Maryland 2024 Regular Session

Maryland House Bill HB1123 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11
22
33 EXPLANATION: CAPITALS INDICATE MAT TER ADDED TO EXISTIN G LAW.
44 [Brackets] indicate matter deleted from existing law.
55 *hb1123*
66
77 HOUSE BILL 1123
88 J3, S2 4lr3299
99 CF 4lr2135
1010 By: Delegate Kerr
1111 Introduced and read first time: February 7, 2024
1212 Assigned to: Health and Government Operations
1313
1414 A BILL ENTITLED
1515
1616 AN ACT concerning 1
1717
1818 Maryland Health Care Commission – Health Care Facilities – Cybersecurity for 2
1919 Hospitals 3
2020
2121 FOR the purpose of requiring the Maryland Health Care Commission to adopt minimum 4
2222 cybersecurity standards for hospitals and take certain other actions related to the 5
2323 cybersecurity of hospitals, including supporting hospitals that do not meet the 6
2424 minimum cybersecurity standards; requiring hospitals to comply with the 7
2525 cybersecurity standards adopted by the Commission; requiring the Secretary of 8
2626 Health to consider cybersecurity standards for hospitals when issuing a license to a 9
2727 hospital; and generally relating to cybersecurity for hospitals. 10
2828
2929 BY repealing and reenacting, with amendments, 11
3030 Article – Health – General 12
3131 Section 19–103 13
3232 Annotated Code of Maryland 14
3333 (2023 Replacement Volume) 15
3434
3535 BY adding to 16
3636 Article – Health – General 17
3737 Section 19–113 18
3838 Annotated Code of Maryland 19
3939 (2023 Replacement Volume) 20
4040
4141 SECTION 1. BE IT ENACTED BY THE GENERAL ASSEMBLY OF MARYLAND, 21
4242 That the Laws of Maryland read as follows: 22
4343
4444 Article – Health – General 23
4545
4646 19–103. 24
4747
4848 (a) There is a Maryland Health Care Commission. 25 2 HOUSE BILL 1123
4949
5050
5151
5252 (b) The Commission is an independent commission that functions in the 1
5353 Department. 2
5454
5555 (c) The purpose of the Commission is to: 3
5656
5757 (1) Develop health care cost containment strategies to help provide access 4
5858 to appropriate quality health care services for all Marylanders, after consulting with the 5
5959 Health Services Cost Review Commission; 6
6060
6161 (2) Promote the development of a health regulatory system that provides, 7
6262 for all Marylanders, financial and geographic access to quality health care services at a 8
6363 reasonable cost by: 9
6464
6565 (i) Advocating policies and systems to promote the efficient delivery 10
6666 of and improved access to health care services; and 11
6767
6868 (ii) Enhancing the strengths of the current health care service 12
6969 delivery and regulatory system; 13
7070
7171 (3) Facilitate the public disclosure of medical claims data for the 14
7272 development of public policy; 15
7373
7474 (4) Establish and develop a medical care database on health care services 16
7575 rendered by health care practitioners; 17
7676
7777 (5) Encourage the development of clinical resource management systems 18
7878 to permit the comparison of costs between various treatment settings and the availability 19
7979 of information to consumers, providers, and purchasers of health care services; 20
8080
8181 (6) In accordance with Title 15, Subtitle 12 of the Insurance Article, 21
8282 develop a uniform set of effective benefits to be included in the Comprehensive Standard 22
8383 Health Benefit Plan; 23
8484
8585 (7) Analyze the medical care database and provide, in aggregate form, an 24
8686 annual report on the variations in costs associated with health care practitioners; 25
8787
8888 (8) Ensure utilization of the medical care database as a primary means to 26
8989 compile data and information and annually report on trends and variances regarding fees 27
9090 for service, cost of care, regional and national comparisons, and indications of malpractice 28
9191 situations; 29
9292
9393 (9) Establish standards for the operation and licensing of medical care 30
9494 electronic claims clearinghouses in Maryland; 31
9595
9696 (10) Reduce the costs of claims submission and the administration of claims 32
9797 for health care practitioners and payors; 33 HOUSE BILL 1123 3
9898
9999
100100
101101 (11) Determine the cost of mandated health insurance services in the State 1
102102 in accordance with Title 15, Subtitle 15 of the Insurance Article; 2
103103
