<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<congress>109th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>S. 3713</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20060721">July 21, 2006</action-date>
			<action-desc><sponsor name-id="S278">Mrs. Clinton</sponsor> introduced
			 the following bill; which was read twice and referred to the
			 <committee-name committee-id="SSJU00">Committee on the
			 Judiciary</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To protect privacy rights associated with electronic and
		  commercial transactions. </official-title>
	</form>
	<legis-body>
		<section id="S1" section-type="section-one"><enum>1.</enum><header>Short
			 title</header><text display-inline="no-display-inline">This Act may be cited as
			 the <quote><short-title>Privacy Rights and OversighT for
			 Electronic and Commercial Transactions Act of 2006</short-title></quote> or the
			 <quote><short-title>PROTECT
			 Act</short-title></quote>.</text>
		</section><section id="IDb6ca7efe372d480a90d380d8adc5ddb1"><enum>2.</enum><header>Private right of
			 action</header>
			<subsection id="ID10e8ea9a65b24685a3b02d35b26b970b"><enum>(a)</enum><header>Compromised
			 data</header>
				<paragraph id="idC8824DFA37344F669D72D6C1C2AAE551"><enum>(1)</enum><header>In
			 general</header><text>It shall be unlawful for any for profit entity that
			 stores, processes, or otherwise handles the personal data of an individual to
			 compromise the personal, nonpublic information of that individual through
			 theft, loss, data breach or other malfeasance.</text>
				</paragraph><paragraph id="idBF25FD8B86724E44B64B55A32E23F0ED"><enum>(2)</enum><header>Liability</header><text>An
			 entity that violates this subsection shall—</text>
					<subparagraph id="id2307E286E39E497EA01B1F50AB8DC51D"><enum>(A)</enum><text>be liable to the
			 injured individual for $1,000; and</text>
					</subparagraph><subparagraph id="id24F75115420B4D9F859336F0E35C7287"><enum>(B)</enum><text>have a net
			 liability arising from any individual data breach, theft, or loss event of not
			 to exceed 1 percent of annual revenues for the entity.</text>
					</subparagraph></paragraph></subsection><subsection id="ID103852f428f34593b98075bc94ca5814"><enum>(b)</enum><header>Identity
			 theft</header>
				<paragraph id="id5E1EAA2FCBDC46F3B077BF43EFE03951"><enum>(1)</enum><header>In
			 general</header><text>It shall be unlawful for any for profit entity to issue
			 credit or an account for services to an unauthorized individual or make an
			 inaccurate change to a credit report as a result of identity theft.</text>
				</paragraph><paragraph id="idC840E69019604248A78D0CC82B549964"><enum>(2)</enum><header>Liability</header><text>An
			 entity that violates this subsection shall—</text>
					<subparagraph id="idBB3B65A37A0942B3BF4701C75B87C01A"><enum>(A)</enum><text>be liable for
			 $5,000 to the injured individual for each instance of unauthorized use;
			 and</text>
					</subparagraph><subparagraph id="id81AF57A7718946A98F491749EAA19A80"><enum>(B)</enum><text>have a net
			 liability for identity thefts resulting from a specific data breach event of
			 not to exceed 5 percent of annual revenues for the entity.</text>
					</subparagraph></paragraph></subsection><subsection id="ID7680cee7bafd4becba015fe15328a6ae"><enum>(c)</enum><header>Small business
			 exception</header><text>A small business as defined by the standards of the
			 Small Business Administration shall be exempt from this section although
			 nothing in this section shall prohibit private rights of action against any
			 entity for data loss or identity theft.</text>
			</subsection><subsection id="ID1fd9c1b255fa4f1f89ff0d020c919768"><enum>(d)</enum><header>Collective
			 action</header><text>A collective action may be brought under this section
			 pursuant to the procedures provided in section 16(b) of the Fair Labor
			 Standards Act of 1938.</text>
			</subsection></section><section id="id182D7592284544A1971781AE5586901A"><enum>3.</enum><header>Opt-in for
			 certain types of information</header><text display-inline="no-display-inline">Section 502 of the Gramm-Leach-Bliley Act
			 (15 U.S.C. 6802) is amended by adding at the end the following:</text>
			<quoted-block display-inline="no-display-inline" id="id95401AD2C10342989A6C9AF94183F7E6" style="OLC">
				<subsection id="idD9A12C3E2E4A49C8A830F191A58025B7"><enum>(f)</enum><header>Opt in
				requirement for certain information</header>
					<paragraph id="id8885E3793D154F21AC07D396A5EB9448"><enum>(1)</enum><header>Limitation</header><text>Notwithstanding
				subsection (b), a financial institution may not disclose usage data relating to
				a consumer to a nonaffiliated third part, unless—</text>
						<subparagraph id="id0A2CEB623F144BAEA40B6A73A4245E78"><enum>(A)</enum><text>such financial
				institution clearly and conspicuously requests authority from the consumer, in
				writing or in electronic form or other form permitted by the regulations
				prescribed under section 504 to disclose such information to such third party;
				and</text>
						</subparagraph><subparagraph id="id580175BEF6524F9985D6477FA9C74C72"><enum>(B)</enum><text>the consumer
				affirmatively authorizes such disclosure, in writing.</text>
						</subparagraph></paragraph><paragraph id="id7884718676B64B03B0B0E4A2B0121147"><enum>(2)</enum><header>Definition</header><text>As
				used in this subsection, the term <quote>usage data</quote>, means any
				information relating to purchase history records or any listing of items and
				services purchased by the consumer to whom the information
				relates.</text>
					</paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block>
		</section><section id="id4E2FE871A6D849B38F403EBE1E757806"><enum>4.</enum><header>Chief Privacy
			 Officer within the Office of Management and Budget</header>
			<subsection id="id08E3AA5C51C940DD800993A8D6730729"><enum>(a)</enum><header>Definitions</header><text>In
			 this section—</text>
				<paragraph id="id2935E40D54F548509CD7EEFEDD4B9854"><enum>(1)</enum><text>the term
			 <term>agency</term> has the meaning given under section 551(1) of title 5,
			 United States Code; and</text>
				</paragraph><paragraph id="idB039CCE1964B44AAADF084512D6C1072"><enum>(2)</enum><text>the term
			 <term>system of records</term> has the meaning given under section 552a(5) of
			 title 5, United States Code.</text>
				</paragraph></subsection><subsection id="id543D297F37BA4DB195C3F3C4A975BB68"><enum>(b)</enum><header>Designation of
			 Chief Privacy Officer</header><text display-inline="yes-display-inline">The
			 President shall designate a senior officer within the Office of Management and
			 Budget as the Chief Privacy Officer, who shall have primary responsibility for
			 privacy policy throughout all agencies.</text>
			</subsection><subsection id="id222E52BBE0274C5DA5EACDB1867C9AAB"><enum>(c)</enum><header>Responsibilities</header><text>The
			 Chief Privacy Officer shall—</text>
				<paragraph id="idA875E6C84C7245B3BF4D0DD1C22AF2F8"><enum>(1)</enum><text>ensure that the
			 technologies procured and use of technologies by agencies sustain, and do not
			 erode, privacy protections relating to the use, collection, and disclosure of
			 personally identifiable information;</text>
				</paragraph><paragraph id="idB85A327B690B47A7A8D44AD94E79B0C6"><enum>(2)</enum><text>ensure that
			 agency officers have the authority to enforce rules and regulations relating to
