[House Hearing, 118 Congress]
[From the U.S. Government Publishing Office]


                  PROTECTING CRITICAL INFRASTRUCTURE FROM 
                   CYBER ATTACKS: EXAMINING EXPERTISE OF 
                   SECTOR-SPECIFIC AGENCIES

=======================================================================

                                HEARING

                               BEFORE THE

                        SUBCOMMITTEE ON OVERSIGHT AND 
                              INVESTIGATIONS

                                 OF THE

                    COMMITTEE ON ENERGY AND COMMERCE
                        HOUSE OF REPRESENTATIVES

                    ONE HUNDRED EIGHTEENTH CONGRESS

                             FIRST SESSION

                               __________

                              MAY 16, 2023

                               __________

                           Serial No. 118-37


     Published for the use of the Committee on Energy and Commerce
     
[GRAPHIC NOT AVAILABLE IN TIFF FORMAT]     

                   govinfo.gov/committee/house-energy
                        energycommerce.house.gov
                        
                                __________

                   U.S. GOVERNMENT PUBLISHING OFFICE                    
56-055 PDF                  WASHINGTON : 2025                  
          
-----------------------------------------------------------------------------------     
                        
                    COMMITTEE ON ENERGY AND COMMERCE

                   CATHY McMORRIS RODGERS, Washington
                                  Chair
MICHAEL C. BURGESS, Texas            FRANK PALLONE, Jr., New Jersey
ROBERT E. LATTA, Ohio                  Ranking Member
BRETT GUTHRIE, Kentucky              ANNA G. ESHOO, California
H. MORGAN GRIFFITH, Virginia         DIANA DeGETTE, Colorado
GUS M. BILIRAKIS, Florida            JAN SCHAKOWSKY, Illinois
BILL JOHNSON, Ohio                   DORIS O. MATSUI, California
LARRY BUCSHON, Indiana               KATHY CASTOR, Florida
RICHARD HUDSON, North Carolina       JOHN P. SARBANES, Maryland
TIM WALBERG, Michigan                PAUL TONKO, New York
EARL L. ``BUDDY'' CARTER, Georgia    YVETTE D. CLARKE, New York
JEFF DUNCAN, South Carolina          TONY CARDENAS, California
GARY J. PALMER, Alabama              RAUL RUIZ, California
NEAL P. DUNN, Florida                SCOTT H. PETERS, California
JOHN R. CURTIS, Utah                 DEBBIE DINGELL, Michigan
DEBBBIE LESKO, Arizona               MARC A. VEASEY, Texas
GREG PENCE, Indiana                  ANN M. KUSTER, New Hampshire
DAN CRENSHAW, Texas                  ROBIN L. KELLY, Illinois
JOHN JOYCE, Pennsylvania             NANETTE DIAZ BARRAGAN, California
KELLY ARMSTRONG, North Dakota, Vice  LISA BLUNT ROCHESTER, Delaware
    Chair                            DARREN SOTO, Florida
RANDY K. WEBER, Sr., Texas           ANGIE CRAIG, Minnesota
RICK W. ALLEN, Georgia               KIM SCHRIER, Washington
TROY BALDERSON, Ohio                 LORI TRAHAN, Massachusetts
RUSS FULCHER, Idaho                  LIZZIE FLETCHER, Texas
AUGUST PFLUGER, Texas
DIANA HARSHBARGER, Tennessee
MARIANNETTE MILLER-MEEKS, Iowa
KAT CAMMACK, Florida
JAY OBERNOLTE, California
                                 ------                                

                           Professional Staff

                      NATE HODSON, Staff Director
                   SARAH BURKE, Deputy Staff Director
               TIFFANY GUARASCIO, Minority Staff Director
              Subcommittee on Oversight and Investigations

                      H. MORGAN GRIFFITH, Virginia
                                 Chairman
MICHAEL C. BURGESS, Texas            KATHY CASTOR, Florida
BRETT GUTHRIE, Kentucky                Ranking Member
JEFF DUNCAN, South Carolina          DIANA DeGETTE, Colorado
GARY J. PALMER, Alabama              JAN SCHAKOWSKY, Illinois
DEBBIE LESKO, Arizona, Vice Chair    PAUL TONKO, New York
DAN CRENSHAW, Texas                  RAUL RUIZ, California
KELLY ARMSTRONG, North Dakota        SCOTT H. PETERS, California
KAT CAMMACK, Florida                 FRANK PALLONE, Jr., New Jersey (ex 
CATHY McMORRIS RODGERS, Washington       officio)
    (ex officio)
                            
                            C O N T E N T S

                              ----------                              
                                                                   Page
Hon. H. Morgan Griffith, a Representative in Congress from the 
  Commonwealth of Virginia, opening statement....................     1
    Prepared statement...........................................     4
Hon. Kathy Castor, a Representative in Congress from the State of 
  Florida, opening statement.....................................    10
    Prepared statement...........................................    12
Hon. Cathy McMorris Rodgers, a Representative in Congress from 
  the State of Washington, opening statement.....................    14
    Prepared statement...........................................    16
Hon. Frank Pallone, Jr., a Representative in Congress from the 
  State of New Jersey, opening statement.........................    19
    Prepared statement...........................................    21

                               Witnesses

Puesh Kumar, Director, Office of Cybersecurity, Energy Security, 
  and Emergency Response, Department of Energy...................    23
    Prepared statement...........................................    26
    Answers to submitted questions...............................   102
Brian Mazanec, Ph.D., Deputy Director, Office of Preparedness, 
  Administration for Strategic Preparedness and Response, 
  Department of Health and Human Services........................    32
    Prepared statement...........................................    34
    Answers to submitted questions...............................   106
David Travers, Ph.D., Director, Water Infrastructure and Cyber 
  Resilience Division, Environmental Protection Agency...........    40
    Prepared statement...........................................    42

                           Submitted Material

Inclusion of the following was approved by unanimous consent.
List of documents submitted for the record.......................    78
Letter of April 24, 2023, from the American Water Works 
  Association and the United States Conference of Mayors to 
  Michael Regan, Administrator, Environmental Protection Agency, 
  and Richard Revesz, Administrator, Office of Information and 
  Regulatory Affairs.............................................    79
Letter of March 17, 2023, from American Water Works Association, 
  et al., to Michael Regan, Administrator, Environmental 
  Protection Agency, and Richard Revesz, Administrator, Office of 
  Information and Regulatory Affairs.............................    83
Letter of January 25, 2023, from American Water Works 
  Association, et al., to Michael Regan, Administrator, 
  Environmental Protection Agency................................    87
Letter of December 9, 2021, from G. Tracy Mehan III, Executive 
  Director, Government Affairs, American Water Works Association, 
  et al., to Radhika Fox, Assistant Administrator for Water, 
  Environmental Protection Agency................................    95
Letter of May 16, 2023, from Desmarie Waterhouse, Senior Vice 
  President of Advocacy and Communications and General Counsel, 
  American Public Power Association, to Mr. Griffith and Ms. 
  Castor.........................................................    97

 
   PROTECTING CRITICAL INFRASTRUCTURE FROM CYBER ATTACKS: EXAMINING 
                 EXPERTISE OF SECTOR-SPECIFIC AGENCIES

                              ----------                              


                         TUESDAY, MAY 16, 2023

                  House of Representatives,
      Subcommittee on Oversight and Investigations,
                          Committee on Energy and Commerce,
                                                    Washington, DC.
    The subcommittee met, pursuant to call, at 2:23 p.m., in 
the John D. Dingell Room 2123 Rayburn House Office Building, 
Hon. Morgan Griffith (chairman of the subcommittee) presiding.
    Members present: Representatives Griffith, Guthrie, Duncan, 
Palmer, Lesko, Crenshaw, Cammack, Rodgers (ex officio), Castor 
(subcommittee ranking member), DeGette, Schakowsky, Tonko, 
Ruiz, Peters, and Pallone (ex officio).
    Also present: Representative Kelly.
    Staff present: Sean Brebbia, Chief Counsel, Oversight and 
Investigations; Sarah Burke, Deputy Staff Director; Jerry 
Couri, Deputy Chief Counsel for Environment; Lauren Eriksen, 
Clerk, Oversight and Investigations; Christen Harsha, Senior 
Counsel, Oversight and Investigations; Tara Hupman, Chief 
Counsel; Peter Kielty, General Counsel; Emily King, Member 
Services Director; Chris Krepich, Press Secretary; John Strom, 
Counsel, Oversight and Investigations; Joanne Thomas, Counsel, 
Oversight and Investigations; Austin Flack, Minority Junior 
Professional Staff Member; Waverly Gordon, Minority Deputy 
Staff Director and General Counsel; Tiffany Guarascio, Minority 
Staff Director; Liz Johns, Minority GAO Detailee; Will 
McAuliffe, Minority Chief Counsel, Oversight and 
Investigations; Elysa Montfort, Minority Press Secretary; 
Christina Parisi, Minority Professional Staff Member; Greg 
Pugh, Minority Staff Assistant; Harry Samuels, Minority 
Oversight Counsel; and Caroline Wood, Minority Research 
Analyst.
    Mr. Griffith. All right, I'll ask all of our guests and 
people in the audience to please take their seats. The 
Subcommittee on Oversight and Investigations will now come to 
order.
    The Chair recognizes himself for 5 minutes for an opening 
statement.

OPENING STATEMENT OF HON. H. MORGAN GRIFFITH, A REPRESENTATIVE 
         IN CONGRESS FROM THE COMMONWEALTH OF VIRGINIA

    Thank you all for appearing before us at today's hearing of 
the Energy and Commerce Committee, Subcommittee on Oversight 
and Investigations. Defending our Nation's critical 
infrastructure from cyber attacks is an increasingly difficult 
endeavor for Federal regulators and cybersecurity experts. Over 
the past few years, escalating geopolitical tensions, an uptick 
in ransomware use, and increased criminal and foreign cyber 
attack capacity have raised Congress' concerns.
    The increased interconnectedness of critical 
infrastructure, such as hospitals, pipelines, and wastewater 
plants has furthered the proliferation of operational 
technology monitored by and connected to online computer 
systems, which has also heightened risks. Malicious actors are 
demonstrating an increased willingness and a growing capacity 
to execute cyber attacks.
    For example, the Director of National Intelligence reported 
that China is almost certainly capable of launching cyber 
attacks that could disrupt critical services in the United 
States and would almost certainly consider doing so if it 
feared that a major conflict with our Nation was imminent. 
Russia also remains a top cyber threat and seeks to improve its 
capabilities to target critical infrastructure. Also, hacking 
tools are now widely available to criminal organizations 
seeking to attack businesses, large and small.
    Critical infrastructure is a broad term that refers to 
physical or virtual systems and assets vital to the United 
States. Their destruction would debilitate the national 
economy, public health, and/or security. Often-used examples 
include our highways, utilities, dams, food manufacturing 
facilities, and emergency medical services.
    According to the Federal Bureau of Investigations 2022 
Internet Crime Report, of the 2,385 reported ransomware 
attacks, 870 affected critical infrastructure organizations. 
Healthcare and public health infrastructure were the most 
common types of critical infrastructure attacked. Presidential 
Policy Directive 21 has previously suggested a national 
framework on monitoring critical infrastructure.
    Under the Fiscal Year 2022 National Defense Authorization 
Act, there are currently 16 defined critical infrastructure 
sectors. Each sector is assigned a so-called Sector Risk 
Management Agency. Importantly, Presidential Policy Directive 
21 noted that each critical infrastructure sector possesses 
unique characteristics and risks, and therefore benefits from 
the specialized knowledge of Federal agencies most familiar 
with regulating that sector.
    That brings up the witnesses. Joining us today we have the 
Department of Energy, which carries out the Sector Risk 
Management Agency duties for the energy sector composed of 
electricity, oil, and natural gas segments, including their 
production, refining, storage, and distribution facilities. 
Nearly every industry depends on electricity and fuel. In fact, 
Presidential Policy Directive 21 identified the energy sector 
as uniquely critical due to its enabling function for all other 
critical infrastructure sectors.
    Subcommittee welcomes Mr. Puesh Kumar. Did I get close?
    Mr. Kumar. That's pretty good.
    Mr. Griffith. All right. Director of the Department of 
Office of Cybersecurity, Energy Security, and Emergency 
Response.
    Additionally, we are pleased to have Dr. David Travers from 
the Environmental Protection Agency's Office of Water. The EPA 
serves as the Sector Risk Management Agency for water and 
wastewater--sector--the sector on water and wastewater. Safe 
drinking water is essential human health and our Nation's 
economy. But water systems face increasing threats from 
malicious actors.
    Last but not least, the subcommittee welcomes Dr. Brian 
Mazanec from the Department of Health and Human Services 
Administration for Strategic Preparedness and Response that 
performs the Sector Risk Management Agency role for the 
healthcare and public sector--for the--for healthcare in the 
public sector--public health sector. This sector encompasses a 
diverse array of both publicly and privately owned entities 
such as the healthcare facilities, research centers, and 
medical materials supply chains.
    Today we hope to learn more about the emerging 
cybersecurity challenges that specifically threaten each of 
these sectors and what actions these agencies are taking to 
prepare for ever-evolving cyber threats. Also, much of our 
Nation's critical infrastructure network includes many non-
Federal entities like municipalities and private enterprises.
    We hope to learn more about how agencies partner with other 
system operators to share information and coordinate efforts 
across their sectors. We will also examine some of the recent 
cybersecurity activities at these agencies to identify any 
legislative opportunities for them to improve their efforts or 
serve as more effective partners with stakeholders and with 
those of us in Congress.
    I thank our witnesses for being here today.
    [The prepared statement of Mr. Griffith follows:]
    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
    
    Mr. Griffith. I now yield back my time and recognize the 
ranking member of the subcommittee, Ms. Castor, for her 5-
minute opening statement.

