<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-ELT24126-7RW-KX-T1P"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 S3893 IS: Enhanced Cybersecurity for SNAP Act of 2024</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2024-03-07</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>118th CONGRESS</congress><session>2d Session</session><legis-num>S. 3893</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20240307">March 7, 2024</action-date><action-desc><sponsor name-id="S247">Mr. Wyden</sponsor> (for himself, <cosponsor name-id="S418">Mr. Fetterman</cosponsor>, and <cosponsor name-id="S373">Mr. Cassidy</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSAF00">Committee on Agriculture, Nutrition, and Forestry</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To amend the Food and Nutrition Act of 2008 to require the promulgation of cybersecurity and digital service regulations relating to the use of EBT cards under the supplemental nutrition assistance program, and for other purposes.</official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause"><section section-type="section-one" id="S1"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Enhanced Cybersecurity for SNAP Act of 2024</short-title></quote>.</text></section><section commented="no" display-inline="no-display-inline" id="id37d79ebcaeef48f8be9b4b90eee03daf"><enum>2.</enum><header>Enhanced cybersecurity for EBT cards</header><text display-inline="no-display-inline">Section 7(h) of the Food and Nutrition Act of 2008 (<external-xref legal-doc="usc" parsable-cite="usc/7/2016">7 U.S.C. 2016(h)</external-xref>) is amended by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idA96BD922268443ED97B4F5215D64C772"><paragraph id="idc2efbceacb0f4454acd526e153c3faad"><enum>(15)</enum><header>Cybersecurity of EBT cards</header><subparagraph commented="no" display-inline="no-display-inline" id="id20e8a4e1328043ba9bb47710592e0176"><enum>(A)</enum><header display-inline="yes-display-inline">Definitions</header><text>In this paragraph:</text><clause commented="no" display-inline="no-display-inline" id="id6edcad724ac94cd491da325d703548db"><enum>(i)</enum><header display-inline="yes-display-inline">Chip-enabled</header><subclause commented="no" display-inline="no-display-inline" id="id5644b50ea265458282a54ea34c4a7551"><enum>(I)</enum><header>In general</header><text display-inline="yes-display-inline">The term <term>chip-enabled</term>, with respect to a payment card, means a payment card that uses industry standard secure payment technology, as identified by the Administrator of the Food and Nutrition Service in consultation with the Secretary of the Treasury and the Director of the National Institute of Standards and Technology, that—</text><item id="idda28eeaef1c54e45810fb8505661851f"><enum>(aa)</enum><text>provides for secure card-based payment; and</text></item><item id="id32c02c60870d4ff99887d7e407231f30"><enum>(bb)</enum><text>is resistant to cloning.</text></item></subclause><subclause id="idafff5d918d46465f868b0103d3baf174"><enum>(II)</enum><header>EMV chip</header><text>The Administrator of the Food and Nutrition Service, in consultation with the Secretary of the Treasury and the Director of the National Institute of Standards and Technology, shall consider whether the secure payment technology described in subclause (I) should meet the standards published by EMVCo for contact and contactless payments.</text></subclause></clause><clause commented="no" display-inline="no-display-inline" id="id9523f00f9e1e4f9695b1f7abd701b2c1"><enum>(ii)</enum><header>Mobile friendly</header><text>The term ‘mobile friendly’ has the meaning given the term in section 3559(b) of title 44, United States Code.</text></clause><clause commented="no" display-inline="no-display-inline" id="idf3b8dc3d58e4477b93a879f798e7ba18"><enum>(iii)</enum><header>NIST PIN and password standards</header><text>The term <quote>NIST PIN and password standards</quote> means the PIN and password standards described in Special Publication 800–63B entitled <quote>Digital Identity Guidelines</quote> (or a successor document) of the National Institute of Standards and Technology. </text></clause><clause commented="no" display-inline="no-display-inline" id="id1e8b519b45fa490fb84fc5e8c37ab936"><enum>(iv)</enum><header>PIN</header><text>The term <quote>PIN</quote> has the meaning given the term <quote>personal identification number (PIN)</quote> in section 271.2 of title 7, Code of Federal Regulations (or successor regulations).