<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="HA894367F8E6642D6A8E2F6DB40EEB7B6" public-private="public">
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>110 HR 516 IH: Federal Agency Data Privacy Protection
</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2007-01-17</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
	<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>110th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>H. R. 516</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20070117">January 17, 2007</action-date>
			<action-desc><sponsor name-id="D000597">Mrs. Jo Ann Davis of
			 Virginia</sponsor> introduced the following bill; which was referred to the
			 <committee-name committee-id="HGO00">Committee on Oversight and Government
			 Reform</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To increase the security of sensitive data maintained by
		  the Federal Government.</official-title>
	</form>
	<legis-body id="H83BF8D5EC7F74AF7B4C834EFD08B2EBA" style="OLC">
		<section commented="no" display-inline="no-display-inline" id="HBAD32DD45EF14E5C929E8577DF8D3977" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Federal Agency Data Privacy Protection
			 Act</short-title></quote>.</text>
		</section><section id="H370D609C6B994882B292252F084604D5"><enum>2.</enum><header>Definition of
			 sensitive data</header><text display-inline="no-display-inline">In this
			 Act:</text>
			<paragraph id="H6E1FE2E168EF4B92B908B0E822A4E560"><enum>(1)</enum><header>Sensitive
			 data</header><text>The term <quote>sensitive data</quote> includes the
			 following:</text>
				<subparagraph id="H843A3D1BB9D34811B09F63BEF7E14BA"><enum>(A)</enum><text>Social security
			 numbers.</text>
				</subparagraph><subparagraph id="H225161A443E94CBDADA8F08371CD00BB"><enum>(B)</enum><text>Financial
			 records.</text>
				</subparagraph><subparagraph id="H7E402B126EDD4C00B01DD85700C74C8B"><enum>(C)</enum><text>Previous or
			 current health records, including hospital or treatment records of any kind,
			 including drug and alcohol rehabilitation records.</text>
				</subparagraph><subparagraph id="H6A12AD3F87A7417099615719EFC5E2C"><enum>(D)</enum><text>Criminal
			 records.</text>
				</subparagraph><subparagraph id="HBAA034C5861242E69562D1105F97AC3E"><enum>(E)</enum><text>Licenses.</text>
				</subparagraph><subparagraph id="H9064EE807A6046CCB9ADB4FB49F95BF1"><enum>(F)</enum><text>License denials,
			 suspensions, or revocations.</text>
				</subparagraph><subparagraph id="HA65157B3698A4EF9A451EF75EBB94560"><enum>(G)</enum><text>Tax
			 returns.</text>
				</subparagraph><subparagraph id="H8FDEE3DC6AA04C8D9728F5682C8EDFEF"><enum>(H)</enum><text>Information that
			 has been specifically authorized under criteria established by an Executive
			 order or an Act of Congress to be kept classified in the interest of national
			 defense or foreign policy.</text>
				</subparagraph><subparagraph id="HDD5BD764E5574EC891BF239B8231F28D"><enum>(I)</enum><text>Personally
			 identifiable information.</text>
				</subparagraph></paragraph><paragraph id="H6E6ADB57B0154F22B5AB4E3C17D786E1"><enum>(2)</enum><header>Personally
			 identifiable information</header><text>The term <quote>personally identifiable
			 information</quote> means any information, in any form or medium, that relates
			 to the past, present, or future physical or mental health, predisposition, or
			 condition of an individual or the provision of health care to an
			 individual.</text>
			</paragraph><paragraph id="HF3E3B7541CB54C4F83BD7625A11F97E7"><enum>(3)</enum><header>Federal computer
			 system</header><text>The term <quote>Federal computer system</quote> has the
			 meaning given such term in section 20(d) of the National Institute of Standards
			 and Technology Act (<external-xref legal-doc="usc" parsable-cite="usc/15/278g-3">15 U.S.C. 278g–3(d)</external-xref>).</text>
			</paragraph><paragraph id="H44A19B32A1AE4CB981F279ABCB8B27F7"><enum>(4)</enum><header>Agency</header><text>The
			 term <quote>agency</quote> has the meaning provided in section 3502(1) of title
			 44, United States Code.</text>
			</paragraph><paragraph id="H968C56FEBFF644DB827BAB1C93EB52B5"><enum>(5)</enum><header>Record</header><text>The
			 term <quote>record</quote> has the meaning provided in section 552a(a) of title
			 5, United States Code.</text>
			</paragraph></section><section id="HB33A7670C46D48D6AC4451078EC3B80"><enum>3.</enum><header>Requirement for
			 use of encryption for sensitive data</header>
			<subsection id="H157C4F11A0784D6F86DBBA75B9376BEB"><enum>(a)</enum><header>Requirement for
			 encryption</header>
				<paragraph id="H7E2EE0441F7D463C8B1CCC34A74CA4F7"><enum>(1)</enum><header>In
			 general</header><text display-inline="yes-display-inline">All sensitive data
			 maintained by the Federal Government, including such data maintained in Federal
			 computer systems, shall be secured by the use of the most secure encryption