  OPENING STATEMENT OF HON. KATHY CASTOR, A REPRESENTATIVE IN 
               CONGRESS FROM THE STATE OF FLORIDA

    Ms. Castor. Well, thank you, Mr. Chairman, and good 
afternoon. I'm glad we're having this important hearing to get 
a better understanding from the agency experts as to the 
threats to critical infrastructure and how they are addressing 
those threats and how we can support their efforts.
    Everyday folks in my district and across the country count 
on being able to turn on the lights, have easy access to clean 
water, and ensure that they can receive confidential and life-
sustaining medical treatment. Yet the critical infrastructure 
that makes these things possible is increasingly under threat 
from criminals and foreign adversaries who carry out cyber 
attacks to steal people's personal information and disrupt our 
way of life.
    So we must prepare and protect critical infrastructure now 
from more common and sophisticated cyber attacks. They target 
not only the agencies here before us today but also the 
utilities companies and healthcare providers throughout the 
sectors that they oversee. Every hospital and utility is a 
target for bad actors seeking to profit from sensitive 
information or undermine our national security.
    Criminal networks have targeted hospitals and public health 
agencies in ransomware attacks because they know that these 
organizations store our neighbors' most personal information. 
So I want to do all that I can to protect my neighbors and the 
hospitals and health systems that serve them.
    Foreign adversaries like Russia have used cyber attacks to 
steal information from hundreds of Federal agencies in critical 
infrastructure organizations. Just last year at the start of 
Putin's unprovoked invasion of Ukraine, Russian hackers tried 
to take control of energy facilities in the United States, and 
while those hackers were ultimately thwarted by the Department 
of Energy and its Federal and sector partners, it demonstrates 
the seriousness of cyber threats and the risks that they pose.
    Many critical infrastructure organizations can take steps 
to prepare for and prevent cyber attacks. In doing so, the 
impact of an attack can be mitigated, but it takes an 
understanding of sector-specific cybersecurity threats to 
ensure that the finite resources that we have are spent on the 
most effective measures. That's why the work that the 
Department of Energy, the Environmental Protection Agency, and 
the Department of Health and Human Services, the work that they 
do to develop cybersecurity best practices and educate their 
sector partners, is so important.
    The agencies have the expertise necessary to identify 
sector- and sometimes facility-specific cyber threats and can 
use their existing regulatory authorities to make sure that 
countermeasures reach the organizations that need them the 
most. And as we tackle the rising cost and risks of the climate 
crisis, cybersecurity will only become more important. Clean 
energy resources will help us reduce climate pollution while 
new technologies that replace legacy systems can help existing 
power sources operate more efficiently.
    But new technologies can also give hackers new angles to 
attack our energy security, so we need to make sure that the 
energy and other critical infrastructure resources are well 
protected so that at the same time we can benefit from 
technological innovation. Agencies are already taking steps to 
address foreseeable cyber threats, and Congress can and should 
continue to support their efforts in a bipartisan manner. By 
listening and learning from our experts, Congress can make sure 
agencies have the tools they need to keep our neighbors safe, 
counter cyber threats, and protect critical infrastructure.
    So I look forward to hearing from our witnesses today about 
their important cybersecurity work and see how Congress can be 
helpful in supporting the most effective cybersecurity tools.
    [The prepared statement of Ms. Castor follows:]
    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
    
    Ms. Castor. Thank you, and I yield back.
    Mr. Griffith. Thank you, gentlelady, for yielding back. I 
now recognize the gentlelady who is The Chair of the full 
committee, Ms. McMorris Rodgers, for her 5 minutes.

      OPENING STATEMENT OF HON. CATHY McMORRIS RODGERS, A 
    REPRESENTATIVE IN CONGRESS FROM THE STATE OF WASHINGTON

    Mrs. Rodgers. Thank you, Chair Griffith. Today we are here 
to learn more about cyber attacks that threaten essential 
services and products that we as a Nation need to survive, 
attacks that could deprive us of access to emergency services, 
food and water, and the ability to communicate with one 
another. As Chair Griffith described, our critical 
infrastructure is essential to the security of our Nation, our 
economic prosperity, and our way of life.
    We depend on critical infrastructure to power our homes, 
ensure that we get to work, call for help in an emergency, 
supply us with clean water, and produce our food. With 
technological advances, this network has become increasingly 
more complex and interconnected. However, as our physical 
infrastructure and digital systems become more intertwined, new 
opportunities bring them new challenges. Bad actors, whether 
criminal organizations or foreign adversaries, have 
demonstrated a growing interest in launching cyber attacks on 
critical infrastructure, and unfortunately, many have 
demonstrated that they have the capability to do so.
    For example, the number of yearly cyber attacks on United 
States hospitals reportedly doubled between 2016 and 2021. 
Hospitals have increasingly become targets for ransomware gangs 
which assume control of online networks and then demand a 
ransom to unlock them. This means care and treatments are 
delayed when lives are on the line.
    Additionally, in 2021 a hacker altered the chemical levels 
in the water supply at a water treatment facility in Florida. 
Last June, another report concluded that 89 percent of 
electricity, oil and gas, and manufacturing firms experienced 
cyber attacks affecting population and energy supply over the 
previous 12 months.
    Securing our critical infrastructure from cyber threats and 
responding quickly to minimize and contain interruptions to 
these services will require the unique skills and resources of 
nearly all of our Federal agencies. Each of our Sector Risk 
Management Agencies possess specialized knowledge and expertise 
to help them identify new and evolving cyber threats in each of 
the infrastructure sectors. Through their experiences, 
regulating and communicating with critical infrastructure 
owners and operators, these agencies have gained extensive 
knowledge of the utilities, industries, and facilities that 
comprise each sector.
    For example, the Department of Health and Human Services is 
uniquely well positioned to respond to emerging threats to our 
hospital system online record systems because HHS is the agency 
already in direct communications with the healthcare sector. 
Similarly, we plan to explore whether our Sector Risk 
Management Agencies effectively partner with private entities, 
utilities, and non-Federal Government entities that make up the 
critical infrastructure network.
    Many of these entities, especially small businesses, local 
governments, or small utilities, may not have the resources to 
address the constantly shifting cyber attacks that they face 
and can benefit greatly from the resources and technical 
assistance our Sector Risk Management Agencies can provide. Our 
Federal agencies are also well positioned to provide 
leadership, coordinate efforts, and information sharing among 
members in each critical infrastructure sector.
    Much of our critical infrastructure is owned or operated by 
the private sector, so we hope to learn more from our 
management agencies the strategies for forging partnerships 
across relevant industries. We hope to learn more about how 
these agencies listen to non-Federal partners and receive their 
feedback to ensure Federal cybersecurity programs appropriately 
serve those they seek to protect.
    In the same vein, in carrying out their cybersecurity 
responsibilities, Federal agencies should incorporate their 
expertise they gather from their regulated entities and other 
non-Federal partners to inform their efforts. As we've 
discussed, many of our critical infrastructure sectors are 
heavily intertwined and rely on each other to function 
properly. As such, we hope to learn more about our Sector Risk 
Management Agencies' efforts to coordinate with each other and 
share expertise, lessons learned, and best practices.
    Cyber threats to our critical infrastructure present a 
serious threat to our national security. We can be prepared for 
these threats if we effectively harness the expertise and 
creativity of our Federal agencies, non-Federal governments, 
utilities, and industry.
    Again, I thank our witnesses for sharing their perspectives 
today, and I look forward to this discussion.
    [The prepared statement of Mrs. Rodgers follows:]
    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
    
    Mrs. Rodgers. I yield back.
    Mr. Griffith. The gentlelady yields back. I now recognize 
the gentleman from New Jersey, the ranking member of the full 
committee, Mr. Pallone, for his 5-minute opening statement.

OPENING STATEMENT OF HON. FRANK PALLONE, Jr., A REPRESENTATIVE 
            IN CONGRESS FROM THE STATE OF NEW JERSEY

    Mr. Pallone. Thank you, Mr. Chairman. Today the 
subcommittee continues its important bipartisan oversight of 
cybersecurity and protecting our Nation's critical 
infrastructure from cyber attacks. Federal agencies within our 
committee's jurisdiction and their partners in the private 
sector face serious cybersecurity threats to critical energy, 
water, and health systems. Major cyber incidents have 
repeatedly shown how harmful attacks on critical infrastructure 
can be to our Nation.
    We all remember the ransomware attack on the Colonial Gas 
Pipeline. The attack triggered panic buying that contributed to 
fuel shortages and higher gas prices across the East Coast and 
the South. At the end of last year, cyber criminals stole the 
electronic patient records of more than 3 million patients from 
a California hospital system. That breach exposed sensitive 
personal information, including patients' Social Security 
numbers, test results and diagnoses, and prescription history. 
And then earlier this year, the personal healthcare information 
of Members and staff was stolen when DC Health Link was 
breached.
    Cyber threats to critical energy, water, and health 
infrastructure are unfortunately becoming more common, and 
attacks are more costly. In 2022, hundreds of cyber attacks 
cost healthcare organizations billions of dollars and made it 
harder for doctors and other healthcare providers from caring 
for patients for months afterwards. Companies that own critical 
infrastructure face thousands of cyber attacks every year.
    While many of these attacks are unsuccessful thanks to the 
cyber defenses these companies have established, successful 
cyber attacks can have devastating consequences. During the 
early days of Russia's invasion of Ukraine, Russian hackers 
unsuccessfully targeted America's energy grid. Experts have 
said that this incident is the closest we have come to losing 
control of grid infrastructure and that the methods used 
represent an unprecedented threat.
    That's why bipartisan efforts in this committee are so 
important to bolster cybersecurity for critical infrastructure 
overseen by the Department of Energy, the Environmental 
Protection Agency, and the Department of Health and Human 
Services. We worked together on the bipartisan America's Water 
Infrastructure Act of 2018, and this law requires water systems 
to complete risk assessments and develop emergency response 
plans that account for cybersecurity risks.
    But despite these efforts, there are still gaps in the 
ability of Federal agencies to prevent potential cyber attacks. 
In 2020, Russian hackers gained access to an updated--an update 
server at SolarWinds, a software company serving critical 
infrastructure companies and Federal agencies. For months the 
attackers were able to use SolarWinds systems to penetrate 
networks at hundreds of organizations and dozens of Federal 
agencies. And while the method of attack was not necessarily 
new, the scale and scope was unprecedented. It exposed 
vulnerabilities and cybersecurity gaps that put critical 
infrastructure at risk.
    I strongly believe that DOE, EPA, and HHS are best equipped 
to handle internal and sector-relevant cybersecurity concerns. 
Much of our critical infrastructure relies on unique systems 
and specialized workforces. These agencies have the 
institutional knowledge and expertise to engage with their 
private-sector partners to address complex sector-specific 
threats. We must focus on giving these agencies the resources 
they need to fight constantly evolving threats.
    But the Republicans' Default of America Act threatens 
indiscriminate cuts to Federal agencies overseeing 
infrastructure. I'm concerned that it could seriously hamstring 
cybersecurity efforts at a time when we must be ramping up our 
defenses against cyber threats from criminal and foreign 
adversaries. And Federal agencies need tools that enable them 
to leverage sector-specific expertise and institutional 
knowledge to prevent and respond to cybersecurity concerns.
    With bipartisan congressional support, DOE, EPA, HHS, and 
other Federal agencies can continue to develop more efficient 
and robust cybersecurity defenses while also partnering with 
the private sector to protect our critical infrastructure 
systems. So I hope to continue this committee's important 
bipartisan work on this topic.
    Well, I look forward to hearing from our witnesses on the 
progress they've made and the challenges that they continue to 
face.
    [The prepared statement of Mr. Pallone follows:]
   [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
    
    Mr. Pallone. With that, Mr. Chairman, thank you, and I 
yield back.
    Mr. Griffith. Thank the gentleman for yielding back. That 
concludes Members' opening statements. I would like to remind 
all Members that their opening statements can be made a part of 
the record pursuant to committee rules.
    All right, we want to thank all of our witnesses for being 
here today and taking your time to testify before this 
subcommittee. Each witness will have the opportunity to give an 
opening statement of 5 minutes followed by a round of questions 
from Members. Our witnesses today are Puesh Kumar, Director of 
Office of Cybersecurity, Energy Security, and Emergency 
Response, Department of Energy; Dr. Brian Mazanec, Deputy 
Director, Office of Preparedness, Department of Health and 
Human Services; David Travers, Director of Water Infrastructure 
and Cyber Resilience Division, Environmental Protection Agency. 
We appreciate all of you being here today, and I look forward 
to hearing from you on this important issue.
    As you are aware, this committee is holding an oversight 
hearing, and when doing so, we have the practice of taking 
testimony under oath. Do any of you have any objection to 
testifying under oath?
    [No response.]
    Mr. Griffith. Seeing no objections, we'll proceed. The 
Chair also advises you you're entitled to be advised by counsel 
pursuant to House Rules. Do any of you desire to be advised by 
counsel during your testimony today?
    [No response.]
    Mr. Griffith. Seeing that none have requested that, would 
each of you rise and raise your right hand, please?
    [Witnesses sworn.]
    Mr. Griffith. Seeing that all witnesses answered in the 
affirmative--you are--you may seat--be seated.
    Seeing all witnesses have answered in the affirmative, you 
are now sworn in and under oath subject to the penalties set 
forth in title 18, section 1001 of the United States Code.
    With that, we will now recognize Puesh Kumar for his 5-
minute opening statement.

