H. R. 2029—741 (6) HEALTH CARE INDUSTRY STAKEHOLDER.—The term ‘‘health care industry stakeholder’’ means any— (A) health plan, health care clearinghouse, or health care provider; (B) advocate for patients or consumers; (C) pharmacist; (D) developer or vendor of health information technology; (E) laboratory; (F) pharmaceutical or medical device manufacturer; or (G) additional stakeholder the Secretary determines necessary for purposes of subsection (b)(1), (c)(1), (c)(3), or (d)(1). (7) SECRETARY.—The term ‘‘Secretary’’ means the Secretary of Health and Human Services. (b) REPORT.— (1) IN GENERAL.—Not later than 1 year after the date of enactment of this Act, the Secretary shall submit to the Committee on Health, Education, Labor, and Pensions of the Senate and the Committee on Energy and Commerce of the House of Representatives a report on the preparedness of the Department of Health and Human Services and health care industry stakeholders in responding to cybersecurity threats. (2) CONTENTS OF REPORT.—With respect to the internal response of the Department of Health and Human Services to emerging cybersecurity threats, the report under paragraph (1) shall include— (A) a clear statement of the official within the Department of Health and Human Services to be responsible for leading and coordinating efforts of the Department regarding cybersecurity threats in the health care industry; and (B) a plan from each relevant operating division and subdivision of the Department of Health and Human Services on how such division or subdivision will address cybersecurity threats in the health care industry, including a clear delineation of how each such division or subdivision will divide responsibility among the personnel of such division or subdivision and communicate with other such divisions and subdivisions regarding efforts to address such threats. (c) HEALTH CARE INDUSTRY CYBERSECURITY TASK FORCE.— (1) IN GENERAL.—Not later than 90 days after the date of the enactment of this Act, the Secretary, in consultation with the Director of the National Institute of Standards and Technology and the Secretary of Homeland Security, shall convene health care industry stakeholders, cybersecurity experts, and any Federal agencies or entities the Secretary determines appropriate to establish a task force to— (A) analyze how industries, other than the health care industry, have implemented strategies and safeguards for addressing cybersecurity threats within their respective industries; (B) analyze challenges and barriers private entities (excluding any State, tribal, or local government) in the

Select target paragraph3