			 the collection, processing, and storage of personally identifiable information
			 within, between, and among agencies;</text>
				</paragraph><paragraph id="idFE1CE3C11B2749158FE6B5E93C7961EF"><enum>(3)</enum><text>ensure that
			 personally identifiable information contained in each system of records is
			 handled in full compliance with fair information practices required under
			 section 552a of title 5, United States Code, (commonly referred to as the
			 <quote>Privacy Act</quote>);</text>
				</paragraph><paragraph id="idBC369C4176B9407FBA1EE08B50F8DFD8"><enum>(4)</enum><text>evaluate
			 legislative and regulatory proposals involving collection, use, and disclosure
			 of personally identifiable information by agencies;</text>
				</paragraph><paragraph id="id47ABA313715E45D98210296672E25738"><enum>(5)</enum><text>exercise
			 responsibility under the direction of the Director of the Office of Management
			 and Budget with respect to privacy impact assessment rules, regulations, and
			 oversight under section 208 of the E-Government Act of 2002 (44 U.S.C. 3501
			 note); and</text>
				</paragraph><paragraph id="id0B5641902346465B876B692C31225A36"><enum>(6)</enum><text>submit an annual
			 report to the Congress containing an analysis of each agency of Federal
			 activities that affect privacy, including complaints of privacy violations,
			 implementation of section 552a of title 5, United States Code, (commonly
			 referred to as the <quote>Privacy Act</quote>), internal controls, and other
			 matters.</text>
				</paragraph></subsection><subsection id="id9D8967B5BD284B5888D9184CF40803B5"><enum>(d)</enum><header>Agency reports
			 to the Chief Privacy Officer </header><text>The head of each agency and the
			 Chief Privacy Officer of each agency established under section 522 of the
			 Consolidated Appropriations Act, 2005 (relating to Chief Privacy Officers) (5
			 U.S.C. 552a note; Public Law 108–447; 118 Stat. 3268) shall—</text>
				<paragraph id="idAA4F9A350CAB42A0B5431F73423D0BE1"><enum>(1)</enum><text>provide to the
			 Chief Privacy Officer established under this section such information as the
			 Chief Privacy Officer considers necessary for the completion of the annual
			 reports under subsection (c)(6); and</text>
				</paragraph><paragraph id="idB84C4F7678054E3FAC6DEF22B3D1DC5B"><enum>(2)</enum><text>submit annual
			 reports to the Chief Privacy Officer established under this section that
			 include—</text>
					<subparagraph id="idE460BC1EDA0244CB8321639A0C2F237B"><enum>(A)</enum><text>an assessment of
			 agency policies and protocols relating to data security; and</text>
					</subparagraph><subparagraph id="id19F7590FFF35414FAFDDAE27E58CAA20"><enum>(B)</enum><text>a description of
			 the actions that are being taken to ensure protection against—</text>
						<clause id="idAB7976331AE54B74843EAAACDC588CC4"><enum>(i)</enum><text>threats and
			 hazards to data security; and</text>
						</clause><clause id="id5CB53BA7745545A0A24878697661E9FA"><enum>(ii)</enum><text>unauthorized
			 access or use of data.</text>
						</clause></subparagraph></paragraph></subsection><subsection id="id5D60196A1329475CB08437EDD2A908CC"><enum>(e)</enum><header>Notifications
			 on Breaches of Personally Identifiable Information </header>
				<paragraph id="idD5D62BC522F742FA83A406B53B79BE8F"><enum>(1)</enum><header>Notification to
			 individual</header>
					<subparagraph id="idBA42E776EED14F529A8F45110F1F6EDC"><enum>(A)</enum><header>In
			 general</header><text>If a system of records maintained by an agency is
			 breached and data with personally identifiable information is accessed or
			 disclosed without authorization as a result of that breach, the agency shall
			 provide timely notification to each individual affected by that breach.</text>
					</subparagraph><subparagraph id="id8A3C6E482248481CAEFEFD3E54F19941"><enum>(B)</enum><header>Exception</header><text>An
			 agency may delay notification under subparagraph (A) on the basis of national
			 security.</text>
					</subparagraph></paragraph><paragraph id="id78958721C4BD469E81FBB7FF9E69BC8B"><enum>(2)</enum><header>Notification to
			 major credit reporting services</header>
					<subparagraph id="id60066444C0AC4CB687B39E76865CE236"><enum>(A)</enum><header>In
			 general</header><text>If an individual receives notification of a breach under
			 paragraph (1), the individual may request the agency to provide notification of
			 the breach to all major credit reporting services.</text>
					</subparagraph><subparagraph id="id1FE8B21D544B48F5A2E918FA68C9CB92"><enum>(B)</enum><header>Notification</header><text>Upon
			 the receipt of a request under subparagraph (A), the agency shall provide
			 notification of the breach to all major credit reporting services.</text>
					</subparagraph></paragraph><paragraph id="id7B3E73BD2B394547A14FEE09E859EC3C"><enum>(3)</enum><header>No cost to
			 individual</header><text>Notification under paragraphs (1) or (2) shall be at
			 no cost to any individual.</text>
				</paragraph></subsection></section><section id="idA571B9E0EB474D8A98C1CB6CFE2432ED"><enum>5.</enum><header>Rulemaking
			 relating to disclosures</header><text display-inline="no-display-inline">Section 504 of the Gramm-Leach-Bliley Act
			 (15 U.S.C. 6804) is amended by adding at the end the following:</text>
			<quoted-block display-inline="no-display-inline" id="id313B38D1FF044C08B0C8E4E30F938639" style="OLC">
				<subsection id="id52B96A69EF5F4EF68DCC9A7C66B7D618"><enum>(c)</enum><header>Disclosure
				regulations</header><text>The Federal Trade Commission and each of the Federal
				functional regulators shall, promptly upon the date of enactment of this
				subsection, issue final rules applicable to financial institutions subject to
				their authority to require standard, clear, easy to understand disclosures of
				what specific information could be shared under this title, the types of third
				parties with which such information could be shared, and when consumers are
				given opt out
				opportunities.</text>
				</subsection><after-quoted-block>.</after-quoted-block></quoted-block>
		</section><section id="idC7C5E079A74441EAAC1C029805BBBA81"><enum>6.</enum><header>Annual
			 disclosures to consumers</header><text display-inline="no-display-inline">Section 503 of the Gramm-Leach-Bliley Act
			 (15 U.S.C. 6803) is amended by adding at the end the following:</text>
			<quoted-block display-inline="no-display-inline" id="id810EBE9BA1BC41DDB1A337D93021C229" style="OLC">
				<subsection id="id7383DB3854A04806A3102E89D1C60590"><enum>(c)</enum><header>Annual
				disclosures</header><text>In addition to the disclosures required under
				subsection (a), upon written request of a consumer, each financial institution
				shall provide free of charge to the consumer up to once each year, a copy of
				all information maintained by the financial institution relating to the
				consumer, including any consolidated
				profile.</text>
				</subsection><after-quoted-block>.</after-quoted-block></quoted-block>
		</section><section id="idA0F6B9AF60F140F0B3F41044AD9196F2"><enum>7.</enum><header>Automatic free
			 annual credit reports</header><text display-inline="no-display-inline">Section
			 612(a) of the Fair Credit Reporting Act (15 U.S.C. 1681j(a)) is amended by
			 striking <quote>period upon request of the consumer and</quote> and inserting
			 <quote>period,</quote>.</text>
