Floor SpeechNeutral2026-06-09
Text of Senate Amendment 5819
Bill Cassidy
RLA · Senator
HealthcareEnvironmentForeign PolicyLaborTechnologyInfrastructure
Context
On 2026-06-09, Senator Bill Cassidy (R-LA) delivered a floor speech titled "Text Of Senate Amendment 5819" in the Senate.
Full Text
Text of Senate Amendment 5819 Congressional Record, Volume 172 Issue 97 (Tuesday, June 9, 2026) [Congressional Record Volume 172, Number 97 (Tuesday, June 9, 2026)] [Senate] [Pages S2703-S2705] From the Congressional Record Online through the Government Publishing Office [ www.gpo.gov ] SA 5819. Mr. CASSIDY submitted an amendment intended to be proposed by him to the bill S. 3315, to require the Secretary of Health and Human Services and the Director of the Cybersecurity and Infrastructure Security Agency to coordinate to improve cybersecurity in the health care and public health sectors, and for other purposes; which was ordered to lie on the table; as follows: Strike all after the enacting clause and insert the following: SECTION 1. SHORT TITLE. This Act may be cited as the ``Health Care Cybersecurity and Resiliency Act of 2026''. SEC. 2. DEFINITIONS. In this Act: (1) Agency.--The term ``Agency'' means the Cybersecurity and Infrastructure Security Agency. (2) Business associate.--The term ``business associate'' has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations (or a successor regulation). (3) Covered entity.--The term ``covered entity'' has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations (or a successor regulation). (4) Cybersecurity incident.--The term ``cybersecurity incident'' has the meaning given the term ``incident'' in section 3552 of title 44, United States Code. (5) Cybersecurity state coordinator.--The term ``Cybersecurity State Coordinator'' means a Cybersecurity State Coordinator appointed under section 2217(a) of the Homeland Security Act of 2002 (6 U.S.C. 665c(a)). (6) Director.--The term ``Director'' means the Director of the Agency. (7) Healthcare and public health sector.--The term ``Healthcare and Public Health Sector'' means the Healthcare and Public Health sector, as identified in National Security Memorandum-22 (April 30, 2024; relating to critical infrastructure security and resilience). (8) Information sharing and analysis organization.--The term ``Information Sharing and Analysis Organization'' has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650). (9) Information system.--The term ``information system'' has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650). (10) Recognized security practices.--The term ``recognized security practices'' has the meaning given such term in section 13412(b)(1) of the HITECH Act (42 U.S.C. 17941(b)(1)). (11) Secretary.--The term ``Secretary'' means the Secretary of Health and Human Services. SEC. 3. DEPARTMENT COORDINATION WITH THE AGENCY. (a) In General.--The Secretary and the Director shall coordinate, including by entering into a cooperative agreement, as appropriate, to improve cybersecurity in the Healthcare and Public Health Sector. (b) Assistance.-- (1) In general.--The Secretary shall coordinate with the Director to make resources available to entities that are receiving information shared through programs managed by the Director or the Secretary, including Information Sharing and Analysis Organizations, sector coordinating councils, and non-Federal entities. (2) Scope.--The coordination under paragraph (1) shall include-- (A) developing products specific to the needs of Healthcare and Public Health Sector entities; (B) sharing information relating to cyber threat indicators and appropriate defensive measures, including automating cyber threat information sharing, in a manner that adequately protects against unauthorized access or disclosure; and (C) providing technical assistance to covered entities and business associates to improve cybersecurity preparedness. (c) Joint Cybersecurity Planning.-- (1) In general.--Not later than 1 year after the date of enactment of this Act, the Secretary and the Director shall establish a joint cybersecurity capability plan to coordinate responses to significant cybersecurity incidents affecting the Healthcare and Public Health Sector. (2) Elements.--The joint cybersecurity capability plan established under paragraph (1) shall include-- (A) protocols for rapid information sharing during sector- wide cybersecurity incidents; (B) coordination mechanisms with the sector coordinating council for the Healthcare and Public Health Sector; and (C) coordination with Cybersecurity State Coordinators for incidents affecting multiple States. (3) Submission to congress.-- (A) In general.--Not later than 1 year after the date of enactment of this Act, the Secretary shall submit to the Committee on Health, Education, Labor, and Pensions of the Senate and the Committee on Energy and Commerce of the House of Representatives the final joint cybersecurity capability plan prepared under paragraph (1) and a description of how such plan implements the elements required under paragraph (2). (B) Updates.