 STATEMENTS OF PUESH KUMAR, DIRECTOR, OFFICE OF CYBERSECURITY, 
ENERGY SECURITY, AND EMERGENCY RESPONSE, DEPARTMENT OF ENERGY; 
BRIAN MAZANEC, Ph.D., DEPUTY DIRECTOR, OFFICE OF PREPAREDNESS, 
    ADMINISTRATION FOR STRATEGIC PREPAREDNESS AND RESPONSE, 
  DEPARTMENT OF HEALTH AND HUMAN SERVICES; AND DAVID TRAVERS, 
  Ph.D., DIRECTOR, WATER INFRASTRUCTURE AND CYBER RESILIENCE 
           DIVISION, ENVIRONMENTAL PROTECTION AGENCY

                    STATEMENT OF PUESH KUMAR

    Mr. Kumar. Good afternoon.
    Mr. Griffith. You have to push your button there.
    Mr. Kumar. All right, can you----
    Mr. Griffith. There we go.
    Mr. Kumar. All right. Good afternoon, Chair McMorris 
Rodgers, Chair Griffith, and Ranking Member Castor, and 
distinguished members of the subcommittee. Thank you for the 
opportunity to testify on behalf of the Department of Energy on 
the unique role we play as the Sector Risk Management Agency 
for the U.S. energy sector. I appreciate the interest and 
support from this committee on this critical issue.
    From 2019 through 2023, each Annual Threat Assessment of 
the U.S. intelligence community from the Director of National 
Intelligence has pointed to persistent and malicious cyber 
threats facing U.S. infrastructure. These reports are clear. 
Our adversaries are targeting U.S. energy infrastructure, and 
it is a threat to national security.
    In May 2021, Colonial Pipeline proactively shut down its 
pipeline system for 5 days after a cyber criminal group 
compromised the company's IT network with ransomware. The 
shutdown ultimately led to a disruption in the supply of 
petroleum products across multiple States. During the Colonial 
Pipeline incident, DOE coordinated a whole-of-government 
response which restored operations quickly and safely while 
moving field supplies to impacted areas, mitigating impacts to 
consumers. This response reflects our understanding of 
consequence management for the U.S. energy sector, our 
knowledge of the relevant forensics, and our deep appreciation 
of the impact of energy disruptions for the American public.
    Given the immense gravity of the threats we face, it is 
imperative that we employ a whole-of-government approach to 
risk management and mitigation. The SRMA model allows us to 
scale and to work in concert with our counterparts and with 
partners across the entirety of the Federal Government. As the 
SRMA for the energy sector, DOE has the day-to-day 
responsibility and sector-specific expertise to work within the 
sector and collaborate with the Cybersecurity and 
Infrastructure Security Agency, or CISA, as the national 
coordinator.
    We value our partnership with CISA. While we bring a depth 
of knowledge of the energy sector and the tactical and 
technical elements that keep power and fuel flowing to 
Americans, CISA serves an important coordinator function and 
has a unique perspective that is invaluable to DOE's risk 
management activities.
    DOE is uniquely qualified to manage the ever-changing risk 
landscape for America's energy sector because we have a depth 
of knowledge specific to generation, transmission, 
distribution, and consumption of energy of all forms. We also 
have tremendous expertise on cybersecurity. Additionally, we 
have an exceptional breadth of capabilities across the 
department from nuclear physicists and security specialists to 
subject matter experts in renewable energy and deployment. We 
regularly avail ourselves to the immense trove of knowledge 
readily available across the entire department.
    My office, the Office of Cybersecurity, Energy Security, 
and Emergency Response, or CESER, executes our SRMA 
responsibilities. CESER is built upon a foundation of strong 
partnerships with industry, State, local, territorial, and 
Tribal communities, regulators, suppliers, and manufacturers, 
and the world-class experts at the DOE national laboratories, 
in addition to academia. It is through these trusted 
partnerships that we are able to execute our responsibilities 
on behalf of DOE as the SRMA for the energy sector.
    Through these many efforts ranging from our Energy Threat 
Analysis Center, or ETAC, pilot to work on securing energy 
systems were recently highlighted in the President's National 
Cyber Strategy. The ETAC will bring innovative and robust 
capabilities to the energy sector and will help us keep pace 
with the cyber threats headed towards us as a nation. ETAC 
provides an excellent example of the new and innovative 
capabilities that our Nation needs to build to effectively 
collaborate between industry and government to defend our 
critical infrastructure.
    DOE is adept at deploying innovative solutions to complex 
problems and will continue to do so in the service of the 
American people, ensuring that U.S. energy sector becomes 
secure and resilient.
    In closing I would like to thank the members of the 
subcommittee once more for your continued support for SRMAs and 
for DOE, and CESER specifically. Your commitment to protecting 
America's critical infrastructure is essential to our continued 
success. You understand that energy security is critical to our 
national security.
    I am proud of the work that we are doing in DOE and CESER 
to ensure that the U.S. energy sector remains secure and 
resilient for Americans today and for generations to come.
    Thank you for the opportunity to testify today. I look 
forward to your questions.
    [The prepared statement of Mr. Kumar follows:]
    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
    
    Mr. Griffith. Thank you so much. I now recognize Dr. 
Mazanec for his 5 minutes of opening statement.

               STATEMENT OF BRIAN MAZANEC, Ph.D.

    Dr. Mazanec. Thank you, Mr. Chairman.
    Good afternoon, Chairman Griffith, Vice Chair Lesko, 
Ranking Member Castor, distinguished members of the committee, 
and staff. Thank you for the opportunity to discuss the 
Department of Health and Human Services Administration for 
Strategic Preparedness and Response, known as ASPR's, efforts 
to strengthen the healthcare and public health sector's 
preparedness for and response to cyber attacks. ASPR is the 
department Sector Risk Management Agency, or SRMA, lead. My 
testimony today summarizes the growing cyber threat, the role 
of ASPR as the SRMA lead, and our approach to strengthening the 
sector's cybersecurity.
    As you are all too well aware, the healthcare and public 
health sector continues to experience increasingly 
sophisticated cyber attacks that exploit complex hospital 
infrastructures, underfunded cybersecurity functions, and 
numerous vulnerable legacy metal--medical devices. These cyber 
attacks against the sector are growing both in number and 
severity.
    The frequency of cyber attacks on hospitals, as has already 
been noted, more than doubled from 2016 to 2021, with 
ransomware being the largest threat. Of note, last week the 
Journal of the American Medical Association published a study 
indicating that cyber attacks against hospitals not only affect 
the targeted institution but have a blast radiuslike effect on 
the surrounding area, similar to conventional disasters.
    ASPR is responsible for coordinating healthcare and public 
health SRMA activities, which we do working as a team with key 
partners across HHS to include the HHS 405(d) Program and the 
Health Sector Cybersecurity Coordination Center, known as HC3, 
and the FDA, to name a few. ASPR in its SRMA role and with 
active involvement from stakeholders across the department 
proactively confronts these growing cyber threats and 
strengthens the Healthcare and Public Health Sector's cyber 
security posture. Doing so is critical as cyber attacks in this 
sector have a very real impact on the health and safety of 
individual Americans.
    Imagine the impact on patients as a hospital is forced to 
abruptly shift to paper records following a ransomware attack 
on its electronic health records system or loses its ability to 
conduct MRIs. Cyber safety is patient safety. I'll highlight a 
few examples of what we are doing to combat this threat.
    First, jointly with our interagency and private-sector 
partners, we develop resources to support risk mitigation 
activities. We recently published the 2023 edition of the 
Health Industry's Cybersecurity Practices, known as the HICP, 
and the Healthcare and Public Health Sector Cybersecurity 
Framework Implementation Guide.
    Second, we facilitate sector coordination and in doing so 
leverage these resources I just mentioned as well as others and 
collaborate on initiatives to strengthen the sector's cyber 
posture. Internal to HHS, ASPR manages the Healthcare and 
Public Health SRMA Cyber Working Group, which brings together 
experts from across HHS each week to coordinate activities. 
External to the department, multiple HHS divisions work with 
the Healthcare and Public Health Sector through various sector-
focused councils and venues. For example, we regularly 
coordinate with over 15 government and over 300 private-sector 
partner organizations through the Healthcare Sector 
Coordinating Council Joint Cybersecurity Working Group.
    The third area of SRMA activities that I want to highlight 
today focus on leading response planning and supporting 
incident response. Response planning for cyber incidents is 
critical as the frequency and intensity of these attacks 
increase. HHS recently completed a Healthcare and Public Health 
Sector Cyber Incident Response Plan. Additionally, HHS has 
organized with CISA and other interagency partners over a dozen 
tabletop exercises to improve incident response processes.
    In responding to cyber threats facing the sector, ASPR 
coordinates closely with our staff in the regions as well as 
with CISA and the FBI to inform response operations and 
mitigate the impacts of patient care and safety. In addition to 
these activities, the department also utilizes its regulatory 
role to strengthen the sector's cyber posture.
    While I have touched on the efforts within ASPR and across 
HHS that seek to move the needle forward to strengthen in 
cybersecurity in the sector, more work needs to be done to meet 
this growing threat. We are in the process of establishing a 
dedicated cyber division within ASPR's Office of Critical 
Infrastructure Protection. If ASPR is granted direct higher 
authority, as requested through the Pandemic and All Hazards 
Preparedness in Advancing Innovation Act, PAHPA, 
reauthorization process, we would be able to more quickly bring 
on board critical staff with cyber expertise.
    Dedicated resources are needed to implement and operate 
supporting systems, as included in the President's 2024 budget 
request, to ensure ASPR and HHS are best positioned to execute 
its SRMA responsibilities to prepare for and respond to cyber 
attacks on the healthcare and public health sector.
    Chairman Griffith, Vice Chair Lesko, Ranking Member Castor, 
that concludes my statement. I look forward to your questions.
    [The prepared statement of Dr. Mazanec follows:]
    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
    
    Mr. Griffith. Thank you so much. Now I recognize Mr.--Dr. 
Travers for his 5-minute opening statement.

               STATEMENT OF DAVID TRAVERS. Ph.D.

    Dr. Travers. Great. Good afternoon, Chairman Griffith, 
Ranking Member Castor, and members of the committee. I am David 
Travers, and I serve as the Director of the Water 
Infrastructure and Cyber Resilience Division at USCPA. Thank 
you for the opportunity to speak to you today about the 
agency's work with our partners to improve the security and 
resilience of America's water systems to the threat of cyber 
attacks. This mission is among EPA's highest homeland security 
priorities.
    Water systems are frequently targeted for cyber attacks by 
both state-sponsored actors and criminal groups. These attacks 
have stolen valuable financial and customer information, 
destroyed information networks, and disabled communication 
systems. Recovery costs have ranged into the millions of 
dollars. Importantly, cyber attacks can also manipulate and 
disable the process control networks for the treatment and 
distribution of water, which has the potential to endanger 
public health. The adoption of cybersecurity best practices by 
water systems to reduce the risk of these attacks is essential.
    EPA is the Sector Risk Management Agency for the water and 
wastewater system sector. We are responsible for enhancing the 
sector's security and resilience against all hazards, including 
cyber attacks. Multiple Federal statutes, directives, and 
Executive orders mandate the agency's cybersecurity mission.
    The water and wastewater system sector includes just under 
150,000 drinking water systems and 16,000 wastewater systems 
across the United States and territories. The utilities range 
in size from serving less than 500 to over 8 million customers. 
Most water systems are small and face unique challenges with 
the resources and expertise needed for providing safe drinking 
water.
    EPA fulfills its mission in cybersecurity in coordination 
with DHS, the Water Sector Coordinating Council of industry 
representatives, and other Federal, State, local, Tribal, 
territorial and private-sector partners. EPA has worked with 
these partners for over 10 years to promote the adoption of 
cybersecurity best practices by water and wastewater systems. 
We provide training, develop guidance tools and resources, and 
offer technical assistance.
    For instance, we have trained thousands of water systems 
nationwide on cybersecurity risks and resilience. EPA has given 
one-on-one technical assistance by subject matter experts to 
hundreds of water and wastewater systems to identify gaps in 
cybersecurity practices and implement remediation actions 
tailored to the utility's resources and goals. EPA has created 
a suite of cybersecurity guidance materials and tools 
specifically for the water sector in key areas like cyber 
incident planning and emergency response.
    While the work of EPA and its partners have made important 
gains in cybersecurity, the most significant cyber risk in the 
water sector remains the failure of many utilities to adopt 
best practices. This critical vulnerability is apparent both 
from a recent industry survey, which showed that most utilities 
had not taken key steps to protect their operations, and from 
cyber incidents at water systems which have exploited the 
failure to implement cybersecurity best practices.
    Due to this continued vulnerability, the increasing 
frequency of cyber attacks on critical infrastructure 
facilities as reported by the FBI and DHS, and the public 
health risk of a cyber attack on a water system, EPA has 
recently used existing regulatory authority to improve 
cybersecurity in the sector. In March, EPA issued a memo 
stating that regular State audits of water system operations, 
called sanitary surveys, must include an evaluation of 
cybersecurity. If the State finds a significant deficiency in 
cybersecurity during the sanitary survey, then the water system 
must correct it. States determine how they evaluate their water 
systems and what actions their water systems take to correct 
deficiencies.
    The use of sanitary surveys to improve cybersecurity at 
water systems builds on the provisions of 2018 America's Water 
Infrastructure Act, or AWIA. Under EPA's policy, cybersecurity 
practices are assessed at all water systems not just the 
subject to AWIA. And the State ensures that water systems take 
corrective actions to address deficiencies.
    EPA knows that many States lack capacity to assist water 
systems in protecting against cyber threats. Consequently, EPA 
is providing robust guidance, training, and technical 
assistance to help States. For example, EPA's Water Sector 
Cybersecurity Evaluation Program carries out assessments of 
cybersecurity practices at water systems upon request, which 
can lift the burden for the State to perform the assessment 
during a sanitary survey.
    Moving forward, the agency will continue to strive with our 
water sector partners in the essential work of ensuring that 
water systems adopt cybersecurity best practices that will 
reduce risk, enhance resilience, and protect public health.
    Thank you for the opportunity to testify before you today, 
and I look forward to our discussion.
    [The prepared testimony of Dr. Travers follows:]
    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
    