		</section><section id="id9CF9C13D4BC54C4D9610A5A8D50F2371"><enum>8.</enum><header>Notice of
			 security breaches</header>
			<subsection id="idC1A537DC688E4505B4D3111B5740B926"><enum>(a)</enum><header>Notice to
			 persons affected</header><text>Each Federal agency, and each business entity,
			 whether a nonprofit or for profit concern, shall promptly notify each person
			 who may be a victim of identity theft due to a security breach involving the
			 agency or entity, including the theft or potential theft of or other
			 inappropriate access to identifying information relating to that person that is
			 collected or maintained by the agency or business entity.</text>
			</subsection><subsection id="idC952A4F2CF474B85B89772E6A5210D7C"><enum>(b)</enum><header>Notice to
			 consumer reporting agencies</header><text>Each Federal agency and business
			 entity described in subsection (a) shall promptly notify each consumer
			 reporting agency described in section 603(p) of the Fair Credit Reporting Act
			 (15 U.S.C. 1681a(p)) of a security breach described in subsection (a),
			 including the names of all persons affected or potentially affected
			 thereby.</text>
			</subsection><subsection id="id9FBA64C8629C48EDBC9603E4A690501A"><enum>(c)</enum><header>Regulations</header><text>The
			 Federal Trade Commission shall issue regulations to carry out the provisions of
			 this section.</text>
			</subsection></section><section id="id46C1E14487C64978B84D241E7CBAA83C"><enum>9.</enum><header>Security freeze
			 on credit reports</header><text display-inline="no-display-inline">Section 605B
			 of the Fair Credit Reporting Act (15 U.S.C. 1681C–2) is amended to read as
			 follows:</text>
			<quoted-block display-inline="no-display-inline" id="id7649DC6F564544CCBA4673F7858226FE" style="OLC">
				<section id="id2C4593CF5A1D42D09D90A4BD34B3B8B9"><enum>605B.</enum><header>Security
				freeze on release of information</header>
					<subsection id="idBAE63882BE9F4159BC753B11FF0286DE"><enum>(a)</enum><header>In
				general</header>
						<paragraph id="id9F3F2D917C9644F696DFC1A5AC5AADE1"><enum>(1)</enum><header>Consumer
				placement of a security freeze on individual credit files</header><text>A
				consumer may place a security freeze on his or her file by making a request to
				a consumer reporting agency in writing, by telephone, or through a secure
				electronic connection made available by the consumer reporting agency.</text>
						</paragraph><paragraph id="IDd8f0e7eb77064f5283ac2ffcebe3c448"><enum>(2)</enum><header>Consumer
				disclosure</header><text>If a consumer requests a security freeze under this
				section, the consumer reporting agency shall disclose to the consumer the
				process of placing and removing the security freeze and explain to the consumer
				the potential consequences of the security freeze. A consumer reporting agency
				may not imply or inform a consumer that the placement or presence of a security
				freeze on the file of the consumer may negatively affect the consumer's credit
				score.</text>
						</paragraph></subsection><subsection id="IDa982cd75c8204684bb6ebdfa369d7d0c"><enum>(b)</enum><header>Effect of
				security freeze</header>
						<paragraph id="IDc2b04ab9179244b2bf7be85f68220b9f"><enum>(1)</enum><header>Release of
				information blocked</header><text>If a security freeze is in place on the file
				of a consumer, a consumer reporting agency may not release information relating
				to that file for consumer credit purposes to a third party without prior
				express authorization from the consumer.</text>
						</paragraph><paragraph id="ID8e74282cc44049578f3bf894ef0fd742"><enum>(2)</enum><header>Information
				provided to third parties</header><text>Paragraph (1) does not prevent a
				consumer reporting agency from advising a third party that a security freeze is
				in effect with respect to the file of a consumer. If a third party requests
				access to the file of a consumer on which a security freeze is in place in
				connection with an application for credit, the third party may treat the
				application as incomplete.</text>
						</paragraph><paragraph id="IDd883fc399ac54b3aa8932d45ce6b4d37"><enum>(3)</enum><header>Consumer credit
				score not affected</header><text>The placement of a security freeze on a
				consumer file may not be taken into account for any purpose in determining the
				credit score of the consumer to whom the account relates.</text>
						</paragraph></subsection><subsection id="IDbe275c0809cb42f0af17409044061543"><enum>(c)</enum><header>Removal;
				temporary suspension</header>
						<paragraph id="ID4675ecace0774fd197bcf17ae85e3bf1"><enum>(1)</enum><header>In
				general</header><text>Except as provided in paragraph (4), a security freeze
				under this section shall remain in place until the consumer requests that the
				security freeze be removed. A consumer may remove a security freeze on his or
				her credit file by making a request to a consumer reporting agency in writing,
				by telephone, or through a secure electronic connection made available by the
				consumer reporting agency.</text>
						</paragraph><paragraph id="ID45b3188594214eb187a3a5852f666277"><enum>(2)</enum><header>Conditions</header><text>A
				consumer reporting agency may remove a security freeze placed on the file of a
				consumer only—</text>
							<subparagraph id="IDe2aed843393643a99a0e09745f22ce52"><enum>(A)</enum><text>upon request of
				the consumer, pursuant to paragraph (1); or</text>
							</subparagraph><subparagraph id="IDa2af4f991aaf4ca9b835ae59795c9257"><enum>(B)</enum><text>if the agency
				determines that the credit file of the consumer was frozen due to a material
				misrepresentation of fact by the consumer.</text>
							</subparagraph></paragraph><paragraph id="ID3d534edf6d6e4483bb6091240f0a55c8"><enum>(3)</enum><header>Notification to
				consumer</header><text>If a consumer reporting agency intends to remove a
				security freeze on the file of a consumer pursuant to paragraph (2)(B), the
				consumer reporting agency shall notify the consumer in writing prior to
				removing the security freeze.</text>
						</paragraph><paragraph id="IDddafbf102a83468697eb9be2a93a72a3"><enum>(4)</enum><header>Temporary
				suspension</header><text>A consumer may have a security freeze on his or her
				credit file temporarily suspended by making a request to a consumer reporting
				agency in writing or by telephone and specifying beginning and ending dates for
				the period during which the security freeze is not to apply to that
				file.</text>
						</paragraph></subsection><subsection id="ID75ae091604784c60ac7f9d33684af179"><enum>(d)</enum><header>Response times;
				notification of other entities</header>
						<paragraph id="ID73a3c30111174bf8a0aa259832640cf9"><enum>(1)</enum><header>In
				general</header><text>A consumer reporting agency shall—</text>
							<subparagraph id="IDc550bc8862a24c99ac7035e90066ced7"><enum>(A)</enum><text>place a security
				freeze on the file of a consumer under subsection (a) not later than 5 business
				days after receiving a request from the consumer under subsection (a)(1);
				and</text>
							</subparagraph><subparagraph id="IDfde8e50837e0454b862980a5f3166dbc"><enum>(B)</enum><text>remove or
				temporarily suspend a security freeze not later than 3 business days after
				receiving a request for removal or temporary suspension from the consumer under
				subsection (c).</text>
