Us Code § 1533 - Improving cybersecurity in the health care industry

Full text of Us Code United States Code § 1533 — Improving cybersecurity in the health care industry, with citation guidance and answers to common questions.

§ 1533. Improving cybersecurity in the health care industry

(a) Definitions

In this section:

(1) Appropriate congressional committees

The term "appropriate congressional committees" means—

(A) the Committee on Health, Education, Labor, and Pensions, the Committee on Homeland Security and Governmental Affairs, and the Select Committee on Intelligence of the Senate; and

(B) the Committee on Energy and Commerce, the Committee on Homeland Security, and the Permanent Select Committee on Intelligence of the House of Representatives.

(2) Business associate

The term "business associate" has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations (as in effect on the day before December 18, 2015).

(3) Covered entity

The term "covered entity" has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations (as in effect on the day before December 18, 2015).

(4) Cybersecurity threat; cyber threat indicator; defensive measure; Federal entity; non-Federal entity; private entity

The terms "cybersecurity threat", "cyber threat indicator", "defensive measure", "Federal entity", "non-Federal entity", and "private entity" have the meanings given such terms in section 1501 of this title.

(5) Health care clearinghouse; health care provider; health plan

The terms "health care clearinghouse", "health care provider", and "health plan" have the meanings given such terms in section 160.103 of title 45, Code of Federal Regulations (as in effect on the day before December 18, 2015).

(6) Health care industry stakeholder

The term "health care industry stakeholder" means any—

(A) health plan, health care clearinghouse, or health care provider;

(B) advocate for patients or consumers;

(C) pharmacist;

(D) developer or vendor of health information technology;

(E) laboratory;

(F) pharmaceutical or medical device manufacturer; or

(G) additional stakeholder the Secretary determines necessary for purposes of subsection (b)(1), (c)(1), (c)(3), or (d)(1).

(7) Secretary

The term "Secretary" means the Secretary of Health and Human Services.

(b) Report

(1) In general

Not later than 1 year after December 18, 2015, the Secretary shall submit to the Committee on Health, Education, Labor, and Pensions of the Senate and the Committee on Energy and Commerce of the House of Representatives a report on the preparedness of the Department of Health and Human Services and health care industry stakeholders in responding to cybersecurity threats.

(2) Contents of report

With respect to the internal response of the Department of Health and Human Services to emerging cybersecurity threats, the report under paragraph (1) shall include—

(A) a clear statement of the official within the Department of Health and Human Services to be responsible for leading and coordinating efforts of the Department regarding cybersecurity threats in the health care industry; and

(B) a plan from each relevant operating division and subdivision of the Department of Health and Human Services on how such division or subdivision will address cybersecurity threats in the health care industry, including a clear delineation of how each such division or subdivision will divide responsibility among the personnel of such division or subdivision and communicate with other such divisions and subdivisions regarding efforts to address such threats.

(c) Health care industry cybersecurity task force

(1) In general

Not later than 90 days after December 18, 2015, the Secretary, in consultation with the Director of the National Institute of Standards and Technology and the Secretary of Homeland Security, shall convene health care industry stakeholders, cybersecurity experts, and any Federal agencies or entities the Secretary determines appropriate to establish a task force to—

(A) analyze how industries, other than the health care industry, have implemented strategies and safeguards for addressing cybersecurity threats within their respective industries;

(B) analyze challenges and barriers private entities (excluding any State, tribal, or local government) in the health care industry face securing themselves against cyber attacks;

(C) review challenges that covered entities and business associates face in securing networked medical devices and other software or systems that connect to an electronic health record;

(D) provide the Secretary with information to disseminate to health care industry stakeholders of all sizes for purposes of improving their preparedness for, and response to, cybersecurity threats affecting the health care industry;

(E) establish a plan for implementing subchapter I of this chapter, so that the Federal Government and health care industry stakeholders may in real time, share actionable cyber threat indicators and defensive measures; and

(F) report to the appropriate congressional committees on the findings and recommendations of the task force regarding carrying out subparagraphs (A) through (E).

(2) Termination

The task force established under this subsection shall terminate on the date that is 1 year after the date on which such task force is established.

(3) Dissemination

Not later than 60 days after the termination of the task force established under this subsection, the Secretary shall disseminate the information described in paragraph (1)(D) to health care industry stakeholders in accordance with such paragraph.

