H. R. 2029—740 information, the Director of the National Institute of Standards and Technology shall, on an ongoing basis, facilitate and support the development of methods for reducing cybersecurity risks to emergency response providers using the process described in section 2(e) of the National Institute of Standards and Technology Act (15 U.S.C. 272(e)). (2) REPORT.—The Director of the National Institute of Standards and Technology shall submit to Congress a report on the result of the activities of the Director under paragraph (1), including any methods developed by the Director under such paragraph, and shall make such report publicly available on the website of the National Institute of Standards and Technology. (d) RULE OF CONSTRUCTION.—Nothing in this section shall be construed to— (1) require a State to report data under subsection (a); or (2) require a non-Federal entity (as defined in section 102) to— (A) adopt a recommended measure developed under subsection (b); or (B) follow the result of the activities carried out under subsection (c), including any methods developed under such subsection. SEC. 405. IMPROVING INDUSTRY. CYBERSECURITY IN THE HEALTH CARE (a) DEFINITIONS.—In this section: (1) APPROPRIATE CONGRESSIONAL COMMITTEES.—The term ‘‘appropriate congressional committees’’ means— (A) the Committee on Health, Education, Labor, and Pensions, the Committee on Homeland Security and Governmental Affairs, and the Select Committee on Intelligence of the Senate; and (B) the Committee on Energy and Commerce, the Committee on Homeland Security, and the Permanent Select Committee on Intelligence of the House of Representatives. (2) BUSINESS ASSOCIATE.—The term ‘‘business associate’’ has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations (as in effect on the day before the date of the enactment of this Act). (3) COVERED ENTITY.—The term ‘‘covered entity’’ has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations (as in effect on the day before the date of the enactment of this Act). (4) CYBERSECURITY THREAT; CYBER THREAT INDICATOR; DEFENSIVE MEASURE; FEDERAL ENTITY; NON-FEDERAL ENTITY; PRIVATE ENTITY.—The terms ‘‘cybersecurity threat’’, ‘‘cyber threat indicator’’, ‘‘defensive measure’’, ‘‘Federal entity’’, ‘‘nonFederal entity’’, and ‘‘private entity’’ have the meanings given such terms in section 102 of this division. (5) HEALTH CARE CLEARINGHOUSE; HEALTH CARE PROVIDER; HEALTH PLAN.—The terms ‘‘health care clearinghouse’’, ‘‘health care provider’’, and ‘‘health plan’’ have the meanings given such terms in section 160.103 of title 45, Code of Federal Regulations (as in effect on the day before the date of the enactment of this Act).

Select target paragraph3