							</subparagraph></paragraph><paragraph id="ID72a0c2f5f89e41d0ad7d9840d7e40694"><enum>(2)</enum><header>Notification to
				other agencies</header><text>If the consumer so requests in writing or by
				telephone, a consumer reporting agency shall notify all other consumer
				reporting agencies described in section 603(p)(1) not later than 3 days after
				placing, removing, or temporarily suspending a security freeze on the file of
				the consumer under subsection (a), (c)(2)(A), or (c)(4), respectively.</text>
						</paragraph><paragraph id="IDacf0188adb08405e823fc10c29b17b9a"><enum>(3)</enum><header>Implementation
				by other covered entities</header><text>A consumer reporting agency that is
				notified of a request under paragraph (2) to place, remove, or temporarily
				suspend a security freeze on the file of a consumer shall—</text>
							<subparagraph id="ID4b2f49c2d21b4da495987febd235034c"><enum>(A)</enum><text>request proper
				identification from the consumer, in accordance with subsection (f), not later
				than 3 business days after receiving the notification; and</text>
							</subparagraph><subparagraph id="IDf422e68195e146e9858ae5ee9d25cfb9"><enum>(B)</enum><text>place, remove, or
				temporarily suspend the security freeze on that credit report not later than 3
				business days after receiving proper identification.</text>
							</subparagraph></paragraph></subsection><subsection id="IDac03386b33ad4822ad0f914110a876ab"><enum>(e)</enum><header>Confirmation</header><text>Except
				as provided in subsection (c)(3), whenever a consumer reporting agency places,
				removes, or temporarily suspends a security freeze on the file of a consumer at
				the request of that consumer under subsection (a) or (c), respectively, it
				shall send a written confirmation thereof to the consumer not later than 10
				business days after placing, removing, or temporarily suspending the security
				freeze on the file. This subsection does not apply to the placement, removal,
				or temporary suspension of a security freeze by a consumer reporting agency
				because of a notification received under subsection (d)(2).</text>
					</subsection><subsection id="ID5939052d93cb4ebc8060e0ed3c5f7168"><enum>(f)</enum><header>Identification
				required</header><text>A consumer reporting agency may not place, remove, or
				temporarily suspend a security freeze on the file of a consumer or otherwise
				provide a credit report or score in accordance with this section at the request
				of the consumer, unless the consumer provides proper identification (within the
				meaning of section 610(a)(1) and the regulations thereunder).</text>
					</subsection><subsection id="ID50e381895b7b4eb881d6c08816b6b9f7"><enum>(g)</enum><header>Exceptions</header><text>This
				section does not apply to the use of a consumer credit report by any of the
				following:</text>
						<paragraph id="ID9c6131cf8f964d2091eaf165b1306fba"><enum>(1)</enum><text>A person or
				entity, or a subsidiary, affiliate, or agent of that person or entity, or an
				assignee of a financial obligation owing by the consumer to that person or
				entity, or a prospective assignee of a financial obligation owing by the
				consumer to that person or entity in conjunction with the proposed purchase of
				the financial obligation, with which the consumer has or had prior to
				assignment an account or contract, including a demand deposit account, or to
				whom the consumer issued a negotiable instrument, for the purposes of reviewing
				the account or collecting the financial obligation owing for the account,
				contract, or negotiable instrument.</text>
						</paragraph><paragraph id="IDb62bcc2a8a594819811fd87144063012"><enum>(2)</enum><text>Any Federal,
				State, or local agency, law enforcement agency, trial court, or private
				collection agency acting pursuant to a court order, warrant, subpoena, or other
				compulsory process.</text>
						</paragraph><paragraph id="IDeefbe2d47cd441d89d92315c9562c7ca"><enum>(3)</enum><text>A child support
				agency or its agents or assigns acting pursuant to subtitle D of title IV of
				the Social Security Act (42 U.S.C. et seq.) or similar State law.</text>
						</paragraph><paragraph id="IDc2a705c86779452897a9f903f4763b8d"><enum>(4)</enum><text>The Department of
				Health and Human Services, a similar State agency, or the agents or assigns of
				the Federal or State agency acting to investigate Medicare or Medicaid
				fraud.</text>
						</paragraph><paragraph id="IDa07b09f104874c05aa2141a29c523eeb"><enum>(5)</enum><text>The Internal
				Revenue Service or a State or municipal taxing authority, or a State department
				of motor vehicles, or any of the agents or assigns of these Federal, State, or
				municipal agencies acting to investigate or collect delinquent taxes, or unpaid
				court orders, or to fulfill any of their other statutory
				responsibilities.</text>
						</paragraph><paragraph id="ID3d85005577974bc68581408b8dba6b54"><enum>(6)</enum><text>The use of
				consumer credit information for the purposes of prescreening as provided in
				this title.</text>
						</paragraph><paragraph id="IDb12893c2dd4149c6bd885cc552a2f331"><enum>(7)</enum><text>Any person or
				entity administering a credit file monitoring subscription to which the
				consumer has subscribed.</text>
						</paragraph><paragraph id="ID5f2b17b9b10a4b3aaec2fdb66c323738"><enum>(8)</enum><text>Any person or
				entity for the purpose of providing a consumer with a copy of his or her credit
				report or credit score, upon the request of the consumer and upon provision of
				appropriate identification in accordance with subsection (f).</text>
						</paragraph></subsection><subsection id="IDad95a0a08c4a473e95e51a7caf3674eb"><enum>(h)</enum><header>Fees</header>
						<paragraph commented="no" id="ID69e329132a104d9b88cfc0ab7db52127"><enum>(1)</enum><header>In
				general</header><text>Except as provided in paragraph (2), a consumer reporting
				agency may charge a reasonable fee, as determined by the Commission by rule,
				promulgated in accordance with section 553 of title 5, United States Code, for
				placing, removing, or temporarily suspending a security freeze on the file of a
				consumer under this section.</text>
						</paragraph><paragraph id="IDf943fb0db8e348da9bdc3be725a60248"><enum>(2)</enum><header>Exception for
				identification theft victims</header><text>A consumer reporting agency may not
				charge a fee for placing, removing, or temporarily suspending a security freeze
				on the file of a consumer, if—</text>
							<subparagraph id="ID40685519119046b5b2b684777726dd16"><enum>(A)</enum><text>the consumer is a
				victim of identity theft;</text>
							</subparagraph><subparagraph id="IDbbf1cebf034742b1aa5ea1579805a3d9"><enum>(B)</enum><text>the consumer
				requests the security freeze in writing;</text>
							</subparagraph><subparagraph id="ID08b7229ffb5148b8859c64b23b8381a8"><enum>(C)</enum><text>the consumer has
				filed a police report with respect to the theft, or an identity theft report
				(as defined in section 603(q)(4)), not later than 90 days after the date on
				which the theft occurred or was discovered by the consumer;</text>
							</subparagraph><subparagraph id="IDfd378d3a4f284a739175f286d270011f"><enum>(D)</enum><text>the consumer
				provides a copy of the police report to the consumer reporting agency;
				and</text>
							</subparagraph><subparagraph id="ID08e844b8c22f4d0896f7452239dcda0c"><enum>(E)</enum><text>the
