<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" dms-version="" public-private="public">

	<form>

		<distribution-code display="yes">II</distribution-code>

		<congress>109th CONGRESS</congress>

		<session>1st Session</session>

		<legis-num>S. 810</legis-num>

		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>

		<action stage="Pre-Introduction">

			<action-date date="20050414">April 14, 2005</action-date>

			<action-desc><sponsor name-id="S278">Mrs. Clinton</sponsor> introduced

			 the following bill; which was read twice and referred to the

			 <committee-name committee-id="SSJU00">Committee on the

			 Judiciary</committee-name></action-desc>

		</action>

		<legis-type>A BILL</legis-type>

		<official-title>To regulate the transmission of personally identifiable

		  information to foreign affiliates and subcontractors</official-title>

	</form>

	<legis-body>

		<section id="S1" section-type="section-one"><enum>1.</enum><header>Short

			 title</header><text display-inline="no-display-inline">This Act may be cited as

			 the <quote><short-title>Safeguarding Americans From

			 Exporting Identification Data Act</short-title></quote> or the

			 <quote><short-title>SAFE-ID

			 Act</short-title></quote>.</text>

		</section><section id="IDC137398A6B564282A7C3EC53876901F2"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">As used in this Act:</text>

			<paragraph id="id5C484CE18CAC456B861F7A3BA8F0A5E6"><enum>(1)</enum><header>Business

			 enterprise</header><text>The term <term>business enterprise</term>

			 means—</text>

				<subparagraph id="id2A0A9E06214744A5AF2B5B0ECEC7EF2D"><enum>(A)</enum><text>any organization,

			 association, or venture established to make a profit;</text>

				</subparagraph><subparagraph id="idF66EBF994887490D9604A1CFD0719BCC"><enum>(B)</enum><text>any health care

			 business;</text>

				</subparagraph><subparagraph id="idB2B7B3C29B2E471B8402DD8852CF0FCE"><enum>(C)</enum><text>any private,

			 nonprofit organization; or</text>

				</subparagraph><subparagraph id="id2235F036356A4E618E574752A1C639F1"><enum>(D)</enum><text>any contractor,

			 subcontractor, or potential subcontractor of an entity described in

			 subparagraph (A), (B), or (C).</text>

				</subparagraph></paragraph><paragraph id="idD732E63080F448CEAB02897EA06F2ECF"><enum>(2)</enum><header>Health care

			 business</header><text>The term <term>health care business</term> means any

			 business enterprise or private, nonprofit organization that collects or retains

			 personally identifiable information about consumers in relation to medical

			 care, including—</text>

				<subparagraph id="idA08F4013EE904B219960B1A8D0C253D3"><enum>(A)</enum><text>hospitals;</text>

				</subparagraph><subparagraph id="id22285AF8DF354EFB92E4B4F3C8B5BF94"><enum>(B)</enum><text>health

			 maintenance organizations;</text>

				</subparagraph><subparagraph id="id925F429DFDC941D696BC39A1D20967BB"><enum>(C)</enum><text>medical

			 partnerships;</text>

				</subparagraph><subparagraph id="id287ECB92CF2D438186BDCF5B1614D0C3"><enum>(D)</enum><text>emergency medical

			 transportation companies;</text>

				</subparagraph><subparagraph id="id8EBC73679D30452DA3782F16C69D5E92"><enum>(E)</enum><text>medical

			 transcription companies;</text>

				</subparagraph><subparagraph id="id1D9E9A09AD3A438280C21EA73263B069"><enum>(F)</enum><text>banks that

			 collect or process medical billing information; and</text>

				</subparagraph><subparagraph id="id10A88906743546E1A0A01CF5F769806E"><enum>(G)</enum><text>subcontractors,

			 or potential subcontractors, of the entities described in subparagraphs (A)

			 through (F).</text>

				</subparagraph></paragraph><paragraph id="id3965587E222F4E96ACEF671FECAEEBAE"><enum>(3)</enum><header>Personally

			 identifiable information</header><text>The term <term>personally identifiable

			 information</term> includes information such as—</text>

				<subparagraph id="idD40DF90DD2274323852A1A86AF277240"><enum>(A)</enum><text>name;</text>

