H. R. 2029—742
health care industry face securing themselves against cyber
attacks;
(C) review challenges that covered entities and business associates face in securing networked medical devices
and other software or systems that connect to an electronic
health record;
(D) provide the Secretary with information to disseminate to health care industry stakeholders of all sizes for
purposes of improving their preparedness for, and response
to, cybersecurity threats affecting the health care industry;
(E) establish a plan for implementing title I of this
division, so that the Federal Government and health care
industry stakeholders may in real time, share actionable
cyber threat indicators and defensive measures; and
(F) report to the appropriate congressional committees
on the findings and recommendations of the task force
regarding carrying out subparagraphs (A) through (E).
(2) TERMINATION.—The task force established under this
subsection shall terminate on the date that is 1 year after
the date on which such task force is established.
(3) DISSEMINATION.—Not later than 60 days after the termination of the task force established under this subsection, the
Secretary shall disseminate the information described in paragraph (1)(D) to health care industry stakeholders in accordance
with such paragraph.
(d) ALIGNING HEALTH CARE INDUSTRY SECURITY APPROACHES.—
(1) IN GENERAL.—The Secretary shall establish, through
a collaborative process with the Secretary of Homeland Security, health care industry stakeholders, the Director of the
National Institute of Standards and Technology, and any Federal entity or non-Federal entity the Secretary determines
appropriate, a common set of voluntary, consensus-based, and
industry-led guidelines, best practices, methodologies, procedures, and processes that—
(A) serve as a resource for cost-effectively reducing
cybersecurity risks for a range of health care organizations;
(B) support voluntary adoption and implementation
efforts to improve safeguards to address cybersecurity
threats;
(C) are consistent with—
(i) the standards, guidelines, best practices, methodologies, procedures, and processes developed under
section 2(c)(15) of the National Institute of Standards
and Technology Act (15 U.S.C. 272(c)(15));
(ii) the security and privacy regulations promulgated under section 264(c) of the Health Insurance
Portability and Accountability Act of 1996 (42 U.S.C.
1320d–2 note); and
(iii) the provisions of the Health Information Technology for Economic and Clinical Health Act (title XIII
of division A, and title IV of division B, of Public
Law 111–5), and the amendments made by such Act;
and
(D) are updated on a regular basis and applicable
to a range of health care organizations.
(2) LIMITATION.—Nothing in this subsection shall be interpreted as granting the Secretary authority to—