<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<congress>112th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>S. 3351</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20120627">June 27, 2012</action-date>
			<action-desc><sponsor name-id="S332">Mr. Franken</sponsor> introduced
			 the following bill; which was read twice and referred to the
			 <committee-name committee-id="SSHR00">Committee on Health, Education, Labor,
			 and Pensions</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To amend the American Recovery and Reinvestment Act with
		  respect to the privacy of protected health information.</official-title>
	</form>
	<legis-body>
		<section id="S1" section-type="section-one"><enum>1.</enum><header>Short
			 title</header><text display-inline="no-display-inline">This Act may be cited as
			 the <quote><short-title>Protect Our Health Privacy
			 Act</short-title></quote>.</text>
		</section><section id="id2428BD9854FD47C0930B193136EEEFAE"><enum>2.</enum><header>Reporting
			 requirements</header>
			<subsection id="id7C738C66CD68484FBA210B64E0401409"><enum>(a)</enum><header>Notification in
			 the case of breach</header><text>Paragraph (2) of section 13402(i) of division
			 A of the American Recovery and Reinvestment Act of 2009 (42 U.S.C. 17932(i)) is
			 amended to read as follows:</text>
				<quoted-block display-inline="no-display-inline" id="id85F2F828A6AE47359C803B0A214F10FD" style="OLC">
					<paragraph id="idAB7ABCEA86374B788B9CAB201292B39B"><enum>(2)</enum><header>Information</header><text>The
				information described in this paragraph regarding breaches specified in
				paragraph (1) shall include—</text>
						<subparagraph id="id57bc7f5d909b472c91616541d7860f38"><enum>(A)</enum><text>the number and
				nature of all such breaches, including a description of the types of unsecured
				protected health information that were involved in each breach;</text>
						</subparagraph><subparagraph id="id3045a320c0f64986b0a237a15b48348c"><enum>(B)</enum><text>the identity of
				the covered entity involved in each breach, or if the breach affected less than
				500 individuals, the kind of covered entity involved (such as a health plan,
				health care clearinghouse, or a health care provider who transmits any health
				information in electronic form in connection with a transaction covered by this
				subtitle); and</text>
						</subparagraph><subparagraph id="idab37f70bceda490fa29116bed3a2ff4f"><enum>(C)</enum><text>actions taken in
				response to such
				breaches.</text>
						</subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="id585B934262D94E7EBEBB97BD030FC92B"><enum>(b)</enum><header>Report on
			 compliance</header><text>Section 13424 of division A of the American Recovery
			 and Reinvestment Act of 2009 (42 U.S.C. 17954) is amended—</text>
				<paragraph id="id3EDCA7ED139D4F1BB9A99E39592D5BED"><enum>(1)</enum><text>in subsection
			 (a)(1)—</text>
					<subparagraph id="idFF58F00BE5064E45BB28E6989D5625FB"><enum>(A)</enum><text>by amending
			 subparagraph (B) to read as follows:</text>
						<quoted-block display-inline="no-display-inline" id="idBD3BF0A6F3A24E3DA9756A1F31E2394D" style="OLC">
							<subparagraph id="idC400C98885AD43D881D67373CB1E6A79"><enum>(B)</enum><text>information about
				such complaints resolved informally, including—</text>
								<clause id="idc13863bc3a1841f4b46e7602f9068c47"><enum>(i)</enum><text>the number of
				such complaints resolved informally;</text>
								</clause><clause id="iddd7f12f12a08447ab9eabc1d6ae90204"><enum>(ii)</enum><text>a summary of the
				types of complaints so resolved, including identification of the most common
				types complaints so resolved, categorized by the privacy and security rule
				allegedly violated;</text>
								</clause><clause id="id54a8405c04c04efcadba300ea2268c64"><enum>(iii)</enum><text>for each such
				category, the average amount of time between receipt of a complaint to
				resolution of such complaint;</text>
								</clause><clause id="ide44559e2ec0d444fb2de816fb3354108"><enum>(iv)</enum><text>examples, with