				consumer—</text>
								<clause id="idF5648FACD0E54FA6A045C49BF16827F6"><enum>(i)</enum><text>has been notified
				by any entity that personally identifiable information handled by that entity
				has been compromised or breached; and</text>
								</clause><clause id="idFEE3547D30BE41A2BD9993DB50755C28"><enum>(ii)</enum><text>notifies the
				consumer reporting agency of such compromise or breach.</text>
								</clause></subparagraph></paragraph></subsection><subsection id="IDeca2443be27c455ab2ed25d38c0c3ac1"><enum>(i)</enum><header>Limitation on
				information changes in frozen files</header>
						<paragraph id="ID92060a1863d64ef19ee6da7aa077d214"><enum>(1)</enum><header>In
				general</header><text>If a security freeze is in place on the file of consumer,
				a consumer reporting agency may not change any of the following official
				information in that file without sending a written confirmation of the change
				to the consumer, not later than 30 days after the change is made:</text>
							<subparagraph id="ID8bfb40b8832346e9a73e236c7fd2cd7f"><enum>(A)</enum><text>Name.</text>
							</subparagraph><subparagraph id="ID10c8fdd3241547f29c439cfaa3cd4e46"><enum>(B)</enum><text>Date of
				birth.</text>
							</subparagraph><subparagraph id="IDf07cbfb52d10449391227b4ea536ff54"><enum>(C)</enum><text>Social Security
				number.</text>
							</subparagraph><subparagraph id="ID73c474ec00274f7681b4b0dc75b3bb47"><enum>(D)</enum><text>Address.</text>
							</subparagraph></paragraph><paragraph id="ID9afa3fd4352d454689cad0342aafeee0"><enum>(2)</enum><header>Confirmation</header><text>Paragraph
				(1) does not require written confirmation for technical modifications of a
				consumer's official information, including name and street abbreviations,
				complete spellings, or transposition of numbers or letters. In the case of an
				address change, the written confirmation shall be sent to both the new address
				and to the former address.</text>
						</paragraph></subsection><subsection id="ID5cb599cc92e7407481a0adf10610e7a7"><enum>(j)</enum><header>Certain entity
				exemptions</header>
						<paragraph id="IDdff9c42a058a4287b120d92458d2819c"><enum>(1)</enum><header>Aggregators and
				other agencies</header><text>The provisions of subsections (a) through (i) do
				not apply to a consumer reporting agency that acts only as a reseller of credit
				information by assembling and merging information contained in the data base of
				another consumer reporting agency or multiple consumer reporting agencies, and
				does not maintain a permanent data base of credit information from which new
				consumer credit reports are produced.</text>
						</paragraph><paragraph id="ID3a435c26207348c7900f0a3808144804"><enum>(2)</enum><header>Other exempted
				entities</header><text>The following entities are not required to place a
				security freeze on the file of a consumer under this section:</text>
							<subparagraph id="IDd95242fd04ae4a89be35b879556a0c2c"><enum>(A)</enum><text>A check services
				or fraud prevention services company which issues reports on incidents of fraud
				or authorizations for the purpose of approving or processing negotiable
				instruments, electronic funds transfers, or similar methods of payments.</text>
							</subparagraph><subparagraph id="ID273c1e6eae0e41979897319e3ac0875f"><enum>(B)</enum><text>A deposit account
				information service company which issues reports regarding account closures due
				to fraud, substantial overdrafts, ATM abuse, or similar negative information
				regarding a consumer, to inquiring banks or other financial institutions for
				use only in reviewing a consumer request for a deposit account at the inquiring
				bank or financial institution.</text>
							</subparagraph></paragraph></subsection><subsection id="id73A1169A5330499FB72FEDF9C1CA85DE"><enum>(k)</enum><header>State
				Preemption</header><text>This section shall preempt any provision of State of
				local law, regulation, or rule that requires consumer reporting agencies to
				comply with the request of a consumer to place, remove, or temporarily suspend
				a prohibition on the release by a consumer reporting agency of information from
				its files on that consumer, but only if it is determined by the Commission that
				this section will provide materially stronger consumer protections than those
				afforded to consumers under otherwise applicable State or local
				law.</text>
					</subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
		</section><section id="id5AA70DD0A6F24235BB8AE3468D756269" section-type="subsequent-section"><enum>10.</enum><header>Safeguarding
			 Americans from exporting identification data</header>
			<subsection id="IDC137398A6B564282A7C3EC53876901F2"><enum>(a)</enum><header>Definitions</header><text display-inline="yes-display-inline">As used in this section:</text>
				<paragraph id="id5C484CE18CAC456B861F7A3BA8F0A5E6"><enum>(1)</enum><header>Business
			 enterprise</header><text>The term <term>business enterprise</term>
			 means—</text>
					<subparagraph id="id2A0A9E06214744A5AF2B5B0ECEC7EF2D"><enum>(A)</enum><text>any organization,
			 association, or venture established to make a profit;</text>
					</subparagraph><subparagraph id="idF66EBF994887490D9604A1CFD0719BCC"><enum>(B)</enum><text>any health care
			 business;</text>
					</subparagraph><subparagraph id="idB2B7B3C29B2E471B8402DD8852CF0FCE"><enum>(C)</enum><text>any private,
			 nonprofit organization; or</text>
					</subparagraph><subparagraph id="id2235F036356A4E618E574752A1C639F1"><enum>(D)</enum><text>any contractor,
			 subcontractor, or potential subcontractor of an entity described in
			 subparagraph (A), (B), or (C).</text>
					</subparagraph></paragraph><paragraph id="idD732E63080F448CEAB02897EA06F2ECF"><enum>(2)</enum><header>Health care
			 business</header><text>The term <term>health care business</term> means any
			 business enterprise or private, nonprofit organization that collects or retains
			 personally identifiable information about consumers in relation to medical
			 care, including—</text>
					<subparagraph id="idA08F4013EE904B219960B1A8D0C253D3"><enum>(A)</enum><text>hospitals;</text>
					</subparagraph><subparagraph id="id22285AF8DF354EFB92E4B4F3C8B5BF94"><enum>(B)</enum><text>health
			 maintenance organizations;</text>
					</subparagraph><subparagraph id="id925F429DFDC941D696BC39A1D20967BB"><enum>(C)</enum><text>medical
			 partnerships;</text>
					</subparagraph><subparagraph id="id287ECB92CF2D438186BDCF5B1614D0C3"><enum>(D)</enum><text>emergency medical
			 transportation companies;</text>
					</subparagraph><subparagraph id="id8EBC73679D30452DA3782F16C69D5E92"><enum>(E)</enum><text>medical
			 transcription companies;</text>
					</subparagraph><subparagraph id="id1D9E9A09AD3A438280C21EA73263B069"><enum>(F)</enum><text>banks that
			 collect or process medical billing information; and</text>
					</subparagraph><subparagraph id="id10A88906743546E1A0A01CF5F769806E"><enum>(G)</enum><text>subcontractors,
			 or potential subcontractors, of the entities described in subparagraphs (A)
			 through (F).</text>
					</subparagraph></paragraph><paragraph id="id3965587E222F4E96ACEF671FECAEEBAE"><enum>(3)</enum><header>Personally
			 identifiable information</header><text>The term <term>personally identifiable
			 information</term> includes information such as—</text>