</text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id4222c7f8cbab42df8001e5adc18f0647"><enum>(B)</enum><header display-inline="yes-display-inline">Regulations</header><clause id="idb24d7c0b99514ea8a9158dc91736fc16"><enum>(i)</enum><header>In general</header><text>Not later than 2 years after the date of enactment of this paragraph, the Secretary shall promulgate, and every 5 years thereafter, the Secretary shall review and update as necessary, cybersecurity and digital service regulations relating to EBT cards and mobile payments under the supplemental nutrition assistance program, including, at a minimum, to ensure that cybersecurity measures for EBT cards and mobile payments keep pace with security safeguards used by the private sector and required by Federal agencies for credit, debit, and other payment cards and mobile payments.</text></clause><clause id="id7c2843bf28f84e01b0642fbe1134d962"><enum>(ii)</enum><header>Requirements</header><text>The Secretary shall ensure that the cybersecurity and digital service regulations described in clause (i) require the following:</text><subclause id="ide0c4ab35555d4cb694f0037d7eca91a7"><enum>(I)</enum><item commented="no" display-inline="yes-display-inline" id="idc906dc6283774b199b15d1feebe80531"><enum>(aa)</enum><text>Each State shall operate the user interfaces listed on the list of required user interfaces maintained by the Secretary under item (dd)(AA), in accordance with this subclause, 1 or more user interfaces of which households in the State may, at the election of the applicable household, use to manage the EBT account of the applicable household.</text></item><item commented="no" display-inline="no-display-inline" indent="up1" id="id7d80cf8e88a3447788b5b737e265619c"><enum>(bb)</enum><subitem commented="no" display-inline="yes-display-inline" id="id33dee31a9ac7401e95b82f3efc22a7cd"><enum>(AA)</enum><text>A State may operate other user interfaces under item (aa) in addition to the required user interfaces on the list maintained by the Secretary under item (dd)(AA).</text></subitem><subitem commented="no" display-inline="no-display-inline" indent="up1" id="idbdd7307cb67d417db421198fa435e51a"><enum>(BB)</enum><text>Any web-based online portal operated by a State as a user interface shall be mobile friendly.</text></subitem></item><item commented="no" display-inline="no-display-inline" id="idd2d12077ba34451ba4440cc15146edaa" indent="up1"><enum>(cc)</enum><text>Each user interface offered by a State under items (aa) and (bb), as applicable, shall—</text><subitem id="idb61ee18bda674f5c91ccd1e14885a99c"><enum>(AA)</enum><text>provide information in each language in which the State agency is required to make material available pursuant to section 272.4(b) of title 7, Code of Federal Regulations (or successor regulations); </text></subitem><subitem id="idc67715390257487fa43fe7d25b4c8d5a"><enum>(BB)</enum><text>be available to households at least 99 percent of the time; and</text></subitem><subitem commented="no" display-inline="no-display-inline" id="idd582f2b90d5d4d2a865ed7acabf8cb4c"><enum>(CC)</enum><text display-inline="yes-display-inline">include any other features required by the Secretary.</text></subitem></item><item commented="no" display-inline="no-display-inline" indent="up1" id="id8246a2254089411fa36b4c64edc64344"><enum>(dd)</enum><subitem commented="no" display-inline="yes-display-inline" id="id99861e4ef40549e4819a38f48815f878"><enum>(AA)</enum><text>The Secretary shall maintain a list of required user interfaces for purposes of item (aa), which may include a web-based online portal and a mobile application.</text></subitem><subitem commented="no" display-inline="no-display-inline" indent="up1" id="id11a9559e4c8947cd8fdf28d6f15aac22"><enum>(BB)</enum><text>The list under subitem (AA) shall include an application programming interface through which at least 1 user interface offered by a State under item (aa) allows households to delegate access to some or all account features identified by the Secretary to third-party provided software. No fee shall be charged to any party for the use of that application programming interface. </text></subitem><subitem commented="no" display-inline="no-display-inline" indent="up1" id="id7c58d88a727446de86c471be62a1ecdc"><enum>(CC)</enum><text>During the 10-year period following the date on which the regulations promulgated pursuant to clause (i) become final, unless the Secretary extends that period, the Secretary shall maintain on the list under subitem (AA) the following user interfaces: text message, voice telephone service, and a nondigital user interface that does not require the use of a phone or computer by the household.