<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-type="olc" bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-BON22229-745-8Y-1H4"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S3983 IS: PATCH Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2022-03-31</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>2d Session</session><legis-num>S. 3983</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20220331">March 31, 2022</action-date><action-desc><sponsor name-id="S373">Mr. Cassidy</sponsor> (for himself and <cosponsor name-id="S354">Ms. Baldwin</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSHR00">Committee on Health, Education, Labor, and Pensions</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To amend the Federal Food, Drug, and Cosmetic Act to require, for purposes of ensuring cybersecurity, the inclusion in any premarket submission for a cyber device of information to demonstrate a reasonable assurance of safety and effectiveness throughout the lifecycle of the cyber device, and for other purposes.</official-title></form><legis-body style="OLC" display-enacting-clause="yes-display-enacting-clause" id="H29B1FC5E426C4EC2B953126AAAB1428E"><section section-type="section-one" id="H3153DB9EE8B9446D9D91B9BB98F3F071"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>PATCH Act</short-title></quote>.</text></section><section id="H3E5C0BEF9DC443DAB7B686675D58757D"><enum>2.</enum><header>Ensuring cybersecurity of medical devices</header><subsection id="H7148D0675B62459981B3B5C6A3E7A54B"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Subchapter A of chapter V of the Federal Food, Drug, and Cosmetic Act (<external-xref legal-doc="usc" parsable-cite="usc/21/351">21 U.S.C. 351 et seq.</external-xref>) is amended by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="H6858958BD86C411C80CB5BCA8EE1F85D"><section id="HA3D12C6854AC456AABF74314CD9E5C0E"><enum>524B.</enum><header>Ensuring cybersecurity of devices</header><subsection id="HA378C6C6A2414569B5DC75615EB5C1F6"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">For purposes of ensuring cybersecurity throughout the lifecycle of a cyber device, any person who submits a premarket submission for the cyber device shall include such information as the Secretary may require to ensure that the cyber device meets such cybersecurity requirements as the Secretary determines to be appropriate to demonstrate a reasonable assurance of safety and effectiveness, including at a minimum the cybersecurity requirements under subsection (b). The Secretary may establish exemptions to the requirements under this subsection. </text></subsection><subsection id="HCCD35764C60D41938DB5018DAD2C234B"><enum>(b)</enum><header>Cybersecurity requirements</header><text>At a minimum, the manufacturer of a cyber device shall meet the following cybersecurity requirements:</text><paragraph id="HB9FF386CD0424329A734BD456B3E882A"><enum>(1)</enum><text>The manufacturer shall have a plan to appropriately monitor, identify, and address in a reasonable time postmarket cybersecurity vulnerabilities and exploits.</text></paragraph><paragraph id="H6CF0E410CD89446CA5E8F7EAB4BFACF4"><enum>(2)</enum><text display-inline="yes-display-inline">The manufacturer shall—</text><subparagraph id="H67E149F339D94CA1A71FC234508D173B"><enum>(A)</enum><text>have a plan and procedures for a Coordinated Vulnerability Disclosure to be part of submissions to the Food and Drug Administration; and</text></subparagraph><subparagraph id="HE099A7AFD64A4C9595456703C839EE2A"><enum>(B)</enum><text>collect and maintain such other information as the Secretary may (by order published in the Federal Register or by other process) require to demonstrate a reasonable assurance of the safety and effectiveness of the cyber device.</text></subparagraph></paragraph><paragraph id="H1D849A64D9C34893847E85F654EE4B5E"><enum>(3)</enum><text display-inline="yes-display-inline">The manufacturer shall design, develop, and maintain processes and procedures to make available updates and patches to the cyber device and related systems throughout the lifecycle of the cyber device to address—</text><subparagraph id="HC544E7141D4941E8866BBBDB6CE1F098"><enum>(A)</enum><text display-inline="yes-display-inline">on a reasonably justified regular cycle, known unacceptable vulnerabilities; and</text></subparagraph><subparagraph id="H5800ABDC724F412BBB40052AE2B19DE4"><enum>(B)</enum><text>as soon as possible out of cycle, critical vulnerabilities that could cause uncontrolled risks.