    Mr. Griffith. Thank you very much for your testimony. And 
we will now move into the question-and-answer portion of the 
hearing, and I will begin the questioning and recognize myself 
for 5 minutes.
    Dr. Mazanec, as you discussed in your testimony, hospitals' 
cybersecurity incidents are particularly expensive and can lead 
to tremendous patient impact, such as the temporary 
cancellation of elective procedures and patient diversion to 
nearby hospitals--when there are nearby hospitals. In some of 
the rural areas, they aren't there. Much more difficult.
    Given these potentially devastating effects, could you give 
a broad example of what the Administration for Strategic 
Preparedness and Response does to mitigate a cyber attack when 
they first hear of it?
    Dr. Mazanec. Thank you, Mr. Chairman, that's an excellent 
question. As you noted in your question, I think part of the 
challenge we face with the healthcare and public health sector 
is the complexity of the sector itself. It's incredibly 
diverse, you have large hospital systems, you have small, rural 
hospitals. Very different resource allocations to address the 
growing and pervasive cyber threat that exists.
    One of the things that we're doing I mentioned in my 
opening statement in terms of developing resources, we tailor 
those and try to make them as accessible as possible, 
particularly for those underresourced or smaller hospitals. So 
the HICP, the Health Industry Cybersecurity Practices Guide 
that we recently updated, has essentially bifurcated sections 
that focus and have resources ready to go off the shelf for 
small hospitals as well as resources tailored to the larger 
elements of this sector.
    But this is something that we need to continue to stay 
abreast of and focus on, and we're actively working with our 
partners in the sector to understand their needs, and we'll 
continue to provide tailored resources as best we can.
    Mr. Griffith. Thank you very much.
    Dr. Travers, the Water and Wastewater Sector relies on a 
stable energy supply to power water utilities. Given this 
interdependence, how does the EPA coordinate with the 
Department of Energy to prepare for a cyber incident that 
interrupts the supply of energy to a water system?
    Dr. Travers. Thank you for the question, Chairman Griffith. 
Each of us on the panel today I think represents a sector 
critical to this Nation. I'm not sure what community could 
function without power, water, and adequate healthcare. We 
engage extensively with other Sector Risk Management Agencies, 
including the Department of Energy and Health and Human 
Services.
    So an example of that coordination, since you asked 
specifically about energy, we have activities relevant to the 
Department of Energy where we developed a Power Resilience 
Guide which enables water systems to build redundancy, 
understand the countermeasures that are available to them to 
enhance their resilience if the power should go out, whether 
because of a cyber attack or because of a natural disaster.
    We also host training of both power sector entities and 
water systems so that each can understand the dependence of one 
on the other. As you implied in your question, water systems 
cannot function generally without a supply of electricity. It's 
critical for the treatment of water, distribution of water, 
storage of water--virtually every facet of producing and 
delivering water systems.
    But because of these robust engagements with both DOE, with 
entities within the energy sector, and with entities within the 
water sector, I believe we have cultivated a robust level of 
coordination among our respective sectors.
    Mr. Griffith. Thank you.
    Mr. Kumar, Colonial Pipeline of May 2021 obviously caused a 
great deal of disruption. How did the Department's knowledge of 
and preexisting relationship within the oil and gas sector 
prepare to assist with a Federal response?
    Mr. Kumar. Chairman, thank you for the question. When it 
came to Colonial, when you're responding to an incident, that 
doesn't--that relationship isn't developed during an incident, 
it's developed during blue sky days, as well call it. We've had 
a longstanding relationship with Colonial because of natural 
hazards, because of hurricanes, and other climate-based risks 
that we were working with them on long before the cyber 
incident.
    And so when Colonial happened, we were one of their first 
calls. They called us and said, hey, we just had this cyber 
incident and we think we have to turn off the pipeline. And so 
we were able to immediately get into gear and work with them to 
understand what is going to be the potential impact of fuel 
supply, but also the cyber side.
    So it really ended up being two incidents. One was the 
cyber side in terms of the cyber actors potentially on their 
networks. The other part that we were concerned about was the 
consequence of a pipeline, a critical pipeline, being down. And 
so we were able to not only leverage our own expertise across 
the Department, across offices such as our office, fossil 
energy, but also the national laboratories, to really come and 
support them, and we brought along the entire whole-of-
government approach, so we brought DHS, the FBI, and other 
agencies to ensure Colonial had the support they needed. I was 
on daily calls with Colonial's CEO.
    And so this is really important. We need to have those 
relationships with the sector well before an incident, whether 
it's a cyber attack or a physical incident, to be able to carry 
out our responsibilities.
    Mr. Griffith. And help me with my recollection. Did you all 
coordinate with the other suppliers in the areas close by to 
try to increase their supply, or was that another agency?
    Mr. Kumar. Absolutely, sir. We worked with all of the 
suppliers to make sure. We also worked with the States because 
the States need to be prepared.
    Mr. Griffith. Right.
    Mr. Kumar. So it was--we had to work with everyone.
    Mr. Griffith. Thank you very much, I appreciate it.
    And I yield back. I now recognize the gentlelady from 
Florida, Ms. Castor, ranking member of this subcommittee, for 
her 5 minutes of questioning.
    Ms. Castor. Well, thank you, Mr. Chairman, and thanks again 
to our witnesses for being here.
    I believe that improving grid resiliency and the whole 
modernization of the grid is an important part of our 
transition to cleaner, cheaper energy. And while we often think 
of physical infrastructure as the transformers and the power 
lines, there are very innovative new digital tools, distributed 
systems, all sorts of flexible technologies that are also 
essential to resiliency.
    So I want you to help explain what you see going on in the 
energy sector. I know we're very focused on the--this brazen 
cyber attack on--like a Colonial Pipeline hack that can bring 
regions of the country to a standstill, but I think that 
relying on a diverse mix of clean energy, energy efficiency 
tools can really help mitigate the reach of cyber attacks on 
our energy system. What do you see going on across the country 
now with these new, innovative technologies?
    Mr. Kumar. Ranking Member Castor, thank you for that 
question. The energy sector is undergoing a tremendous shift. 
We're looking at new sources of energy that are going to be 
connecting into the electric grid as we know it. We're going to 
be looking at new technologies to power all of these 
connections, and so we're seeing a lot of changes. And from my 
vantage point, there's some big shifts. Certainly the threats.
    We're continuing to see increased cyber threats, but we're 
seeing digitization. It's not--it's clean energy's fueling it, 
but it's also consumers wanting more control over their energy 
usage, whether it's electric vehicles plugging in or smart 
thermostats. We're seeing a lot more of this connectivity.
    And so as we see this connectivity, there's certainly 
concerns that we have when it comes to cybersecurity. We want 
to make sure that as we're deploying these new systems we're 
building in cybersecurity. That has to be a fundamental thing 
that we do, much like decades ago we built in safety. So 
cybersecurity, we think, has to be fundamental to this.
    Now as we start to think of technologies and architecture 
such as microgrids and energy storage, there's also an 
opportunity there, because as we're building out these new 
types of distribution-connected resources, they could also act 
as resilience for the grid. So if there's a certain portion on 
the grid that goes down because of a hurricane or a cyber 
incident, could we separate that portion so that we can harden 
another portion?
    There's opportunities we have to build in resilience as we 
go forward, and that's something that we're really focused on 
working on in partnership with other departments of the agency. 
So that's--it's a really great point, and I appreciate the 
question.
    Ms. Castor. So what is the current status of the law if a 
utility or an energy supplier undergoes a cyber attack? You 
said Colonial, for example, contacted DOE, but remind us, what 
is the current status of the law for those critical 
infrastructure energy suppliers to notify you about a cyber 
attack?
    Mr. Kumar. Ma'am, that's a great question. We--at DOE we 
have a reporting requirement. We've had it for over a decade, 
where electricity companies have to report to the Department 
whenever there's any type of disruption to the bulk power 
system. And again, it's broader than cyber. It's hurricanes and 
other outages, anything that can cause a disruption on the 
electricity sector, it needs to be reported to the Department.
    And so to that end, we have the reporting requirement for 
electricity, and we think it's really helpful because we need 
to understand what could be the cascading impact across the 
country. And so we get that reporting, we get it through not 
only directly, the electricity companies, but we also work 
closely with organizations called the Information Sharing and 
Analysis Centers, or the ISACs. Those ISACs are comprised of 
electricity, oil and natural gas companies, and increasingly 
renewable companies.
    And so we work with them on a daily basis, if not a minute-
by-minute basis, on what's going on in the sector so we can get 
ahead of it and be able to take quick action.
    Ms. Castor. And you feel like the private-sector entities 
are fully bought in with you, they're--you haven't come across 
folks that are trying to hide the ball or distract you or--
what's the current status of cooperation across the energy 
sector?
    Mr. Kumar. Generally speaking, what we see is these 
companies want to let us know what's going on because they also 
want to share that information and cascade it with their peers 
across the sector. That's generally what I have seen, and so we 
need to continue encouraging that because, if something's 
happening in one part of the country, we need another energy 
company to know in another part of the company--country. So 
this is a really important piece. Generally, I am seeing that 
they are willing to share when there is an incident.
    Ms. Castor. Thank you very much.
    I yield back my time.
    Mr. Griffith. The gentlelady yields back. I now recognize 
the gentleman from Kentucky, Chairman of the Energy 
Subcommittee--excuse me, of the Health Subcommittee.
    Mr. Guthrie. Yes, sir.
    Mr. Griffith. I got my Energy Subcommittee in the chair 
coming up.
    Mr. Guthrie. You got the next one. You get Energy next.
    Mr. Griffith. Yes, get Energy next. First it's going to be 
Health.
    Mr. Guthrie. First it will be Health.
    Mr. Griffith. Mr. Guthrie of Kentucky, 5 minutes.
    Mr. Guthrie. So thanks.
    Mr. Mazanec, that leads into--and thanks for all you guys 
for being here today. That--the panelists.
    That leads into one of my questions. So PAHPA of 2019, the 
Pandemic Act, included a directive for HHS to create a strategy 
for public health preparedness in response to address 
cybersecurity threats. So of that directive, I was just--my 
questions are, can you explain the process behind the 
directive? Was ASPR in charge, or did the Secretary lead the 
point? And what was the opportunity for interagencies across 
HHS and then outside groups to participate?
    Dr. Mazanec. Thank you, Congressman. So in terms of the 
specific reporting requirement that you mentioned from the 
prior PAHPA authorization, we did complete that report in 
coordination, as we do many of our activities in this area, 
with our partners across the Department. I believe we delivered 
that report a little over a year or so ago. Happy to work with 
you and your staff to make sure you have a copy.
    I would note going forward, as my fellow panelists here and 
many on the committee have mentioned, the threat is not static, 
it is continuing to evolve, so that is sort of a point-in-time 
report that we develop. But we are continuing efforts now 
working, again, very closely across the Department with our key 
partners with CISA, the FBI, the interagency, and the sector to 
develop more--the most relevant and timely resources and 
strategies to address this threat.
    Mr. Guthrie. OK, thanks. And did the HHS Secretary lead 
that, or was ASPR the leader of that, or--of that effort?
    Dr. Mazanec. ASPR is the designated SRMA lead for the 
Department, so we serve as sort of the quarterback role for all 
of these activities in partnership with the other key 
participants in the Department.
    Mr. Guthrie. OK. And then also, Mr. Mazanec, according to a 
June 2021 GAO study, HHS information security, that ASPR led 
seven collaborative groups to--looked at seven collaborative 
groups to fulfill cybersecurity responsibilities that are 
designed to help agencies to consider when collaborating. So 
I'll just say the report says, and I quote, about five groups 
``did not have the mechanisms in place to monitor and evaluate 
progress. While the charters of these five groups define goals, 
none describe the process for monitoring and evaluating 
reporting progress.''
    How was ASPR working with these five groups specifically?
    Dr. Mazanec. Thank you, Congressman. So I believe the GAO-
21-403 report that you're citing focused on the various 
coordinated mechanisms we had at the Department at the time. We 
are working through implementation of those recommendations and 
just recently updated the charter of the SRMA cyber working 
group, which, as I mentioned in my opening remarks, is that 
function--that coordinating entity internal to the Department 
that meets every week to address these issues with key 
participants from CMS, from FDA, our office of Chief 
Information Officer, with ASPR, again, in sort of that 
quarterbacklike role coordinating efforts.
    And we're continuing to work through revisions as 
appropriate based on the GAO recommendations to those various 
groups and subgroups.
    Mr. Guthrie. OK, thanks, appreciate that.
    And now, Mr. Kumar and Mr. Travers, first with Mr. Kumar--
you both would answer this. Last year I had a municipal utility 
that had ransomware and was shut down for 18 hours for water 
disruption, the utility provider was. Are there specific risk 
factors that utility operators in your respective sector need 
to prepare for, and do you provide cyber best practice for 
local utility providers? So if you would just go first and then 
Mr. Travers next, that would be great.
    Mr. Kumar. Representative, absolutely. We actually provide 
not only tools that the smaller utilities can use to gauge 
their own cyber posture and then make investment decisions to 
up their cyber posture, we also provide technical assistance. 
Currently, my office is executing a program called a Rural and 
Municipal Utility Grant Program that is specifically focused on 
providing cybersecurity, technical assistance, and funding 
directly to rural cooperatives and municipal utilities across 
the country to really help them up their cyber posture.
    Mr. Guthrie. Thank you. And, Mr. Travers, from EPA's 
perspective?
    Dr. Travers. Sure. Thank you, Congressman. You asked about 
risk factors. In terms of those smaller systems, they tend to 
be at higher risk than the larger systems, although all water 
systems certainly could be potentially victims of cyber 
threats. Water--small water systems generally lack capacity of 
larger water systems, for example. You can expect a larger 
water system, for example, to have an entire IT department, 
whereas for smaller water systems, they are much more 
constrained in terms of their resources.
    Because, however, small systems are critical to sustaining 
the public health of their communities, EPA has provided very 
extensive and robust tools, training, direct technical 
assistance to smaller water systems. And I'll just give you one 