					<subparagraph id="idD40DF90DD2274323852A1A86AF277240"><enum>(A)</enum><text>name;</text>
					</subparagraph><subparagraph id="id98C4520070254953A54274261F81AF88"><enum>(B)</enum><text>postal
			 address;</text>
					</subparagraph><subparagraph id="idB5D3664F8CC8460D9C9EDE7EE0A0DB3E"><enum>(C)</enum><text>financial
			 information;</text>
					</subparagraph><subparagraph id="idD6F965E25FE9439B83A9131BEDC9FFC4"><enum>(D)</enum><text>medical
			 records;</text>
					</subparagraph><subparagraph id="id978424997A3E4747A81556561BB935D2"><enum>(E)</enum><text>date of
			 birth;</text>
					</subparagraph><subparagraph id="id65E8A220D5794E4E837FC2AFC7CBA338"><enum>(F)</enum><text>phone
			 number;</text>
					</subparagraph><subparagraph id="id2505E7C068174BE2B4F21F7D6C1ECB6A"><enum>(G)</enum><text>e-mail
			 address;</text>
					</subparagraph><subparagraph id="id5039FF0804D84D18AD4495713C2BCF88"><enum>(H)</enum><text>social security
			 number;</text>
					</subparagraph><subparagraph id="idF98CD307570C454CA7B559A96FBC4F86"><enum>(I)</enum><text>mother's maiden
			 name;</text>
					</subparagraph><subparagraph id="idF6FA62BF0C10451BA73150592766FA18"><enum>(J)</enum><text>password;</text>
					</subparagraph><subparagraph id="id349879C8F0F14B039B7303340C0B72F5"><enum>(K)</enum><text>State
			 identification information; and</text>
					</subparagraph><subparagraph changed="not-changed" commented="no" id="id324BA8BA521E49D3B9D2A3E5BE817337"><enum>(L)</enum><text>driver's license
			 number.</text>
					</subparagraph></paragraph></subsection><subsection id="idA5E1A9A5C9304052AE8DC8280972C5AA"><enum>(b)</enum><header>Transmission of
			 information</header>
				<paragraph id="id61F0FD680D73437E83A18F0013CCA967"><enum>(1)</enum><header>Prohibition</header><text>A
			 business enterprise may not disclose personally identifiable information
			 regarding a resident of the United States to any foreign branch, affiliate,
			 subcontractor, or unaffiliated third party located in a foreign country
			 unless—</text>
					<subparagraph id="id9038A9C20F074A38AF5DAF467769D2EA"><enum>(A)</enum><text>the business
			 enterprise provides the notice of privacy protections described in sections 502
			 and 503 of the Gramm-Leach-Bliley Act (15 U.S.C. 6802 and 6803) or required by
			 the regulations promulgated pursuant to section 264(c) of the Health Insurance
			 Portability and Accountability Act of 1996 (42 U.S.C. 1320d–2 note), as
			 appropriate;</text>
					</subparagraph><subparagraph id="idC10D0AF9DC444D0EAF7F238060DDC0D4"><enum>(B)</enum><text>the business
			 enterprise complies with the safeguards described in section 501(b) of the
			 Gramm-Leach-Bliley Act (15 U.S.C. 6801(b)), as appropriate;</text>
					</subparagraph><subparagraph id="id9DCC7968C4FC4953B7134827480AFF9F"><enum>(C)</enum><text>the consumer is
			 given the opportunity, before the time that such information is initially
			 disclosed, to object to the disclosure of such information to such foreign
			 branch, affiliate, subcontractor, or unaffiliated third party; and</text>
					</subparagraph><subparagraph id="idB57829924A2A46C0ABA8052549D48ECD"><enum>(D)</enum><text>the consumer is
			 given an explanation of how the consumer can exercise the nondisclosure option
			 described in subparagraph (C).</text>
					</subparagraph></paragraph><paragraph changed="not-changed" commented="no" id="id03C2549D9E584C02960DE58D827F147B"><enum>(2)</enum><header>Health care
			 businesses</header><text display-inline="yes-display-inline">A health care
			 business may not terminate an existing relationship with a consumer of health
			 care services to avoid the consumer from objecting to the disclosure under
			 paragraph (1)(C).</text>
				</paragraph><paragraph changed="not-changed" commented="no" id="id98BC19C2C53F49928208A52411350445"><enum>(3)</enum><header>Effect on
			 business relationship</header>
					<subparagraph changed="not-changed" commented="no" id="id0A9502CCA5B74828BA6F17161814C31F"><enum>(A)</enum><header>Nondiscrimination</header><text>A
			 business enterprise may not discriminate against or deny an otherwise qualified
			 consumer a financial product or a health care service because the consumer has
			 objected to the disclosure under paragraph (1)(C).</text>
					</subparagraph><subparagraph changed="not-changed" commented="no" id="idDC9E811273B14EFAB1488F9D3B4C8EED"><enum>(B)</enum><header>Products and
			 services</header><text>A business enterprise shall not be required to offer or
			 provide a product or service through affiliated entities or jointly with
			 nonaffiliated business enterprises.</text>
					</subparagraph><subparagraph changed="not-changed" commented="no" id="idDA9D28EC72C245598D54F841D4C9B946"><enum>(C)</enum><header>Incentives and
			 discounts</header><text>Nothing in this subsection is intended to prohibit a
			 business enterprise from offering incentives or discounts to elicit a specific
			 response to the notice required under paragraph (1).</text>
					</subparagraph></paragraph><paragraph id="IDD0A96548FA2E4F1ABA6FBED2C43E7E05"><enum>(4)</enum><header>Liability</header>
					<subparagraph id="idFB71BE1D3FE440B7A2F2D6F138C66925"><enum>(A)</enum><header>In
			 general</header><text>A business enterprise that knowingly and directly
			 transfers personally identifiable information to a foreign branch, affiliate,
			 subcontractor, or unaffiliated third party shall be liable to any person
			 suffering damages resulting from the improper storage, duplication, sharing, or
			 other misuse of such information by the transferee.</text>
					</subparagraph><subparagraph changed="not-changed" commented="no" id="id9B492AC1E8C84D24893103133486DE15"><enum>(B)</enum><header>Civil
			 action</header><text>An injured party under subparagraph (A) may sue in law or
			 in equity in any court of competent jurisdiction to recover the damages
			 sustained as a result of a violation of this subsection.</text>
					</subparagraph></paragraph><paragraph id="id4318DC836EE74BAF8032EDA23CD67672"><enum>(5)</enum><header>Rulemaking</header><text>The
			 Chairman of the Federal Trade Commission shall promulgate regulations through
			 which the Chairman may enforce the provisions of this subsection and impose a
			 civil penalty for a violation of this section.</text>
				</paragraph></subsection><subsection id="ID368E9B835936495E89EEA43D5CD4A3BF"><enum>(c)</enum><header>Privacy for
			 consumers of health services</header><text display-inline="yes-display-inline">The Secretary of Health and Human Services
			 shall revise the regulations promulgated pursuant to
			 <external-xref legal-doc="act" parsable-cite="HIPAA/264(c)">section
			 264(c)</external-xref> of the <act-name parsable-cite="HIPAA">Health Insurance
			 Portability and Accountability Act of 1996</act-name> (<external-xref legal-doc="usc" parsable-cite="usc/42/1320d-2 note">42 U.S.C. 1320d–2 note</external-xref>) to
			 require a covered entity (as defined by such regulations) that outsources
			 protected health information (as defined by such regulations) outside the
			 United States to include in such entity’s notice of privacy protections—</text>
				<paragraph id="IDB78C979F1CF04687B41F02773BF0D753"><enum>(1)</enum><text>notification that
			 the covered entity outsources protected health information to business
			 associates (as defined by such regulations) for processing outside the United
			 States;</text>
				</paragraph><paragraph id="IDB747E5556DC24F2DB8F4840ABCA9F3D8"><enum>(2)</enum><text>a description of