				</subparagraph><subparagraph id="id98C4520070254953A54274261F81AF88"><enum>(B)</enum><text>postal

			 address;</text>

				</subparagraph><subparagraph id="idB5D3664F8CC8460D9C9EDE7EE0A0DB3E"><enum>(C)</enum><text>financial

			 information;</text>

				</subparagraph><subparagraph id="idD6F965E25FE9439B83A9131BEDC9FFC4"><enum>(D)</enum><text>medical

			 records;</text>

				</subparagraph><subparagraph id="id978424997A3E4747A81556561BB935D2"><enum>(E)</enum><text>date of

			 birth;</text>

				</subparagraph><subparagraph id="id65E8A220D5794E4E837FC2AFC7CBA338"><enum>(F)</enum><text>phone

			 number;</text>

				</subparagraph><subparagraph id="id2505E7C068174BE2B4F21F7D6C1ECB6A"><enum>(G)</enum><text>e-mail

			 address;</text>

				</subparagraph><subparagraph id="id5039FF0804D84D18AD4495713C2BCF88"><enum>(H)</enum><text>social security

			 number;</text>

				</subparagraph><subparagraph id="idF98CD307570C454CA7B559A96FBC4F86"><enum>(I)</enum><text>mother's maiden

			 name;</text>

				</subparagraph><subparagraph id="idF6FA62BF0C10451BA73150592766FA18"><enum>(J)</enum><text>password;</text>

				</subparagraph><subparagraph id="id349879C8F0F14B039B7303340C0B72F5"><enum>(K)</enum><text>state

			 identification information; and</text>

				</subparagraph><subparagraph changed="not-changed" commented="no" id="id324BA8BA521E49D3B9D2A3E5BE817337"><enum>(L)</enum><text>driver's license

			 number.</text>

				</subparagraph></paragraph></section><section id="idA5E1A9A5C9304052AE8DC8280972C5AA"><enum>3.</enum><header>Transmission of

			 information</header>

			<subsection id="id61F0FD680D73437E83A18F0013CCA967"><enum>(a)</enum><header>Prohibition</header><text>A

			 business enterprise may not disclose personally identifiable information

			 regarding a resident of the United States to any foreign branch, affiliate,

			 subcontractor, or unaffiliated third party located in a foreign country

			 unless—</text>

				<paragraph id="id9038A9C20F074A38AF5DAF467769D2EA"><enum>(1)</enum><text>the business

			 enterprise provides the notice of privacy protections described in sections 502

			 and 503 of the Gramm-Leach-Bliley Act (15 U.S.C. 6802 and 6803) or required by

			 the regulations promulgated pursuant to section 264(c) of the Health Insurance

			 Portability and Accountability Act of 1996 (42 U.S.C. 1320d–2 note), as

			 appropriate;</text>

				</paragraph><paragraph id="idC10D0AF9DC444D0EAF7F238060DDC0D4"><enum>(2)</enum><text>the business

			 enterprise complies with the safeguards described in section 501(b) of the

			 Gramm-Leach-Bliley Act (15 U.S.C. 6801(b)), as appropriate;</text>

				</paragraph><paragraph id="id9DCC7968C4FC4953B7134827480AFF9F"><enum>(3)</enum><text>the consumer is

			 given the opportunity, before the time that such information is initially

			 disclosed, to object to the disclosure of such information to such foreign

			 branch, affiliate, subcontractor, or unaffiliated third party; and</text>

				</paragraph><paragraph id="idB57829924A2A46C0ABA8052549D48ECD"><enum>(4)</enum><text>the consumer is

			 given an explanation of how the consumer can exercise the nondisclosure option

			 described in paragraph (3).</text>

				</paragraph></subsection><subsection changed="not-changed" commented="no" id="id03C2549D9E584C02960DE58D827F147B"><enum>(b)</enum><header>Health care

			 businesses</header><text display-inline="yes-display-inline">A health care

			 business may not terminate an existing relationship with a consumer of health

			 care services to avoid the consumer from objecting to the disclosure under

			 subsection (a)(3).</text>

			</subsection><subsection changed="not-changed" commented="no" id="id98BC19C2C53F49928208A52411350445"><enum>(c)</enum><header>Effect on

			 business relationship</header>

				<paragraph changed="not-changed" commented="no" id="id0A9502CCA5B74828BA6F17161814C31F"><enum>(1)</enum><header>Nondiscrimination</header><text>A

