<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-type="olc" bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-BAI21081-R17-WX-8M0"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>116 S199 IS: Secure Data and Privacy for Contact Tracing Act of 2021</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-02-03</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>1st Session</session><legis-num>S. 199</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20210203">February 3, 2021</action-date><action-desc><sponsor name-id="S353">Mr. Schatz</sponsor> (for himself and <cosponsor name-id="S354">Ms. Baldwin</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSHR00">Committee on Health, Education, Labor, and Pensions</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To authorize the Director of the Centers for Disease Control and Prevention to award grants to eligible State, Tribal, and territorial public health agencies to develop and administer a program for digital contact tracing for COVID–19, and for other purposes.</official-title></form><legis-body style="OLC" display-enacting-clause="yes-display-enacting-clause" id="H77A8D506EAE04FE39086FE15EE395BF9"><section section-type="section-one" id="HC17E552A881A46D2A594D6055DD3B16D"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Secure Data and Privacy for Contact Tracing Act of 2021</short-title></quote>.</text></section><section id="H68005E647755431D8700AA9C23235766"><enum>2.</enum><header>Grant program for digital contact tracing for COVID–19</header><subsection id="H5119F09DD46E42E990788A37FCA80B63"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">The Director of the Centers for Disease Control and Prevention shall award grants to eligible State, Tribal, and territorial public health agencies to—</text><paragraph id="H424B459A92A9457BBFEC2A46B3D02F3F"><enum>(1)</enum><text display-inline="yes-display-inline">establish a contact-tracing program that implements traditional contact-tracing protocols with the assistance of digital contact-tracing technology to track and prevent the spread of COVID–19;</text></paragraph><paragraph id="H49436835E5E2405587425EB1AC98646E"><enum>(2)</enum><text display-inline="yes-display-inline">incorporate digital contact-tracing technology into a contact-tracing program that implements traditional contact-tracing protocols to track and prevent the spread of COVID–19; and</text></paragraph><paragraph id="id039caa16df954647b873c07def265a92"><enum>(3)</enum><text>expand or maintain an existing program as described in subparagraph (1).</text></paragraph></subsection><subsection id="id2e9f672fcae14e3382f543373e66561b"><enum>(b)</enum><header>Use of funds</header><paragraph id="id4D1BA0A76C6F41E39A29F1470FE3794C"><enum>(1)</enum><header>In general</header><text>Funds received through a grant under this section, may be used for—</text><subparagraph id="id224927E715FD46958CC5496770BAE32A"><enum>(A)</enum><text>the development, maintenance, or staffing of digital contact-tracing programs;</text></subparagraph><subparagraph id="idB44F7FC504DC4EE09936D2AA55445039"><enum>(B)</enum><text>associated outreach and marketing; or</text></subparagraph><subparagraph id="id96F97CBFEE244822986935C1009F5C54"><enum>(C)</enum><text>other activities identified by a State, Tribal, or territorial public health agency as advancing the effectiveness and reach of digital contact-tracing technologies.</text></subparagraph></paragraph><paragraph id="id1e7726f9193d417f8f002cd7c02f585d"><enum>(2)</enum><header>Education and outreach</header><text>Of the funds received by a State, Tribal, or territorial public health agency through a grant under this section, the agency may use not more than 10 percent of such funds to integrate education and outreach related to vaccines for COVID–19 into digital contact-tracing programs. </text></paragraph></subsection><subsection id="H316406C006784458AE46C2FA83D14770"><enum>(c)</enum><header>Funding disqualification</header><text display-inline="yes-display-inline">If a State, Tribal, or territorial public health agency develops or procures any digital contact-tracing technology with respect to COVID–19 that does not meet each of the requirements listed in subsection (d), such State, Tribal, or territorial public health agency shall be ineligible to receive or continue to receive—</text><paragraph id="H1D70A9FD81AA4B1290B94FB72E71F5A8"><enum>(1)</enum><text>any funds through a grant under this section; and</text></paragraph><paragraph id="H4EE67BCCD3494CBBB63910EC2763F08F"><enum>(2)</enum><text>any other Federal funds, including under the CARES Act (<external-xref legal-doc="public-law" parsable-cite="pl/116/136">Public Law 116–136</external-xref>), for any digital contact-tracing technology with respect to COVID–19.