H. R. 2029—741
(6) HEALTH CARE INDUSTRY STAKEHOLDER.—The term
‘‘health care industry stakeholder’’ means any—
(A) health plan, health care clearinghouse, or health
care provider;
(B) advocate for patients or consumers;
(C) pharmacist;
(D) developer or vendor of health information technology;
(E) laboratory;
(F) pharmaceutical or medical device manufacturer;
or
(G) additional stakeholder the Secretary determines
necessary for purposes of subsection (b)(1), (c)(1), (c)(3),
or (d)(1).
(7) SECRETARY.—The term ‘‘Secretary’’ means the Secretary
of Health and Human Services.
(b) REPORT.—
(1) IN GENERAL.—Not later than 1 year after the date
of enactment of this Act, the Secretary shall submit to the
Committee on Health, Education, Labor, and Pensions of the
Senate and the Committee on Energy and Commerce of the
House of Representatives a report on the preparedness of the
Department of Health and Human Services and health care
industry stakeholders in responding to cybersecurity threats.
(2) CONTENTS OF REPORT.—With respect to the internal
response of the Department of Health and Human Services
to emerging cybersecurity threats, the report under paragraph
(1) shall include—
(A) a clear statement of the official within the Department of Health and Human Services to be responsible
for leading and coordinating efforts of the Department
regarding cybersecurity threats in the health care industry;
and
(B) a plan from each relevant operating division and
subdivision of the Department of Health and Human Services on how such division or subdivision will address cybersecurity threats in the health care industry, including a
clear delineation of how each such division or subdivision
will divide responsibility among the personnel of such division or subdivision and communicate with other such divisions and subdivisions regarding efforts to address such
threats.
(c) HEALTH CARE INDUSTRY CYBERSECURITY TASK FORCE.—
(1) IN GENERAL.—Not later than 90 days after the date
of the enactment of this Act, the Secretary, in consultation
with the Director of the National Institute of Standards and
Technology and the Secretary of Homeland Security, shall convene health care industry stakeholders, cybersecurity experts,
and any Federal agencies or entities the Secretary determines
appropriate to establish a task force to—
(A) analyze how industries, other than the health care
industry, have implemented strategies and safeguards for
addressing cybersecurity threats within their respective
industries;
(B) analyze challenges and barriers private entities
(excluding any State, tribal, or local government) in the