<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-GOE24245-0PL-HL-TTW"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 S4054 IS: Health Care Cybersecurity Improvement Act of 2024</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2024-03-22</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>118th CONGRESS</congress><session>2d Session</session><legis-num>S. 4054</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20240322">March 22, 2024</action-date><action-desc><sponsor name-id="S327">Mr. Warner</sponsor> introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSFI00">Committee on Finance</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require entities to meet minimum cybersecurity standards to be eligible for Medicare accelerated and advance payment programs if the reason for the need for such payments is due to a cybersecurity incident.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Health Care Cybersecurity Improvement Act of 2024</short-title></quote>.</text></section><section id="id758c43a6ee534bcf957ff9624e53a2cb"><enum>2.</enum><header>Modification of the Medicare hospital accelerated payment program</header><text display-inline="no-display-inline">Section 1815(e)(3) of the Social Security Act (<external-xref legal-doc="usc" parsable-cite="usc/42/1395g">42 U.S.C. 1395g(e)(3)</external-xref>) is amended—</text><paragraph commented="no" display-inline="no-display-inline" id="id54507a12d9c64e7ea28e9c6ada2a23ba"><enum>(1)</enum><text>by inserting <quote>(A)</quote> after <quote>(3)</quote>;</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id7a53b18fb38d40c980f8e12478cc9de3"><enum>(2)</enum><text>by inserting <quote>subparagraph (B) and</quote> after <quote>Subject to</quote>; and</text></paragraph><paragraph id="idc4673b85dd7f46a381d9163fb0a661bc"><enum>(3)</enum><text>by adding at the end the following new subparagraph:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idA8580D03976D419590B200CE60F13179"><subparagraph commented="no" display-inline="no-display-inline" id="idac0cc343743342ee85d21f035a45b057" indent="up1"><enum>(B)</enum><text>Beginning on the date that is 2 years after the date of enactment of the <short-title>Health Care Cybersecurity Improvement Act of 2024</short-title>, if the Secretary determines that a cybersecurity incident led to the disruptions of the operations of such hospital’s intermediary or the unusual circumstances to such hospital’s operation that resulted in such significant cash flow problems, accelerated payments shall not be made to such hospital under subparagraph (A) unless—</text><clause commented="no" display-inline="no-display-inline" id="id3da2447bfe004648a7fc52088a84be03"><enum>(i)</enum><text display-inline="yes-display-inline">such hospital meets minimum cybersecurity standards, as determined by the Secretary; and </text></clause><clause commented="no" display-inline="no-display-inline" id="id82a463a10b164d99ae89cdb8d55e0f44"><enum>(ii)</enum><text display-inline="yes-display-inline">in the case of operations of such hospital's intermediary, such intermediary meets minimum cybersecurity standards, as determined by the Secretary.</text></clause></subparagraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></section><section id="id67218077f9444621801c385238bca629"><enum>3.</enum><header>Modification of the Medicare Part B advance payment program</header><text display-inline="no-display-inline">Beginning on the date that is 2 years after the date of enactment of this Act, in the event of a cybersecurity incident, as determined by the Secretary of Health and Human Services, leading to the making of payments pursuant to the program described in section 421.214 of title 42, Code of Federal Regulations (or any successor regulation), such payments shall not be made to a provider of services or supplier unless—</text><paragraph id="id1b8f944aee654c9eb68ebfa2943f3cb3"><enum>(1)</enum><text>such provider of services or supplier meets minimum cybersecurity standards, as determined by the Secretary; and</text></paragraph><paragraph id="ide4a725fe748b4ea387fa15330737e2bb"><enum>(2)</enum><text>in the case of such provider's or supplier’s intermediary being the target of such incident, such intermediary meets minimum cybersecurity standards, as determined by the Secretary.</text></paragraph></section></legis-body></bill> 