</text></subitem></item></subclause><subclause id="ideb77280975f34db0a989b9bd0e84c6e0"><enum>(II)</enum><item commented="no" display-inline="yes-display-inline" id="id34e7973bdf534d09a05360db46a79849"><enum>(aa)</enum><text>Each State shall provide households on an opt-in basis—</text><subitem commented="no" display-inline="no-display-inline" id="ida4f71126cae541fe82ef22bd43add874" indent="up1"><enum>(AA)</enum><text display-inline="yes-display-inline">through each digital user interface offered under subclause (I), timely electronic notice of transactions using the EBT account of the household; and </text></subitem><subitem commented="no" display-inline="no-display-inline" id="id75d82915e7564cea940540317da48692" indent="up1"><enum>(BB)</enum><text display-inline="yes-display-inline">through each user interface offered under subclause (I), access to, including the ability to search, historical transactions for not less than the preceding 12 months. </text></subitem></item><item commented="no" display-inline="no-display-inline" id="idf2251eed5ef54f8a94cbc286c3d6f0ec" indent="up1"><enum>(bb)</enum><text display-inline="yes-display-inline">Transaction information under subitems (AA) and (BB) of item (aa) shall include the amount of the transaction, the merchant for the transaction, the city and State of the merchant for an in-person transaction, and the delivery address or collection address for an online transaction. </text></item><item id="id0222f056be7641aeafa082929807a19a" indent="up1"><enum>(cc)</enum><text>Each State shall offer households the ability, through each user interface offered under subclause (I), to report a fraudulent transaction to the State.</text></item><item id="id315b20a98550450eadcfd7e17ec0171e" indent="up1"><enum>(dd)</enum><text>A State shall not require a household to respond to or acknowledge a notice of transaction delivered pursuant to item (aa)(AA).</text></item><item id="id61a6b89eadf540fe9610e686b723c080" indent="up1"><enum>(ee)</enum><text>A State shall notify a household that has received reimbursement for EBT card fraud pursuant to section 501(b)(2) of division HH of the Consolidated Appropriations Act, 2023 (<external-xref legal-doc="usc" parsable-cite="usc/7/2016a">7 U.S.C. 2016a(b)(2)</external-xref>), of the ability of the household to opt in to restricting the use of the EBT card as described in subclause (III) and of the remaining funds that may be reimbursed if the household experiences fraud again. </text></item></subclause><subclause id="iddc37136d1dc44b49aedfa3ebf152d3e0"><enum>(III)</enum><text>Each State shall provide households issued an EBT card the ability, through each user interface offered under subclause (I)—</text><item id="id203635067f764cbc80271befdf8fc431"><enum>(aa)</enum><text>to make the use of that EBT card for online transactions workable only through virtual card numbers or other tokenization technology, such as through a mobile payment service, which shall require a different virtual card number for each individual online merchant;</text></item><item id="id9dfd224b20b1480688d6c6ab6e865fb7"><enum>(bb)</enum><text>to freeze and unfreeze the EBT account of the household for transactions in which the card number printed on the EBT card is manually entered, either for an in-person transaction or an online transaction; and</text></item><item id="id9091e22837e2435d8fb2304c12e0a1f9"><enum>(cc)</enum><text>to check the enrollment status of the household, including the date on which the household is required to apply for recertification. </text></item></subclause><subclause commented="no" display-inline="no-display-inline" id="idfffd803eecca4fb298d9ba2e9832bdb1"><enum>(IV)</enum><text display-inline="yes-display-inline">The requirements described in items (aa) and (bb) of subclause (III) shall terminate 5 years after the date on which the regulation promulgated pursuant to that subclause becomes final, unless the Secretary extends that period. </text></subclause><subclause commented="no" display-inline="no-display-inline" id="id47169258d2bb4ecbb524f4c59fae8bde"><enum>(V)</enum><text>A State may opt to make ineffective the use of the card number printed on the EBT card to complete an online transaction, and require online transactions to occur only in accordance with subclause (III)(aa).