			 the privacy laws of the country to which the protected health information will
			 be sent;</text>
				</paragraph><paragraph id="id824FB348DE0F4021926F76FB53BFC3EE"><enum>(3)</enum><text>any additional
			 risks and consequences to the privacy and security of protected health
			 information that arise as a result of the processing of such information in a
			 foreign country;</text>
				</paragraph><paragraph id="ID6FA03E6E5A0F4381A2D4FA611E090E3D"><enum>(4)</enum><text>additional
			 measures the covered entity is taking to protect the protected health
			 information outsourced for processing outside the United States;</text>
				</paragraph><paragraph id="idA1329B1391404BD8BE01F44E82B4A749"><enum>(5)</enum><text>notification that
			 the protected health information will not be outsourced outside the United
			 States if the consumer objects; and</text>
				</paragraph><paragraph id="ID4B4A62F9AF9546D7BBDCC8E6759B4E74"><enum>(6)</enum><text>a certification
			 that—</text>
					<subparagraph id="IDB6C8F0C6F0B142689204AD8F9502B160"><enum>(A)</enum><text>the covered
			 entity has taken reasonable steps to identify the locations where protected
			 health information is outsourced by such business associates;</text>
					</subparagraph><subparagraph id="ID1D7A6DEA88AB40E4977F88C43BC5707D"><enum>(B)</enum><text>attests to the
			 privacy and security of the protected health information outsourced for
			 processing outside the United States; and</text>
					</subparagraph><subparagraph id="ID1CAF108A612F4EE899DACA5C7B572C71"><enum>(C)</enum><text>states the
			 reasons for the determination by the covered entity that the privacy and
			 security of such information is maintained.</text>
					</subparagraph></paragraph></subsection><subsection id="ID6D6A3EEBB8CE4F49901F5B741B9F382E"><enum>(d)</enum><header>Privacy for
			 consumers of financial services</header><text display-inline="yes-display-inline">Section 503(b) of the Gramm-Leach-Bliley
			 Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6803(b)">15 U.S.C.
			 6803(b)</external-xref>) is amended—</text>
				<paragraph id="IDB6EDE89C05004B239CC7A5090181D890"><enum>(1)</enum><text>in paragraph (3),
			 by striking <quote>and</quote> after the semicolon;</text>
				</paragraph><paragraph id="ID48EB775DCE3F464E94B193AD22FB5DA7"><enum>(2)</enum><text>in paragraph (4),
			 by striking the period at the end and inserting <quote>; and</quote>;
			 and</text>
				</paragraph><paragraph id="ID4926528ED33C4099BBB164E6074A3C91"><enum>(3)</enum><text>by adding at the
			 end the following:</text>
					<quoted-block display-inline="no-display-inline" id="IDB3AFB0C64BB440738A2E4983A7437E78" style="OLC">
						<paragraph id="IDE50D0ED805364E6483294D2819749C33"><enum>(5)</enum><text>if the financial
				institution outsources nonpublic personal information outside the United
				States—</text>
							<subparagraph id="IDE5C5819149C04298871E874423605B07"><enum>(A)</enum><text>information
				informing the consumer in simple language—</text>
								<clause id="ID34CFADA3846444B89A74C044EAE40D7B"><enum>(i)</enum><text>that the
				financial institution outsources nonpublic personal information to entities for
				processing outside the United States;</text>
								</clause><clause id="id02962266F5E7413D9EF6BD4640AC429D"><enum>(ii)</enum><text>of the privacy
				laws of the country to which nonpublic personal information will be
				sent;</text>
								</clause><clause id="ID188567060D194221A8B49B885B8A38B4"><enum>(iii)</enum><text>of any
				additional risks and consequences to the privacy and security of an
				individual’s nonpublic personal information that arise as a result of the
				processing of such information in a foreign country; and</text>
								</clause><clause id="ID80A4503BF4824733A8AAE9B85852CBCA"><enum>(iv)</enum><text>of the
				additional measures the financial institution is taking to protect the
				nonpublic personal information outsourced for processing outside the United
				States; and</text>
								</clause></subparagraph><subparagraph id="IDAE068219A7674971831C419BDD4DB000"><enum>(B)</enum><text>a certification
				that—</text>
								<clause id="ID5958F3CED8884E599E3F597151B63CA9"><enum>(i)</enum><text>the financial
				institution has taken reasonable steps to identify the locations where
				nonpublic personal information is outsourced by such entities;</text>
								</clause><clause id="IDE6FED6CE51BB4474A51EE0005EBCA280"><enum>(ii)</enum><text>attests to the
				privacy and security of the nonpublic personal information outsourced for
				processing outside the United States; and</text>
								</clause><clause changed="not-changed" commented="no" id="ID1246BE5C04934D709B6D8D9DE0F00B0D"><enum>(iii)</enum><text>states the
				reasons for the determination by the institution that the privacy and security
				of such information is
				maintained.</text>
								</clause></subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection changed="not-changed" commented="no" display-inline="no-display-inline" id="id91E2F6B577BF48C199366DF714A4DF7B"><enum>(e)</enum><header>Effective
			 date</header><text display-inline="yes-display-inline">This section shall take
			 effect on the expiration of the date which is 90 days after the date of
			 enactment of this Act.</text>
			</subsection></section><section id="IDa83c071180424fd6a3bab0e61c77964c"><enum>11.</enum><header>Telephone and
			 communications records </header>
			<subsection id="ID552c3d5e6d7743dabfa34898cd3468db"><enum>(a)</enum><header>In
			 general</header><text>Not later than 120 days after the date of enactment of
			 this Act, the Federal Trade Commission, the Federal Communications Commission
			 and the Attorney General shall establish a Center for Telecommunications
			 Records Privacy (referred to in this section as the <quote>Center</quote>)
			 which shall consist of the appropriate designees of each agency which shall be
			 established by a memorandum of understanding among the agencies.</text>
			</subsection><subsection id="ID4d88007ef3f54aab9f0314cdacadeb6c"><enum>(b)</enum><header>Responsibilities</header><text>The
			 Center shall—</text>
				<paragraph id="idBF1FB35A2C034A3581B7FB3D30E87382"><enum>(1)</enum><text>be charged with
			 evaluating the current rules, regulations and law regarding the unauthorized
			 disclosure, access, and sharing of telephone and telephony technology call
			 records and identify gaps in coverage and enforcement regarding the
			 unauthorized disclosure, sharing, or sale of telephone and communications
			 records; and</text>
				</paragraph><paragraph id="ID852b546961514034be79a26d68baeaf2"><enum>(2)</enum><text>on an annual
			 basis—</text>
					<subparagraph id="id06246520179E43058DEB22DC8A78383F"><enum>(A)</enum><text>provide an
			 assessment of the frequency and scope of the unauthorized and criminal
			 disclosure of telecommunications records and provide an evaluation of the
			 effectiveness of enacted laws and regulations;</text>
					</subparagraph><subparagraph id="id88CAC0444E7A42299D82E028FE93B4F4"><enum>(B)</enum><text>identify new
			 telecommunications technologies not covered by current law or regulation;
			 and</text>
					</subparagraph><subparagraph id="idEBF562BEEBA040E2BADC4854653EF12F"><enum>(C)</enum><text>make
			 recommendations to Congress regarding other legislative or regulatory steps
			 that can be taken to address emerging issues.</text>
