H. R. 2029—743
(A) provide for audits to ensure that health care
organizations are in compliance with this subsection; or
(B) mandate, direct, or condition the award of any
Federal grant, contract, or purchase, on compliance with
this subsection.
(3) NO LIABILITY FOR NONPARTICIPATION.—Nothing in this
section shall be construed to subject a health care industry
stakeholder to liability for choosing not to engage in the voluntary activities authorized or guidelines developed under this
subsection.
(e) INCORPORATING ONGOING ACTIVITIES.—In carrying out the
activities under this section, the Secretary may incorporate activities that are ongoing as of the day before the date of enactment
of this Act and that are consistent with the objectives of this
section.
(f) RULE OF CONSTRUCTION.—Nothing in this section shall be
construed to limit the antitrust exemption under section 104(e)
or the protection from liability under section 106.
SEC. 406. FEDERAL COMPUTER SECURITY.
(a) DEFINITIONS.—In this section:
(1) COVERED SYSTEM.—The term ‘‘covered system’’ shall
mean a national security system as defined in section 11103
of title 40, United States Code, or a Federal computer system
that provides access to personally identifiable information.
(2) COVERED AGENCY.—The term ‘‘covered agency’’ means
an agency that operates a covered system.
(3) LOGICAL ACCESS CONTROL.—The term ‘‘logical access
control’’ means a process of granting or denying specific
requests to obtain and use information and related information
processing services.
(4) MULTI-FACTOR AUTHENTICATION.—The term ‘‘multifactor authentication’’ means the use of not fewer than 2
authentication factors, such as the following:
(A) Something that is known to the user, such as
a password or personal identification number.
(B) An access device that is provided to the user,
such as a cryptographic identification device or token.
(C) A unique biometric characteristic of the user.
(5) PRIVILEGED USER.—The term ‘‘privileged user’’ means
a user who has access to system control, monitoring, or administrative functions.
(b) INSPECTOR GENERAL REPORTS ON COVERED SYSTEMS.—
(1) IN GENERAL.—Not later than 240 days after the date
of enactment of this Act, the Inspector General of each covered
agency shall submit to the appropriate committees of jurisdiction in the Senate and the House of Representatives a report,
which shall include information collected from the covered
agency for the contents described in paragraph (2) regarding
the Federal computer systems of the covered agency.
(2) CONTENTS.—The report submitted by each Inspector
General of a covered agency under paragraph (1) shall include,
with respect to the covered agency, the following:
(A) A description of the logical access policies and
practices used by the covered agency to access a covered
system, including whether appropriate standards were followed.