</text></subclause><subclause id="ida322d92de180469cb01d5b0608e1ef69"><enum>(VI)</enum><text>Not later than 2 years after the date on which the regulations promulgated pursuant to clause (i) become final, States shall begin issuing chip-enabled EBT cards.</text></subclause><subclause id="id3cc5e2d0a51547e392b8050679f13ecb"><enum>(VII)</enum><text>Not later than 4 years after the date on which the regulations promulgated pursuant to clause (i) become final, States may not issue new EBT cards with magnetic stripes.</text></subclause><subclause id="id331935a26dd84fb1804e551015e42732"><enum>(VIII)</enum><text>Not later than 5 years after the date on which the regulations promulgated pursuant to clause (i) become final, States shall be required to reissue any existing valid EBT cards with magnetic stripes as chip-enabled EBT cards without magnetic stripes.</text></subclause><subclause id="idf6e97a2a6e9547419816ff7bcaa85479"><enum>(IX)</enum><text>In the case of a chip-enabled EBT card reissued pursuant to any of subclauses (VI) through (VIII), absent suspicion of fraud, as applicable, a State shall—</text><item commented="no" display-inline="no-display-inline" id="ide69b7ffb7a584123b1e9ed90ea069e69"><enum>(aa)</enum><text display-inline="yes-display-inline">reissue a new chip-enabled EBT card; and</text></item><item commented="no" display-inline="no-display-inline" id="idec6aee94960548beb1c0dad0a3a324bd"><enum>(bb)</enum><text>deactivate the current chip-enabled EBT card on the date that is the earlier of—</text><subitem commented="no" display-inline="no-display-inline" id="id4f8260bd15cb4c20a29d24a97f5ec2f8"><enum>(AA)</enum><text display-inline="yes-display-inline">the date on which the new chip-enabled EBT card is activated; and</text></subitem><subitem commented="no" display-inline="no-display-inline" id="id40459bd5d8254816980fe4902cfa8b0e"><enum>(BB)</enum><text>30 days after the date on which the new chip-enabled EBT card is sent to the household. </text></subitem></item></subclause></clause><clause commented="no" display-inline="no-display-inline" id="id4a290ce58d1f41c490a398010dd04557"><enum>(iii)</enum><header>Sunset for requirement to use chip technology</header><text>Under the cybersecurity regulations described in clause (i), all EBT cards issued during the 5-year period following the deadline for carrying out clause (ii)(VIII) shall be chip-enabled, unless the Secretary extends that period. </text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id7ec8516861df4d86bab089d4430978ae"><enum>(C)</enum><header>Reimbursements</header><text>Each State upgrading EBT cards to comply with the regulations promulgated under subparagraph (B)(i) shall receive reimbursement from the Secretary in an amount determined by the Secretary to cover all reasonable costs incurred by the State, including—</text><clause id="id05a86e53a4a74e7faeba6b7597e51f65"><enum>(i)</enum><text>the 1-time up-front costs paid by the State to card vendors; </text></clause><clause id="id856e7ffaf98f4f51a36b9131aa287aa0"><enum>(ii)</enum><text>the additional annual fees associated with chip-enabled cards paid by States to card vendors; and</text></clause><clause commented="no" display-inline="no-display-inline" id="idd753ea67c9254f609b182dc3cf179858"><enum>(iii)</enum><text>postage or other delivery-related costs.</text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idf53b1dd452624ef3bbf9e1ea93e98e74"><enum>(D)</enum><header>Prohibition on password and PIN requirements inconsistent with federal cybersecurity standards</header><text>Beginning 60 days after the date of enactment of this paragraph, a State agency may not require, with respect to a PIN for use of an EBT card or a password for access to an online account or mobile application managing the EBT card—</text><clause commented="no" display-inline="no-display-inline" id="id14810b0811334e029964a02855942500"><enum>(i)</enum><text display-inline="yes-display-inline">that the PIN or password be periodically changed in circumstances that are prohibited by the NIST PIN and password standards; or </text></clause><clause commented="no" display-inline="no-display-inline" id="idb7742d45aacd4fe89e675a35db9259a0"><enum>(ii)</enum><text display-inline="yes-display-inline">that the password meet complexity requirements that are prohibited by the NIST PIN and password standards.