</text></paragraph></subsection><subsection id="H7A0CF7C14EE6430A8D39E08F95A6527A"><enum>(d)</enum><header>Digital contact-Tracing requirements</header><text display-inline="yes-display-inline">A State, Tribal, or territorial public health agency may use a grant under this section for digital contact-tracing technology, as described in subsections (a) and (b), only if the technology meets each of the following requirements:</text><paragraph id="HCF2264882EE64BF28933101540A25D70"><enum>(1)</enum><text>The technology shall be voluntary for the user and provide to the user complete and clear information on the intended use and processing of data collected by the technology. To be voluntary for the user, the technology shall meet requirements including each of the following:</text><subparagraph id="H641DF8C2A1864F96B8635BFFDD844802"><enum>(A)</enum><text>Use of the technology and of contact-tracing data collected using the technology shall be predicated on the user’s affirmative consent.</text></subparagraph><subparagraph id="HF3A0ABC4C5A747569715D00A4CCF5BC6"><enum>(B)</enum><text>Use of the technology shall not be a condition for the reception of government benefits.</text></subparagraph><subparagraph id="H2F38FE612F2A45E0961D8835F089805F"><enum>(C)</enum><text>Use of the technology shall not be made a condition of employment or employment status.</text></subparagraph></paragraph><paragraph id="HB55D873C8BAB43F992C1D4E93E7580AB"><enum>(2)</enum><text>The technology shall limit the collection of data by the technology to only the data that is necessary to meet contact-tracing objectives, including—</text><subparagraph id="HA026B5872CC740708017E02958DD9C27"><enum>(A)</enum><text>the status of any person as an infected or potentially infected person; and</text></subparagraph><subparagraph id="H10C80FEA78184E9C9260D044392C062D"><enum>(B)</enum><text>the proximity of a person to someone who is symptomatic or has tested positive.</text></subparagraph></paragraph><paragraph id="HA62A60F9411A4C87A865BBA070485535"><enum>(3)</enum><text>The technology—</text><subparagraph id="HD63DAD02109249F6A9B5519505762637"><enum>(A)</enum><text display-inline="yes-display-inline">shall delete or de-identify any contact-tracing data that is individually identifiable information not later than the date that is 30 days after the end of the COVID–19 emergency declaration; and</text></subparagraph><subparagraph id="H692C5F7EDA28451390CD2C05D8B6CCD1"><enum>(B)</enum><text>shall include notifications to prompt users to disable or completely remove any digital contact-tracing technology where practical.</text></subparagraph></paragraph><paragraph id="HDAA0375093A740E8B5C47814F2CC477D"><enum>(4)</enum><text>The technology shall have robust contact detection specifications, including for distance and time, that allow for detection consistent with guidance of the Centers for Disease Control and Prevention on COVID–19.</text></paragraph><paragraph id="HD869925C66894865AB2108C1B441ACD3"><enum>(5)</enum><text>The technology shall ensure that the storing of proximity and any contact-tracing data is encrypted to the maximum extent possible.</text></paragraph></subsection><subsection id="H8200FF2F228B43C2912896839521116C"><enum>(e)</enum><header>Plan for interoperability</header><text>As a condition on receipt of a grant under this section, a State, Tribal, or territorial public health agency shall—</text><paragraph id="H73DF0379C11E46A2A217283F55ACCCBA"><enum>(1)</enum><text>develop and make publicly available a plan for how the digital contact-tracing technology of the agency with respect to COVID–19 augments—</text><subparagraph id="HF040522E0C6645F2B9E717C4743DF1AC"><enum>(A)</enum><text>traditional contact-tracing efforts, if applicable; and</text></subparagraph><subparagraph id="HB89567B694DB4736BC08700307E95E59"><enum>(B)</enum><text> statewide efforts to prevent, prepare for, and respond to COVID–19; and</text></subparagraph></paragraph><paragraph id="H5B4E89300E7040869EF8A595928FB4B0"><enum>(2)</enum><text>include in such plan a description of the agency’s efforts to ensure that