			 standard recognized by the National Institute of Standards and
			 Technology.</text>
				</paragraph><paragraph id="HAC9ED1769B804759A45642D778D8CBA0"><enum>(2)</enum><header>Updating
			 required every 6 months</header><text>Any sequence of characters (known as an
			 encryption key) used to secure an encryption standard used on Federal computer
			 systems shall be changed every 6 months, at a minimum, to provide additional
			 security.</text>
				</paragraph><paragraph id="HFC6A6DD4216E47E9B1AB24795730A2F9"><enum>(3)</enum><header>Implementation</header><text>The
			 requirements of this subsection shall be implemented not later than 6 months
			 after the date of the enactment of this Act.</text>
				</paragraph></subsection><subsection id="HCB9B08D902824864BC007C32D03310DC"><enum>(b)</enum><header>Federal agency
			 responsibilities</header><text>The head of each agency shall be responsible for
			 complying with the requirements of subsection (a) within the agency. Such
			 requirement shall be considered to be a requirement of subchapter III of
			 <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, for purposes of section
			 3544(a)(1)(B) of such title.</text>
			</subsection></section><section id="HBD42F6508AD5487E984EB9BFCBA4807C"><enum>4.</enum><header>Requirements
			 relating to access by agency personnel to sensitive data</header>
			<subsection id="H8B74FF7595D84B36A49D69AB3E956B6F"><enum>(a)</enum><header>On-site
			 access</header><text>No employee of the Federal government may have access to
			 sensitive data on Government property unless the employee has received a
			 security clearance at the <quote>secret</quote> level or higher and has
			 completed a financial disclosure form, in accordance with applicable provisions
			 of law and regulation.</text>
			</subsection><subsection id="H9EB957C4D1224843B3AC220082907226"><enum>(b)</enum><header>Off-site
			 access</header>
				<paragraph id="HCFCEAA564C454B4393212339DEB711BA"><enum>(1)</enum><header>Prohibition</header><text>Sensitive
			 data maintained by an agency may not be transported or accessed from a location
			 off Government property unless a request for such transportation or access is
			 submitted and approved by the Inspector General of the agency in accordance
			 with paragraph (2).</text>
				</paragraph><paragraph id="H5C29F2EC6C9440E4956FC063FC0006AB"><enum>(2)</enum><header>Procedures</header>
					<subparagraph id="HB568657C24C945308CCE1BED1F5C3B88"><enum>(A)</enum><header>Deadline for
			 approval or disapproval</header><text>In the case of any request submitted
			 under paragraph (1) to an Inspector General of an agency, the Inspector General
			 shall approve or disapprove the request within 2 business days after the date
			 of submission of the request.</text>
					</subparagraph><subparagraph id="H22776AEF9A474CF28DDA54FFCCAAC191"><enum>(B)</enum><header>Limitation to
			 10,000 records</header><text>If a request is approved, the Inspector General
			 shall limit the access to not more than 10,000 records at a time.</text>
					</subparagraph></paragraph><paragraph id="H2625130ACB2D457A991EC1175B89BF56"><enum>(3)</enum><header>Encryption</header><text display-inline="yes-display-inline">Any technology used to store, transport, or
			 access sensitive data during for purposes of off-site access approved under
			 this subsection shall be secured by the use of the most secure encryption
			 standard recognized by the National Institute of Standards and
			 Technology.</text>
				</paragraph></subsection><subsection id="HA62F7F3E386F4B03B44FB213DF32E35B"><enum>(c)</enum><header>Implementation</header><text>The
			 requirements of this subsection shall be implemented not later than 6 months
			 after the date of the enactment of this Act.</text>
			</subsection></section><section id="H9DDF892E01B84FCAA9F480A5EBAF5455"><enum>5.</enum><header>Requirements
			 relating to government contractors involving sensitive data</header>
			<subsection id="HCDA20C8D08F44466922C731D87A3F4E5"><enum>(a)</enum><header>Applicability to
			 government contractors</header><text>In entering into any contract that may
			 involve sensitive data in electronic or digital form on 10,000 or more United
			 States citizens, an agency shall require the contractor and employees of the
			 contractor to comply with the requirements of sections 3 and 4 of this Act in
			 the performance of the contract, in the same manner as agencies and government
			 employees comply with such requirements.</text>
			</subsection><subsection id="H2166E29F917B467800B5A363DC51346"><enum>(b)</enum><header>Implementation</header><text>The
			 requirements of this subsection shall be implemented with respect to contracts
			 entered into on or after the date occurring 6 months after the date of the
			 enactment of this Act.</text>
			</subsection></section></legis-body>
</bill>