				entity and patient names and other individually identifiable health information
				redacted, of complaints resolved informally and the Secretary’s rationale for
				resolving such complaints informally; and</text>
								</clause><clause id="id04a9a87a6b5c4337831dc269df29fa74"><enum>(v)</enum><text>the number of
				covered entities that received technical assistance from the Secretary during
				such year in order to achieve compliance with such provisions and the types of
				such technical assistance
				provided.</text>
								</clause></subparagraph><after-quoted-block>;</after-quoted-block></quoted-block>
					</subparagraph><subparagraph id="id734B33C39B91415FBCDC12017FE132B7"><enum>(B)</enum><text>in subparagraph
			 (E), by inserting <quote>and a summary of the outcome of such subpoenas or
			 inquiries</quote> after <quote>inquiries issued</quote>;</text>
					</subparagraph><subparagraph id="idF1DED1B6DAEE457BB40B76D4079F6A75"><enum>(C)</enum><text>in subparagraph
			 (F), by striking <quote>following year; and</quote> and inserting
			 <quote>following year and enforcement priorities for the succeeding
			 year;</quote>;</text>
					</subparagraph><subparagraph id="idEDF3BE26C7154615B5FE35E27D8CCFF5"><enum>(D)</enum><text>in subparagraph
			 (G), by striking the period at the end and inserting a semicolon; and</text>
					</subparagraph><subparagraph id="idEAB9310796A349A7A6053D43132D22D0"><enum>(E)</enum><text>by adding at the
			 end the following:</text>
						<quoted-block display-inline="no-display-inline" id="id182882286DD64808AB8AD4F2DBF617BC" style="OLC">
							<subparagraph id="idD09CEB859E0B44B38799D3BA208B90D8"><enum>(H)</enum><text>the number of
				State attorney general actions that were pursued under this subtitle and notice
				of which was provided to the Secretary pursuant to section 1176(d)(4) of the
				Social Security Act; and</text>
							</subparagraph><subparagraph id="id9B19165B26284DA19DE2E482BF793066"><enum>(I)</enum><text>the number of
				health privacy or health security or data breach complaints referred to the
				Attorney General, including—</text>
								<clause id="id3f195f59e6004bd5bb63bcec6fa9bbf5"><enum>(i)</enum><text>whether the
				Attorney General declined enforcement; and</text>
								</clause><clause id="id6ea62890034341eda7b940bb21621fb5"><enum>(ii)</enum><text>the number of
				complaints referred to the Attorney General but returned to the Secretary for
				enforcement and a summary of enforcement actions taken by the Secretary with
				respect to such complaints, including informal resolutions, civil monetary
				penalties, resolution agreements or settlements, or voluntary compliance
				actions.</text>
								</clause></subparagraph><after-quoted-block>;
				and</after-quoted-block></quoted-block>
					</subparagraph></paragraph><paragraph id="id5187C164250A467F8DEA057F177E6CAE"><enum>(2)</enum><text>by adding at the
			 end the following:</text>
					<quoted-block display-inline="no-display-inline" id="id542A405E32CE499BB2951D43CFF5847C" style="OLC">
						<subsection id="idCA2EE4E4E1774A3BB6ADCFF4B21C4F72"><enum>(g)</enum><header>Annual
				studies</header>
							<paragraph id="idF8AC55D877D649088F414CCBF24EB1C2"><enum>(1)</enum><header>In
				general</header><text>For the first year beginning after the date of enactment
				of the <short-title>Protect Our Health Privacy
				Act</short-title>, and every year thereafter, the Attorney General shall submit
				to the Committee on the Judiciary of the Senate and the Committee on the
				Judiciary of the House of Representatives a report concerning complaints of
				alleged violations described in section 1177 of the Social Security Act,
				including violations of the provisions of this subtitle relating to privacy and
				security of health information, that were referred to the Department of Justice
				by the Department of Health and Human Services, the Federal Bureau of
				Investigation, or another State or Federal agency during the year for which the