the digital contact-tracing technologies of the agency with respect to COVID–19 are interoperable with the digital contact-tracing technology and public health agency databases of other jurisdictions with respect to COVID–19; and</text></paragraph><paragraph id="H91B4B6D0C5E94E39A4CAEB388F35FC25"><enum>(3)</enum><text>ensure that data collected by the digital contact-tracing technology of the agency—</text><subparagraph id="H9196534C673645B1AAAD6B8847C7BF13"><enum>(A)</enum><text>is accessed and processed only by public health authorities (or their designees); and</text></subparagraph><subparagraph id="HD4AE1CFB91874B27977C0EDD9D933B1B"><enum>(B)</enum><text>is not shared with any person, or accessed or used by any person, for any purpose other than diagnosis, containment, treatment, or reduction of, or research into, COVID–19.</text></subparagraph></paragraph></subsection><subsection id="H959D263F6F0E4B90AF10E9B665B09B80"><enum>(f)</enum><header>Independent security assessments</header><paragraph id="H9FBF4EF0F9754D118396CC3EBC8C8B77"><enum>(1)</enum><header>In general</header><text>As a condition on receipt of a grant under this section, a State, Tribal, or territorial public health agency shall—</text><subparagraph id="H18247372B1F04A5880CE7C6889EF2A5F"><enum>(A)</enum><text>establish procedures for completing or obtaining independent security assessments of digital contact-tracing infrastructure to ensure that physical and network security is resilient and secure; and</text></subparagraph><subparagraph id="H322BB9E90B394E07A5F694D521EC252A"><enum>(B)</enum><text>develop a process to address the mitigation or remediation of the security vulnerabilities discovered during such independent security assessments.</text></subparagraph></paragraph><paragraph id="HE85F5F6FC0EB46589CF2E1F36FA4F8BF"><enum>(2)</enum><header>Source code</header><text display-inline="yes-display-inline">A State, Tribal, or territorial public health agency should consider making public the source code of the digital contact-tracing technology used by the agency.</text></paragraph></subsection><subsection id="HC39EAA89B1FF4A2F9D92017A4E858F0E"><enum>(g)</enum><header>Application</header><text display-inline="yes-display-inline">To seek a grant under this section, an eligible State, Tribal, or territorial public health agency shall submit an application in such form, in such manner, and containing such information and assurances as the Director may require.</text></subsection><subsection commented="no" id="H52BB0F78359849308CEC0056AAFA7525"><enum>(h)</enum><header>Securing digital contact-Tracing data</header><paragraph commented="no" id="HACAFC1F37421423E9D370078743DD22C"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The provisions of the HIPAA privacy and security law (as defined in section 3009(a)(2) of the Public Health Service Act (<external-xref legal-doc="usc" parsable-cite="usc/42/300jj-19">42 U.S.C. 300jj–19(a)(2)</external-xref>)) shall apply to a State, Tribal, or territorial public health agency receiving a grant under subsection (a) with respect to individually identifiable health information (as defined in section 1171(a)(6) of the Social Security Act (<external-xref legal-doc="usc" parsable-cite="usc/42/1320d">42 U.S.C. 1320d(a)(6)</external-xref>)) received by, maintained on, or transmitted through a contact-tracing program described in such subsection (a) in the same manner as such provisions apply with respect to such information and a covered entity (as defined in section 13400(3) of the HITECH Act (<external-xref legal-doc="usc" parsable-cite="usc/42/17921">42 U.S.C. 17921(3)</external-xref>)). </text></paragraph><paragraph commented="no" id="H5E7AC5C2748C44B38DC369ABB40B9D24"><enum>(2)</enum><header>Business associates</header><subparagraph id="H0A1EB48BA0CF4C4F84641B73C3E5C913"><enum>(A)</enum><header>In general</header><text>Any entity with a contract in effect with an agency described in paragraph (1) for the development, maintenance, or operation of a program described in such paragraph shall be deemed to be a business associate of such agency for purposes of subtitle D of the HITECH Act (<external-xref legal-doc="usc" parsable-cite="usc/42/17921">42 U.S.C. 17921</external-xref> et seq.).