<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H5131F5A215C645D3BBE5EF686B8769A4" public-private="public">
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>109 HR 6163 IH: Federal Agency Data Breach Protection
</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2006-09-25</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
	<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>109th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>H. R. 6163</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20060925">September 25, 2006</action-date>
			<action-desc><sponsor name-id="D000136">Mr. Tom Davis of
			 Virginia</sponsor> (for himself, <cosponsor name-id="P000555">Ms. Pryce of
			 Ohio</cosponsor>, and <cosponsor name-id="S001149">Mr. Sweeney</cosponsor>)
			 introduced the following bill; which was referred to the
			 <committee-name committee-id="HGO00">Committee on Government
			 Reform</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To amend title 44, United States Code, to strengthen
		  requirements related to security breaches of data involving the disclosure of
		  sensitive personal information.</official-title>
	</form>
	<legis-body id="HDB793F9C56714A2F8C2102A66D7CFE5B" style="OLC">
		<section id="HA346285EA52242939FD74845FC5B359" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Federal Agency Data Breach Protection
			 Act</short-title></quote>.</text>
		</section><section id="H205E53DE6D284EDE91488E777175743E"><enum>2.</enum><header>Federal agency
			 data breach notification requirements</header>
			<subsection id="H5D8DEF3B1F66495BAD00DA94C8D74195"><enum>(a)</enum><header>Authority of
			 director of Office of Management and Budget To establish data breach
			 policies</header><text><external-xref legal-doc="usc" parsable-cite="usc/44/3543">Section 3543(a)</external-xref> of title 44, United States Code, is
			 amended—</text>
				<paragraph id="H1F2570BF3A364EE487FF89D0095F9F6"><enum>(1)</enum><text>by
			 striking <quote>and</quote> at the end of paragraph (7);</text>
				</paragraph><paragraph id="H621B7D4A36C945A0B9171598C1A0E1D4"><enum>(2)</enum><text>by striking the
			 period and inserting <quote>; and</quote> at the end of paragraph (8);
			 and</text>
				</paragraph><paragraph id="H668BA8024A0E44DBA009FD967684C277"><enum>(3)</enum><text>by adding at the
			 end the following:</text>
					<quoted-block id="HF0F0DCF2C4AB4209A821D276BCA404F" style="OLC">
						<paragraph id="HBE52AE09F78E43DCA831C6E729ADA41E"><enum>(9)</enum><text display-inline="yes-display-inline">establishing policies, procedures, and
				standards for agencies to follow in the event of a breach of data security
				involving the disclosure of sensitive personal information and for which harm
				to an individual could reasonably be expected to result, specifically
				including—</text>
							<subparagraph id="H33863A49D1B34CA5A91DDC78A73DA293"><enum>(A)</enum><text>a requirement for
				timely notice to be provided to those individuals whose sensitive personal
				information could be compromised as a result of such breach, except no notice
				shall be required if the breach does not create a reasonable risk of identity
				theft, fraud, or other unlawful conduct regarding such individual;</text>
							</subparagraph><subparagraph id="H97859A612FD84906A3AB7C0347C8DC24"><enum>(B)</enum><text>guidance on
				determining how timely notice is to be provided; and</text>
							</subparagraph><subparagraph id="H43A85A405F894D10B2CB81A0C8DA32B2"><enum>(C)</enum><text>guidance regarding
				whether additional special actions are necessary and appropriate, including
				data breach analysis, fraud resolution services, identity theft insurance, and
				credit protection or monitoring
				services.</text>
							</subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection id="H0D8050D24FA14DF3B990FFF6E00E04D"><enum>(b)</enum><header>Authority of
			 chief information officer To enforce data breach policies and develop and
			 maintain inventories</header><text><external-xref legal-doc="usc" parsable-cite="usc/44/3544">Section 3544(a)(3)</external-xref> of title 44, United
			 States Code, is amended—</text>
				<paragraph id="HC9BC9357FBC647F78CCAD40045005753"><enum>(1)</enum><text>by inserting after
			 <quote>authority to ensure compliance with</quote> the following: <quote>and,
			 to the extent determined necessary and explicitly authorized by the head of the
			 agency, to enforce</quote>;</text>
				</paragraph><paragraph id="HE5A58264A35B4E059307584BDA944402"><enum>(2)</enum><text>by striking
			 <quote>and</quote> at the end of subparagraph (D);</text>
