<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="HC289FCD03E164D718109BCC9079B2BC6" public-private="public">
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>109 HR 6109 IH: Stop Endangering the Records of
</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2006-09-19</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
	<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>109th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>H. R. 6109</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20060919">September 19, 2006</action-date>
			<action-desc><sponsor name-id="M001151">Mr. Murphy</sponsor> (for
			 himself, <cosponsor name-id="G000549">Mr. Gerlach</cosponsor>,
			 <cosponsor name-id="P000585">Mr. Platts</cosponsor>,
			 <cosponsor name-id="S001158">Mr. Salazar</cosponsor>,
			 <cosponsor name-id="H001033">Ms. Hart</cosponsor>, <cosponsor name-id="B001243">Mrs. Blackburn</cosponsor>, <cosponsor name-id="B001246">Mr.
			 Bradley of New Hampshire</cosponsor>, <cosponsor name-id="M001147">Mr.
			 McCotter</cosponsor>, <cosponsor name-id="H000676">Mr. Hoekstra</cosponsor>,
			 and <cosponsor name-id="L000552">Mr. LaHood</cosponsor>) introduced the
			 following bill; which was referred to the <committee-name committee-id="HVR00">Committee on Veterans’
			 Affairs</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To amend title 38, United States Code, to provide for
		  enhanced protection of sensitive personal information processed or maintained
		  by the Secretary of Veterans Affairs.</official-title>
	</form>
	<legis-body id="HE33428696ED84C10BD00B36BEDB52A1" style="OLC">
		<section id="HC732C4BE3ED84CF885234119D98C5790" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Stop Endangering the Records of
			 Veterans (SERVE) Act of 2006</short-title></quote>.</text>
		</section><section id="HD540DA5A2BBC4F9DACE5202FADFCD600"><enum>2.</enum><header>Findings</header><text display-inline="no-display-inline">Congress finds as follows:</text>
			<paragraph id="H357FA35CC8844ED388A012BB2B583240"><enum>(1)</enum><text>Identity theft
			 remains a critical problem for consumers. In May 2006, the Federal Trade
			 Commission revealed that 10,000,000 individuals are subjected to theft of their
			 personal identification licenses and records each year.</text>
			</paragraph><paragraph id="H5676D9B6AC7C40FA0091EE1C06DA37CF"><enum>(2)</enum><text>Recent thefts of
			 computer hardware containing sensitive personal information from the Department
			 of Veterans Affairs and its contractors have made millions of veterans
			 vulnerable to identity theft and fraud.</text>
			</paragraph><paragraph id="HBA1B2EB481654DE0B26D0388DACA6CDB"><enum>(3)</enum><text>On May 22, 2006,
			 the Department of Veterans Affairs announced an employee laptop containing
			 personal records of nearly 26,500,000 million veterans and spouses had been
			 stolen.</text>
			</paragraph><paragraph id="H00677B7881CF4E28B732317EAD62A061"><enum>(4)</enum><text>On August 7, 2006,
			 a desktop computer containing personal information of more than 38,000 veterans
			 was stolen from a subcontractor hired to assist in insurance collections for
			 medical centers of the Department of Veterans Affairs in Pittsburgh and
			 Philadelphia, Pennsylvania.</text>
			</paragraph><paragraph id="HBBB868C8859E404E9D47CE323F603B09"><enum>(5)</enum><text>In August 2006, in
			 response to the loss of these records, the Secretary of Veterans Affairs
			 created the office of Special Advisor to the Secretary for Information
			 Security.</text>
			</paragraph><paragraph id="H3749A020B4854F9CBDAD78EAF9A0459F"><enum>(6)</enum><text>On August 14,
			 2006, the Secretary announced the award of a $3,700,000 contract to a
			 service-disabled, veteran-owned small business to upgrade all Department
			 computers with enhanced data security encryption systems.</text>
			</paragraph><paragraph id="HB13B11C7018E409E8175E9AFD4DDBE5E"><enum>(7)</enum><text>In order to
			 prevent the Nation’s veterans from being exposed to identity theft and fraud,