				report is being prepared.</text>
							</paragraph><paragraph id="id0EC61E15D2FA4922A9ECAD0F0267B280"><enum>(2)</enum><header>Requirements</header><text>Each
				report required under paragraph (1) shall—</text>
								<subparagraph id="id1403317E43304E928218E9FAECEC7BCC"><enum>(A)</enum><text>be made available
				to the public on the websites of the Department of Justice and the Department
				of Health and Human Services; and</text>
								</subparagraph><subparagraph id="idDDF214CC186F4F4594EA60D7A92B2887"><enum>(B)</enum><text>include, with
				respect to complaints received during the year for which the report is being
				prepared—</text>
									<clause id="id893016bf047b4233905c4dc0e8e2ae93"><enum>(i)</enum><text>the total number
				of complaints received;</text>
									</clause><clause id="id42cdc6347cb745e3bd98032736e83a20"><enum>(ii)</enum><text>the number of
				complaints received that were eligible for criminal enforcement; and</text>
									</clause><clause id="idBC9ADEDE8F52451098832A3AF15152F1"><enum>(iii)</enum><text>of the
				complaints described in clause (ii), a summary of how each complaint was
				resolved that—</text>
										<subclause id="id5265461C125B45959B0C3026AACF7F3B"><enum>(I)</enum><text>includes the
				rationale for declining enforcement, if applicable; and</text>
										</subclause><subclause id="id04BF04562FEB4CDA9B537380C0EE601B"><enum>(II)</enum><text>does not
				identify the patients, individuals, or entities
				involved.</text>
										</subclause></clause></subparagraph></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection></section><section commented="no" id="idF02F3AE803DE4379A895E2178EE6B098"><enum>3.</enum><header>Encryption for
			 portable media</header>
			<subsection commented="no" id="id672D0CB1DE0649B29ACD68FCA0B7B052"><enum>(a)</enum><header>Guidance
			 regarding unsecured protected health information</header>
				<paragraph commented="no" id="id6CF80D34872B4EE8915783F7A2FF32CC"><enum>(1)</enum><header>In
			 general</header><text>Section 13402(h)(2) of division A of the American
			 Recovery and Reinvestment Act of 2009 (42 U.S.C. 17932(h)(2)) is amended by
			 inserting <quote>, including protected health information stored on portable
			 media (as defined by the Secretary, which shall include thumb drives, laptop
			 computers, tablet computers, and other similar devices),</quote> after
			 <quote>protected health information</quote>.</text>
				</paragraph><paragraph commented="no" id="id667412D4BD624D71B22261CC2C48CB10"><enum>(2)</enum><header>Applicable</header><text>The
			 amendment made by paragraph (1) shall apply to updated guidance issued under
			 section 13402(h)(2) of division A of the American Recovery and Reinvestment Act
			 of 2009 (42 U.S.C. 17932(h)(2)) after the date of enactment of this Act.</text>
				</paragraph></subsection><subsection commented="no" id="id8E596CF1EA524AA5B6926233CD00F61E"><enum>(b)</enum><header>Portable media
			 encryption requirement</header>
				<paragraph commented="no" id="idD3D47B0C7CF04EFE979A08F0F0909DB3"><enum>(1)</enum><header>In
			 general</header><text>Section 13401 of division A of the American Recovery and
			 Reinvestment Act of 2009 (42 U.S.C. 17931) is amended by adding at the end the
			 following:</text>
					<quoted-block display-inline="no-display-inline" id="id1FB47FC1C03242A58EFEF777FC7D3CDC" style="OLC">
						<subsection commented="no" id="idD02A916BAA434A44AFA14820E987DCDC"><enum>(d)</enum><header>Portable media
				encryption requirement</header><text>Not later than 1 year after the date of
				enactment of the <short-title>Protect Our Health Privacy
				Act</short-title>, the Secretary shall issue regulations to require covered
				entities and business associates to render protected health information that is
				stored on portable media (as defined by the Secretary, which shall include
				thumb drives, laptop computers, tablet computers, and other similar devices)
				unusable, unreadable, or indecipherable to unauthorized