</text></subparagraph></paragraph><paragraph id="H08354A373B1F49809F374F5D34990EE6"><enum>(4)</enum><text display-inline="yes-display-inline">The manufacturer shall furnish to the Secretary a software bill of materials, including commercial, open-sourced, and off-the-shelf software components that will be provided to users.</text></paragraph></subsection><subsection id="HECC46635556F4E528CA3DC395DAC1612"><enum>(c)</enum><header>Substantial equivalence</header><text display-inline="yes-display-inline">In making a determination of substantial equivalence under section 513(i) for a cyber device, the Secretary may—</text><paragraph id="HD1BBA37D2DDE43C096A144B4F77E29E6"><enum>(1)</enum><text>find that cybersecurity information for the cyber device described in the relevant premarket submission in the cyber device’s use environment is inadequate; and</text></paragraph><paragraph id="H96BF68186C174CAF9F6E80B31A9874EE"><enum>(2)</enum><text>issue a nonsubstantial equivalence determination based on this finding.</text></paragraph></subsection><subsection id="HFDD7FDBD4CDB4C4EA15254E458961652"><enum>(d)</enum><header>Definition</header><text display-inline="yes-display-inline">In this section:</text><paragraph id="H691980394C2D4122AF0241E38164920D"><enum>(1)</enum><text display-inline="yes-display-inline">The term <term>cyber device</term> means a device that—</text><subparagraph id="H68375870E7AF44C294727BCBADE1BD2B"><enum>(A)</enum><text>includes software; or</text></subparagraph><subparagraph id="H016754E0A2B24BFB9C53FC36216AB853"><enum>(B)</enum><text>is intended to connect to the internet.</text></subparagraph></paragraph><paragraph id="H61CFEC0791A34E388ED4AF20ACA531C6"><enum>(2)</enum><text>The term <term>lifecycle of the cyber device</term> includes the postmarket lifecycle of the cyber device.</text></paragraph><paragraph id="H47DF88BCD21644AF95921AB93142FEB0"><enum>(3)</enum><text>The term <term>premarket submission</term> means any submission under section 510(k), 513, 515(c), 515(f), or 520(m).</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="HAD134EFCC6B8443E8C00EBDC3F9559C9"><enum>(b)</enum><header>Prohibited act</header><text display-inline="yes-display-inline">Section 301(q) of the Federal Food, Drug, and Cosmetic Act (<external-xref legal-doc="usc" parsable-cite="usc/21/331">21 U.S.C. 331(q)</external-xref>) is amended by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="H4D94775999C24CCF91C992A22C67F1E4"><paragraph id="H188F9807924E4444A44FC432D8531118" indent="up1"><enum>(3)</enum><text display-inline="yes-display-inline">The failure to comply with any requirement under section 524B (relating to ensuring the cybersecurity).</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="H810E1A216633492D9B934A5C88019529"><enum>(c)</enum><header>Adulteration</header><text>Section 501 of the Federal Food, Drug, and Cosmetic Act (<external-xref legal-doc="usc" parsable-cite="usc/21/351">21 U.S.C. 351</external-xref>) is amended by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="H200B753ED05D4B949A6E2C52064D5C6D"><subsection id="H23CFB7F0364D4B3AAD5E8635E2F0DA95"><enum>(k)</enum><text display-inline="yes-display-inline">If it is a device with respect to which the sponsor is in violation of section 524B (relating to ensuring cybersecurity).</text></subsection><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="H58D6DB6918BA4FC7AE89A32FCCF7A31D"><enum>(d)</enum><header>Misbranding</header><text display-inline="yes-display-inline">Section 502(t) of the Federal Food, Drug, and Cosmetic Act (<external-xref legal-doc="usc" parsable-cite="usc/21/352">21 U.S.C. 352(t)</external-xref>) is amended—</text><paragraph id="H44CC1D9E2E2B44B78EC9D848365C43DF"><enum>(1)</enum><text>by striking <quote>or (3)</quote> and inserting <quote>(3)</quote>; and</text></paragraph><paragraph id="HB3A75BB435D343AC939088FE3D80D9BA"><enum>(2)</enum><text>by inserting before the period at the end the following: <quote>, or (4) to furnish a software bill of materials as required under section 524B (relating to ensuring the cybersecurity)</quote>.</text></paragraph></subsection></section></legis-body></bill> 

