<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-TAM23556-F9L-48-RC7"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 S1493 IS: 9–8–8 Lifeline Cybersecurity Responsibility Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2023-05-09</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>118th CONGRESS</congress><session>1st Session</session><legis-num>S. 1493</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20230509">May 9, 2023</action-date><action-desc><sponsor name-id="S403">Ms. Sinema</sponsor> (for herself and <cosponsor name-id="S419">Mr. Mullin</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSHR00">Committee on Health, Education, Labor, and Pensions</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To amend title V of the Public Health Service Act to secure the suicide prevention lifeline from cybersecurity incidents, and for other purposes.</official-title></form><legis-body style="OLC"><section id="H25A232D1D66D46188F81718F359C9F7C" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>9–8–8 Lifeline Cybersecurity Responsibility Act</short-title></quote>. </text></section><section id="H241AFCE602004CACA8BCC3450B3BCAC1"><enum>2.</enum><header>Protecting suicide prevention lifeline from cybersecurity incidents</header><subsection id="H4BBBA8E557794FD3955460CFB683AD5C"><enum>(a)</enum><header>National suicide prevention lifeline program</header><text>Section 520E–3(b) of the Public Health Service Act (42 U.S.C. 290bb–36c(b)) is amended—</text><paragraph id="H2CD469044F7A41339C4FAA0196A486C8"><enum>(1)</enum><text>in paragraph (4), by striking <quote>and</quote> at the end;</text></paragraph><paragraph id="HBFDB06F3714D4A54BE8CF23E3CE39018"><enum>(2)</enum><text>in paragraph (5), by striking the period at the end and inserting <quote>; and</quote>; and</text></paragraph><paragraph id="H9E1F32B313904174A6378C407E758CB0"><enum>(3)</enum><text>by adding at the end the following:</text><quoted-block id="H637DD2290A9848A4B664C49822C9F3AC" style="OLC"><paragraph id="H23F2A6EF65BF4902BE1906685C1A1752"><enum>(6)</enum><text display-inline="yes-display-inline">coordinating with the Chief Information Security Officer of the Department of Health and Human Services to take such steps as may be necessary to ensure the program is protected from cybersecurity incidents and eliminates known cybersecurity vulnerabilities.</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection><subsection id="HFEDAFD2074CC40B6B0F1DBC2DE649430"><enum>(b)</enum><header>Reporting</header><text>Section 520E–3 of the Public Health Service Act (<external-xref legal-doc="usc" parsable-cite="usc/42/290bb-36c">42 U.S.C. 290bb–36c</external-xref>) is amended—</text><paragraph id="H1AE83DC8804B4D9EA025C38B2422AFC0"><enum>(1)</enum><text>by redesignating subsection (f) as subsection (g); and</text></paragraph><paragraph id="HE9D1B65780994A69B5CFEDB79AA7D85B"><enum>(2)</enum><text>by inserting after subsection (e) the following: </text><quoted-block id="HF7D82A79B5D542AE898F55FEDE369A8C" style="OLC"><subsection id="H49739C5129644141AAAA00CF88971374"><enum>(f)</enum><header>Cybersecurity reporting</header><paragraph id="H9AF56252D61D45F4A9ACB282719C1A55"><enum>(1)</enum><header>In general</header><subparagraph id="HD5ED487B651E404193B476B3E6E845C0"><enum>(A)</enum><header>In general</header><text>The program’s network administrator receiving Federal funding pursuant to subsection (a) shall report to the Assistant Secretary, in a manner that protects personal privacy, consistent with applicable Federal and State privacy laws—</text><clause id="H17C667F2A8534088BD90D2E76C348369"><enum>(i)</enum><text display-inline="yes-display-inline">any identified cybersecurity vulnerabilities to the program within 24 hours of identification of such a vulnerability; and</text></clause><clause id="HA3A08C5C8C5E4D2E929C9825F776AC34"><enum>(ii)</enum><text display-inline="yes-display-inline">any identified cybersecurity incidents to the program within 24 hours of identification of such incident.</text></clause></subparagraph><subparagraph id="H0A0E56775DA34F2FAE170CB663958755"><enum>(B)</enum><header>Local and regional crisis centers</header><text>Local and regional crisis centers participating in the program shall report to the program’s network administrator identified in subparagraph (A), in a manner that protects personal privacy, consistent with applicable Federal and State privacy laws—</text><clause id="H7F3E866F18664AD8BA0B51D0DC8880BC"><enum>(i)</enum><text>any identified cybersecurity vulnerabilities to the program within 24 hours of identification of such vulnerability; and</text></clause><clause id="HC49C785E4D8A42F590CB4A87009DB93C"><enum>(ii)</enum><text display-inline="yes-display-inline">any identified cybersecurity incidents to the program within 24 hours of identification of such incident.</text></clause></subparagraph></paragraph><paragraph id="HC4BBDC95A449493E962E07A9ABD97ECC"><enum>(2)</enum><header>Notification</header><text display-inline="yes-display-inline">If the program’s network administrator receiving funding pursuant to subsection (a) discovers, or is informed by a local or regional crisis center pursuant to paragraph (1)(B) of, a cybersecurity vulnerability or incident, within 24 hours of such discovery or receipt of information, such entity shall report the vulnerability or incident to the Assistant Secretary.</text></paragraph><paragraph id="H944BDA131C6B4E96A3E107ADA14C738B"><enum>(3)</enum><header>Clarification</header><subparagraph id="H711DE55386B84644AB914A31CC8F3E20"><enum>(A)</enum><header>Oversight</header><clause id="H22EA8F0B1D234DF882185BEC7CFD08AC"><enum>(i)</enum><header>Local and regional crisis center</header><text display-inline="yes-display-inline">Except as provided in clause (ii), local and regional crisis centers participating in the program shall oversee all technology each center employs in the provision of services as a participant in the program.</text></clause><clause id="H5CE91B8FA8474BECA6D9F8D2E1550CD9"><enum>(ii)</enum><header>Network administrator</header><text display-inline="yes-display-inline"> The program’s network administrator receiving Federal funding pursuant to subsection (a) shall oversee the technology each crisis center employs in the provision of services as a participant in the program if such oversight responsibilities are established in the applicable network participation agreement.</text></clause></subparagraph><subparagraph id="H5C9564F238764B9C8A36084829DAB939"><enum>(B)</enum><header>Supplement, not supplant</header><text>The cybersecurity incident reporting requirements under this subsection shall supplement, and not supplant, cybersecurity incident reporting requirements under other provisions of applicable Federal law that are in effect on the date of the enactment of the <short-title>9–8–8 Lifeline Cybersecurity Responsibility Act</short-title>.</text></subparagraph></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection><subsection id="H55FB7BB098394EB9912CA34EC1C3F1C7"><enum>(c)</enum><header>Study</header><text display-inline="yes-display-inline">Not later than 180 days after the date of the enactment of this Act, the Comptroller General of the United States shall—</text><paragraph id="HE58A9EF32E124B559012C151761DB22F"><enum>(1)</enum><text display-inline="yes-display-inline">conduct and complete a study that evaluates cybersecurity risks and vulnerabilities associated with the 9–8–8 National Suicide Prevention Lifeline; and</text></paragraph><paragraph id="H56CDE0DC0C5B43EBBE28952FE0AFC346"><enum>(2)</enum><text>submit a report of the findings of such study to the Committee on Energy and Commerce of the House of Representatives and the Committee on Health, Education, Labor, and Pensions of the Senate.</text></paragraph></subsection></section></legis-body></bill> 

