<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-HEN22260-47J-0N-K5R"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>104 S3904 IS: Healthcare Cybersecurity Act of 2022</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2022-03-23</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>2d Session</session><legis-num>S. 3904</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20220323">March 23, 2022</action-date><action-desc><sponsor name-id="S402">Ms. Rosen</sponsor> (for herself and <cosponsor name-id="S373">Mr. Cassidy</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To enhance the cybersecurity of the Healthcare and Public Health Sector.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Healthcare Cybersecurity Act of 2022</short-title></quote>.</text></section><section id="id43222bc438474f728fe70b738041a08e"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act—</text><paragraph id="id5dff81e10ac3446f93cf7bd4bdd3c833"><enum>(1)</enum><text>the term <term>Agency</term> means the Cybersecurity and Infrastructure Security Agency;</text></paragraph><paragraph id="id6b13fab3eb7b4828add752713b2016e2"><enum>(2)</enum><text>the term <term>Cybersecurity State Coordinator</term> means a Cybersecurity State Coordinator appointed under section 2217(a) of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/665c">6 U.S.C. 665c(a)</external-xref>);</text></paragraph><paragraph id="id4c3f2f2870504dc4b57670448a1f296c"><enum>(3)</enum><text>the term <term>Department</term> means the Department of Health and Human Services;</text></paragraph><paragraph id="id93168bdad9d24866b57c3ce8ef9453af"><enum>(4)</enum><text>the term <term>Director</term> means the Director of the Agency;</text></paragraph><paragraph id="ide84affd2a2894b56bd07ca3386856110"><enum>(5)</enum><text>the term <term>Healthcare and Public Health Sector</term> means the Healthcare and Public Health sector, as identified in Presidential Policy Directive 21 (February 12, 2013; relating to critical infrastructure security and resilience);</text></paragraph><paragraph id="id502760130AEF44768EB63428315E3373"><enum>(6)</enum><text>the term <term>Information Sharing and Analysis Organizations</term> has the meaning given that term in section 2222 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/671">6 U.S.C. 671</external-xref>); and</text></paragraph><paragraph id="idc3a696aba64740b385d09210f6a36663"><enum>(7)</enum><text>the term <term>Secretary</term> means the Secretary of Health and Human Services.</text></paragraph></section><section id="id3367ff481d5448a3b42735b0f0bd54be"><enum>3.</enum><header>Findings</header><text display-inline="no-display-inline">Congress finds the following:</text><paragraph id="idb775d3668d1a41eebb12f181c37bc4d1"><enum>(1)</enum><text>Healthcare and Public Health Sector assets are increasingly the targets of malicious cyberattacks, which result not only in data breaches, but also increased healthcare delivery costs, and can ultimately affect patient health outcomes.</text></paragraph><paragraph id="id9fd84428ffeb4174ae248c91d76bbef4"><enum>(2)</enum><text>Data reported to the Department shows that almost every month in 2020, more than 1,000,000 people were affected by data breaches at healthcare organizations. Cyberattacks on healthcare facilities rose 55 percent in 2020, and these attacks also resulted in a 16 percent increase in the average cost of recovering a patient record in 2020, as compared to 2019.</text></paragraph><paragraph id="id831ec5af215f445396146d6af92fd9b5"><enum>(3)</enum><text>According to data from the Office for Civil Rights of the Department, health information breaches have increased since 2016, and in 2020 alone, the Department reported 663 breaches on covered entities, as defined under the Health Insurance Portability and Accountability Act of 1996 (<external-xref legal-doc="public-law" parsable-cite="pl/104/191">Public Law 104–191</external-xref>), affecting more than 500 people, with over 33,000,000 total people affected by health information breaches.</text></paragraph></section><section id="id8c82b4501ae54102aa355a55a87e3ea6"><enum>4.</enum><header>Agency collaboration with the Department</header><subsection id="id156fb17cf9164d629380b6098a394fab"><enum>(a)</enum><header>In general</header><text>The Agency shall collaborate with the Department, including by entering into an agreement, as appropriate, to improve cybersecurity in the Healthcare and Public Health Sector.</text></subsection><subsection id="id423c9114d4aa4f1d8996044ee26547c0"><enum>(b)</enum><header>Assistance</header><paragraph id="id148093F76B684CEEA4B923D4640C1279"><enum>(1)</enum><header>In general</header><text>The Agency shall coordinate with and make resources available to Information Sharing and Analysis Organizations, information sharing and analysis centers, and non-Federal entities that are receiving information shared through programs managed by the Department.</text></paragraph><paragraph id="idFC2F4D4C9DE94C1D9C791087872A1323"><enum>(2)</enum><header>Scope</header><text>The coordination under paragraph (1) shall include—</text><subparagraph id="id581907c6d88f495796eb261bde626ce0"><enum>(A)</enum><text>developing products specific to the needs of Healthcare and Public Health Sector entities; and</text></subparagraph><subparagraph id="id99816ede545c46e0b2dfc26c5543e8ef"><enum>(B)</enum><text>sharing information relating to cyber threat indicators and appropriate defensive measures.</text></subparagraph></paragraph></subsection></section><section id="idee0127d503d649e5b876dd9ba5f2ddca"><enum>5.