104104 (12) Promote the availability of information to consumers on charges by 3
105105 practitioners and reimbursements from payors; 4
106106
107107 (13) Oversee and administer the Maryland Trauma Physician Services 5
108108 Fund in conjunction with the Health Services Cost Review Commission; [and] 6
109109
110110 (14) Establish policies and standards to protect the confidentiality of patient 7
111111 and health care practitioner information related to legally protected health care as defined 8
112112 in § 4–301 of this article; AND 9
113113
114114 (15) ESTABLISH AND ENFORCE CYBERSECURIT Y STANDARDS AND 10
115115 PRACTICES FOR HEALTH CARE FACILITIES . 11
116116
117117 (d) The Commission shall coordinate the exercise of its functions with the 12
118118 Department and the Health Services Cost Review Commission to ensure an integrated, 13
119119 effective health care policy for the State. 14
120120
121121 19–113. 15
122122
123123 (A) IN THIS SECTION, “HOSPITAL” HAS THE MEANING STAT ED IN § 19–301 16
124124 OF THIS TITLE. 17
125125
126126 (B) THE COMMISSION SHALL : 18
127127
128128 (1) ADOPT MINIMUM CYBERSE CURITY STANDARDS FOR HOSPITALS 19
129129 THAT: 20
130130
131131 (I) PROTECT PRIVATE DATA , SUCH AS PATIENT AND EMPLOYEE 21
132132 RECORDS, HELD BY THE HOSPITAL ; 22
133133
134134 (II) ENABLE A HOSPITAL TO MAINTAIN ROUTINE FUN CTIONS; 23
135135 AND 24
136136
137137 (III) ARE CONSISTENT WITH T HE NATIONAL INSTITUTE OF 25
138138 STANDARDS AND TECHNOLOGY AND CYBERSECURITY AND INFRASTRUCTURE 26
139139 SECURITY AGENCY RECOMMENDATION S FOR HOSPITALS ; 27
140140
141141 (2) REVIEW AND REVISE THE STANDARDS SET UNDER ITEM (1) OF 28
142142 THIS SUBSECTION ON A REGULAR BASIS ; 29
143143 4 HOUSE BILL 1123
144144
145145
146146 (3) PARTICIPATE IN OPPORT UNITIES TO LEARN ABO UT HOSPITAL 1
147147 CYBERSECURITY FROM E XPERT ENTITIES; 2
148148
149149 (4) LEARN FROM THE EXPERI ENCES OF GOVERNMENT AGENCIES IN 3
150150 OTHER STATES THAT SE T MINIMUM CYBERSECUR ITY STANDARDS FOR HO SPITALS; 4
151151
152152 (5) PROVIDE FOR THIRD –PARTY ASSESSMENTS OF HOSPITALS FOR 5
153153 COMPLIANCE WITH MINI MUM CYBERSECURITY ST ANDARDS; 6
154154
155155 (6) ON OR BEFORE JANUARY 1, 2026, AND EVERY 2 YEARS 7
156156 THEREAFTER : 8
157157
158158 (I) COLLECT CERTIFICATION S OF A HOSPITAL’S COMPLIANCE 9
159159 WITH THE MINIMUM CYB ERSECURITY STANDARDS ADOPTED UNDER ITEM (1) OF 10
160160 THIS SUBSECTION ; AND 11
161161
162162 (II) SUBMIT A REPORT TO TH E STATE CHIEF INFORMATION 12
163163 SECURITY OFFICER, OR THE OFFICER’S DESIGNEE; AND 13
164164
165165 (7) SUPPORT HOSPITALS THA T DO NOT MEET THE MI NIMUM 14
166166 CYBERSECURITY STANDA RDS ADOPTED UNDER IT EM (1) OF THIS SUBSECTION T O 15
167167 REMEDIATE VULNERABIL ITIES OR ADDRESS CYB ERSECURITY ASSESSMEN T 16
168168 FINDINGS. 17
169169
170170 (C) EACH HOSPITAL SHALL : 18
171171
172172 (1) (I) COMPLY WITH THE CYBERSECURITY STANDA RDS ADOPTED 19
173173 UNDER SUBSECTION (B)(1) OF THIS SECTION; AND 20
174174
175175 (II) SUBMIT A CERTIFICATIO N OF COMPLIANCE WITH THE 21
176176 STANDARDS AS DIRECTE D BY THE COMMISSION; 22
177177
178178 (2) DESIGNATE A CHIEF INF ORMATION SECURITY OF FICER TO 23
179179 OVERSEE COMPLIANCE W ITH THE REQUIREMENTS OF T HIS SECTION; 24
180180
181181 (3) IMMEDIATELY REPORT A CYBERSECURITY INCIDE NT TO THE 25
182182 COMMISSION, RELEVANT LAW ENFORCE MENT AGENCIES , AND HOSPITAL 26
183183 ADMINISTRATORS ; 27
184184
185185 (4) MAINTAIN A CYBERSECUR ITY INCIDENT RESPONS E PLAN AND 28
186186 TEST THE PLAN AT LEA ST ANNUALL Y; AND 29
187187
188188 (5) MAINTAIN A MOBILE DEV ICE MANAGEMENT PROGR AM THAT: 30 HOUSE BILL 1123 5
189189
190190
191191
192192 (I) IS CONSISTENT WITH FE DERAL GUIDANCE ; 1
193193
194194 (II) INCLUDES AN ENTERPRIS E MOBILE PLATFORM ; AND 2
195195
196196 (III) INCLUDES A MOBILE THR EAT DEFENSE PROGRAM . 3
197197
198198 (D) THE SECRETARY SHALL CONSI DER THE STANDARDS ADOPTED UN DER 4
199199 THIS SECTION WHEN IS SUING A LICENSE TO A HOSPITAL. 5
200200
201201 SECTION 2. AND BE IT FURTHER ENACTED, That it is the intent of the General 6
202202 Assembly that the Maryland Health Care Commission work with the Cybersecurity and 7
203203 Infrastructure Security Agency and the Office of Security Management to improve the 8
204204 Commission’s capacity to implement the provisions of this Act. 9
205205
206206 SECTION 3. AND BE IT FURTHER ENACTED, That this Act shall take effect 10
207207 October 1, 2024. 11
208208