example. We had a technical assistance provider effort whereby 
EPA sends out a cybersecurity expert to assess the 
cybersecurity gaps at small water systems and to develop risk 
mitigation plans so that those smaller systems can address 
those gaps.
    Mr. Guthrie. Thank you, I appreciate your answers.
    My time's expired, and I yield back.
    Mr. Griffith. The gentleman yields back. I now recognize 
the gentlelady from Colorado, Ms. DeGette, for her 5 minutes of 
questioning.
    Ms. DeGette. Thank you very much.
    Well, these questions sort of piggyback on what the 
previous Member was asking about, because I want to talk a 
little bit about the experience and technical expertise of the 
DOE employees in protecting the energy grid. And in particular, 
I was--when I was preparing for this hearing, I learned that 
DOE has established the Energy Threat Analysis Center, or ETAC, 
pilot at the National Renewable Energy Lab, which is just 
outside my congressional district and is a great source of 
pride for everybody in Colorado and for a lot of us on this 
committee.
    What ETAC is doing is it's helping to increase 
collaboration with the industry and between Federal agencies to 
detect, prevent, and respond to threats to the energy sector, 
including cybersecurity threats. So, Mr. Kumar, I wanted to ask 
you, how has the ETAC pilot allowed DOE to leverage its 
relationships and expertise to protect the energy sector, 
particularly from emerging cyber threats, and how is that pilot 
going?
    Mr. Kumar. Representative DeGette, thank you for that 
question. And the National Renewable Laboratory has been a 
tremendous leader in helping us stand up this pilot effort that 
we're undertaking.
    Really the ETAC is meant to connect dots. Right now from a 
cyber perspective, what's happening is individual companies are 
seeing cyber threats on their individual networks, we're seeing 
cyber threats to the intelligence community, but we're not 
putting the pieces together to really understand what is the 
risk to our national security and what's the larger trends that 
are happening in the sector, and we need to be doing that if 
we're going to stay ahead of the threat that we're facing.
    And the ETAC is really meant to do that. It's meant to not 
only bring the people together, subject matter experts from 
electric power utilities, petroleum engineers, and the 
Government together to really understand these threats. And 
this is where we're not only leveraging the expertise of the 
entire Department but also the national laboratories. They have 
tremendous analytical expertise, they have tremendous machine 
expertise that we can bring to analyze threats, analyze data.
    We've used them for the nuclear industry for many years, 
and they've been tremendous assets for us. We should be doing 
the same on the cyber front, and so that's where we're 
leveraging the capabilities of those national laboratories, and 
we're all certainly leading a lot of the efforts, but we have a 
number of other laboratories engaged as well.
    Ms. DeGette. And where are we at with these efforts?
    Mr. Kumar. So we have already been conducting efforts, so 
we're doing pilot efforts where we're already looking at 
threats. We've actually--during the Russia/Ukraine conflict, we 
had identified cyber threats, and we were able to get cyber 
advisories out to the entire energy sector as a result of this. 
We're still working through fully standing up the ETAC, and for 
that we would need help from Congress and others. And so we 
look forward to working with you on that.
    Ms. DeGette. What's your timeline, do you think?
    Mr. Kumar. So we're already operationalizing the pilot, but 
to fully stand it up, we're looking at doing that in 2027. 
Again, that will require both resources and some authorities to 
fully stand up the ETAC.
    Ms. DeGette. Well, we look forward to working with you on 
it because it's really important that we have an integrated 
system like the one that ETAC is envisioning.
    Just one last question for you: As Sector Risk Management 
Agency for the energy sector, what is DOE doing to proactively 
address cyber threats to the U.S. energy sector?
    Mr. Kumar. So, ma'am, we have to take a multifaceted 
approach to this because the threat is too great. the threats 
from China, Russia, and even ransomware groups nowadays. And so 
we really think they fall into three big buckets. One, we need 
to think about policies. What are the policies--not only do we 
need to think about policies at a national level but also 
standards, and so what are some of those policies we need to be 
implementing to stay ahead of the threat?
    The second thing is we need to look at all the training and 
technical assistance that we can provide to the sector, 
exercising for cyber events.
    And third, and probably one of the most important pieces, 
is the partnerships. As I mentioned earlier regarding Colonial, 
it's those partnerships that we need to have during blue sky 
days that we can leverage to be able to combat these threats 
when we see them on our networks and when they impact the 
delivery of energy supply across the country.
    Ms. DeGette. Great, thank you.
    Thank you, I yield back.
    Mr. Griffith. The gentlelady yields back. And now I 
recognize the subcommittee chair of Energy, Mr. Duncan, for his 
5 minutes of questioning.
    Mr. Duncan. Thank you. Thank you for mentioning Energy 
twice. I'm going to focus on that a little bit here.
    The prior administration, Mr. Kumar, issued Executive Order 
EO 13920 entitled ``Securing the United States Bulk Power 
System.'' This Executive order implemented critical steps to 
ensure equipment of the bulk power system was not susceptible 
to foreign cyber intrusion. The Biden administration suspended 
this order on day one and since then has taken little or no 
action to ensure our bulk power system is not susceptible to 
cyber intrusion from hostile foreign adversaries like China, 
Russia through critical grid equipment like transformers, 
capacitors, and electrical relays.
    As chairman of the Subcommittee on Energy, protecting our 
critical energy infrastructure from cyber threats remains a top 
priority, and I'm extremely concerned that the suspension of 
this Executive order unnecessarily jeopardizes the integrity of 
our electrical power system.
    What was the rationale for essentially revoking the order?
    Mr. Kumar. Representative, thank you for your question, and 
thanks for recognizing the importance of supply chain security. 
That's exactly what that Executive order was focused on, is how 
do we ensure that our manufacturers and suppliers, and who are 
they, how are they providing all this critical equipment, and 
how do we ensure it's secure?
    So one of the reasons--this remains a priority for us. We 
took a step back to take a holistic approach. In that Executive 
order, we ran into a number of implementation challenges. Also 
we felt like it didn't truly address the threat we were facing 
from adversarial nation states out there like China.
    And so what we've done is we've taken a step back to review 
policies, review testing. So my office conducts cyber testing 
of critical components from all over the sector. But how do we 
really take a methodical approach to address the threat we are 
seeing from manufacturers, from places where we don't think we 
should be looking at infrastructure? So we're working on a lot 
of those efforts behind the scenes, but supply chain security 
still remains a top priority for us.
    Mr. Duncan. So just as a sidebar, a contract was issued as 
we build out infrastructure to a European country, I believe, 
that is working to do this work, and infrastructure 
requirements are about 60,000 capacitors--HVDC capacitors, 
right? This European company is sourcing those capacitors from 
Siemens in Germany and an Italian company.
    So you talk about onshore and domestic supply, we have a 
capacitor manufacturer in the United States that does the same 
thing, but yet this company is sourcing from Europe. And if 
Europe is continuing to build out their infrastructure, they 
may decide, ``There's not enough capacitors for the U.S., we're 
going to use them here,'' and then this company is left 
shortchanged.
    So how do you address that? How do you address future 
contracts for infrastructure buildout when you're talking about 
domestic supply chain?
    Mr. Kumar. Representative, so domestic manufacturing is 
absolutely something we should be prioritizing. It not only 
is----
    Mr. Duncan. Why aren't you?
    Mr. Kumar. So that is definitely a priority for the 
Secretary.
    Mr. Duncan. Then why issue a contract to a company that's 
sourcing their capacitors from Europe?
    Mr. Kumar. Representative, I don't know the specifics of 
that incident, but I'm happy to look into it and get back with 
you.
    Mr. Duncan. Yes, please do. The Biden administration set a 
goal of a carbon-free power sector by 2035. This on top of the 
numerous tax credits for solar and wind, leading to a massive 
buildout of renewable generating resources on the grid, I have 
serious concerns with the cyber vulnerabilities of renewable 
because of the digital connectivity to manage those systems, 
whether it's moving the solar panels or coordinating wind. They 
are more susceptible to cyber attacks. So what is the DOE doing 
to ensure cybersecurity is built into these devices rather than 
trying to solve the vulnerabilities after an attack?
    Mr. Kumar. Representative, that's an excellent question, 
and it's exactly what we need to be doing. So we released a 
strategy last year called Cyber Informed Engineering, and one 
of the big focus areas for us at the Department and my office 
in CESER is to partner with a lot of the renewable energy 
community to build cybersecurity in.
    We actually have an opportunity unlike any other before. We 
have been bolting on cybersecurity. We now have an opportunity 
to say, much like we require safety in our products, we should 
require cybersecurity. And so that is something we're working 
with standards organizations, with the manufacturers 
themselves, and the developers out there to build in 
cybersecurity. So that is absolutely a priority, and I 
appreciate you recognizing it.
    Mr. Duncan. In light of emerging technologies like 
artificial intelligence, what are the departments, all of you, 
doing to stay ahead of this evolving cyber threat with--from 
AI?
    Mr. Kumar. Representative, AI and other emerging threats 
such as quantum are things we need to keep an eye out for, and 
we need to ensure that we're building it. And so from our end, 
DOE, my office also has a cyber R&D program, and we prioritize 
some of our R&D work to look at quantum-resistant technologies 
but also how do we get ahead of that AI threat, so that's 
really important.
    Mr. Duncan. But you're also using cyber learning. You said 
a minute ago--machine learning, rather. That seems like it's 
counterproductive, using machine learning to target AI.
    Mr. Kumar. Representative, we----
    Mr. Duncan. Is it not teaching itself?
    Mr. Kumar. We--so we need to take a--we need to use all 
these technologies. We not only need to look at how does--
machine learning can be used against us, but how can we use 
machine learning to protect ourselves as well.
    Mr. Duncan. Yes. Thank you. My time's expired. I appreciate 
the answers.
    Mr. Griffith. I thank the gentleman for his questions. He 
yields back. I now recognize the gentlelady from Illinois, Ms. 
Schakowsky, for her 5 minutes of questioning.
    Ms. Schakowsky. Thank you, Mr. Chairman, and thank you to 
our witnesses today.
    Dr. Mazanec, you mentioned in your testimony that 
ransomware attacks have tripled in the last several years, and 
these attacks have exposed, I understand, nearly 42 million 
pieces of personal information that health--people who ask for 
healthcare and have been exposed. In Illinois, cyber attacks 
have also been a real problem, and, in fact, we had one of our 
hospitals close because--in--it was the St. Margaret Health in 
Peru, Illinois, a fairly small town, small area, which I'm sure 
really suffered because of the closing of that hospital.
    So I wanted to ask you, how is the Department of Health and 
Human Services helping hospitals and various other kind of 
health facilities to better prepare themselves and prevent 
where they can these kinds of cyber attacks?
    Dr. Mazanec. Thank you, Congresswoman, for the question. 
And as I mentioned in my opening statement, we are taking a 
number of steps to address the threat. And the threat is not 
static, the sector is evolving. There was a mention of AI. 
That's--AI is a capability that's being integrated into the 
public health system in the future, and likely that's going to 
increase, and that's going to increase the surface space. So 
the threat is evolving. We need to elevate our game as well in 
how we address it.
    As I mentioned in my opening statement, we do that in a 
number of key ways. One is developing resources, and those are 
resources that are tailored and can be used to--by various 
aspects of the sector to harden their infrastructure with the 
top 10 best practices, for example, that are tailored to the 
healthcare public health sector, they're identified in the 
HICP, the Health Industry Cybersecurity Practices Guide that we 
put out. We will then--we provide that to the sector, then we 
facilitate coordination with the sector to raise awareness of 
these resources to help better understand their needs so we can 
develop new resources to meet them.
    And then we also track incidents as they occur. I don't 
have the specifics of the St. Margaret Health incident in front 
of me, but those are the kind of things that we do monitor when 
they occur--assist working with our interagency partners as we 
can from an incident response perspective--and that's something 
we're looking to do more of in the future as well.
    Ms. Schakowsky. Well, let me ask you about data collection. 
Do you have any estimate over time how many hospitals or 
healthcare centers actually have closed in part at least 
because of cyber attacks?
    Dr. Mazanec. That's a complicated and nuanced question, an 
excellent question. A number of industry groups and others have 
reported figures associated with the number of attacks. I've 
seen around 14, 15 hundred attacks a week of various flavors in 
the sector, so it's a pervasive and growing threat. It's 
important for us as we, sort of, as the Sector Risk Management 
Agency to understand those challenges, understand how the 
threat's evolving, how the sector's evolving.
    So one of the key efforts that we have underway, we 
recently completed the Hospital Cyber Resiliency Initiative 
Landscape Analysis, which was essentially a case study 
collecting some actual data and evidence to understand what 
practices are in place in some of these hospitals, what's the 
threat they face, how can we best support them. We have some 
other efforts that are underway now to continue to collect 
evidence like that to better understand the threat going 
forward.
    Ms. Schakowsky. And once you have that evidence, what kind 
of work does HHS do in terms of transferring best practices for 
these healthcare institutions?
    Dr. Mazanec. Absolutely. So I mentioned HICP already. 
That's kind of a marquee product that we put out in partnership 
with the sector and working with the sector directly. They 
played a key role in developing that resource as well.
    Another resource we put out recently was the Healthcare 
Public Health Sector Cybersecurity Framework, which takes the 
best practices that NIST puts out in general for cybersecurity 
and maps them to and explains how to apply them in the context 
of healthcare and public health. So those are two key resources 
we put out, but we also go out to the sector, are available, 
can provide technical expertise if there are questions on how 
to implement these, and we look to develop additional guidance 
and resources going forward as well as we----
    Ms. Schakowsky. And, finally, let me just ask you, what is 
HHS doing in terms of also partnering with the public sector to 
minimize these kinds of attacks?
    Dr. Mazanec. Thank you, Congresswoman. That's, again, a 
great question. This is a key partnership. That's been a theme 
I think today in the questions, but it is a partnership both 
within HHS, with the interagency, and with the sector directly.
    We work very closely through a number of venues with the 
Health Sector Coordinating Council Joint Cybersecurity Working 
Group. They have biweekly meetings that we participate in. 
Those are representatives from across the sector, different 
types of hospital systems, and we really in that venue hear 