--If the Secretary and the Director update the joint cybersecurity capability plan required under this subsection, the Secretary shall submit to the Committee on Health, Education, Labor, and Pensions of the Senate and the Committee on Energy and Commerce of the House of Representatives such updated plan and a description of how such plan implements the elements required under paragraph (2). SEC. 4. CLARIFYING CYBERSECURITY RESPONSIBILITIES AT THE DEPARTMENT OF HEALTH AND HUMAN SERVICES. (a) In General.--The Secretary shall delegate a representative to lead oversight and coordination of activities within the Department of Health and Human Services to support internal and external cybersecurity resilience within the Healthcare and Public Health Sector, including coordination and communication with other public and private entities related to preparedness for, and responses to, cybersecurity incidents, consistent with applicable provisions of the Public Health Service Act (42 U.S.C. 201 et seq.), other applicable laws, and National Security Memorandum-22 (April 30, 2024; relating to critical infrastructure security and resilience). Such activities shall not include implementation or enforcement of part 160 and subparts A and C of part 164 of title 45, Code of Federal Regulations (or successor regulations) (commonly known as the ``HIPAA Security Rule''). (b) Reports.-- (1) Report on delegation.--Not later than 60 days after delegating a representative under subsection (a), and any time a new representative is delegated under such subsection, the Secretary shall submit to the Committee on Health, Education, Labor, and Pensions of the Senate and the Committee on Energy and Commerce of the House of Representatives a report that describes how such representative will implement steps to improve internal and external cybersecurity resilience within the Healthcare and Public Health Sector. (2) Annual report.--Not later than 1 year after the date of enactment of this Act, and annually thereafter, the Secretary shall submit to the Committee on Health, Education, Labor, and Pensions of the Senate and the Committee on Energy and Commerce of the House of Representatives a report on the state of cybersecurity in the Healthcare and Public Health Sector, including-- (A) an assessment of the most significant cybersecurity threats and vulnerabilities facing the Healthcare and Public Health Sector; (B) a summary of major cybersecurity incidents affecting the Healthcare and Public Health Sector during the preceding year; (C) an assessment of the overall cybersecurity posture of the Healthcare and Public Health Sector; (D) a description of actions taken by the Department of Health and Human Services to improve cybersecurity; and [[Page S2704]] (E) recommendations to improve Healthcare and Public Health Sector cybersecurity. SEC. 5. CYBERSECURITY INCIDENT RESPONSE PLAN. Section 405 of the Cybersecurity Act of 2015 (6 U.S.C. 1533) is amended-- (1) in subsection (a)-- (A) in paragraph (4)-- (i) in the paragraph heading, by inserting ``information system;'' after ``federal entity;''; and (ii) by inserting `` `information system','' after `` `Federal entity',''; (B) by redesignating paragraphs (4) through (7) as paragraphs (6) through (9), respectively; and (C) by inserting after paragraph (3) the following: ``(4) Cybersecurity incident.--The term `cybersecurity incident' has the meaning given the term `incident' in section 3552 of title 44, United States Code. ``(5) Cybersecurity risk.--The term `cybersecurity risk' has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).''; and (2) in subsection (d), by adding at the end the following: ``(4) Plan.-- ``(A) In general.--Not later than 1 year after the date of enactment of the Health Care Cybersecurity and Resiliency Act of 2026, the Secretary shall expand and implement the Cyber Annex of the All Hazards Plan of the Department of Health and Human Services to inform applicable personnel within the Department of Health and Human Services of processes and protocols to prepare for, and respond to, cybersecurity incidents. ``(B) Scope.--The plan under subparagraph (A) shall address cybersecurity incidents involving information systems, including hardware, software, databases, and networks, used or maintained by, or on behalf of, the Department. ``(C) Elements.--The plan under subparagraph (A) shall include strategies-- ``(i) to assess cybersecurity risks; ``(ii) to prevent cybersecurity incidents; ``(iii) to detect and identify cybersecurity incidents; ``(iv) to minimize damage in the event of a cybersecurity incident; ``(v) to protect data; ``(vi) to recover from any cybersecurity incidents expeditiously; and ``(vii) to communicate and share non-sensitive information about cybersecurity incidents with entities in the Healthcare and Public Health Sector (as defined in section 2 of the Health Care Cybersecurity and Resiliency Act of 2026). ``(D) Consultation.--In developing the plan under subparagraph (A), the Secretary shall consult w