				</paragraph><paragraph id="HD80F85075F294AD98779E07936CB158C"><enum>(3)</enum><text>by inserting
			 <quote>and</quote> at the end of subparagraph (E); and</text>
				</paragraph><paragraph id="HAD77683F09434D5E007371681F5B9250"><enum>(4)</enum><text>by adding at the
			 end the following:</text>
					<quoted-block id="H5FB9E727665541C1B4B4BE8EB80014F4" style="OLC">
						<subparagraph id="H92B5D8F8B82B45DB87B58291E224968F"><enum>(F)</enum><text>developing and
				maintaining an inventory of all personal computers, laptops, or any other
				hardware containing sensitive personal
				information;</text>
						</subparagraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection id="HD1EE7A29A57A43729927BE5000BF678C"><enum>(c)</enum><header>Inclusion of
			 data breach notification in agency information security
			 programs</header><text><external-xref legal-doc="usc" parsable-cite="usc/44/3544">Section 3544(b)</external-xref> of title 44, United States Code, is
			 amended—</text>
				<paragraph id="H024C8147D57C402396FEF41EB09DCE48"><enum>(1)</enum><text>by striking
			 <quote>and</quote> at the end of paragraph (7);</text>
				</paragraph><paragraph id="H3DB5243CE82248B096F84FFBD5C2ECD"><enum>(2)</enum><text>by
			 striking the period and inserting <quote>; and</quote> at the end of paragraph
			 (8); and</text>
				</paragraph><paragraph id="H8E4B97F737A248A488DE64EBBFE9FE00"><enum>(3)</enum><text>by adding at the
			 end the following:</text>
					<quoted-block id="HB2C43565DB7745F797027945F6956CD5" style="OLC">
						<paragraph id="HBCE17E1B38074363AE21F58679FEC182"><enum>(9)</enum><text>procedures for
				notifying individuals whose sensitive personal information is compromised
				consistent with policies, procedures, and standards established under section
				3543(a)(9) of this
				title.</text>
						</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection id="HAA1DFF1F54CC45B6A05D22E5CC006076"><enum>(d)</enum><header>Authority of
			 agency chief human capital officers To assess federal personal
			 property</header><text><external-xref legal-doc="usc" parsable-cite="usc/5/1402">Section 1402(a)</external-xref> of title 5, United States Code, is
			 amended—</text>
				<paragraph id="HAA278AD583634DD294B52C8B1E392D97"><enum>(1)</enum><text>by striking
			 <quote>, and</quote> at the end of paragraph (5) and inserting a
			 semicolon;</text>
				</paragraph><paragraph id="H7E2A750B16BB44D9BB48003E6B03A2D7"><enum>(2)</enum><text>by striking the
			 period and inserting <quote>; and</quote> at the end of paragraph (6);
			 and</text>
				</paragraph><paragraph id="H4487D2F35B18499EA516C1C209564768"><enum>(3)</enum><text>by adding at the
			 end the following:</text>
					<quoted-block id="H35F700A9B1E34BE9BC66AEEB7B005000" style="OLC">
						<paragraph id="H1815E4051CDF425CB274B280B6E6119E"><enum>(7)</enum><text>prescribing
				policies and procedures for exit interviews of employees, including a full
				accounting of all Federal personal property that was assigned to the employee
				during the course of
				employment.</text>
						</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection id="HD62C3D2A080848BEA7B097C53F77798F"><enum>(e)</enum><header>Sensitive
			 personal information definition</header><text><external-xref legal-doc="usc" parsable-cite="usc/44/3542">Section 3542(b)</external-xref> of title 44,
			 United States Code, is amended by adding at the end the following new
			 paragraph:</text>
				<quoted-block id="H8A24B253B46D4B798DAF4DB64793D4EE" style="OLC">
					<paragraph id="H7D62A21EA44042F18231548CCC46D69"><enum>(4)</enum><text>The term
				<quote>sensitive personal information</quote>, with respect to an individual,
				means any information about the individual maintained by an agency,
				including—</text>
						<subparagraph id="HA3CC99D2A99B418BA000E50BD8C289F"><enum>(A)</enum><text>education,
				financial transactions, medical history, and criminal or employment
				history;</text>
						</subparagraph><subparagraph id="HA9094FA859C7441CA2A057C469C7A233"><enum>(B)</enum><text>information that
				can be used to distinguish or trace the individual’s identity, including name,
				social security number, date and place of birth, mother’s maiden name, or
				biometric records; or</text>
						</subparagraph><subparagraph id="HC25000141F16418F8FF91600731C60D5"><enum>(C)</enum><text>any other personal
				information that is linked or linkable to the
				individual.</text>
						</subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection></section></legis-body>
</bill>


