11 | 4 | | AN ACT |
---|
12 | 5 | | relating to the use, collection, and security of health care data |
---|
13 | 6 | | collected by the Department of State Health Services. |
---|
14 | 7 | | BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS: |
---|
15 | 8 | | SECTION 1. Section 108.009, Health and Safety Code, is |
---|
16 | 9 | | amended by adding Subsection (c) to read as follows: |
---|
17 | 10 | | (c) The department or another entity as determined by the |
---|
18 | 11 | | department to collect data from a provider under Subsection (a) |
---|
19 | 12 | | shall maintain a database that does not include identifying |
---|
20 | 13 | | information for use as authorized by law, including this chapter. |
---|
21 | 14 | | SECTION 2. Chapter 108, Health and Safety Code, is amended |
---|
22 | 15 | | by adding Section 108.0095 to read as follows: |
---|
23 | 16 | | Sec. 108.0095. NOTIFICATION OF DATA COLLECTION. (a) A |
---|
24 | 17 | | provider shall provide to a patient whose data is being collected |
---|
25 | 18 | | under this chapter written notice on a form prescribed by the |
---|
26 | 19 | | department of the collection of the patient's data for health care |
---|
27 | 20 | | purposes. |
---|
28 | 21 | | (b) The notice provided under this section must include the |
---|
29 | 22 | | name of the agency or entity receiving the data and of an individual |
---|
30 | 23 | | within the agency or entity whom the patient may contact regarding |
---|
31 | 24 | | the collection of data. |
---|
32 | 25 | | (c) The department shall include the notice required under |
---|
33 | 26 | | this section on an existing department form and make the form |
---|
34 | 27 | | available on the department's Internet website. |
---|
35 | 28 | | SECTION 3. Section 108.011(d), Health and Safety Code, as |
---|
36 | 29 | | amended by S.B. 219, Acts of the 84th Legislature, Regular Session, |
---|
37 | 30 | | 2015, is amended to read as follows: |
---|
38 | 31 | | (d) The executive commissioner shall adopt procedures to |
---|
39 | 32 | | establish the accuracy and consistency of the public use data |
---|
40 | 33 | | before releasing the public use data to the public. The department |
---|
41 | 34 | | may adopt additional procedures as the department determines |
---|
42 | 35 | | necessary. The procedures adopted under this subsection must meet |
---|
43 | 36 | | available best practices and national standards for public research |
---|
44 | 37 | | on and consumer use of health care data collected by governmental |
---|
45 | 38 | | agencies. |
---|
46 | 39 | | SECTION 4. Section 108.013(a), Health and Safety Code, as |
---|
47 | 40 | | amended by S.B. 219, Acts of the 84th Legislature, Regular Session, |
---|
48 | 41 | | 2015, is amended to read as follows: |
---|
49 | 42 | | (a) The data received by the department under this chapter |
---|
50 | 43 | | shall be used by the department and commission only for the benefit |
---|
51 | 44 | | of the public. Subject to specific limitations established by this |
---|
52 | 45 | | chapter and department rule, the department shall make |
---|
53 | 46 | | determinations on requests for information in favor of access. |
---|
54 | 47 | | SECTION 5. Chapter 108, Health and Safety Code, is amended |
---|
55 | 48 | | by adding Section 108.0132 to read as follows: |
---|
56 | 49 | | Sec. 108.0132. PROHIBITED CHARGE TO CERTAIN STATE AGENCIES |
---|
57 | 50 | | FOR DATA. The department may not charge a fee to the commission or |
---|
58 | 51 | | any other health and human services agency for the use of any data |
---|
59 | 52 | | collected under this chapter. |
---|
60 | 53 | | SECTION 6. Chapter 108, Health and Safety Code, is amended |
---|
61 | 54 | | by adding Section 108.0136 to read as follows: |
---|
62 | 55 | | Sec. 108.0136. REPORT; NOTIFICATION OF CYBER ATTACK. (a) |
---|
63 | 56 | | The department shall prepare for the commissioner an annual report |
---|
64 | 57 | | describing the security measures taken to protect data collected |
---|
65 | 58 | | under this chapter and any breaches, attempted cyber attacks, and |
---|
66 | 59 | | security issues related to the data that are encountered during the |
---|
67 | 60 | | calendar year. |
---|
68 | 61 | | (b) The report described by this section is not subject to |
---|
69 | 62 | | Chapter 552, Government Code, but may be released on request to a |
---|
70 | 63 | | member of the legislature. |
---|
71 | 64 | | (c) If a cyber attack occurs targeting data collected under |
---|
72 | 65 | | this chapter, the department shall notify the Department of Public |
---|
73 | 66 | | Safety of the State of Texas and the Federal Bureau of Investigation |
---|
74 | 67 | | of the attack. |
---|
75 | 68 | | SECTION 7. This Act takes effect September 1, 2015. |
---|