			 business enterprise may not discriminate against or deny an otherwise qualified

			 consumer a financial product or a health care service because the consumer has

			 objected to the disclosure under subsection (a)(3).</text>

				</paragraph><paragraph changed="not-changed" commented="no" id="idDC9E811273B14EFAB1488F9D3B4C8EED"><enum>(2)</enum><header>Products and

			 services</header><text>A business enterprise shall not be required to offer or

			 provide a product or service through affiliated entities or jointly with

			 nonaffiliated business enterprises.</text>

				</paragraph><paragraph changed="not-changed" commented="no" id="idDA9D28EC72C245598D54F841D4C9B946"><enum>(3)</enum><header>Incentives and

			 discounts</header><text>Nothing in this subsection is intended to prohibit a

			 business enterprise from offering incentives or discounts to elicit a specific

			 response to the notice required under subsection (a).</text>

				</paragraph></subsection><subsection id="IDD0A96548FA2E4F1ABA6FBED2C43E7E05"><enum>(d)</enum><header>Liability</header>

				<paragraph id="idFB71BE1D3FE440B7A2F2D6F138C66925"><enum>(1)</enum><header>In

			 general</header><text>A business enterprise that knowingly and directly

			 transfers personally identifiable information to a foreign branch, affiliate,

			 subcontractor, or unaffiliated third party shall be liable to any person

			 suffering damages resulting from the improper storage, duplication, sharing, or

			 other misuse of such information by the transferee.</text>

				</paragraph><paragraph changed="not-changed" commented="no" id="id9B492AC1E8C84D24893103133486DE15"><enum>(2)</enum><header>Civil

			 action</header><text>An injured party under paragraph (1) may sue in law or in

			 equity in any court of competent jurisdiction to recover the damages sustained

			 as a result of a violation of this section.</text>

				</paragraph></subsection><subsection id="id4318DC836EE74BAF8032EDA23CD67672"><enum>(e)</enum><header>Rulemaking</header><text>The

			 Chairman of the Federal Trade Commission shall promulgate regulations through

			 which the Chairman may enforce the provisions of this section and impose a

			 civil penalty for a violation of this section.</text>

			</subsection></section><section id="ID368E9B835936495E89EEA43D5CD4A3BF"><enum>4.</enum><header>Privacy for

			 consumers of health services</header><text display-inline="no-display-inline">The Secretary of Health and Human Services

			 shall revise the regulations promulgated pursuant to

			 <external-xref legal-doc="act" parsable-cite="HIPAA/264(c)">section

			 264(c)</external-xref> of the <act-name parsable-cite="HIPAA">Health Insurance

			 Portability and Accountability Act of 1996</act-name> (<external-xref legal-doc="usc" parsable-cite="usc/42/1320d-2 note">42 U.S.C. 1320d–2 note</external-xref>) to

			 require a covered entity (as defined by such regulations) that outsources

			 protected health information (as defined by such regulations) outside the

			 United States to include in such entity’s notice of privacy protections—</text>

			<paragraph id="IDB78C979F1CF04687B41F02773BF0D753"><enum>(1)</enum><text>notification that

			 the covered entity outsources protected health information to business

			 associates (as defined by such regulations) for processing outside the United

			 States;</text>

			</paragraph><paragraph id="IDB747E5556DC24F2DB8F4840ABCA9F3D8"><enum>(2)</enum><text>a description of

			 the privacy laws of the country to which the protected health information will

			 be sent;</text>

			</paragraph><paragraph id="id824FB348DE0F4021926F76FB53BFC3EE"><enum>(3)</enum><text>any additional

			 risks and consequences to the privacy and security of protected health

			 information that arise as a result of the processing of such information in a

			 foreign country;</text>

			</paragraph><paragraph id="ID6FA03E6E5A0F4381A2D4FA611E090E3D"><enum>(4)</enum><text>additional

			 measures the covered entity is taking to protect the protected health

			 information outsourced for processing outside the United States;</text>

			</paragraph><paragraph id="idA1329B1391404BD8BE01F44E82B4A749"><enum>(5)</enum><text>notification that

			 the protected health information will not be outsourced outside the United

			 States if the consumer objects; and</text>

			</paragraph><paragraph id="ID4B4A62F9AF9546D7BBDCC8E6759B4E74"><enum>(6)</enum><text>a certification

