<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H626985BC1E4748178AF2BF3A2E768430" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 HR 10455 IH: Healthcare Cybersecurity Improvement Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2024-12-17</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">118th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 10455</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20241217">December 17, 2024</action-date><action-desc><sponsor name-id="K000385">Ms. Kelly of Illinois</sponsor> introduced the following bill; which was referred to the <committee-name committee-id="HIF00">Committee on Energy and Commerce</committee-name>, and in addition to the Committees on <committee-name committee-id="HWM00">Ways and Means</committee-name>, and <committee-name committee-id="HSY00">Science, Space, and Technology</committee-name>, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned</action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To direct the Secretary of Health and Human Services to establish the Health Sector Cybersecurity Coordination Center, and for other purposes.</official-title></form><legis-body id="H2E947F4206E645638973015D3B5E4499" style="OLC"><section id="H8AB90FEB7B224CF397429537CAF915E7" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Healthcare Cybersecurity Improvement Act</short-title></quote>.</text></section><section id="HBBA6155F0D524068A92D7917D09F79CE"><enum>2</enum><header>Findings</header><text display-inline="no-display-inline">Congress finds that—</text><paragraph id="H201E79E9CE204AC38E0D5681D8724289"><enum>(1)</enum><text>the Department of Health and Human Services found that ransomware attacks on hospitals have more than doubled from 2019 to 2020, with more than 239,000,000 attacks attempted;</text></paragraph><paragraph id="H2C7D96FBCA4D41F2BCAF8B7CF8C59186"><enum>(2)</enum><text>in 2020, over 630 health care organizations were subject to data breaches, leading to over 29,000,000 health records publicly released; and</text></paragraph><paragraph id="H412B5644D7E44B318C8C9551C2BED984"><enum>(3)</enum><text>studies indicate that attacks on our nation’s health care systems will only increase as hospitals are forced to balance health care costs with an increasingly digital health care system.</text></paragraph></section><section id="H93C5C70068B04A569FE3795CCC3FF9F1"><enum>3</enum><header>Health Sector Cybersecurity Coordination Center</header><subsection id="HFC87EA45827E4C42AEC9DBC503AB8009"><enum>(a)</enum><header>Establishment</header><text display-inline="yes-display-inline">Not later than 120 days after the date of the enactment of this Act, the Secretary of Health and Human Services (in this Act referred to as the <quote>Secretary</quote>) shall, in consultation, as appropriate, with other relevant officials within the Department of Health and Human Services, including the Commissioner of Food and Drugs, the Assistant Secretary for Preparedness and Response, and the Officer for Civil Rights and Civil Liberties, establish a center for purposes of coordinating cybersecurity across the health care sector to be known as the Health Sector Cybersecurity Coordination Center (in this section referred to as the <quote>Center</quote>). </text></subsection><subsection id="H07EC533FBFD24F159F25CCC654318DDF"><enum>(b)</enum><header>Duties</header><text display-inline="yes-display-inline">The Center shall—</text><paragraph id="H3952AB6F3D9248D1B83323ECC049BB3C"><enum>(1)</enum><text display-inline="yes-display-inline">support the defense of the information technology infrastructure of the health care sector, including by—</text><subparagraph id="HB94C5DC32DC64CE78152D6364CC0C143"><enum>(A)</enum><text>strengthening coordination and information sharing within the sector; and</text></subparagraph><subparagraph id="HD89032D888C34822B4C4598B0CCFAAA9"><enum>(B)</enum><text display-inline="yes-display-inline">developing a plan to protect, detect, respond to, and recover from cybersecurity risks and incidents, including for entities with limited technical capacity; and</text></subparagraph></paragraph><paragraph id="H24F6D2707C8742B49018CDF9049B7EAE"><enum>(2)</enum><text display-inline="yes-display-inline">develop and support technical capabilities and provide advice regarding the development of standards, to prevent and mitigate cyber attacks, including—</text><subparagraph id="H2CD91DE7C64F4CC383EBB863E0C81EE8"><enum>(A)</enum><text>the Commissioner of Food and Drugs; and</text></subparagraph><subparagraph id="HC8436E99C63E4C9EB7A46529833FF365"><enum>(B)</enum><text>the Assistant Secretary for Preparedness and Response.