what their concerns are, hear their feedback on what they're 
looking for from us, we provide resources. And there's a number 
of other groups like that that we facilitate.
    That's a key part of ASPR's role as the SRMA lead within 
the Department, is managing that entire process. But it's a 
critical partnership for us. We cannot do this just on the 
government side.
    Ms. Schakowsky. Thank you so much.
    And with that, I yield back my time.
    Mr. Griffith. Thank you, gentlelady, for yielding back. I 
now recognize the gentlelady from Arizona, the vice chair of 
the subcommittee, for her 5 minutes of questioning.
    Mrs. Lesko. Thank you, Mr. Chair. Let me get out my 
questions.
    My first questions are for Mr. Kumar. Mr. Kumar, the Biden 
administration, in my opinion, has sought to limit and 
eventually eliminate the use of coal, oil, and natural gas as 
fuel. However, many Americans still rely on these resources to 
heat and power their homes. Has the Biden administration's push 
to shift to more renewables caused CESER to focus more of its 
cybersecurity efforts on incorporating renewable resources into 
the grid, and will the Department subsequently be investing 
less resources in securing infrastructure utilizing coal, oil, 
and natural gas?
    Mr. Kumar. Representative, thank you for the question. 
CESER looks at all forms of generation, electric--we--whether 
it's nuclear, whether it's coal. My office is really focused on 
ensuring regardless of generation source, we are ensuring the 
security of it. And so to that end, we not only partner on the 
electricity side with some of the clean energy community 
because we want to make sure that it is secure, but we also 
colead an entire group focused on the oil and natural gas 
industry, on security, and resilience. So there shouldn't be a 
difference in us working with the oil and natural gas industry 
or the coal industry.
    But, yes, we also need to be focused in on these new 
sources of generation so we can build cybersecurity into them 
as well.
    Mrs. Lesko. Yes, I was just trying to determine if, because 
there's more of them, right, I would assume more companies that 
you're dealing with, if you have to have--if you have a limited 
amount of resources, and if you're able to cover them all.
    Mr. Kumar. Certainly I would say not only is the fact that 
we have new market players such as the clean energy community, 
but the reality is we also have more digitization in the 
sector, so we do need to do more in general to get ahead of 
this threat. And then, of course, we're seeing an increased 
threat. So all of these things we have to stay on top of, and 
certainly we appreciate Congress and the White House's 
continued support of our budget request to stay ahead of these 
threats, ma'am.
    Mrs. Lesko. Thank you. I have another question for you, Mr. 
Kumar. According to BlackBerry's most recent Global Threat 
Intelligence Report, which I have right here, the U.S. electric 
and gas industries have been targeted by cyber attacks in the 
last 6 months, including by Russia-linked malware attempting to 
compromise energy-sector industrial control systems, an 
escalation from attacks on business IT systems to include 
operational technology. Russia has physically and digitally 
degraded nearly half of Ukraine's power infrastructure.
    What is DOE, as Sector Risk Management Agency for the 
energy sector, doing to proactively address cyber threats to 
the U.S. energy sector?
    Mr. Kumar. Representative, as you alluded to, the cyber 
threat is increasing, and it's not just on our business and 
email networks, it's focused on our operational networks that 
control our power grid, our pipelines across the country, and 
that is where we're seeing cyber adversaries focus their 
efforts. And so we as a department have had to shift where we 
focus as well, and so the approach that we are taking in CESER 
is what we call a threat-informed approach.
    So where is the adversary headed, where is the threat 
headed? That's where we want to prioritize our efforts, our 
resources so that we can stay ahead of that threat, and so 
that's been our focus is, to really conduct hands-on training 
to show how a cyber event could impact a pipeline or electric 
operations. And so we're taking what we learn of those cyber 
threats that you're alluding to and baking them into everything 
that we do as a department.
    Mrs. Lesko. Good. Mr. Mazanec, did the cybersecurity risks 
and cyber attacks increase during the height of the COVID 
pandemic?
    Dr. Mazanec. Thank you, Vice Chair Lesko, it's an excellent 
question. So the COVID pandemic absolutely heightened the 
threats that we saw to the sector. The system was stressed 
generally, separate from just the cyber threats that were 
present. And, of course, as I mentioned in my opening remarks 
and I think is widely recognized, cybersecurity is a--generally 
an underfunded research in healthcare--or resource in 
healthcare and public health.
    So it was already stretched thin, and the pandemic 
exacerbated that. So we did see an increase. We're seeing year 
over year even as we end the public health emergency and leave 
the pandemic, the threat is continuing to grow, and we--
certainly that was the case during the pandemic as well.
    Mrs. Lesko. Thank you, and I yield back.
    Mr. Griffith. The gentlelady yields back. I now recognize 
the gentleman from California, Dr. Ruiz, for his 5 minutes of 
questions.
    Mr. Ruiz. Hey, thank you, Mr. Chairman.
    As it's been mentioned, cybersecurity is among one of the 
most pressing national security issues that our country is 
facing. Cyber attacks are on the rise and on pace to shatter 
record-setting numbers. In the last 5 years alone, the College 
of the Desert in my district, the Imperial Community College in 
my district, and the Imperial County, an office that is 
responsible for critical infrastructure in my district, were 
hit with cyber attacks. The San Bernardino County was also--
Sheriff's Department was also recently hit by cybersecurity 
attacks.
    While, thankfully, no critical infrastructure was damaged 
in those specific cases, we continue to be concerned about 
future attacks. One area of specific concern is the 
vulnerability of our water systems. As a district that is 
currently struggling with getting access to clean water, any 
attacks on our water systems would be catastrophic. The reason 
for this is that breaches in the cybersecurity of a water 
system can compromise the safety and quality of water supplies 
as attackers may tamper with treatment processes or introduce 
harmful substances posing significant health risks.
    And living in the desert with 116 degrees, the lack of 
water or undrinkable water is an emergency, OK. Unfortunately, 
smaller water systems that serve some of the country's most 
vulnerable populations, like those in my district, often lack 
the resources to help them prepare for and mitigate the impacts 
of water system disruptions, including those caused by cyber 
attacks.
    So, Dr. Travers, can you provide examples how the EPA has 
helped smaller and underresourced water systems to identify 
their unique system risks and take steps to mitigate them?
    Dr. Travers. Thank you for your question, Congressman Ruiz. 
The security of small systems is an essential component of our 
Homeland Security mission. As you cited, these systems, though 
small, are critical to the viability of the communities they 
serve, whether they're in a desert community or not. EPA has 
provided extensive assistance to smaller systems.
    I cited earlier, for instance, an effort that we had 
underway targeted specifically towards smaller and 
disadvantaged systems, whereby we would dispatch subject matter 
experts in cybersecurity to smaller water systems to assess the 
cybersecurity practices at those communities and to recommend 
basic cybersecurity measures that they could enact to close 
those cybersecurity gaps. And these are not resource-intensive 
steps that they can take, these are steps more related to 
process like having strong, unique passwords. It's very basic.
    Mr. Ruiz. Yes, thank you.
    Dr. Travers. Yes.
    Mr. Ruiz. Thank you. A robust, well-trained workforce is 
essential to preparing for and responding to cyber attacks on 
critical infrastructure, and yet we currently are experiencing 
a cybersecurity workforce shortage of 700,000 individuals. Cal 
State University San Bernardino has one of the largest, aside 
from the Government, of training in cybersecurity experts.
    Dr. Travers, how does the EPA plan to address this 
cybersecurity workforce shortage at a pace that will meet this 
rapidly growing problem?
    Dr. Travers. Thank you for the question, Congressman. EPA, 
in addition to the assistance that I mentioned earlier, we also 
provide extensive training to actual circuit riders and train 
the trainer-type programs, whereby we work closely, for example 
with the National Water Association, USDA, the Rural Community 
Assistance Program so that those individuals, who often are a 
source of technical expertise to smaller systems, have the 
ability to provide critical assistance on cybersecurity----
    Mr. Ruiz. Great.
    Dr. Travers [continuing]. To those smaller systems to 
compensate for that lack of workforce.
    Mr. Ruiz. Can I suggest you partner with universities like 
Cal State San Bernardino--Cal State University San Bernardino 
to outreach into local communities? Because one of the issues 
is that we need the workforce also in these smaller, rural 
areas. And so how are you working to increase the effectiveness 
of the smaller water systems to increase their expertise and 
cybersecurity experts and workforce?
    Dr. Travers. Yes, thank you, Congressman. We are happy to 
work with literally any entity that can help us access smaller 
water systems and to lend assistance to communities who are in 
need of our assistance, so we are happy to partner with local 
universities, with States, local community groups to provide 
assistance.
    Mr. Ruiz. Thank you, yield back.
    Mrs. Lesko [presiding]. Thank you. And now I recognize the 
Chair of the Energy and Commerce Committee, Representative 
Cathy McMorris Rodgers.
    Mrs. Rodgers. Thank you, Madam Chair.
    The Executive Office of the President released his National 
Cybersecurity Strategy in March. Include--it includes five 
pillars, including Pillar 1 on defending critical 
infrastructure. And I know, Director Kumar, you referenced this 
in your written testimony, you mentioned the National Strategy.
    I just wanted to ask each one of you to speak a little bit 
more about your agency's role in developing this National 
Strategy, what your involvement was, what additional actions 
you think your agency should be taking, feedback on the 
strategy, working with the private sector as a place to start.
    So, Mr. Kumar, if you would start, that would be great.
    Mr. Kumar. Thank you so much, Chairwoman. The National 
Cyber Strategy really was bringing together an entire 
government to say what are our gaps in cybersecurity as a 
country, what do we need to be doing to address them? CESER 
represented the Department of Energy as part of the senior 
steering committee to help develop the report. We helped advise 
the White House on areas where we think we need to be doing 
more.
    And so to that end, there are a couple of areas where we 
identified, and thankfully they made their way into the 
strategy. And so the first was we need to be--we need 
operational collaboration between industry and government on 
cyber. We all can't go at it alone. We need to be partnering 
more closely, we need to shift how we look at cyber threats, we 
need to be sitting shoulder to shoulder with operators of the 
electric grid, with the intelligence community. And so to that 
end, the Energy Threat Analysis Center pilot that we are 
piloting right now was included.
    The second area of focus we suggested was, as we see new 
renewable energy and other energy sources connecting into the 
grid, we absolutely have to ensure the cybersecurity of those 
systems. And so, again, that was also referenced. And we'll be 
leading an effort to bring together the clean energy community 
with cybersecurity experts to build cybersecurity into it.
    And last but not least, an area where we think there needs 
to be a tremendous amount of focus is a concept we call cyber-
informed engineering. We have to develop cybersecurity into 
these systems, whether it's large pieces of transformers or 
whether it is solar panels or anything else, cyber just has to 
be a part of it. So that end, this national cyber-informed 
engineering strategy needs to be developed, and we need to do 
more to work with standards, orgs, manufacturers, suppliers, 
and everyone to do more in this space.
    And so overall, we got a tremendous amount of support, and 
we're very--it was a very collaborative process.
    Mrs. Rodgers. Thank you.
    Dr. Mazanec. Thank you very much for the question. So HHS, 
similar to the Department of Energy, participated in the 
interagency process that developed the National Cyber Strategy. 
In terms of the benefits for us going forward and how we're 
using that strategy, I would say first of all, it's very 
helpful in that it provides a common lexicon that we can use as 
we engage in that critical collaboration with our partners to 
talk about the threat, talk about and frame what we're doing.
    It also directed the development of an implementation plan 
that is currently in development, and that provides a venue for 
us, along with others in the interagency, to participate and 
try to use that framework to enhance how we collaborate and 
work together as a team across the Government.
    The last piece I would note as well is the strategy 
indicated a move towards minimum mandatory standards. That's 
something for the healthcare and public health sector, as I 
mentioned in some of my comments, is really complicated and 
challenging. It's a very diverse and complicated sector but 
something that we have heard from our industry partners that 
they are interested in.
    I mentioned earlier some of the resources we put out that 
provide guidance, voluntary standards, if you will, that they 
could adopt. But the National Cyber Strategy provides a 
framework for us to continue to explore in a very thoughtful 
and evidence-based way how to develop minimum mandatory 
standards for the sector, if appropriate.
    Mrs. Rodgers. And would you--I'm going to keep going, but 
would you also speak to what kind of feedback we've gotten from 
the private sector?
    Dr. Mazanec. So from the healthcare public health 
perspective, the feedback thus far has been very positive. I 
mentioned the venues we coordinate in. We got very positive 
feedback from the strategy.
    Mrs. Rodgers. OK, good. Thank you.
    Mr. Travers?
    Dr. Travers. Thank you for the question. So I personally 
participated in the interagency work group that was responsible 
for developing the Cybersecurity Strategy. I certainly felt 
that it was a very collaborative process, felt as the other 
panelists have expressed, our voices were heard, and that EPA 
was able to advocate for the sorts of concerns and issues that 
confront the water sector.
    Certainly we appreciated the strategy as it underscored the 
importance of partnerships with the private sector, working 
with them to leverage their expertise and experience in 
providing products, and also leveraging our existing resources 
so that we don't duplicate efforts. So that--Dr. Mazanec 
mentioned standards so that we don't all go off in separate 
directions, developing standards that don't have consistency 
and aren't based on a fairly uniform approach.
    And then, finally, the--we appreciated the fact that the 
document emphasizes the importance of the sector risk 
management role, as Sector Risk Management Agencies have a 
unique understanding of our respective sectors.
    Mrs. Rodgers. Thank you.
    Dr. Travers. So we were pleased to see that reflected in 
the document as well.
    Mrs. Rodgers. Thank you. Good. I'm pleased to hear that 
too. Thank you all for being here.
    I yield back.
    Mrs. Lesko. Thank you. I'd like to recognize Representative 
Tonko from New York for 5 minutes of questioning.
    Mr. Tonko. Thank you, Madam Chair, and thank you to our 
panelists and to--for being here and for your leadership.
    As past chair and now ranking member of the Environment 
Subcommittee, ensuring that all Americans have easy access to 
safe drinking water has been a long-time priority. Our 
community drinking water and wastewater systems provide a 
critical service for the American public. The resilience of 
these systems in the face of cybersecurity threats is key to 
ensuring that everyone has clean water.