</text></subparagraph><subparagraph id="HF8E018234ECA4EB0879FB4F4B5F82613"><enum>(B)</enum><header>Revision of sample agreement</header><text display-inline="yes-display-inline">Not later than 180 days after the date of the enactment of this Act, the Secretary shall revise the sample business associate agreement provisions published on January 25, 2013, to take account of the provisions of this subsection.</text></subparagraph><subparagraph id="H0D5982882ABE46B2A9C4E481DD04D303"><enum>(C)</enum><header>Effective date</header><text>The provisions of subparagraph (A) shall apply beginning on the day after the Secretary revises the provisions described in subparagraph (B).</text></subparagraph></paragraph></subsection><subsection commented="no" id="HA7B87D46E4D9400182BB303ED46C4A53"><enum>(i)</enum><header>Limitation on use of data</header><text display-inline="yes-display-inline">Data generated in connection with the operation of digital contact-tracing technology funded pursuant to this section may not be used for any punitive purpose, including law enforcement, immigration enforcement, or criminal prosecution. Such data and any information derived from it, whether in whole or in part, may not be received as evidence in any trial, hearing, or other proceeding in or before any court, grand jury, department, officer, agency, regulatory body, legislative committee, or other authority of the United States, a State, or a political subdivision thereof.</text></subsection><subsection id="HD014647B7DBF4A4CA8A6B9B56B2D5213"><enum>(j)</enum><header>Report to Congress</header><text>Not later than 24 months after the date of enactment of this Act, the Comptroller General of the United States shall—</text><paragraph id="HB05A71FD738D4AD79B2581DD6726E0FF"><enum>(1)</enum><text display-inline="yes-display-inline">evaluate the outcome of the grants awarded under this section, including an assessment of the impact of the implementation of digital contact-tracing programs funded through such grants on the spread of COVID–19; and</text></paragraph><paragraph id="H71EA515CD3814AFEAD89C30BA4A5D100"><enum>(2)</enum><text>submit to the Congress a report on the results of such evaluation.</text></paragraph></subsection><subsection id="HEC2E8741F2E14371B58CB8BCB3804829"><enum>(k)</enum><header>Definitions</header><text>In this section:</text><paragraph id="HCA615C43D4DF44E69F5BA90C922209A9"><enum>(1)</enum><header>Affirmative express consent</header><text display-inline="yes-display-inline">The term <term>affirmative express consent</term> means an affirmative act by an individual that clearly and conspicuously communicates the individual’s authorization for an act or practice, in response to a specific request that—</text><subparagraph id="HD56A7B01399B4C348D3E14425569097D"><enum>(A)</enum><text>is provided to the individual in a clear and conspicuous disclosure that is separate from other options or acceptance of general terms;</text></subparagraph><subparagraph id="HBC1675D22E0C45F9927D3BC8775E6A25"><enum>(B)</enum><text>includes a description of each act or practice for which the individual’s consent is sought and—</text><clause id="HC48A0F95E72845888801F00085F41241"><enum>(i)</enum><text>is written clearly and unmistakably stated; and</text></clause><clause id="HB9EC7A162940407DAB58CF384D674317"><enum>(ii)</enum><text>includes a prominent heading that would enable a reasonable individual to identify and understand the act or practice; and</text></clause></subparagraph><subparagraph id="H1E7DF230EF9A48C6BD3AD1562EF45B2E"><enum>(C)</enum><text>cannot be inferred from inaction. </text></subparagraph></paragraph><paragraph commented="no" id="H262CB6807FA54396BF22CC41BFC87495"><enum>(2)</enum><header>Contact-tracing data</header><text>The term <term>contact-tracing data</term> means information linked or reasonably linkable to a user or device, that—</text><subparagraph id="HA43657731CA845E5B53E780F636FF391"><enum>(A)</enum><text>concerns the COVID–19 pandemic; and</text></subparagraph><subparagraph id="HDDE94DE67AA54A438D059FE995F840E5"><enum>(B)</enum><text>is gathered, processed, or transferred by digital contact-tracing technology.</text></subparagraph></paragraph><paragraph id="H0C47069A853E407E80B9D75CB33E8286"><enum>(3)</enum><header>COVID–19 emergency declaration</header><text display-inline="yes-display-inline">The term <term>COVID–19 emergency declaration</term> has the meaning given to such term in section 1135(g)(1)(B) of the Social Security Act (<external-xref legal-doc="usc" parsable-cite="usc/42/1320b-5">42 U.S.C. 1320b–5</external-xref>).