</text></subparagraph></paragraph></subsection></section><section id="H195577893EB24350A6062000445BCADC"><enum>4</enum><header>Health Care Cybersecurity Grant Program</header><subsection id="H6F78E577C7E948F6B4F75AC21C19D563"><enum>(a)</enum><header>Establishment</header><text>Not later than 1 year after the date of the enactment of this Act, the Secretary shall establish a program to be known as the Health Care Cybersecurity Grant Program for the purpose of awarding grants to eligible entities to obtain equipment and software and hire information technology staff to ensure the protection of critical information systems.</text></subsection><subsection id="HD7E66A64053F47BD9DAD87AE9246997A"><enum>(b)</enum><header>Grant amount</header><text display-inline="yes-display-inline">Not later than 90 days after funds are made available to carry out this section, the Secretary shall publish the maximum amount of a grant available under this section, as determined by the Secretary.</text></subsection><subsection id="HBAB89E2DF0994EFF864D14719482B412"><enum>(c)</enum><header>Report</header><text>Not later than 5 years after the date of the enactment of this Act, the Secretary shall prepare and submit to the Committee on Health, Education, Labor, and Pensions of the Senate and the Committee on Energy and Commerce of the House of Representatives a report on the activities and outcomes of the grant program under this section.</text></subsection><subsection id="H1DA227B7CC8947FEA874100BF722C752"><enum>(d)</enum><header>Definitions</header><text display-inline="yes-display-inline">In this section:</text><paragraph id="HF8078C96946F4D5587608F7327839A33"><enum>(1)</enum><header>Eligible entity</header><text display-inline="yes-display-inline">The term <term>eligible entity</term> means a—</text><subparagraph id="H0A77930D95E54A28A7179FB5A692170F"><enum>(A)</enum><text>hospital with fewer than 300 beds for the provision of patient care; or</text></subparagraph><subparagraph id="H76F1878D2C9446719D49A31019FA9779"><enum>(B)</enum><text>rural health clinic.</text></subparagraph></paragraph><paragraph id="HF5756E2C25D04B4DB3B56561AF54EC3D"><enum>(2)</enum><header>Hospital</header><text display-inline="yes-display-inline">The term <quote>hospital</quote> means a hospital, as defined in section 1861(e) of the Social Security Act (<external-xref legal-doc="usc" parsable-cite="usc/42/1395x">42 U.S.C. 1395x(e)</external-xref>), or a critical access hospital, as defined in section 1861(mm)(1) of such Act (<external-xref legal-doc="usc" parsable-cite="usc/42/1395x">42 U.S.C. 1395x(mm)(1)</external-xref>).</text></paragraph><paragraph id="H0B5005BBF10940AFB7341A12670FF093"><enum>(3)</enum><header>Rural health clinic</header><text>The term <term>rural health clinic</term> has the meaning given such term in section 1861(aa) of the Social Security Act (<external-xref legal-doc="usc" parsable-cite="usc/42/1395x">42 U.S.C. 1395x(aa)(2)</external-xref>).</text></paragraph></subsection><subsection id="H1623C259398949AE9839AE5258612EA9"><enum>(e)</enum><header>Authorization of Appropriations</header><text>There are authorized to be appropriated to carry out this section $100,000,000 for fiscal year 2022, to remain available through fiscal year 2023.</text></subsection></section><section id="HD32EE92CC4854B929ADF24E86F1CD780"><enum>5.</enum><header>Standards for medical devices and information security networks in hospitals</header><subsection id="HD91184186A1F434EB9F27FEEC938A923"><enum>(a)</enum><header>Establishment</header><text display-inline="yes-display-inline">Not later than 1 year after the date of the enactment of this Act, the Director of the National Institute of Standards and Technology, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency and the heads of appropriate Federal agencies, shall develop standards for the protection of information security networks and digital medical devices in hospitals.