</enum><header>Training for healthcare experts</header><text display-inline="no-display-inline">The Cyber Security Advisors and Cybersecurity State Coordinators of the Agency shall, in coordination, as appropriate, with private sector healthcare experts, provide training to Healthcare and Public Health Sector asset owners and operators on— </text><paragraph id="ide00635a38f8a4c87b057980963adeaab"><enum>(1)</enum><text>cybersecurity risks to the Healthcare and Public Health Sector and assets within the sector; and</text></paragraph><paragraph id="idd50a0ac584024c57ad8259b229788d0e"><enum>(2)</enum><text>ways to mitigate the risks to information systems in the Healthcare and Public Health Sector.</text></paragraph></section><section id="id235c626fa74b4a49ad690fbb5d9835d1"><enum>6.</enum><header>Sector-specific study and report</header><subsection id="idc0e8c406f1d0477ea3c6c69c30bda35b"><enum>(a)</enum><header>In general</header><text>Not later than 1 year after the date of enactment of this Act, the Director, in consultation with the Secretary, shall conduct a study and issue a report, which shall include the following elements:</text><paragraph id="id9329322494b34620adbd41f6bdc26c65"><enum>(1)</enum><text>An analysis of how identified cybersecurity risks specifically impact Healthcare and Public Health Sector assets, including the impact on rural and small and medium-sized Healthcare and Public Health Sector assets.</text></paragraph><paragraph id="id1d489026367d43d8a1a3919884ad5ae1"><enum>(2)</enum><text>An evaluation of the challenges Healthcare and Public Health Sector assets face in—</text><subparagraph id="id054589683e87437d8243e893c9578260"><enum>(A)</enum><text>securing—</text><clause id="id38a1d46c6ce14656a8b392edf2cdeb69"><enum>(i)</enum><text>updated information systems owned, leased, or relied upon by Healthcare and Public Health Sector assets;</text></clause><clause id="idc129ff15642b45ab9cb66c190499c243"><enum>(ii)</enum><text>medical devices or equipment owned, leased, or relied upon by Healthcare and Public Health Sector assets, which shall include an analysis of the threat landscape and cybersecurity vulnerabilities of such medical devices or equipment; and</text></clause><clause id="idd8b574b714544dca928cb7c1801edbb1"><enum>(iii)</enum><text>sensitive patient health information and electronic health records;</text></clause></subparagraph><subparagraph id="id254bf3677e9240ceb7b782c115422392"><enum>(B)</enum><text>implementing cybersecurity protocols; and</text></subparagraph><subparagraph id="id0053f9752bc54d3aaa2a4aaaa97ec750"><enum>(C)</enum><text>responding to data breaches or cybersecurity attacks, including the impact on patient access to care, quality of patient care, timeliness of health care delivery, and health outcomes.</text></subparagraph></paragraph><paragraph id="id6c477bd3aadb49c8ad44e26dd18e816d"><enum>(3)</enum><text>An evaluation of best practices for the deployment of trained Cyber Security Advisors and Cybersecurity State Coordinators of the Agency into Healthcare and Public Health Sector assets before, during, and after data breaches or cybersecurity attacks.</text></paragraph><paragraph id="id7c685954bfec400b8f0c6b3dcd191ab7"><enum>(4)</enum><text>An assessment of relevant Healthcare and Public Health Sector cybersecurity workforce shortages, including—</text><subparagraph id="id0c7deb7935664571a8b8700cdbb825ed"><enum>(A)</enum><text>training, recruitment, and retention issues; and</text></subparagraph><subparagraph id="idbaa0d086531a47ce9949db900273e415"><enum>(B)</enum><text>recommendations for how to address these shortages and issues, particularly at rural and small and medium-sized Healthcare and Public Health Sector assets.</text></subparagraph></paragraph><paragraph id="idab7bff5140fe4c72b8780ec32a5965d1"><enum>(5)</enum><text>An identification of cybersecurity challenges related to or brought on by the public health emergency declared by the Secretary under section 319 of the Public Health Service Act (<external-xref legal-doc="usc" parsable-cite="usc/42/247d">42 U.S.C. 247d</external-xref>) on January 27, 2020, with respect to COVID–19.</text></paragraph><paragraph id="id03bb1f09814349348af9ac97189cb7be"><enum>(6)</enum><text>An evaluation of the most accessible and timely ways for the Agency and the Department to communicate and deploy cybersecurity recommendations and tools to Healthcare and Public Health Sector assets.</text></paragraph></subsection><subsection id="id57e8d92adc8c41ec9c32325ba1c132fb"><enum>(b)</enum><header>Report transmittal</header><text>Not later than 60 days after completing the study and report required under subsection (a), the Director shall present the completed report to the Secretary, which the Secretary may, in consultation with the Director, consult when updating the Healthcare and Public Health Sector Specific Plan of the Secretary. </text></subsection><subsection id="ida144464dda354de882205a7110369239"><enum>(c)</enum><header>Congressional briefing</header><text>Not later than 120 days after the date of enactment of this Act, the Director, in consultation with the Secretary, as appropriate, shall provide a briefing on the status of the study and report required under subsection (a) to—</text><paragraph id="idd4cebdf1367b4cdbacf732b329805d31"><enum>(1)</enum><text>the Committee on Health, Education, Labor, and Pensions and the Committee on Homeland Security and Governmental Affairs of the Senate; and</text></paragraph><paragraph id="id003bbd5440414c8ca85f91942f19ea9a"><enum>(2)</enum><text>the Committee on Energy and Commerce and the Committee on Homeland Security of the House of Representatives. </text></paragraph></subsection></section></legis-body></bill> 