				individuals.</text>
						</subsection><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph><paragraph commented="no" id="idE7E1A1015F30452AB79AD33FF48B9311"><enum>(2)</enum><header>Conforming
			 amendment</header><text>Section 13401(b) of such Act (42 U.S.C. 17931(b)) is
			 amended by inserting <quote>or (d)</quote> after <quote>subsection
			 (a)</quote>.</text>
				</paragraph></subsection></section><section commented="no" id="idB92EB8F7E241402792B15654652B6D76"><enum>4.</enum><header>Use of data in
			 business associate contracts; application of minimum necessary standard to
			 business associates</header>
			<subsection commented="no" id="id70C8CF6DB3624FDF953AC238B6133A93"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">Section 13404 of
			 division A of the American Recovery and Reinvestment Act (42 U.S.C. 17934) is
			 amended by adding at the end the following:</text>
				<quoted-block display-inline="no-display-inline" id="idE25E311DA5764782844D652C4771A127" style="OLC">
					<subsection commented="no" id="idF815E784F6FC436194150CC0C5552BBA"><enum>(d)</enum><header>Use of data in
				business associate contracts; application of minimum necessary standard to
				business associates</header>
						<paragraph commented="no" id="idD1F372B8E3744869BA9D82413BA0623A"><enum>(1)</enum><header>Limitation on
				scope and use of protected health information</header><text display-inline="yes-display-inline">As required by section 164.504(e) of title
				45, Code of Regulations (as in effect on the date of enactment of this
				subsection), any business associate agreement between a covered entity and a
				business associate shall limit the use of protected health information by such
				business associate—</text>
							<subparagraph commented="no" id="idA940CCCF15DA4EEAA505935D2E3245A3"><enum>(A)</enum><text display-inline="yes-display-inline">to only such information as necessary for
				the performance of the service or function that the covered entity has
				contracted with the business associate to perform on behalf of the covered
				entity; and</text>
							</subparagraph><subparagraph commented="no" id="idC357C42F8733459F9F22DFFE92735D18"><enum>(B)</enum><text display-inline="yes-display-inline">to only those uses that are necessary for
				the performance of the service or function described in subparagraph
				(A).</text>
							</subparagraph></paragraph><paragraph commented="no" id="id7B80A139C1DF463CB35C45675D5E59F4"><enum>(2)</enum><header>Application of
				minimum necessary standard to business associates</header><text>Section
				164.502(b) of title 45, Code of Federal Regulations shall apply to a business
				associate of a covered entity in the same manner that such section applies to
				the covered entity. The additional requirements of this title that relate to
				the minimum necessary standard with respect to the use, disclosure, and request
				of protected health information that are made applicable with respect to
				covered entities shall also be applicable to such a business associate and
				shall be incorporated into the business associate agreement between the
				business associate and the covered
				entity.</text>
						</paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection commented="no" id="id07AB7B100E10400BBEFF51CC6F2CBBA7"><enum>(b)</enum><header>Conforming
			 amendment</header><text>Subsection (c) of such section 13404 (42 U.S.C. 17934)
			 is amended by striking <quote>(a) or (b)</quote> and inserting <quote>(a), (b),
			 or (d)(2)</quote>.</text>
			</subsection><subsection commented="no" id="id6409BBD981444E78BBECBD24ADB03716"><enum>(c)</enum><header>Clarification</header><text>Nothing
			 in subsection (d)(2) of section 13404 of division A of the American Recovery
			 and Reinvestment Act (42 U.S.C. 17934) (as amended by subsection (a)) affects
			 the application of the minimum necessary standard to business associates
			 pursuant to section 164.504(e) of title 45, Code of Federal Regulations