			 additional Federal safeguards, including those provided by this Act, must be
			 applied to increase accountability of those who handle veterans’ records in
			 order to prevent future losses of sensitive personal information.</text>
			</paragraph></section><section id="H3DB9EEF6C6A5417B9E717085FD84937F"><enum>3.</enum><header>Department of
			 Veterans Affairs information security</header>
			<subsection id="HC55A36980CF14A488D3853139B92C3FE"><enum>(a)</enum><header>Information
			 security</header><text><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/38/57">Chapter 57</external-xref> of title 38, United States Code, is amended
			 by adding at the end the following new subchapter:</text>
				<quoted-block display-inline="no-display-inline" id="H36AA9681E899493E95DDCB5187618F7E" style="USC">
					<subchapter id="HC1C00DA9408C46CC8297F9509DCDA31"><enum>III</enum><header>Information
				Security</header>
						<section id="H9E9F32F3050949D7872723E67B248415"><enum>5721.</enum><header>Definitions</header><text display-inline="no-display-inline">For the purposes of this subchapter:</text>
							<paragraph id="H5050CC8601074F18918052688D607735"><enum>(1)</enum><text display-inline="yes-display-inline">The term <quote>sensitive personal
				information</quote> means the name, address, or telephone number of an
				individual, in combination with any of the following:</text>
								<subparagraph id="HD1F59252830E4BA8AD00922994FC909"><enum>(A)</enum><text>The social security
				number of the individual.</text>
								</subparagraph><subparagraph id="H0A0B7E760C2C49B88464A19747A5E4A0"><enum>(B)</enum><text>The date of birth
				of the individual.</text>
								</subparagraph><subparagraph id="H4E0F30FE40DB4BC2B3EFB25E214C13B"><enum>(C)</enum><text>Any information not
				available as part of the public record regarding the individual's military
				service or health.</text>
								</subparagraph><subparagraph id="H9C0AACEC48B34F84BB132E12F5288EF6"><enum>(D)</enum><text>Any financial
				account or other financial information relating to the individual.</text>
								</subparagraph><subparagraph id="H6859C1BEA19E441F8BCF64925C3DC13D"><enum>(E)</enum><text>The driver's
				license number of the individual.</text>
								</subparagraph></paragraph><paragraph id="H11DA293259E4461F8B8814A9C93FC0B0"><enum>(2)</enum><text display-inline="yes-display-inline">The term <quote>encrypt</quote> means to
				use software to obscure electronic information to make that information
				unreadable for unauthorized employees and contractors of the Department.</text>
							</paragraph></section><section id="H0375C43F4F84413A83488DAAA2463643"><enum>5722.</enum><header>Physical
				security of sensitive personal information processed or maintained by the
				Secretary</header><text display-inline="no-display-inline">The Secretary shall
				physically secure all sensitive personal information processed or maintained by
				the Secretary and all equipment of the Department containing such sensitive
				personal information.</text>
						</section><section id="H91AF7C22DAF641288252C6148E5E2005"><enum>5723.</enum><header>Encryption of
				sensitive personal information processed or maintained by the
				Secretary</header><text display-inline="no-display-inline">The Secretary shall
				encrypt all sensitive personal information processed or maintained by the
				Secretary.</text>
						</section><section id="H0C3DCC89CD2244BF9FC2BB8E385E008F"><enum>5724.</enum><header>Contracts for
				the processing or maintenance of sensitive personal information</header>
							<subsection id="H05188EDF97114D0D95DE50D5D21EA504"><enum>(a)</enum><header>Contract
				requirements</header><text display-inline="yes-display-inline">If the Secretary
				enters into a contract for the performance of any Department function that
				requires access to sensitive personal information, the Secretary shall require
				as a condition of the contract that—</text>
								<paragraph id="H9E36FA4DD3434299AD631C48E504926B"><enum>(1)</enum><text>the contractor
