Click any annotated section or its icon to see analysis.
Section 1
1. Short title This Act may be cited as the Strengthening Cybersecurity in Health Care Act.
Section 2
2. Evaluation of HHS cybersecurity Not later than 2 years after the date of enactment of this Act, and every 2 years thereafter, the Inspector General of the Department of Health and Human Services shall evaluate the cybersecurity practices and protocols of the Department through the conduct of penetration tests and other testing procedures to determine how systems processing, transmitting, or storing mission critical or sensitive data by, for, or on behalf of the Department is currently, or could be compromised and— expose patient data, including Medicare numbers of individuals; or impact patient safety. Not later than 2 years after the date of enactment of this Act, and every 2 years thereafter— the Secretary of Health and Human Services shall submit to Congress a report that describes how the Secretary will update the cybersecurity practices and protocols of the Department of Health and Human Services to adapt to the latest cyberattack strategies; and the Inspector General of the Department of Health and Human Services shall submit to Congress a report that describes— how the Inspector General is currently using Federal funds of the Inspector General to carry out subsection (a); and legislative changes required for the Inspector General to maintain the evaluation described in subsection (a).