<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-BON22381-WHR-V8-5TY"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S4336 IS: Strengthening Cybersecurity for Medical Devices Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2022-05-26</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>2d Session</session><legis-num>S. 4336</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20220526">May 26, 2022</action-date><action-desc><sponsor name-id="S402">Ms. Rosen</sponsor> (for herself and <cosponsor name-id="S391">Mr. Young</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSHR00">Committee on Health, Education, Labor, and Pensions</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require the Secretary of Health and Human Services, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, to annually review and as appropriate update guidance for industry and Food and Drug Administration staff on medical device cybersecurity, and for other purposes.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Strengthening Cybersecurity for Medical Devices Act</short-title></quote>.</text></section><section id="idBFA1AF797A6E4782BAF2C9F7031E199B"><enum>2.</enum><header>Guidance for industry and FDA staff on medical device cybersecurity</header><subsection id="id14FBA8A5F5404787B0DA99D6D9D3426C"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 2 years after the date of enactment of this Act, and every 2 years thereafter, the Secretary of Health and Human Services (referred to in this Act as the <quote>Secretary</quote>), in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall review and, as appropriate and after soliciting and receiving feedback from medical device manufacturers, health care providers, and patient advocates, update the guidance entitled <quote>Content of Premarket Submissions for Management of Cybersecurity in Medical Devices</quote> (or a successor document).</text></subsection><subsection id="idB47FDA71F982495BAD5E7750A6702EF3"><enum>(b)</enum><header>Updating specific provisions</header><text>In updating the guidance under subsection (a), the Secretary may update specific provisions of the guidance, after notice and comment, without reissuing the guidance.</text></subsection></section><section id="idC74AFE19CD1B460FA66E7FCD09A50A98"><enum>3.</enum><header>Resources regarding cybersecurity of medical devices</header><text display-inline="no-display-inline">Not later than 180 days after the date of enactment of this Act, and not less than annually thereafter, the Secretary shall update public information provided by the Food and Drug Administration, including through the webpage on medical devices on the website of the Food and Drug Administration, with information regarding improving cybersecurity of medical devices. Such information shall include information on identifying and addressing cyber vulnerabilities for health care providers, health systems, and medical device manufacturers, and how such entities may access support through the Cybersecurity and Infrastructure Security Agency and other Federal entities, including the Department of Health and Human Services, to improve cybersecurity of medical devices. </text></section><section id="id585B08E5EF2D4949B61B2FBCB12FBEB0"><enum>4.</enum><header>GAO report</header><text display-inline="no-display-inline">Not later than 1 year after the date of enactment of this Act, the Comptroller General of the United States shall publish a report identifying challenges in cybersecurity for medical devices, including legacy devices that may not support certain software security updates. Through such report, the Comptroller General shall examine—</text><paragraph id="id804DCA83515C477681545A937EC7DC68"><enum>(1)</enum><text display-inline="yes-display-inline">challenges for medical device manufacturers, health care providers, health systems, and patients in accessing Federal support to address vulnerabilities across Federal agencies; and </text></paragraph><paragraph id="idD26DFB0A75AF40128A12659D2753BD96"><enum>(2)</enum><text display-inline="yes-display-inline">how Federal agencies can strengthen coordination to better support cybersecurity for medical devices. </text></paragraph></section></legis-body></bill> 

