H. R. 2029—743 (A) provide for audits to ensure that health care organizations are in compliance with this subsection; or (B) mandate, direct, or condition the award of any Federal grant, contract, or purchase, on compliance with this subsection. (3) NO LIABILITY FOR NONPARTICIPATION.—Nothing in this section shall be construed to subject a health care industry stakeholder to liability for choosing not to engage in the voluntary activities authorized or guidelines developed under this subsection. (e) INCORPORATING ONGOING ACTIVITIES.—In carrying out the activities under this section, the Secretary may incorporate activities that are ongoing as of the day before the date of enactment of this Act and that are consistent with the objectives of this section. (f) RULE OF CONSTRUCTION.—Nothing in this section shall be construed to limit the antitrust exemption under section 104(e) or the protection from liability under section 106. SEC. 406. FEDERAL COMPUTER SECURITY. (a) DEFINITIONS.—In this section: (1) COVERED SYSTEM.—The term ‘‘covered system’’ shall mean a national security system as defined in section 11103 of title 40, United States Code, or a Federal computer system that provides access to personally identifiable information. (2) COVERED AGENCY.—The term ‘‘covered agency’’ means an agency that operates a covered system. (3) LOGICAL ACCESS CONTROL.—The term ‘‘logical access control’’ means a process of granting or denying specific requests to obtain and use information and related information processing services. (4) MULTI-FACTOR AUTHENTICATION.—The term ‘‘multifactor authentication’’ means the use of not fewer than 2 authentication factors, such as the following: (A) Something that is known to the user, such as a password or personal identification number. (B) An access device that is provided to the user, such as a cryptographic identification device or token. (C) A unique biometric characteristic of the user. (5) PRIVILEGED USER.—The term ‘‘privileged user’’ means a user who has access to system control, monitoring, or administrative functions. (b) INSPECTOR GENERAL REPORTS ON COVERED SYSTEMS.— (1) IN GENERAL.—Not later than 240 days after the date of enactment of this Act, the Inspector General of each covered agency shall submit to the appropriate committees of jurisdiction in the Senate and the House of Representatives a report, which shall include information collected from the covered agency for the contents described in paragraph (2) regarding the Federal computer systems of the covered agency. (2) CONTENTS.—The report submitted by each Inspector General of a covered agency under paragraph (1) shall include, with respect to the covered agency, the following: (A) A description of the logical access policies and practices used by the covered agency to access a covered system, including whether appropriate standards were followed.

Select target paragraph3