(d) Aligning health care industry security approaches

(1) In general

The Secretary shall establish, through a collaborative process with the Secretary of Homeland Security, health care industry stakeholders, the Director of the National Institute of Standards and Technology, and any Federal entity or non-Federal entity the Secretary determines appropriate, a common set of voluntary, consensus-based, and industry-led guidelines, best practices, methodologies, procedures, and processes that—

(A) serve as a resource for cost-effectively reducing cybersecurity risks for a range of health care organizations;

(B) support voluntary adoption and implementation efforts to improve safeguards to address cybersecurity threats;

(C) are consistent with—

(i) the standards, guidelines, best practices, methodologies, procedures, and processes developed under section 272(c)(15) of title 15;

(ii) the security and privacy regulations promulgated under section 264(c) of the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. 1320d–2 note); and

(iii) the provisions of the Health Information Technology for Economic and Clinical Health Act (title XIII of division A, and title IV of division B, of Public Law 111–5), and the amendments made by such Act; and


(D) are updated on a regular basis and applicable to a range of health care organizations.

(2) Limitation

Nothing in this subsection shall be interpreted as granting the Secretary authority to—

(A) provide for audits to ensure that health care organizations are in compliance with this subsection; or

(B) mandate, direct, or condition the award of any Federal grant, contract, or purchase, on compliance with this subsection.

(3) No liability for nonparticipation

Nothing in this section shall be construed to subject a health care industry stakeholder to liability for choosing not to engage in the voluntary activities authorized or guidelines developed under this subsection.

(e) Incorporating ongoing activities

In carrying out the activities under this section, the Secretary may incorporate activities that are ongoing as of the day before December 18, 2015 and that are consistent with the objectives of this section.

(f) Rule of construction

Nothing in this section shall be construed to limit the antitrust exemption under section 1503(e) of this title or the protection from liability under section 1505 of this title.

(Pub. L. 114–113, div. N, title IV, §405, Dec. 18, 2015, 129 Stat. 2981.)


Editorial Notes

References in Text

Section 264(c) of the Health Insurance Portability and Accountability Act of 1996, referred to subsec. (d)(1)(C)(ii), is section 264(c) of Pub. L. 104–191, which is set out as a note under section 1320d–2 of Title 42, The Public Health and Welfare.

The Health Information Technology for Economic and Clinical Health Act, referred to in subsec. (d)(1)(C)(iii), is title XIII of div. A and title IV of div. B of Pub. L. 111–5, Feb. 17, 2009, 123 Stat. 226, 467, also known as the HITECH Act. For complete classification of this Act to the Code, see Short Title of 2009 Amendment note set out under section 201 of Title 42, The Public Health and Welfare, and Tables.

About This Section

6 U.S.C. § 1533 is part of Title 6 of the United States Code. The United States Code is the official codification of federal statutes maintained by the Office of the Law Revision Counsel of the U.S. House of Representatives. Congress amends the Code through new public laws, which are eventually incorporated into the relevant title.

This section may be cited in legal writing as 6 U.S.C. § 1533. For the most current official text, including any recent amendments, use the official source links below. Do not rely on this page as the sole authority for legal citation or litigation.

How to Read This Statute

Statutes are organized by title, chapter, section, and subsection. Pay attention to words like "shall," "may," "and," and "or," because they determine whether a requirement is mandatory or permissive and whether multiple conditions must all be met. Historical notes and amendments often appear at the end of a section.

Using This Page

This page is intended for research and educational use. Lawyers, students, journalists, and compliance professionals can use it as a starting point, but should always verify the current text through an official government source before relying on it for legal advice, filings, or compliance decisions.

Sources

Frequently Asked Questions About Us Code § 1533

What does United States Code § 1533 cover?

Section 1533 ("Improving cybersecurity in the health care industry") is part of the United States Code, the codified statutory law of Us Code. It sets out the legal rule or procedure described in the text above. Statutes are amended regularly, so always verify against the official source.

How do I cite Us Code § 1533?

A common citation format is "United States Code § 1533" (Us Code). Legal writing may require the code abbreviation, section number, and year or edition. Match the style required by your court, professor, or publisher.

Is this the official text of Us Code law?

No. This page is for research and education and may not include the most recent amendments. For official current law, check the Us Code official source linked on this page or consult a licensed Us Code attorney.

How does Us Code § 1533 apply to my situation?

Statutes are interpreted in context, and application depends on your specific facts. Only a licensed attorney in Us Code can advise on how this section applies to you. Contact your state or local bar association for a referral.

Sources & Verification

Not legal advice. Verify against the official source and consult a licensed attorney in Us Code.