			 (relating to contracts and other arrangements between business associates and
			 covered entities) as in effect on the date of enactment of this Act.</text>
			</subsection></section><section commented="no" id="id878FD054A8D94EC1BB1AFB3BC5C94787"><enum>5.</enum><header>Health
			 information technology improvement initiative</header><text display-inline="no-display-inline">Title XXX of the Public Health Service Act
			 (42 U.S.C. 300jj et seq.) is amended by adding at the end the following:</text>
			<quoted-block display-inline="no-display-inline" id="id67E5549F63434138AAF8F3F268298B2C" style="OLC">
				<section commented="no" id="idBDA906B1267E436CA89572E2A813D187"><enum>3022.</enum><header>Health
				information technology improvement initiative</header>
					<subsection commented="no" id="id688B0EB023A84CFEBE2C38A2606B5B59"><enum>(a)</enum><header>In
				general</header><text>Not later than 18 months after the date of enactment of
				the <short-title>Protect Our Health Privacy
				Act</short-title>, the Secretary shall issue regulations to improve the safety,
				interoperability, and utility of health information technology systems.</text>
					</subsection><subsection commented="no" id="id01D9556CFF404864B7842A23101E75CE"><enum>(b)</enum><header>Content</header><text>The
				regulations issued under subsection (a) shall include—</text>
						<paragraph id="id4e3ab84a5da14175a8cc0a6d7a05c7cb"><enum>(1)</enum><text>a system to track
				the effect of health information technology on the health of patients;
				and</text>
						</paragraph><paragraph id="id0730945bf7ba447eb7a84d218939c6d0"><enum>(2)</enum><text>minimum quality
				and risk management requirements for health information technology
				vendors.</text>
						</paragraph></subsection><subsection id="idED75E4BC02E944CCA1C20B7B1E31E56D"><enum>(c)</enum><header>Health
				information technology adverse health event reporting</header>
						<paragraph id="id707BAB48646C4B59865C78191A5038E3"><enum>(1)</enum><header>In
				general</header><text>The Secretary shall designate an agency within the
				Department of Health and Human Services to promulgate regulations relating to a
				health information technology adverse health event reporting program and
				database. The Department shall consider definitions and standards developed by
				the National Quality Forum before promulgating such regulations.</text>
						</paragraph><paragraph id="id4FE896130441444DA3866EE718808BE3"><enum>(2)</enum><header>Content</header><text>The
				regulations promulgated under paragraph (1) shall include mandatory submission
				of adverse health event reports by health information technology vendors and
				voluntary submission of adverse health event reports by users of health
				information, including patients and their family caregivers.</text>
						</paragraph><paragraph id="id1301ACD5DFEE4E3489F374176D43C1D8"><enum>(3)</enum><header>Use of
				reports</header><text>The agency designated under paragraph (1) shall analyze
				adverse health event reports and report findings and recommendations to the
				applicable industry and policymakers.</text>
						</paragraph><paragraph id="idB0EA7138281B4EA1B5FCF6691CBDCE76"><enum>(4)</enum><header>Protection of
				reports</header><text>The agency designated under paragraph (1) shall remove
				identifying information if adverse health event reports are made public. An
				adverse health event report may not be admitted or used in any action in a
				Federal or State court or any Federal or State administrative proceeding as
				evidence of fault, liability, or occurrence of an adverse health event.</text>
						</paragraph><paragraph id="id66B6876D045743E99A533B306C1CF3DA"><enum>(5)</enum><header>Annual
				report</header><text>The agency designated under paragraph (1) shall use the
				database established under such paragraph to submit to Congress an annual
				report regarding the use and safety of health information
				technology.</text>
						</paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
		</section></legis-body>
</bill>