</text></paragraph><paragraph commented="no" id="H2C00EACC1A814577B4F4AB5E2EA91650"><enum>(4)</enum><header>De-identify</header><text display-inline="yes-display-inline">The term <term>de-identify</term> means to ensure that information cannot reasonably identify, relate to, describe, be capable of being associated with, or be linked, directly or indirectly, to a particular individual.</text></paragraph><paragraph commented="no" id="HBA0981B54C4F4F6FBA2643E602491117"><enum>(5)</enum><header>Designee</header><text>The term <term>designee</term>—</text><subparagraph id="H75DE5D99C09A4C49A9D0522898CF91E2"><enum>(A)</enum><text>subject to subparagraph (B), means any person or entity, other than a public health agency, that collects, processes, or transfers contact-tracing data in the course of performing a service or function on behalf of, for the benefit of, under instruction of, and under contractual agreement with a public health authority; and</text></subparagraph><subparagraph id="H25A5F87C9DAC491B906A5F70D6F98709"><enum>(B)</enum><text display-inline="yes-display-inline">excludes any Federal, State, Tribal, territorial, or local law (including immigration law) enforcement personnel or entity.</text></subparagraph></paragraph><paragraph id="HD2861928CAA840549B711DF048B54B34"><enum>(6)</enum><header>Digital contact-tracing technology</header><subparagraph id="HDD3CC3392D7646BDB195C74FF9DAF214"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">The term <term>digital contact-tracing technology</term> means a website, online application, mobile application, mobile operating system feature, or smart device application that is designed, in part or in full, for the purpose of—</text><clause id="H952ED4FDCA234D9CADE4E35556CA5040"><enum>(i)</enum><text>determining that a contact incident has occurred relating to the COVID–19 pandemic; and</text></clause><clause id="H1FF6AFE92EEE4737A928B356DAB7841C"><enum>(ii)</enum><text>taking consequent steps such as reporting the incident to a public health authority or user, or providing guidance or instructions to the user of the mobile device or the user’s household.</text></clause></subparagraph><subparagraph id="HD913905FEC04472C85C9906B9D74A6C4"><enum>(B)</enum><header>Limitations</header><text display-inline="yes-display-inline">Such term does not include any technology to assist individuals to evaluate whether they are experiencing COVID–19 symptoms to the extent the technology is not used as described in subparagraph (A).</text></subparagraph></paragraph><paragraph id="HCA43333B32C64399970D22F81A78BE87"><enum>(7)</enum><header>Director</header><text display-inline="yes-display-inline">The term <term>Director</term> means the Director of the Centers for Disease Control and Prevention.</text></paragraph><paragraph id="HDC55CDE59C714A42B00D216C886AE1FC"><enum>(8)</enum><header>Mobile Application</header><text display-inline="yes-display-inline">The term <term>mobile application</term> means a software program that runs on the operating system of a mobile device.</text></paragraph><paragraph id="H56BC5F6D526149488B5AA4589D5578D8"><enum>(9)</enum><header>Mobile device</header><text>The term <term>mobile device</term> means a smartphone, tablet computer, or similar portable computing device that transmits data over a wireless connection.</text></paragraph><paragraph commented="no" id="H42783DB3F7C146A2B98C6465AD6FA35A"><enum>(10)</enum><header>Source code</header><text display-inline="yes-display-inline">The term <term>source code</term> is the programming instruction for a computer program in its original form and saved in a file. </text></paragraph><paragraph id="H527E7DF8C51646BBB66F881045CA6675"><enum>(11)</enum><header>Traditional contact tracing</header><text display-inline="yes-display-inline">The term <term>traditional contact tracing</term> means contact tracing by traditional means prior to contemporary digital contact tracing.</text></paragraph><paragraph id="HE350F1494E724361878025F14A48977F"><enum>(12)</enum><header>User</header><text display-inline="yes-display-inline">The term <term>user</term> means a member of the public who utilizes the software or hardware product. </text></paragraph></subsection><subsection id="H3E7123F89BF14469BD14BD7D018993F5"><enum>(l)</enum><header>Authorization of appropriations</header><text>To carry out this section, there are authorized to be appropriated $75,000,000, to remain available until expended.</text></subsection></section></legis-body></bill> 