</text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idef733f75ed2f4878932fbc0c5a8872bf"><enum>(E)</enum><header>Grant program for chip-enabled EBT cards</header><clause commented="no" display-inline="no-display-inline" id="id41c8d6ca9de848fe85399debe6c909e7"><enum>(i)</enum><header display-inline="yes-display-inline">Definitions</header><text>In this subparagraph:</text><subclause commented="no" display-inline="no-display-inline" id="id1afcc48099734e0bb6cd37faa933c2fe"><enum>(I)</enum><header>Administering entity</header><text>The term <term>administering entity</term> means an entity awarded a grant under clause (ii) to provide subgrants to eligible entities.</text></subclause><subclause commented="no" display-inline="no-display-inline" id="ide75095c8d46d4928aa367a49f6e7b59e"><enum>(II)</enum><header display-inline="yes-display-inline">Eligible entity</header><text>The term <term>eligible entity</term> means—</text><item commented="no" display-inline="no-display-inline" id="id79bbfe2f45da4afcb2048760c699eafd"><enum>(aa)</enum><text display-inline="yes-display-inline">an entity described in paragraph (1) or (3) of section 3(o) that—</text><subitem commented="no" display-inline="no-display-inline" id="idfe423a0d701a494fac636f8ccd5fcfae"><enum>(AA)</enum><text display-inline="yes-display-inline">is authorized to participate in the supplemental nutrition assistance program under section 9;</text></subitem><subitem commented="no" display-inline="no-display-inline" id="ide3199b3f92f741c1a0e56ed936d6f791"><enum>(BB)</enum><text>does not have payment terminals that accept chip-enabled EBT cards; and</text></subitem><subitem commented="no" display-inline="no-display-inline" id="ided2ae78c2b14414a80696aafae8b8e8a"><enum>(CC)</enum><text>is located in an area with limited grocery access, as determined by the Secretary; and</text></subitem></item><item commented="no" display-inline="no-display-inline" id="idafac05eb918347b39550edb793aedb18"><enum>(bb)</enum><text>an entity described in paragraph (2), (4), or (5) of section 3(o) that meets the requirements described in subitems (AA) and (BB) of item (aa).</text></item></subclause></clause><clause id="idab136a19c1db4feda3424521c999bc00"><enum>(ii)</enum><header>Grants</header><text>The Secretary shall establish a grant program to award a grant to an administering entity to provide subgrants to eligible entities to upgrade to chip-compatible payment terminals that support contact and contactless payment card technology.</text></clause></subparagraph><subparagraph id="idb44d5c5d53864587bda43a7dfec0a449"><enum>(F)</enum><header>Data collection</header><text>The Secretary shall—</text><clause commented="no" display-inline="no-display-inline" id="id49254752be5449a0ab5d46472d2668bd"><enum>(i)</enum><text display-inline="yes-display-inline">collect, and publish on the website of the Department of Agriculture, data on—</text><subclause id="id2fca34f38aa243f884d11767a771e735"><enum>(I)</enum><text>the length of time each user interface offered by each State pursuant to subparagraph (B)(ii)(I) was unavailable for use, including due to technical problems or maintenance needs; and </text></subclause><subclause commented="no" display-inline="no-display-inline" id="idfa9ece1a5427492c9d2c9935163e8d78"><enum>(II)</enum><text display-inline="yes-display-inline">cybersecurity measures adopted for EBT cards in each State; and </text></subclause></clause><clause commented="no" display-inline="no-display-inline" id="idd7906360a0c345dfa44bf8ab88ad67a7"><enum>(ii)</enum><text display-inline="yes-display-inline">maintain and annually update the data collected under clause (i) to support States in implementing any regulations promulgated pursuant to subparagraph (B)(i). </text></clause></subparagraph><subparagraph id="idedceca9dff564845b3ae31a797d621e0"><enum>(G)</enum><header>Public report</header><clause commented="no" display-inline="no-display-inline" id="idda20945e565248b0bd27f12ce7a97cb7"><enum>(i)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 1 year after the date of enactment of this paragraph, and every 2 years thereafter, the Secretary shall submit to the Committees on Appropriations and Agriculture, Nutrition, and Forestry of the Senate and the Committees on Appropriations and Agriculture of the House of Representatives, and