[Congressional Record Volume 161, Number 153 (Tuesday, October 20, 2015)]
[Senate]
[Page S7365]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 2719. Mr. ALEXANDER submitted an amendment intended to be proposed
by him to the bill S. 754, to improve cybersecurity in the United
States through enhanced sharing of information about cybersecurity
threats, and for other purposes; which was ordered to lie on the table;
as follows:
At the appropriate place, insert the following:
SEC. __. IMPROVING CYBERSECURITY IN THE HEALTH CARE INDUSTRY.
(a) Definitions.--In this section:
(1) Business associate.--The term ``business associate''
has the meaning given such term in section 160.103 of title
45, Code of Federal Regulations.
(2) Covered entity.--The term ``covered entity'' has the
meaning given such term in section 160.103 of title 45, Code
of Federal Regulations.
(3) Health care clearinghouse; health care provider; health
plan.--The terms ``health care clearinghouse'', ``health care
provider'', and ``health plan'' have the meanings given the
terms in section 160.103 of title 45, Code of Federal
Regulations.
(4) Health care industry stakeholder.--The term ``health
care industry stakeholder'' means any--
(A) health plan, health care clearinghouse, or health care
provider;
(B) patient advocate;
(C) pharmacist;
(D) developer of health information technology;
(E) laboratory;
(F) pharmaceutical or medical device manufacturer; or
(G) additional stakeholder the Secretary determines
necessary for purposes of subsection (d)(1), (d)(3), or (e).
(5) Secretary.--The term ``Secretary'' means the Secretary
of Health and Human Services.
(b) Report.--Not later than 1 year after the date of
enactment of this Act, the Secretary shall submit, to the
Committee on Health, Education, Labor, and Pensions of the
Senate and the Committee on Energy and Commerce of the House
of Representatives, a report on the preparedness of the
health care industry in responding to cybersecurity threats.
(c) Contents of Report.--With respect to the internal
response of the Department of Health and Human Services to
emerging cybersecurity threats, the report shall include--
(1) a clear statement of the official within the Department
of Health and Human Services to be responsible for leading
and coordinating efforts of the Department regarding
cybersecurity threats in the health care industry; and
(2) a plan from each relevant operating division and
subdivision of the Department of Health and Human Services on
how such division or subdivision will address cybersecurity
threats in the health care industry, including a clear
delineation of how each such division or subdivision will
divide responsibility among the personnel of such division or
subdivision and communicate with other such divisions and
subdivisions regarding efforts to address such threats.
(d) Health Care Industry Cybersecurity Task Force.--
(1) In general.--Not later than 60 days after the date of
enactment of this Act, the Secretary, in consultation with
the Secretary of Homeland Security, shall convene health care
industry stakeholders, cybersecurity experts, and any Federal
agencies or entities the Secretary determines appropriate to
establish a task force to--
(A) analyze how industries, other than the health care
industry, have implemented strategies and safeguards for
addressing cybersecurity threats within their respective
industries;
(B) analyze challenges and barriers private entities
(notwithstanding section 2(15)(B), excluding any State,
tribal, or local government) in the health care industry face
securing themselves against cyber attacks;
(C) review challenges that covered entities and business
associates face in securing networked medical devices and
other software or systems that connect to an electronic
health record;
(D) provide the Secretary with information to disseminate
to health care industry stakeholders for purposes of
improving their preparedness for, and response to,
cybersecurity threats affecting the health care industry;
(E) establish a plan for creating a single system for the
Federal Government to share information on actionable
intelligence regarding cybersecurity threats to the private
sector in near real time, at no cost to the recipients of
such information, including which Federal agency or other
entity may be best suited to be the central conduit to
facilitate the sharing of such information; and
(F) report to Congress on the findings and recommendations
of the task force regarding carrying out subparagraphs (A)
through (E).
(2) Termination.--The task force established under this
subsection shall terminate on the date that is 1 year after
the date of enactment of this Act.
(3) Dissemination.--Not later than 60 days after the
termination of the task force established under this
subsection, the Secretary shall disseminate the information
described in paragraph (1)(D) to health care industry
stakeholders in accordance with such paragraph.
(e) Cybersecurity Framework.--The Secretary shall
establish, through a collaborative process with the Secretary
of Homeland Security, health care industry stakeholders, the
National Institute of Standards and Technology, and any
Federal agency or entity the Secretary determines
appropriate, a single, voluntary, national health-specific
cybersecurity framework that--
(1) establishes a common set of security practices and
standards that specifically pertain to a range of health care
organizations;
(2) supports voluntary adoption and implementation efforts
to improve safeguards to address cybersecurity threats; and
(3) is consistently updated and applicable to the range of
health care organizations described in paragraph (1).
____________________