</text></subsection><subsection id="HD02F99ED27E74893A60B00D09FE8F970"><enum>(b)</enum><header>Consideration</header><text>In developing standards under subsection (a), the Director shall take into consideration—</text><paragraph id="H63CAE4CD6AE345B18E9CCC5746EEA1E7"><enum>(1)</enum><text>current Federal standards and guidelines, including—</text><subparagraph id="HE90D87AF0F334F6E9A4E38D93924F51C"><enum>(A)</enum><text display-inline="yes-display-inline">standards and guidelines developed under section 4 of the Internet of Things Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–b);</text></subparagraph><subparagraph id="H5659CC8A0D9D443C9EA5DEB4CD303A01"><enum>(B)</enum><text display-inline="yes-display-inline">standards promulgated under section 405(d) of the Cybersecurity Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1533">6 U.S.C. 1533</external-xref>); and</text></subparagraph><subparagraph id="H8528E4A8347E401DAC9D1018737EDD07"><enum>(C)</enum><text display-inline="yes-display-inline">standards developed by the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security with respect to critical infrastructure (as defined in section 1016(e) of the USA PATRIOT Act (<external-xref legal-doc="usc" parsable-cite="usc/42/5195c">42 U.S.C. 5195c(e)</external-xref>); and</text></subparagraph></paragraph><paragraph id="H6BA454CD6E41457F9E269EE202F8DCA3"><enum>(2)</enum><text>general security practices, including—</text><subparagraph id="H1186433B5C7D4C64AE0E0735B1D93D2F"><enum>(A)</enum><text>network segmentation between medical devices and patient information; and</text></subparagraph><subparagraph id="HDB2969A42986473A869866788164FC21"><enum>(B)</enum><text>the methods used to detect medical devices connected to the internal network of a hospital.</text></subparagraph></paragraph></subsection><subsection id="H862CC2EF820E40D2B83E39846C929FD5"><enum>(c)</enum><header>Enforcement under Medicare and Medicaid</header><paragraph id="H06A58FBD3F0240A294A737D97DDF168C"><enum>(1)</enum><header>Medicare</header><text>Section 1866(a)(1) of the Social Security Act (<external-xref legal-doc="usc" parsable-cite="usc/42/1395cc">42 U.S.C. 1395cc(a)(1)</external-xref>) is amended—</text><subparagraph id="H1C570E0189B4404C9F3A040022C67864"><enum>(A)</enum><text>in subparagraph (X), by striking <quote>and</quote> at the end;</text></subparagraph><subparagraph id="H97DB2C9279A5458D8159D69D263C6F21"><enum>(B)</enum><text>in subparagraph (Y)(ii)(V), by striking the period and inserting <quote>, and</quote>; and</text></subparagraph><subparagraph id="HD6C1FE2941324C7CACB0B3B5BB9A9779"><enum>(C)</enum><text>by inserting after subparagraph (Y) the following new subparagraph:</text><quoted-block style="OLC" id="H3F21E1E0BB7D4BBBAD3E71EBC2F41ED3" display-inline="no-display-inline"><subparagraph id="HCBDB1F65C12147FEA83CA8789AE7AF25" indent="up1"><enum>(Z)</enum><text display-inline="yes-display-inline">in the case of a hospital or a critical access hospital, beginning on the date that is 2 years after the date of the enactment of this subparagraph, to comply with the standards developed under section 5(a) of the Healthcare Cybersecurity Improvement Act.</text></subparagraph><after-quoted-block>.</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph id="H61DCA11290044F42B09B9E15C46168A4"><enum>(2)</enum><header>Medicaid</header><text>Section 1902(a) of the Social Security Act (<external-xref legal-doc="usc" parsable-cite="usc/42/1396a">42 U.S.C. 1396a(a)</external-xref>) is amended—</text><subparagraph id="H7F78D05569AF45A1BFB30B611B7457CA"><enum>(A)</enum><text>in paragraph (86), by striking <quote>and</quote> at the end;</text></subparagraph><subparagraph id="H158917A3163C4B4BABB7B197C61C0508"><enum>(B)</enum><text>in paragraph (87)(D), by striking the period and inserting <quote>; and</quote>; and</text></subparagraph><subparagraph id="HAC4B8A2BA9FB4677BDF93C7B7C129B14"><enum>(C)</enum><text>by inserting after paragraph (87) the following new paragraph:</text><quoted-block style="OLC" id="HE739129795FA4B248BAE391B092310A3" display-inline="no-display-inline"><paragraph id="H1502319B905B44DB9852909F88B4D0F6"><enum>(88)</enum><text display-inline="yes-display-inline">provide that, beginning on the date that is 2 years after the date of the enactment of this paragraph, no hospital be eligible to participate under the plan (or a waiver of such plan) unless such hospital complies with the standards developed under section 5(a) of the Healthcare Cybersecurity Improvement Act.