make publicly available on the website of the Department of Agriculture, a report that—</text><subclause id="id32d38a1abc6b4cc383ee67b91c17342e"><enum>(I)</enum><text>identifies trends relating to the theft of benefits, including the frequency of theft of benefits and the location of those thefts;</text></subclause><subclause id="idc1448ab96d3c4036a7256b0b0e7cc465"><enum>(II)</enum><text>evaluates the effectiveness of existing cybersecurity regulations for the supplemental nutrition assistance program, including identifying ineffective measures and the compliance burden borne by individual benefit recipients; </text></subclause><subclause id="id3c458929ece941de92cf498687f0bea9"><enum>(III)</enum><text>describes the efforts of States—</text><item id="id2a09f1f128874d89a788cc7c84b55afb"><enum>(aa)</enum><text>to update cybersecurity measures for EBT cards; and</text></item><item id="id00779d71b0d34605bde9a813192bd701"><enum>(bb)</enum><text>to reimburse stolen benefits; and</text></item></subclause><subclause id="idbf1636e8188a451998529dd456091c2c"><enum>(IV)</enum><text>examines usability issues of EBT cards, including issues that present barriers to households using benefits or affect fraud prevention goals. </text></subclause></clause><clause id="id9ea029ae3e3b4ca490910eed86bb3fba"><enum>(ii)</enum><header>Restricted annex</header><text>The report under clause (i) may include a nonpublicly available annex containing classified or law enforcement-sensitive information.</text></clause></subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></section><section commented="no" display-inline="no-display-inline" id="id4f112a1a88c740639306188d5f85431c"><enum>3.</enum><header>Ensuring no loss of access to benefits due to EBT card damage, loss, or fraud</header><text display-inline="no-display-inline">Section 7(h)(7) of the Food and Nutrition Act of 2008 (<external-xref legal-doc="usc" parsable-cite="usc/7/2016">7 U.S.C. 2016(h)(7)</external-xref>) is amended—</text><paragraph commented="no" display-inline="no-display-inline" id="id9da6a7e70afc46288d2420455804cff2"><enum>(1)</enum><text>by striking <quote>Regulations</quote> and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idAC4373F1974D43AB9CE110430CB53464"><subparagraph commented="no" display-inline="no-display-inline" id="idc643405305db45ad9086d25d4ac67ea9"><enum>(A)</enum><header>In general</header><text>Regulations</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idb77de4e03dbe4cb086f96192caaa6374"><enum>(2)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idC4F74403017D4367A9CE5A71CF3DBE58"><subparagraph commented="no" display-inline="no-display-inline" id="id066745dd295e45f88cf97528826b6510"><enum>(B)</enum><header>Ensuring no loss of access to benefits due to EBT card damage, loss, or fraud</header><text>Not later than 180 days after the date of enactment of the <short-title>Enhanced Cybersecurity for SNAP Act of 2024</short-title>, the Secretary shall promulgate regulations requiring the following:</text><clause id="idca69f66ea8b84f08a53e4f052619ae93"><enum>(i)</enum><text>If an EBT card is damaged, no longer functions properly, is stolen, or is frozen due to fraud, the applicable State shall take the necessary steps to ensure that the household receives a replacement card, either by mail or in person, as selected by the household, not later than 3 business days after the household submits to the State a request for a replacement EBT card.</text></clause><clause id="id58058fabe45d48618d41ae81743bee2b"><enum>(ii)</enum><text>A State shall not require, but shall offer as an option, in-person collection of a new or replacement EBT card.</text></clause></subparagraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></section><section commented="no" display-inline="no-display-inline" id="id50e491615a9f4988964ebf3574ef728b"><enum>4.