    As the Sector Risk Management Agency for water systems, EPA 
is able to draw on extensive relationships and water system 
expertise to support cybersecurity efforts. That's why this 
committee has a long history of working together on a 
bipartisan basis to support EPA's cybersecurity efforts. In 
2018, this committee further enhanced EPA's ability to work 
with water systems to improve their resiliency. The bipartisan 
America's Water Infrastructure Act, or AWIA, gives EPA 
important authorities and tools that can help water systems 
identify risks and plan for emergencies, including those cyber 
attacks.
    So, Dr. Travers, how is EPA using the tools provided by 
Congress in the bipartisan AWIA effort to enhance EPA 
cybersecurity efforts and better partner with water systems?
    Dr. Travers. Thank you for the question, Congressman. AWIA, 
as you rightly cited, represents certainly a statute of 
foundational importance to the Water Sector. It required 
community water systems serving more than 300 people--3,300 
people, excuse me, to prepare risk assessments and emergency 
response plans, which is a critical first step in enhancing the 
resilience and security of these water systems.
    So in response to that congressional mandate, EPA developed 
a suite of tools and training and technical assistance, all of 
which I will note we completed within about 8 months, given the 
very aggressive timeframe within the statute. As a result of 
our efforts, as a result of the partnership that we enjoy with 
our sector, we have seen excellent compliance rates with AWIA. 
That was, of course, the important policy outcome we wanted to 
see. About a hundred percent of large and medium systems have 
complied with the provisions of AWIA, and about 96 percent of 
small systems have complied with the provisions. So I think it 
is an excellent use story, and I think AWIA, as I said, 
imparted a critical impetus and policy directive to the water 
sector that the sector took seriously.
    Mr. Tonko. Thank you, I appreciate that. And while 
cybersecurity threats won't go away, there are steps water 
systems can take to improve their chances of deterring and 
detecting attacks before they impact public safety. Cyber 
threats are constantly evolving and require vigilance and 
forward-looking plans. This is especially true for the 
cybersecurity of critical water systems that we depend upon for 
drinking water.
    So, Dr. Travers, again, how does EPA work with other 
Federal agencies to develop best practices for cybersecurity 
infrastructure, and what sector-specific adaptations are needed 
when translating and communicating these strategies to apply to 
water systems?
    Dr. Travers. Thank you for the question, Congressman. EPA 
has worked extensively with our interagency partners in 
developing best cybersecurity practices for the water sector. 
What we have noted is that many water systems within the sector 
have neglected to adopt basic cybersecurity strategies, and so 
our efforts have focused on underscoring that the adoption of 
very kind of rudimentary practices can be astonishingly 
effective in mitigating the risk of cybersecurity.
    So, for example, you asked about how we adapt cybersecurity 
practices for the water sector. We have provided a checklist, 
again, as a result of the AWIA requirements for water systems, 
so--which is readily accessible to water systems which may have 
limited technical capacity in dealing with cybersecurity, so we 
present it in a form that is a disstilled version of a much 
larger standard developed by NIST, and we conducted extensive 
training and exercises based on those practices. We have also 
actually conducted assessments at utilities themselves 
leveraging those standard.
    And I will say on a final note that we have leveraged 
CISA's cross-sector performance goals in developing our basic 
checklist of cybersecurity practices, again, to ensure 
consistency across the Federal Government.
    Mr. Tonko. Well, thank you. I would say that, based on the 
bipartisanship of AWIA, I hope we can continue to effectively 
respond to those cybersecurity threats.
    And with that, Madam Chair, I yield back. Thank you.
    Mrs. Lesko. Thank you. And now I call on Representative 
Cammack from Florida for 5 minutes of questions.
    Mrs. Cammack. Thank you, Madam Chair, and thank you to our 
witnesses. You're in the home stretch, so hang in there.
    Dr. ``Man-za-nec,'' did I get it right?
    Dr. Mazanec. Almost. ``Maz-a-nec.''
    Mrs. Cammack. Mazanec, OK. Thank you. You noted in your 
testimony that ransomware is currently the largest threat to 
the healthcare and public health sector. Specifically, what can 
you give me in terms of examples, and I'm looking for three, 
that the department of Health and Human Services has planned 
and enacted to address the growing ransomware threat, and what 
you are doing to help health systems and hospitals address that 
growing threat.
    Dr. Mazanec. Thank you, Congresswoman, that's an excellent 
question. I'll highlight a couple things a little more that I 
already touched on, but I think one of the key ways to address 
the ransomware threat or any sort of malign cyber threat is 
through deterrence by denial, hardening the sector so it's less 
appealing to adversaries. There's a lot of financial 
incentives, other incentives that I think make it an easy 
target, the healthcare public health sector--making it an 
appealing target, I should say.
    So some of the resources we have recently developed or 
updated and put out there are essentially resources that help 
harden the target and deter, hopefully, some of the ransomware 
actors. This is--the resources that I'm referencing are things 
like the HICP, the Health Industry Cybersecurity Practices 
Guide, which we updated not that long ago, that has 10 
mitigating strategies in it. Again, not incredibly complicated, 
they're basic things, tools and steps that a diverse array of 
entities within the sector can take to harden their target, 
things like implementing better data protection, IT asset 
management, those kind of cyber hygiene practices.
    We've also facilitated a lot of sector coordination, as I 
mentioned, through the Health Sector Coordinating Council Joint 
Cyber Working Group working with our industry partners and 
other venues. That leads to a lot of information sharing where 
we're working to enhance threat and intelligence sharing. That, 
again, I think helps combat the threat.
    And then ultimately helping ensure from an incident 
response planning perspective that the sector and the entities 
have incident response plans in place. We have our plan that we 
recently updated within the department and that we're ready to 
exercise it should an attack occur to minimize the impact on 
patients and patient's safety.
    Mrs. Cammack. Thank you. Now kind of digging into some of 
the Internet of Things within the hospital systems. Data shows 
that 53 percent of connected medical devices and other Internet 
of Things devices in hospitals have a known critical 
vulnerability. Many of these devices do not have patches or 
compensating controls that are provided by the manufacturers.
    So what is HHS doing to ensure that these vulnerabilities 
are remedied with validated patches and other mitigations from 
the manufacturers and that these solutions are made available 
in a timely manner--and I would like you to define what a 
timely manner is--by the manufacturers, but also how can this 
also be made available to other servicers and technicians 
outside of the manufacturers?
    Dr. Mazanec. Thank you for that question. And indeed, the--
part of what makes the sector so complicated are the diverse 
array of connected, interconnected legacy devices. We--I 
mentioned earlier we recently completed a hospital cyber 
resiliency initiative landscape analysis to really dig in to an 
aspect of the sector and understand the threats they face. One 
of the things that came of that assessment was along the lines 
of your question, a finding that a significant number of 
hospitals--I think it was nearly a hundred percent within the 
population we looked at--had at least some devices that were 
not patched, were at sort of legacy end of life.
    So that's something that we're aware of, we're working to 
address, that we provide, again, these resources that put in 
place a framework for each entity to use to identify where they 
need to update and implement patches, and we're hopeful that 
that will be helpful. And, of course, our colleagues within the 
Food and Drug Administration recently got additional 
authorities--enforcement authorities in the omnibus legislation 
for medical devices, which is not all internet-connected 
devices in the sector, it's a subset of it, but they are 
currently working through how to implement those and address 
that from a medical device perspective.
    Mrs. Cammack. Well, and when you say resources and 
providing resources, is that more technical guidance, or is 
there actually a funding mechanism that goes along with that?
    Dr. Mazanec. So we do not currently directly provide 
funding to address this issue. We provide guidance, we provide 
knowledge-on-demand web-based resources in that sense that can 
help the expertise in the sector more efficiently and 
effectively address this issue. But, as I mentioned, you know, 
the threat is not static, it's growing. As we move forward and 
consider various policy options and part in collaboration 
working with you and your staff, one of the things, of course, 
we will explore is are there more things we can do along the 
lines of funding to address this issue.
    Mrs. Cammack. Well, and I've got one question left, so I'm 
going to get to it as quickly as possible. Last 11 years, 
healthcare has had the highest average cost of $10 million per 
breach with a record number of data breaches in 2021. What is 
HHS doing in order to ensure the timely reporting by 
manufacturers of known cybersecurity vulnerabilities on their 
devices? And again, define timely.
    Dr. Mazanec. So I would--if it's possible, I would like to 
get back to you with--and we can work with our colleagues in 
FDA to get a little more information from a medical device 
perspective, but I do want to highlight the sector as much more 
than just medical devices. There's a lot of additional 
connected devices as part of the Internet of Things.
    Mrs. Cammack. Right.
    Dr. Mazanec. Operational technology. So I think we take a 
holistic approach to the risks facing the sector as the SRMA 
and ASPR. The cyber threats, the other threats, and certainly 
those connected devices exacerbate it. But we can get back to 
you and your staff with additional information on what FDA is 
doing specific to the medical devices that they have 
authorities over.
    Mrs. Cammack. Perfect. I appreciate it. Thank you so much.
    My time is expired, Mr. Chairman. I yield.
    Mr. Griffith [presiding]. The gentlelady yields back. I now 
recognize the gentleman from California, Mr. Peters, for his 5 
minutes of questions.
    Mr. Peters. Thank you, Mr. Chairman.
    I'll follow up somewhat on Mrs. Cammack's questions about 
healthcare. The number of ransomware attacks on health 
organizations more than doubled from 2016 to 2021, exposing 
that personal health information of nearly 42 million patients. 
In May 2021, a health system in my district, Scripps Health, 
was attacked with malware, and when--while Scripps immediately 
launched an investigation and took steps to contain the damage, 
the cyber attack still disrupted care at Scripps and resulted 
in a surge of patients at other healthcare facilities across 
the San Diego area.
    Dr. Mazanec, when a cyber attack happens, how does HHS work 
with hospitals and State public health agencies to respond and 
recover?
    Dr. Mazanec. Thank you, Congressman, that's a great 
question. And I would note from the 2021 Scripps Health 
incident, that was actually the specific attack, and I 
referenced in my opening remarks, the JAMA, the Journal of 
American Medical Association study that came out just last week 
that look--dug into that incident and reported on what they 
call the blast effect to--in terms of creating significant 
detrimental outcomes in the surrounding area too. So it wasn't 
just the affected entity----
    Mr. Peters. Right.
    Dr. Mazanec [continuing]. That had adverse effects. In 
terms of how we respond in general, in that instance and in 
general to an incident, we work, first of all, very closely 
with our interagency partners and our other partners, ASPR 
within the Department of Health and Human Services, so it's a 
team effort in responding. We first observe--get information on 
the incident, and then we convene a healthcare public health 
risk management cyber incident response team, or an HPH cert, 
which is a formal entity within the Department that--with 
interagency participation that will determine the--how to 
classify the incident, how severe it is.
    We're really interested in--from an SRMA perspective on 
impacts to patient health and safety, that's our primary focus, 
our--if there's a data breach, that's significant and 
concerning, but if it doesn't have an adverse effect on patient 
health and safety, that will result in a lower sort of incident 
classification. But depending on how we classify the incident, 
that will inform our response from there in terms of do we 
monitor it or is there assistance we can provide.
    And again, our interagency partners are key. Often it is 
not HHS who has direct contact with the entity, it may be the 
FBI, from a criminal perspective, or our colleagues at CISA.
    Mr. Peters. In terms of your--of the expertise you might 
provide, what is the knowledge and expertise that HHS can bring 
to the healthcare sector in an instance like this?
    Dr. Mazanec. So one of the great strengths of how--and I 
know my colleagues on the panel have noted this for their 
respective sectors as well, but as an SRMA, we do have, I 
think, a unique position and understanding of the patient 
impacts, health and safety. We understand the sector better 
than anyone else. And then we partner with law enforcement, 
FBI, with CISA, who bring other skills to the table to support 
the affected entity however, you know, we best can.
    But we bring that unique vantage point from a healthcare 
public health perspective that I think the others don't 
necessarily have.
    Mr. Peters. I understand also you have promulgated or 
offered voluntary guidelines for organizations. Can you tell me 
about those, and what are you hearing from healthcare systems 
that have implemented the guidelines about their impact on 
cybersecurity?
    Dr. Mazanec. Absolutely. So we just recently provided two 
key resources to the sector that essentially contain voluntary 
best practices. The first is a resource--and both of these I 
should note, too, were developed in close partnership with the 
sector; these are not things that we developed in isolation.
    The first key tool is that the Healthcare Public Health 
Sector Cybersecurity Framework Implementation Guide. This 
essentially takes the NIST best practices for cybersecurity and 
tailors them to the sector. It--both of these just came out a 
few weeks or months ago, so they're still, I think, receiving 
feedback, but it's been very positive.
    The other key tool, and I know I've mentioned it a few 
times already, is the HICP, the Health Industry Cybersecurity 
Practices, that was developed, again, with industry and led by 
our HHS 405(d) Program. That contains the top 10 mitigating 
strategies, has sort of off-the-shelf tools that are tailored 
to small, medium, large hospital systems, so it's a really 
flexible tool with best practices.
    And as we go forward, we'll be collecting data through a 
number of different ways as to how the sector is use--are using 
these, how we can revise them as appropriate going forward, 
again, because the threat is not static here----
    Mr. Peters. Right.
    Dr. Mazanec [continuing]. It is continuing to grow and 
evolve.
    Mr. Peters. Well, I mean, the health systems will always be 
an attractive target for cyber criminals because of the value 
of the data that they hold and the security and health of the 
nation that's behind them. I would say congratulations on an 
acronym like HICP, but it's more than a hiccup in this case, so 
I appreciate your good work, and thank you again for being with 
us today.
    And, Mr. Chairman, I yield back.
    Mr. Griffith. The gentleman yields back. I now recognize 
the gentleman from Alabama, Mr. Palmer, for 5 minutes of 
questioning.
    Mr. Palmer. Thank you, Mr. Chairman. Thank you for holding 
the hearing, and thank you to the witnesses for appearing.
    I might be wrong, but I think the first time that most 
