H. R. 2029—740
information, the Director of the National Institute of Standards
and Technology shall, on an ongoing basis, facilitate and support the development of methods for reducing cybersecurity
risks to emergency response providers using the process
described in section 2(e) of the National Institute of Standards
and Technology Act (15 U.S.C. 272(e)).
(2) REPORT.—The Director of the National Institute of
Standards and Technology shall submit to Congress a report
on the result of the activities of the Director under paragraph
(1), including any methods developed by the Director under
such paragraph, and shall make such report publicly available
on the website of the National Institute of Standards and
Technology.
(d) RULE OF CONSTRUCTION.—Nothing in this section shall be
construed to—
(1) require a State to report data under subsection (a);
or
(2) require a non-Federal entity (as defined in section 102)
to—
(A) adopt a recommended measure developed under
subsection (b); or
(B) follow the result of the activities carried out under
subsection (c), including any methods developed under such
subsection.
SEC.
405.
IMPROVING
INDUSTRY.
CYBERSECURITY
IN
THE
HEALTH
CARE
(a) DEFINITIONS.—In this section:
(1) APPROPRIATE CONGRESSIONAL COMMITTEES.—The term
‘‘appropriate congressional committees’’ means—
(A) the Committee on Health, Education, Labor, and
Pensions, the Committee on Homeland Security and
Governmental Affairs, and the Select Committee on Intelligence of the Senate; and
(B) the Committee on Energy and Commerce, the Committee on Homeland Security, and the Permanent Select
Committee on Intelligence of the House of Representatives.
(2) BUSINESS ASSOCIATE.—The term ‘‘business associate’’
has the meaning given such term in section 160.103 of title
45, Code of Federal Regulations (as in effect on the day before
the date of the enactment of this Act).
(3) COVERED ENTITY.—The term ‘‘covered entity’’ has the
meaning given such term in section 160.103 of title 45, Code
of Federal Regulations (as in effect on the day before the
date of the enactment of this Act).
(4) CYBERSECURITY THREAT; CYBER THREAT INDICATOR;
DEFENSIVE MEASURE; FEDERAL ENTITY; NON-FEDERAL ENTITY;
PRIVATE ENTITY.—The terms ‘‘cybersecurity threat’’, ‘‘cyber
threat indicator’’, ‘‘defensive measure’’, ‘‘Federal entity’’, ‘‘nonFederal entity’’, and ‘‘private entity’’ have the meanings given
such terms in section 102 of this division.
(5) HEALTH CARE CLEARINGHOUSE; HEALTH CARE PROVIDER;
HEALTH PLAN.—The terms ‘‘health care clearinghouse’’, ‘‘health
care provider’’, and ‘‘health plan’’ have the meanings given
such terms in section 160.103 of title 45, Code of Federal
Regulations (as in effect on the day before the date of the
enactment of this Act).