</enum><header>No replacement fees for certain EBT cards</header><text display-inline="no-display-inline">Section 7(h)(8)(A) of the Food and Nutrition Act of 2008 (<external-xref legal-doc="usc" parsable-cite="usc/7/2016">7 U.S.C. 2016(h)(8)(A)</external-xref>) is amended—</text><paragraph commented="no" display-inline="no-display-inline" id="id82E8E0430A814C5DAFA5042835DF8533"><enum>(1)</enum><text display-inline="yes-display-inline">by striking <quote>A State agency</quote> and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id4646A95C51D84C24B1ABD4806C2ADCAE"><clause commented="no" display-inline="no-display-inline" id="idF066B0558CB1415291F436C23ED160E7"><enum>(i)</enum><header>In general</header><text>Except as provided in clause (ii), a State agency</text></clause><after-quoted-block>; and</after-quoted-block></quoted-block></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id41C7569C48EF48F6A83A157E2BA2D326"><enum>(2)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id81341447C41940D08176073E2F5349BB"><clause commented="no" display-inline="no-display-inline" id="id92D1A76AA1DB43289E21F045814BE5C5"><enum>(ii)</enum><header>Exceptions</header><text>Beginning 60 days after the date of enactment of the <short-title>Enhanced Cybersecurity for SNAP Act of 2024</short-title>, a State agency may not collect a charge under clause (i) if the replacement of the EBT card is due to—</text><subclause commented="no" display-inline="no-display-inline" id="id5B1B5FC68297463E89218D54B952C091"><enum>(I)</enum><text display-inline="yes-display-inline">the EBT card malfunctioning;</text></subclause><subclause commented="no" display-inline="no-display-inline" id="idAA8349F417154C788E1B8465FE4C1321"><enum>(II)</enum><text display-inline="yes-display-inline">suspected or reported fraud relating to that EBT card by an individual outside of the household to which the EBT card belongs;</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id9136E66B394E4A3DBEAF9FE2AC8E5402"><enum>(III)</enum><text display-inline="yes-display-inline">the expiration of the EBT card; or</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id3782119E565D456CA7A76A17FBDF7C5D"><enum>(IV)</enum><text display-inline="yes-display-inline">required replacement of the EBT card in compliance with regulations promulgated pursuant to paragraph (15)(B).</text></subclause></clause><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></section><section commented="no" display-inline="no-display-inline" section-type="subsequent-section" id="id1417611eb5ad4a1e82084b94e9802fb6"><enum>5.</enum><header>Requirement for retailer use of chip-enabled payment terminals as a condition of SNAP participation</header><text display-inline="no-display-inline">Section 9(a) of the Food and Nutrition Act of 2008 (<external-xref legal-doc="usc" parsable-cite="usc/7/2018">7 U.S.C. 2018(a)</external-xref>) is amended—</text><paragraph commented="no" display-inline="no-display-inline" id="idb4450ebd54bb4492b4c75675e70c913f"><enum>(1)</enum><text>in paragraph (2)—</text><subparagraph commented="no" display-inline="no-display-inline" id="id991d6d32143d438995349651a443a946"><enum>(A)</enum><text display-inline="yes-display-inline">by striking <quote>(2) The Secretary</quote> and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id784F58F6B5984EB393E0AF319DFB0FA1"><paragraph commented="no" display-inline="no-display-inline" id="idae1e38b8137b4bcb9bcbdb8b03ad38e2"><enum>(2)</enum><header>Regulations</header><text>The Secretary</text></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id001b350487fb4fe4a85fb166c932ccfd"><enum>(B)</enum><text>by indenting the margins of subparagraphs (A) and (B) appropriately;</text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id2bf2efc2c306439096a9bb1a7a1a839a"><enum>(2)</enum><text>by indenting the margin of paragraph (3) appropriately; and</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ida9c00ad49785437f90f31e7cda433dbc"><enum>(3)</enum><text display-inline="yes-display-inline">by adding at the end the following: </text><quoted-block style="OLC" display-inline="no-display-inline" id="id451E201B417345458B40AB0120D9AF3A"><paragraph commented="no" display-inline="no-display-inline" id="id944d75a6ec5f4af5a85f643130afe784"><enum>(5)</enum><header>Chip-enabled payment terminals</header><text>Beginning not later than 180 days after the date on which the regulations promulgated pursuant to section 7(h)(15)(B)(i) become final, the Secretary shall require retail food stores and wholesale food concerns seeking authorization or reauthorization to accept and redeem benefits under the supplemental nutrition assistance program to have a chip-enabled (as defined in section 7(h)(15)(A)) payment terminal at each retail location of the retail food store or wholesale food concern.</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></section><section id="id37abc21787624b449b800ca0eb573d5e"><enum>6.