Federal
Promoting Better Patient Data Security Act of 2019
Source: Congress.gov ·
815 words in original text
Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
I
116TH CONGRESS
1ST SESSION H. R. 5386
To amend the Health Information Technology for Economic and Clinical
Health Act to require consideration, in certain circumstances, of whether
a covered entity or business associate has adequately demonstrated that
it had recognized security practices, and for other purposes.
IN THE HOUSE OF REPRESENTATIVES
DECEMBER 10, 2019
Mr. MCNERNEY (for himself and Mr. BUCSHON) introduced the following bill;
which was referred to the Committee on Energy and Commerce, and in
addition to the Committee on Ways and Means, for a period to be subse-
quently determined by the Speaker, in each case for consideration of such
provisions as fall within the jurisdiction of the committee concerned
A BILL
To amend the Health Information Technology for Economic
and Clinical Health Act to require consideration, in cer-
tain circumstances, of whether a covered entity or busi-
ness associate has adequately demonstrated that it had
recognized security practices, and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘Promoting Better Pa-
4
tient Data Security Act of 2019’’.
5
VerDate Sep 11 2014
00:25 Dec 14, 2019
Jkt 099200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\H5386.IH
H5386
pamtmann on DSKBC07HB2PROD with BILLS
2
•HR 5386 IH
SEC. 2. RECOGNITION OF SECURITY PRACTICES.
1
Part 1 of subtitle D of the Health Information Tech-
2
nology for Economic and Clinical Health Act (42 U.S.C.
3
17931 et seq.) is amended by adding at the end the fol-
4
lowing:
5
‘‘SEC. 13412. RECOGNITION OF SECURITY PRACTICES.
6
‘‘(a) IN GENERAL.—Consistent with the authority of
7
the Secretary under sections 1176 and 1177 of the Social
8
Security Act, when making determinations relating to
9
fines under section 13410, decreasing the length and ex-
10
tent of an audit under section 13411, or remedies other-
11
wise agreed to by the Secretary, the Secretary shall con-
12
sider whether the covered entity or business associate has
13
adequately demonstrated that it had, for not less than the
14
previous 12 months, recognized security practices in place
15
that may—
16
‘‘(1) mitigate fines under section 13410;
17
‘‘(2) result in the early, favorable termination
18
of an audit under section 13411; and
19
‘‘(3) mitigate the remedies that would otherwise
20
be agreed to in any agreement with respect to re-
21
solving potential violations of the HIPAA Security
22
rule (part 160 of title 45 Code of Federal Regula-
23
tions and subparts A and C of part 164 of such
24
title) between the covered entity or business asso-
25
VerDate Sep 11 2014
00:25 Dec 14, 2019
Jkt 099200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\H5386.IH
H5386
pamtmann on DSKBC07HB2PROD with BILLS
3
•HR 5386 IH
ciate and the Department of Health and Human
1
Services.
2
‘‘(b) DEFINITION
AND
MISCELLANEOUS
PROVI-
3
SIONS.—
4
‘‘(1) RECOGNIZED SECURITY PRACTICES.—The
5
term ‘recognized security practices’ means the stand-
6
ards, guidelines, best practices, methodologies, pro-
7
cedures, and processes developed under section
8
2(c)(15) of the National Institute of Standards and
9
Technology Act, the approaches promulgated under
10
section 405(d) of the Cybersecurity Act of 2015, and
11
other programs and processes that address cyberse-
12
curity and that are developed, recognized, or promul-
13
gated through regulations under other statutory au-
14
thorities. Such practices shall be determined by the
15
covered entity or business associate.
16
‘‘(2) LIMITATION.—Nothing in this section
17
shall be construed as providing the Secretary author-
18
ity to increase fines under section 13410, or the
19
length, extent or quantity of audits under section
20
13411, due to a lack of compliance with the recog-
21
nized security practices.
22
‘‘(3) NO LIABILITY FOR NONPARTICIPATION.—
23
Subject to paragraph (4), nothing in this section
24
shall be construed to subject a covered entity or
25
VerDate Sep 11 2014
00:25 Dec 14, 2019
Jkt 099200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\H5386.IH
H5386
pamtmann on DSKBC07HB2PROD with BILLS
4
•HR 5386 IH
business associate to liability for electing not to en-
1
gage in the recognized security practices defined by
2
this section.
3
‘‘(4) RULE
OF
CONSTRUCTION.—Nothing in
4
this section shall be construed to limit the Sec-
5
retary’s authority to enforce the HIPAA Security
6
rule (part 160 of title 45 Code of Federal Regula-
7
tions and subparts A and C of part 164 of such
8
title), or to supersede or conflict with an entity or
9
business associate’s obligations under the HIPAA
10
Security rule.’’.
11
Æ
VerDate Sep 11 2014
00:25 Dec 14, 2019
Jkt 099200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6301
E:\BILLS\H5386.IH
H5386
pamtmann on DSKBC07HB2PROD with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.