SenateS. 5522119th Congress

Protecting Biological Data as Critical Infrastructure Act

Full Text

Official text as published. Use Ctrl+F / Cmd+F to search within the document.

[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[S. 5522 Introduced in Senate (IS)]

<DOC>

119th CONGRESS
  2d Session
                                S. 5522

To amend the Homeland Security Act of 2002 to require the Cybersecurity 
   and Infrastructure Security Agency of the Department of Homeland 
Security to protect genetic and other sensitive biometric data, and for 
                            other purposes.

_______________________________________________________________________

                   IN THE SENATE OF THE UNITED STATES

                           September 24, 2026

 Mr. Young (for himself and Ms. Hassan) introduced the following bill; 
which was read twice and referred to the Committee on Homeland Security 
                        and Governmental Affairs

_______________________________________________________________________

                                 A BILL

 
To amend the Homeland Security Act of 2002 to require the Cybersecurity 
   and Infrastructure Security Agency of the Department of Homeland 
Security to protect genetic and other sensitive biometric data, and for 
                            other purposes.

    Be it enacted by the Senate and House of Representatives of the 
United States of America in Congress assembled,

SECTION 1. SHORT TITLE.

    This Act may be cited as the ``Protecting Biological Data as 
Critical Infrastructure Act''.

SEC. 2. CISA PROTECTION OF GENETIC AND OTHER SENSITIVE BIOMETRIC DATA.

    The Homeland Security Act of 2002 is amended--
            (1) in section 2202 (6 U.S.C. 652)--
                    (A) in subsection (c)--
                            (i) in paragraph (13), by striking ``and'' 
                        after the semicolon;
                            (ii) by redesignating paragraph (14) as 
                        paragraph (17); and
                            (iii) by inserting after paragraph (13) the 
                        following new paragraphs:
            ``(14) oversee the planning, management, and coordination 
        of duties related to security management of, and 
        responsibilities associated with, genetic data systems that 
        involve genomic sequences and other sensitive biometric data, 
        including by ensuring sufficient staff of the Agency to carry 
        out such duties;
            ``(15) provide training for relevant Federal personnel 
        regarding protecting genetic data systems that involve genomic 
        sequences and other sensitive biometric data, including 
        addressing unique security challenges and ethical 
        considerations;
            ``(16) take such actions as may be necessary to ensure the 
        protection of biological data and critical biotechnology 
        infrastructure, including genetic data systems that involve 
        genomic sequences and other sensitive biometric data; and''; 
        and
                    (B) in subsection (e)(1), by adding at the end the 
                following new subparagraphs:
                    ``(S) To treat as critical infrastructure genetic 
                data systems that involve genomic sequences and other 
                sensitive biometric data.
                    ``(T) To consult with United States biotechnology 
                sector stakeholders to gain input for the development 
                of security protocols relating to the genetic data 
                systems referred to in subparagraph (S), as well as 
                relevant Federal agencies responsible for collecting 
                and protecting such systems, such as the Office of 
                Biometric Identity Management of the Department.
                    ``(U) To collaborate with the United States 
                biotechnology sector stakeholders referred to in 
                subparagraph (T), as well as any additional United 
                States stakeholders engaged in biosecurity policy 
                development and enforcement, including by carrying out 
                the following:
                            ``(i) Facilitating engagements between the 
                        Agency and such biotechnology stakeholders and 
                        additional stakeholders to coordinate and 
                        synchronize regarding emerging security 
                        concerns, such as the digital-physical boundary 
                        between genetic sequence data and physical 
                        samples.
                            ``(ii) Providing a secure line of 
                        communication to the Agency for such 
                        biotechnology stakeholders and additional 
                        stakeholders to raise concerns, report 
                        incidents, and request technical assistance.''; 
                        and
            (2) in section 2211(b)(2) (6 U.S.C. 661(b)(2)), by adding 
        at the end the following new subparagraph:
                    ``(E) Genetic and biometric data security.''.
                                 <all>