</enum><header>Report</header><subsection commented="no" display-inline="no-display-inline" id="idfd3d1d03b094490285f7ebdd77bc5625"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Not later than 1 year after the date of enactment of this Act, the Secretary of Agriculture shall submit to the Committees on Appropriations and Agriculture, Nutrition, and Forestry of the Senate and the Committees on Appropriations and Agriculture of the House of Representatives, and make publicly available on the website of the Department of Agriculture, a report on the security of EBT cards (as defined in section 3 of the Food and Nutrition Act of 2008 (<external-xref legal-doc="usc" parsable-cite="usc/7/2012">7 U.S.C. 2012</external-xref>)) issued in the Commonwealth of Puerto Rico, including— </text><paragraph commented="no" display-inline="no-display-inline" id="idca46cdf158384f1e86b13f9d4da8e7dc"><enum>(1)</enum><text>the resistance of those EBT cards to cloning; and</text></paragraph><paragraph id="id9eada43e5371467bb8e7eccad4de6df6"><enum>(2)</enum><text>if appropriate, recommendations for improving the security of the electronic benefit transfer system against EBT card cloning-based fraud.</text></paragraph></subsection><subsection id="id17ce177236c540fd84385f0791d1ff35"><enum>(b)</enum><header>Restricted annex</header><text>The report under subsection (a) may include a nonpublicly available annex containing classified or law enforcement-sensitive information.</text></subsection></section><section commented="no" display-inline="no-display-inline" id="id0933750356ee440bb114dd2d6dcc231c"><enum>7.</enum><header>Conforming amendments</header><text display-inline="no-display-inline">Section 501 of division HH of the Consolidated Appropriations Act, 2023 (<external-xref legal-doc="usc" parsable-cite="usc/7/2016a">7 U.S.C. 2016a</external-xref>), is amended—</text><paragraph commented="no" display-inline="no-display-inline" id="id39c9b4e021084880b7482cf1ef1334ee"><enum>(1)</enum><text>in subsection (a)—</text><subparagraph commented="no" display-inline="no-display-inline" id="id296d024a2f0540e19e4e1acce117a95e"><enum>(A)</enum><text display-inline="yes-display-inline">by striking paragraphs (1) and (2);</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id240fcda9f1d34546b8ba09c168f6a301"><enum>(B)</enum><text>by redesignating paragraphs (3) through (5) as paragraphs (1) through (3), respectively; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id404cb6a314a3428eb968573bd38017b7"><enum>(C)</enum><text>in paragraph (3) (as so redesignated)—</text><clause commented="no" display-inline="no-display-inline" id="id2b116076e0d94123bd080c1116019338"><enum>(i)</enum><text>in subparagraph (B), by adding <quote>and</quote> at the end;</text></clause><clause commented="no" display-inline="no-display-inline" id="id9a04bd2d664d497cb0f8bdd24c02d404"><enum>(ii)</enum><text>by striking subparagraph (C); and</text></clause><clause commented="no" display-inline="no-display-inline" id="id0ec9a4ee36bc4f03b0a71ddea7e446c0"><enum>(iii)</enum><text>by redesignating subparagraph (D) as subparagraph (C); and</text></clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id52f42541be7343aeb6c06d5448d329d1"><enum>(2)</enum><text>in subsection (b)—</text><subparagraph commented="no" display-inline="no-display-inline" id="id10652177a5644df6b14cee5faba97280"><enum>(A)</enum><text>in paragraph (1)—</text><clause commented="no" display-inline="no-display-inline" id="ide2eafd9340664015a432b5743d7deafc"><enum>(i)</enum><text>in subparagraph (A)(vi), by striking <quote>measures</quote> and all that follows through <quote>(a)(1)</quote> and inserting <quote>measures</quote>;</text></clause><clause commented="no" display-inline="no-display-inline" id="idc4b7905d0fae43ab80002a1f34559e20"><enum>(ii)</enum><text>in subparagraph (B), by adding <quote>and</quote> at the end;</text></clause><clause commented="no" display-inline="no-display-inline" id="id56764f4881a849558082e5dc01c772c7"><enum>(iii)</enum><text>in subparagraph (C), by striking <quote>and</quote> at the end; and</text></clause><clause commented="no" display-inline="no-display-inline" id="id84e4e7dfaa524fe0bec4a58207ae9589"><enum>(iv)</enum><text>by striking subparagraph (D); and</text></clause></subparagraph><subparagraph id="idfa24deba0f014b3285252e8166d06a1e"><enum>(B)</enum><text>in paragraph (3), by striking <quote>subsection (a)(3)</quote> and inserting <quote>subsection (a)(1)</quote>.</text></subparagraph></paragraph></section></legis-body></bill> 