				ensures that it will—</text>
									<subparagraph id="H4EE4F42F3EBB41A4B419949C069BF086"><enum>(A)</enum><text>encrypt or encode
				any such information to which the contractor has access; and</text>
									</subparagraph><subparagraph id="HC48AB8BD8D6F4799A58C10BA7E83A1B2"><enum>(B)</enum><text>physically secure
				all such information that it processes or maintains and all equipment
				containing such information; and</text>
									</subparagraph></paragraph><paragraph id="HE02FC4C54F7E421686B98878100041C4"><enum>(2)</enum><text display-inline="yes-display-inline">the contractor agrees to reimburse the
				Secretary for any amount paid by the Secretary to any person as a result of the
				contractor’s unauthorized disclosure of any sensitive personal information to
				which the contractor has access under the contract.</text>
								</paragraph></subsection><subsection id="H66FE5FDBD7EA4743844BC92DF0481D44"><enum>(b)</enum><header>Penalty for
				violations</header><text display-inline="yes-display-inline">Any contractor who
				violates any requirement of this subtitle shall be debarred from contracting
				with the Department for a period of one year.</text>
							</subsection></section><section id="H238C54FC635A4A00AA80D858DB5CF65"><enum>5725.</enum><header>Criminal
				penalty for unauthorized disclosure of sensitive personal
				information</header><text display-inline="no-display-inline">Any person who
				engages in the unauthorized disclosure of sensitive personal information
				processed or maintained by the Secretary or by a contractor performing a
				function on behalf of the Secretary shall be fined in accordance with title 18,
				imprisoned for not more than one year, or
				both.</text>
						</section></subchapter><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="H0C0C1C72EB2B454CA4CABE42037C21BE"><enum>(b)</enum><header>Clerical
			 amendment</header><text>The table of sections at the beginning of such chapter
			 is amended by adding at the end the following new items:</text>
				<quoted-block display-inline="no-display-inline" id="H05CF4EECCFF94E3892FD959F008C8BE9" style="OLC">
					<toc regeneration="no-regeneration">
						<toc-entry level="subchapter">Subchapter III—Information
				Security</toc-entry>
						<toc-entry level="section">5721. Definitions.</toc-entry>
						<toc-entry level="section">5722. Physical security of sensitive
				personal information processed or maintained by the Secretary.</toc-entry>
						<toc-entry level="section">5723. Encryption of sensitive personal
				information processed or maintained by the Secretary.</toc-entry>
						<toc-entry level="section">5724. Contracts for the processing or
				maintenance of sensitive personal information.</toc-entry>
						<toc-entry level="section">5725. Criminal penalty for unauthorized
				disclosure of sensitive personal
				information.</toc-entry>
					</toc>
					<after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="H0858DDEA52E44E5BBAB47310C5EF86AB"><enum>(c)</enum><header>Implementation</header><text>The
			 requirement of <external-xref legal-doc="usc" parsable-cite="usc/38/5723">section 5723</external-xref> of title 38, United States Code, as added by
			 subsection (a), shall be implemented not later than 90 days after the date of
			 the enactment of this Act.</text>
			</subsection></section><section id="H207227CE5C8244DDB11030026B3429E9"><enum>4.</enum><header>Director of
			 Office of Management and Budget study and report</header><text display-inline="no-display-inline">Not later than 180 days after the date of
			 the enactment of this Act, the Director of the Office of Management and Budget
			 shall complete a study of the security of personal information maintained or
			 processed by the Secretary of Veterans Affairs and shall submit to the
			 Committees on Veterans’ Affairs of the Senate and House of Representatives a
			 report containing the findings of that study and any recommendations of the
			 Director.</text>
		</section></legis-body>
</bill>