Americans experienced a cyber attack against our energy 
infrastructure was the attack on the Colonial Pipelines, and 
they might not have realized it as they were sitting in long 
gas lines trying to put gas in their cars.
    What I want to ask you is when--Mr. Kumar, when the 
Department engages in efforts to facilitate coordination 
between the electric and gas subsectors, or I guess any part of 
our energy infrastructure, to guard against and respond to 
cyber attacks, is there a thorough evaluation of the adequacy 
of the firewalls that these companies and other entities are 
using to protect our critical energy infrastructure?
    Mr. Kumar. Representative, thank you for the question. And 
the Colonial Pipeline incident, you're absolutely right, was a 
wakeup call for a lot of Americans and a lot of critical 
infrastructure owners and operators themselves that, you know, 
we need to do more, we need to really ensure that we have 
certain cyber baselines in place.
    Mr. Palmer. I've got several questions, but what I'm really 
asking is, some of the energy infrastructure is obviously 
privately held, very--some of it is--like TBAs, Federal. When 
you're looking at trying to protect against these, are you 
evaluating across the board, whether it's privately on company 
or a government company, their firewalls, they're building to 
harden in their systems?
    Mr. Kumar. Representative, when it's a privately owned 
company, they usually have to invite us in to be able to do 
that type of assessment. We do offer assessments of those 
companies should they choose to take us up on those, so we 
definitely offer them. But again, it does determine if the 
private sector----
    Now on the electricity side, there are--there's a 
regulatory regime where there is enforcement, and they do have 
to validate that they are meeting certain cyber requirements.
    Mr. Palmer. Along the same line, you note in your written 
testimony that CESER facilitates both the Electric Subsector 
Coordinating Council and the Oil and Natural Gas Subsector 
Coordinating Council, and I just wonder if these two entities 
ever interact to examine shared threats, and it's all on the 
same lines of what I led into this with, the shared threats 
with opportunities to collaborate to address them.
    And one of the things that I'm particularly interested in 
is modeling, or what some people would call war gaming, to 
prepare in advance for these. And this happened--in my district 
we have the National Computer Forensics Institute, and they've 
done some of this, particularly in regard to responding to 
ransomware attacks. And I just wonder if the Department of 
Energy is doing anything to facilitate that type of activity to 
model these potential attacks.
    Mr. Kumar. Representative, thank you for that question. And 
absolutely. And we have to make sure we're looking at the 
entire energy sector. So we conduct cyber exercises, and when 
we conduct them we include both electricity and oil and natural 
gas companies, and our scenarios include the interdependencies 
between the sectors but also what kind of modeling capabilities 
can we leverage from national laboratories and other resources 
to understand how a specific cyber threat could actually impact 
Americans across the country. And so that's absolutely a core 
component of what we are doing.
    Mr. Palmer. Now this actually applies across the board to 
the other agencies involved in this hearing, whether it's a 
school system, hospital, or what have you. And I think it's 
very important that we do that and we emphasize that.
    The other thing is, in the role of the national labs in 
trying to identify threats to the electric grid--and not just 
the electric grid but the critical infrastructure across the 
board--is there any evaluation of the risk of--in terms of the 
interconnectivity of everything, interfacing with systems that 
utilize technology that was designed, installed and 
manufactured and maintained by China? I mean, we tend to think 
that we have these boundaries that protect us, but when it 
comes to interconnectivity, I mean, even right down to fiber, 
we're connected.
    And that--all three of you, if you'd like, can respond to 
that. But I think it's one of the critical questions that we 
need to answer.
    Mr. Kumar. Representative, what we're looking at is taking 
a threat-informed picture, and the reality is, one of the 
biggest threats we have is the threat from China, particularly 
when it comes to cyber capabilities. And so, as we do some of 
our testing--for example, we will test critical components for 
cyber vulnerabilities. When we do some of that work, we will--
that is informed by the threat we are seeing, and that informs 
all of our work in our office.
    Mr. Palmer. Mr. Mazanec?
    Dr. Mazanec. And, yes, I would from the HHS perspective and 
for the healthcare public health sector, the supply chain and 
the interdependencies are very significant. We focus on it 
holistically as well. And they're going to only increase as 
there are more and more connected and network devices in the 
medical system.
    Mr. Palmer. Mr. Travers, do you have anything to add to 
that?
    Dr. Travers. Yes, thank you, Congressman. Supply chain and 
third-party availability of cyber tools form a critical part of 
our checklist that we provide to both drinking water and 
wastewater systems, so it is a core part of the messaging and 
training that we provide to the water sector.
    Mr. Palmer. Well, I thank the witnesses.
    I thank the chairman, and I yield back.
    Mr. Griffith. The gentleman yields back. I now recognize 
the gentleman from Texas, Mr. Crenshaw, for his 5 minutes of 
questioning.
    Mr. Crenshaw. Thank you, Mr. Chairman, and thank you all 
for being here.
    I want to focus on our hospitals. So for you, Mr. Mazanec, 
you know, one simple question I have is, who at HHS is our 
private sector supposed to work with in the event of a cyber 
attack?
    Dr. Mazanec. Thank you, Congressman. So HHS brings a lot to 
the table in our SRMA responsibilities here working with the 
sector, but in terms of the lead coordinating entity, it is 
ASPR, the Administration for Strategic Preparedness and 
Response, that is sort of the central quarterbacking function 
within the Department.
    That being said, though, if anyone reaches out, as I 
mentioned in my opening statement, we have a weekly meeting 
with all the key entities across the Department. If anyone is 
unsure of who to contact, if--and that's something we're 
looking to, you know, simplify and clarify for the sector, but 
if they reach out to any part of HHS, we are coordinating 
closely and will make sure we get them connected to who they 
need to be connected with to address the issue.
    Mr. Crenshaw. All right. I didn't even have that on my 
list, I mean, because we got Chief Information Officer--if we 
go to your website--staff trying to research this before I 
asked it, and that wasn't even on my list. We got a Health 
Sector Cybersecurity Coordination Center. What is that?
    Dr. Mazanec. So the Health Sector Cybersecurity 
Coordination Center, which we call HC3, is within the Office of 
the Chief Information Officer. It is a key repository of 
technical expertise and coordinates on--and puts out 
information to the sector tailored to it from a threat 
perspective. Again, there are key participants and partners 
with us with ASPR playing that coordinating----
    Mr. Crenshaw. But a hospital needs a 1-800para.ber attack 
number. Do they have that number?
    Dr. Mazanec. So if they reached out to HC3, they would 
get----
    Mr. Crenshaw. How would they reach out to HC3, like do they 
go to your website, like how do they know?
    Dr. Mazanec. They have a web presence. We have the 405(d) 
Program, which is another program established by Congress that 
engages a lot with the sector, has a very, I think, 
comprehensive web presence that is faced into the sector.
    But your question also indicates the importance of 
clarifying these--who they need to reach out to and engaging 
the sector. That's why some of these venues that I've mentioned 
previously, the Health Sector Coordinating Council Joint 
Cybersecurity Working Group----
    Mr. Crenshaw. Yes.
    Dr. Mazanec [continuing]. Is so important that we're 
engaging and touching the sector proactively so that we're not 
just waiting for them to reach out.
    Mr. Crenshaw. It's extremely important, that's why--and, 
you know, for emergencies we have a very simple number to call, 
9-1-1, right? It should be the same for this if your job is to 
help them.
    Another issue that they--that concern--that hospitals 
report is that regulators that they report to also have the 
ability to penalize them for reporting cyber attacks. You know, 
they can get--they can turn around and get fined after they ask 
for help because of the possibility that private data was 
released, et cetera. So how do you resolve that?
    Dr. Mazanec. So I think--I mean, that is a concern. We're--
we've heard and one of the--I think what they're referencing is 
the HIPAA security rule.
    Mr. Crenshaw. Yes.
    Dr. Mazanec. Which is actually an incentive for the 
adoption of some of the best practices and resources we put out 
there. A covered entity under HIPAA--which, I should note, is 
not the entire sector, it's a subset of the sector that are 
covered by HIPAA--if they have a data breach and they can 
demonstrate that over the preceding 12 months they had 
implemented and taken due diligence to implement voluntarily 
some cyber hygiene best practices like the HICP that we put out 
or the cybersecurity framework, then that will have a 
mitigating effect on whatever penalty they might be subject to. 
So, in fact,----
    Mr. Crenshaw. Yes, but----
    Dr. Mazanec [continuing]. That regulatory role actually 
incentivizes the adoption of some of the best practices.
    Mr. Crenshaw. Ideally, but in another--but it's also easy 
to imagine a different scenario wherein they didn't get around 
to it yet because they're busy, I don't know, doing hospital 
stuff, and so now they won't report these cyber attacks to you, 
and you can't add that to your database. You can't add these 
new attacks to your best practices, you can't help the people 
who were designed--you're designed to help because they're 
like, ``Well, I'm not going to report anything to you, I'll get 
fined.'' That's a problem that should be fixed.
    OK, so two problems that need to be fixed.
    Mr. Kumar, the deal you announced last year, that they're 
putting $45 million into improving the security of American 
energy, in particular tools to protect the power grid, if you 
could just provide a quick update on what solutions have come 
out of this. It's--again, it's very vague statements on the 
website. We can't find much information on what the plan is.
    Mr. Kumar. Representative, when we put out these funding 
announcements, what we do is we target them to threats. So what 
we do is we take intel to say, ``Here are the priority areas 
for the research that we would like folks to actually submit 
their applications to.'' So we're looking at things like how do 
new communications pathways create cyber risks, how do new 
emerging technologies such as AI and quantum could potentially 
impact the sector and therefore we need to develop tools and 
technologies to defend against them?
    So, again, all of our focus areas are mentioned in our 
funding announcements so that when someone submits it--and it 
could be an industry company, it could be academia, it could be 
a national laboratory, it could be universities as well to say 
that they are going to submit for funding requests for that. 
And that's where the 45 million is focused on, and we're----
    Mr. Crenshaw. It's a grant program----
    Mr. Kumar. It's a grant program, yes, sir.
    Mr. Crenshaw [continuing]. For cyber defense companies to 
create the tools--OK.
    Mr. Kumar. Absolutely, sir.
    Mr. Crenshaw. Got it. And I'm out of time. Thank you.
    I yield back.
    Mr. Griffith. The gentleman yields back. We now recognize 
Ms. Kelly of Illinois for her 5 minutes of questioning.
    Ms. Kelly. Thank you, Chair Griffith and Ranking Member 
Castor, for holding this important hearing this afternoon, and 
I want to thank our witnesses for their testimony.
    Mr. Mazanec, thank you for your testimony today. In your 
written testimony, you discuss how growing attacks from more 
aggressive adversaries are growing well beyond data breaches, 
now affecting timely access to patient care. For years, the 
health disparities for Black Americans and other minorities 
have been well documented, and a study by Pew Research Center 
revealed that a major reason attributing to these health 
inequities stems from less access to quality care.
    So how do these cyber attacks directed at healthcare and 
public health critical infrastructure exacerbate health 
inequities among minority populations and among rural 
populations?
    Dr. Mazanec. Thank you, Congresswoman, that's an excellent 
question. I think one of the challenges, again, facing us and 
facing the healthcare public health sector is the incredible 
diversity of the sector. There are some very, very large 
hospital systems, and there are some very small hospitals and 
elements of the sector that really aren't nearly as well 
resourced from a cyber perspective. So one of the things we do 
in trying to make sure everyone is hardened across the sector 
is develop tailored resources that will help and make it more 
efficient and easy for those smaller, less resourced hospitals 
to bolster and harden their infrastructure.
    So the HICP that I've mentioned a few times is definitely 
one of them. It has tailored resources that are designed for 
smaller hospitals that they can pick up and use. We also 
provide--and this is through our 405(d) Program--a knowledge-
on-demand series of courses that, again, can help the sector 
where they maybe don't have as much resident cyber expertise to 
get the basics that they need and implement kind of the key 
mitigating strategies and basic cyber hygiene that should 
harden them as well.
    Ms. Kelly. Yes, my district is urban, suburban, and rural. 
I start in Chicago and go 3 hours south, and there's less 
hospitals as you even go further south, and they're not the, 
you know, University of Chicago or Northwestern and things like 
that. Much smaller hospitals.
    Also, I'm encouraged by HHS's recently published edition of 
the Health Industry Cybersecurity Practices, HICP, the Hospital 
Resiliency Landscape Analysis, and the Healthcare and Public 
Health Sector Cybersecurity Framework Implementation Guide. How 
would a basic set of cybersecurity standards for all American 
hospitals help keep patients safe?
    Dr. Mazanec. So the--again, those resources you just 
mentioned, ma'am, are designed to provide the basic information 
needed to the smaller entities in particular, but they're 
applicable to the sector writ large to ensure that they can 
adopt best practices and harden their infrastructure.
    I would note, too, from a--the diversity of the sector and 
our focus, again, on patient safety and health impacts, 
smaller, rural hospitals and in areas where there aren't 
multiple hospitals have less ability to divert when there is an 
issue. So in some respects, that can make them--the incidents 
even more severe when they occur in those contexts, in addition 
to the fact that they may have less resources to harden their 
target. But this is why, again, we engage closely with the 
sector. We coordinate with them, we're developing tailored 
tools, and we'll continue to do that.
    This is also why we think we need to elevate our activity 
given that the threat is growing as well. Why the--in the 
Fiscal Year 2024 President's Budget Request, we're requesting 
an increase for our activities in this space, and within ASPR, 
we are standing up a dedicated cyber division to focus on these 
issues. And we appreciate your support as we do that.
    Ms. Kelly. Thank you so much, and thank the witnesses.
    And I yield back.
    Mr. Griffith. Thank you, gentlelady, for yielding back.
    Seeing no further Members wishing to ask questions this 
afternoon, I would like to thank all of our witnesses again for 
being here today.
    And pursuant to committee rules, I remind Members they have 
10 business days to submit additional questions for the record, 
and I ask the witnesses to submit their responses within 10 
business days upon receipt of those questions.
    Without objection, committee is adjourned.
    [Whereupon, at 4:20 p.m., the subcommittee was adjourned.]
    [Material submitted for inclusion in the record follows:]
    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]

                                 [all]