					</subparagraph></paragraph></subsection></section><section id="IDb481bfb3d4d04f93a0ad8f3b47bb62c3"><enum>12.</enum><header>Federal Trade
			 Commission rules for data processors and rules for Federal agencies</header>
			<subsection id="IDf2406428c1e144b39b805902a6f30376"><enum>(a)</enum><header>In
			 general</header><text>The Federal Trade Commission shall issue new rules for
			 Federal agencies responsible for working with data processors to ensure the
			 security and confidentiality of nonpublic personal information to—</text>
				<paragraph id="ID5ccae96636d14e43b1b9423666f7d7f8"><enum>(1)</enum><text>protect against
			 any anticipated threats or hazards to the security or integrity of such
			 information;</text>
				</paragraph><paragraph id="IDe78d0ef95197458abe4f1b21b4da7027"><enum>(2)</enum><text>protect against
			 unauthorized access to or use of such information which could result in
			 substantial harm or inconvenience to a customer or the relevant financial
			 institution; and</text>
				</paragraph><paragraph id="IDec9e74361f54484e813483c75f3bf14e"><enum>(3)</enum><text>protect against
			 the illegal or unauthorized collection of personally identifiable information
			 by data processors.</text>
				</paragraph></subsection><subsection id="id4503B3A590214D939EE975AF98823E27"><enum>(b)</enum><header>Definition</header><text>In
			 this section, the term <term>data processor</term> means any entity the
			 business of which in whole or in part is the handling processing, compilation,
			 exchange, transmittal, or other management or processing of the nonpublic
			 personal information of consumers by agreement on behalf of another
			 institution.</text>
			</subsection><subsection id="ID6a78820f9b8340d3aad439dac235e4c1"><enum>(c)</enum><header>Report</header><text>Each
			 Federal agency covered by this section shall submit annual reports to the Chief
			 Privacy Officer established under section 4, which shall include an assessment
			 of agency policies and protocols dealing with data security and what steps are
			 being taken to ensure against threats and hazards to that security and
			 protecting against unauthorized access or use of data.</text>
			</subsection></section><section id="idC588FF9E08174155807AFC5D232C1B5D"><enum>13.</enum><header>Medical
			 records</header>
			<subsection id="ID33d0ae376199455a8747f38802d128f7"><enum>(a)</enum><header>Application of
			 penalties to certain employees</header><text>Section 1177 of the Social
			 Security Act (42 U.S.C. 1320d–6) is amended by adding at the end the
			 following:</text>
				<quoted-block display-inline="no-display-inline" id="id25E22E9590574047B9B4ED3FE66F4032" style="OLC">
					<subsection id="id3056720943B640E18E3330253A7D58DA"><enum>(c)</enum><header>Clarification
				of application</header><text>The provisions of subsection (a) shall apply to
				individuals who knowingly use, obtain, or disclose individually identifiable
				health information or a unique health identifier regardless of the manner in
				which such individuals obtain such information or the relation of the
				individual to the entity that maintains the information involved. The preceding
				sentence shall apply to individuals who illegally hack into computer systems to
				obtain
				data.</text>
					</subsection><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="id104542026A174E86922A939DF45A8AF8"><enum>(b)</enum><header>Expanding the
			 scope of the HIPAA privacy rule</header>
				<paragraph id="id00E8486C00F1439AADDD05BDB2CBEE3D"><enum>(1)</enum><header>In
			 general</header><text>The Secretary of Health and Human Services shall modify
			 the regulations promulgated under section 264(c) of the Health Insurance
			 Portability and Accountability Act (42 U.S.C. 1320dd–2 note) to broaden the
			 scope of who is considered to be a covered entity to include those entities and
			 individuals that disclose health information to other entities in the course of
			 their commercial activities and not in relation to the provision of healthcare
			 services.</text>
				</paragraph><paragraph id="id7A57764A388B44E88577181245374A5F"><enum>(2)</enum><header>Timing</header><text>The
			 Secretary of Health and Human Services shall—</text>
					<subparagraph id="idAFA3A9FB9900433E9093F324793AEA8A"><enum>(A)</enum><text>not later than 12
			 months after the date of enactment of this Act, promulgate a proposed rule for
			 the modifications described in paragraph (1); and</text>
					</subparagraph><subparagraph id="idBA62F02BE054483ABD4F1D5458FD169A"><enum>(B)</enum><text>not later than 24
			 months after the date of enactment of this Act, promulgate a final rule for the
			 modifications described in paragraph (1).</text>
					</subparagraph></paragraph><paragraph id="id211E9CE5BE5643299F72D6CDDA48C987"><enum>(3)</enum><header>Reinstatement
			 of certain consent provisions</header><text>Notwithstanding any other provision
			 of law, the provisions of section 164–506(b) of title 45, Code of Federal
			 Regulations, as in effect on April 14, 2001 and modified in 2002, relating to
			 the consent to use and disclose certain information for treatment, payment, or
			 health care operations, shall be deemed to be reinstated and implemented
			 accordingly.</text>
				</paragraph></subsection><subsection id="idA681861C835541E5BED53798D86AB849"><enum>(c)</enum><header>Reporting
			 requirements</header><text>The Secretary of Health and Human Services shall
			 develop a procedure for the reporting to the Secretary, by individuals or
			 entities receiving assistance from the Department of Health and Human Services,
			 of any unlawful disclosures of identifiable health information in violation of
			 section 1176 or 1177 of the Social Security Act (42 U.S.C. 12320d–5; 1320d–6)
			 or the regulations promulgated under section 264(c) of the Health Insurance
			 Portability and Accountability Act (42 U.S.C. 1320dd–2 note) by such
			 individuals or entities. In developing such procedure, the Secretary
			 shall—</text>
				<paragraph id="id221820BC241C4818819A81C6A7A98F02"><enum>(1)</enum><text>take into
			 consideration the notification procedures used by other public or private
			 sector entities, including the TRICARE program; and</text>
				</paragraph><paragraph id="id40F331E2E0454AD5BC02196AF2937F47"><enum>(2)</enum><text>provide for the
			 appropriate notification, by individuals or entities receiving assistance from
			 the Department of Health and Human Services, to individuals whose identifiable
			 health information has been disclosed in violation of such section 1176 or 1177
			 or such regulations by such individuals or entities.</text>
				</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id09FEACB5D4094DE88ED481782796A75B"><enum>(d)</enum><header>Investigation
			 of complaints</header><text>With respect to a report of an unlawful disclosure
			 of health information under subsection (c), the Secretary of Health and Human
			 Services shall investigate such disclosure using the complaint process
			 contained in subpart C of part 160 of title 45, Code of Federal Regulations (as
			 in effect on the date of enactment of this Act), except that for purposes of
			 the review process contained in section 160.308 of such subpart, the Secretary
			 shall establish a schedule of routine compliance reviews of covered entities
			 (as such term is used for purposes of such section).</text>
			</subsection></section></legis-body>
</bill>