			 that—</text>

				<subparagraph id="IDB6C8F0C6F0B142689204AD8F9502B160"><enum>(A)</enum><text>the covered

			 entity has taken reasonable steps to identify the locations where protected

			 health information is outsourced by such business associates;</text>

				</subparagraph><subparagraph id="ID1D7A6DEA88AB40E4977F88C43BC5707D"><enum>(B)</enum><text>attests to the

			 privacy and security of the protected health information outsourced for

			 processing outside the United States; and</text>

				</subparagraph><subparagraph id="ID1CAF108A612F4EE899DACA5C7B572C71"><enum>(C)</enum><text>states the

			 reasons for the determination by the covered entity that the privacy and

			 security of such information is maintained.</text>

				</subparagraph></paragraph></section><section id="ID6D6A3EEBB8CE4F49901F5B741B9F382E"><enum>5.</enum><header>Privacy for

			 consumers of financial services</header><text display-inline="no-display-inline">Section 503(b) of the Gramm-Leach-Bliley Act

			 (<external-xref legal-doc="usc" parsable-cite="usc/15/6803(b)">15 U.S.C.

			 6803(b)</external-xref>) is amended—</text>

			<paragraph id="IDB6EDE89C05004B239CC7A5090181D890"><enum>(1)</enum><text>in paragraph (3),

			 by striking <quote>and</quote> after the semicolon;</text>

			</paragraph><paragraph id="ID48EB775DCE3F464E94B193AD22FB5DA7"><enum>(2)</enum><text>in paragraph (4),

			 by striking the period at the end and inserting <quote>; and</quote>;

			 and</text>

			</paragraph><paragraph id="ID4926528ED33C4099BBB164E6074A3C91"><enum>(3)</enum><text>by adding at the

			 end the following:</text>

				<quoted-block display-inline="no-display-inline" id="IDB3AFB0C64BB440738A2E4983A7437E78" style="OLC">

					<paragraph id="IDE50D0ED805364E6483294D2819749C33"><enum>(5)</enum><text>if the financial

				institution outsources nonpublic personal information outside the United

				States—</text>

						<subparagraph id="IDE5C5819149C04298871E874423605B07"><enum>(A)</enum><text>information

				informing the consumer in simple language—</text>

							<clause id="ID34CFADA3846444B89A74C044EAE40D7B"><enum>(i)</enum><text>that the

				financial institution outsources nonpublic personal information to entities for

				processing outside the United States;</text>

							</clause><clause id="id02962266F5E7413D9EF6BD4640AC429D"><enum>(ii)</enum><text>of the privacy

				laws of the country to which nonpublic personal information will be

				sent;</text>

							</clause><clause id="ID188567060D194221A8B49B885B8A38B4"><enum>(iii)</enum><text>of any

				additional risks and consequences to the privacy and security of an

				individual’s nonpublic personal information that arise as a result of the

				processing of such information in a foreign country; and</text>

							</clause><clause id="ID80A4503BF4824733A8AAE9B85852CBCA"><enum>(iv)</enum><text>of the

				additional measures the financial institution is taking to protect the

				nonpublic personal information outsourced for processing outside the United

				States; and</text>

							</clause></subparagraph><subparagraph id="IDAE068219A7674971831C419BDD4DB000"><enum>(B)</enum><text>a certification

				that—</text>

							<clause id="ID5958F3CED8884E599E3F597151B63CA9"><enum>(i)</enum><text>the financial

				institution has taken reasonable steps to identify the locations where

				nonpublic personal information is outsourced by such entities;</text>

							</clause><clause id="IDE6FED6CE51BB4474A51EE0005EBCA280"><enum>(ii)</enum><text>attests to the

				privacy and security of the nonpublic personal information outsourced for

				processing outside the United States; and</text>

							</clause><clause changed="not-changed" commented="no" id="ID1246BE5C04934D709B6D8D9DE0F00B0D"><enum>(iii)</enum><text>states the

				reasons for the determination by the institution that the privacy and security

				of such information is

				maintained.</text>

							</clause></subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>

			</paragraph></section><section changed="not-changed" commented="no" id="id91E2F6B577BF48C199366DF714A4DF7B"><enum>6.</enum><header>Effective

			 date</header><text display-inline="no-display-inline">This Act shall take

			 effect on the expiration of the date which is 90 days after the date of

			 enactment of this Act.</text>

		</section></legis-body>

</bill>

