46D29F7DB9E05567E82B"><enum>(c)</enum><header>Applicability of
			 scholarships</header><text><external-xref legal-doc="usc" parsable-cite="usc/38/7902">Section 7902</external-xref> of title 38, United
			 States Code, as added by subsection (a), shall apply with respect to financial
			 assistance provided for an academic semester or term that begins on or after
			 August 1, 2007.</text>
			</subsection><subsection id="H05397160433D498FBE6BE16FC9A17F00"><enum>(d)</enum><header>Clerical
			 amendment</header><text display-inline="yes-display-inline">The tables of
			 chapters at the beginning of such title, and at the beginning of part V of such
			 title, are amended by inserting after the item relating to chapter 78 the
			 following new item:</text>
				<quoted-block display-inline="no-display-inline" id="HC154FF7AC801483B9287032987F056DF" style="USC">
					<toc regeneration="no-regeneration">
						<multi-column-toc-entry level="chapter"><toc-enum>79.</toc-enum><level-header level="chapter">Information Security Education Assistance
				  Program</level-header><target>7901</target></multi-column-toc-entry>
					</toc>
					<after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection></section></legis-body>
	<attestation>
		<attestation-group>
			<attestation-date chamber="House" date="20060926">Passed the House of
			 Representatives September 26, 2006.</attestation-date>
			<attestor display="yes">Karen L. Haas,</attestor>
			<role>Clerk.</role>
		</attestation-group>
	</attestation>
</bill>


