Mandating Regular Cybersecurity Tests to Protect Patient Health Data.
This law requires the Department of Health and Human Services (HHS) to undergo mandatory, regular cybersecurity testing, including penetration tests, to protect sensitive patient data like Medicare numbers. Every two years, an independent Inspector General must check if systems could be compromised, potentially exposing personal information or impacting patient safety. This ensures the government actively updates its defenses against modern cyber threats.
Key points
HHS systems storing sensitive patient data must undergo rigorous penetration testing every two years to identify security weaknesses.
The primary focus is preventing the exposure of confidential information, including Medicare numbers, and ensuring cyberattacks do not compromise patient safety.
HHS must report to Congress on how it plans to update its security protocols to counter the latest cyberattack strategies.
Expired
Additional Information
Print number: 118_S_3773
Sponsor: Sen. Rubio, Marco [R-FL]
Process start date: 2024-02-08