</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></subparagraph></paragraph></subsection><subsection id="H6CCDDD6EC28D4116B599339D193E8930"><enum>(d)</enum><header>Quinquennial review and revision</header><text>Not later than 5 years after the date on which the Secretary publishes the standards under subsection (a), and not less frequently than once every 5 years thereafter, the Secretary, shall review and revise such standards, as appropriate.</text></subsection></section><section id="HF0F3B936495B4116BF5AC6EEEA66BA63"><enum>6.</enum><header>Limitation on liability for a large hospital</header><subsection id="HCC57A4A6F25345558929CC2A60658FF3"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Notwithstanding any other provision of law, a large hospital shall not be liable in any covered civil action to a smaller health entity if such hospital provided<italic></italic> cybersecurity assistance to such entity with respect to electronic data, unless such entity can prove by clear and convincing evidence that the alleged harm was caused by gross negligence or willful misconduct.</text></subsection><subsection id="H6EB1D435C4894D5D9967A76DEE3935FB"><enum>(b)</enum><header>Exception</header><text display-inline="yes-display-inline">For purposes of this section, any acts or omissions by a large hospital resulting from a resource or staffing shortage shall not be considered willful misconduct or gross negligence.</text></subsection><subsection id="H0FDFE19762C24F97A0DD192AAE3DDE94"><enum>(c)</enum><header>Definitions</header><text display-inline="yes-display-inline">In this section:</text><paragraph id="HE8C0E370A8CF4962B2899BE537F9E758"><enum>(1)</enum><header>Covered civil action</header><text>The term <quote>covered civil action</quote> means a civil action under State law from harm resulting from the acquisition, storage, security, use, misuse, disclosure, or transmission of electronic data of any kind, including—</text><subparagraph id="H7645769F2FB34B29B7E49273145365D7"><enum>(A)</enum><text>information security and privacy;</text></subparagraph><subparagraph id="H3CDF5975E68D4030ABA6D9AA393B029C"><enum>(B)</enum><text>penalties, including for regulatory defense;</text></subparagraph><subparagraph id="H40C318B558794FCD887CA5F55693DEFD"><enum>(C)</enum><text>misuse of website media content; and</text></subparagraph><subparagraph id="HE57EC1A23F8943FC883F1DE60848BF8D"><enum>(D)</enum><text display-inline="yes-display-inline">disclosure, misuse, or improper (or inadequate) storage or security of personal and confidential information.</text></subparagraph></paragraph><paragraph id="H0BABEACCB86A485EAEFE47A9BC14A4BE"><enum>(2)</enum><header>Large hospital</header><text display-inline="yes-display-inline">The term <quote>large hospital</quote> means a hospital with 300 or more beds for the provision of patient care.</text></paragraph><paragraph id="H4A11440CF92F4E5485C83BE79D4A111C" display-inline="no-display-inline"><enum>(3)</enum><header>Hospital</header><text>The term <term>hospital</term> has the meaning given such term in section 1861(e) of the Social Security Act (<external-xref legal-doc="usc" parsable-cite="usc/42/1395x">42 U.S.C. 1395x</external-xref>).</text></paragraph><paragraph id="HE925C25207C646CD990B1E8EAC88D6E3"><enum>(4)</enum><header>Rural health clinic</header><text>The term <term>rural health clinic</term> has the meaning given such term in section 1861(aa) of the Social Security Act (<external-xref legal-doc="usc" parsable-cite="usc/42/1395x">42 U.S.C. 1395x(aa)(2)</external-xref>).</text></paragraph><paragraph id="HB0D2E70A04F04749B9A0F2DB9F4788C3"><enum>(5)</enum><header>Small health entity</header><text display-inline="yes-display-inline">The term <quote>small health entity</quote> means—</text><subparagraph id="HAF58D0627B9C4E14B0E1436F49B139C1"><enum>(A)</enum><text>a hospital with fewer than 299 beds for the provision of patient care; and</text></subparagraph><subparagraph id="H63A09F898657490790C58B0B5D8D6025"><enum>(B)</enum><text>a rural health clinic.</text></subparagraph></paragraph></subsection></section></legis-body></bill> 

