1 | 1 | | II |
---|
2 | 2 | | 119THCONGRESS |
---|
3 | 3 | | 1 |
---|
4 | 4 | | STSESSION S. 1007 |
---|
5 | 5 | | To amend title V of the Public Health Service Act to secure the suicide |
---|
6 | 6 | | prevention lifeline from cybersecurity incidents, and for other purposes. |
---|
7 | 7 | | IN THE SENATE OF THE UNITED STATES |
---|
8 | 8 | | MARCH12, 2025 |
---|
9 | 9 | | Mr. M |
---|
10 | 10 | | ULLIN(for himself and Mr. PADILLA) introduced the following bill; |
---|
11 | 11 | | which was read twice and referred to the Committee on Health, Edu- |
---|
12 | 12 | | cation, Labor, and Pensions |
---|
13 | 13 | | A BILL |
---|
14 | 14 | | To amend title V of the Public Health Service Act to secure |
---|
15 | 15 | | the suicide prevention lifeline from cybersecurity inci- |
---|
16 | 16 | | dents, and for other purposes. |
---|
17 | 17 | | Be it enacted by the Senate and House of Representa-1 |
---|
18 | 18 | | tives of the United States of America in Congress assembled, 2 |
---|
19 | 19 | | SECTION 1. SHORT TITLE. 3 |
---|
20 | 20 | | This Act may be cited as the ‘‘9–8–8 Lifeline Cyber-4 |
---|
21 | 21 | | security Responsibility Act’’. 5 |
---|
22 | 22 | | VerDate Sep 11 2014 03:47 Mar 26, 2025 Jkt 059200 PO 00000 Frm 00001 Fmt 6652 Sfmt 6201 E:\BILLS\S1007.IS S1007 |
---|
23 | 23 | | ssavage on LAPJG3WLY3PROD with BILLS 2 |
---|
24 | 24 | | •S 1007 IS |
---|
25 | 25 | | SEC. 2. PROTECTING SUICIDE PREVENTION LIFELINE 1 |
---|
26 | 26 | | FROM CYBERSECURITY INCIDENTS. 2 |
---|
27 | 27 | | (a) N |
---|
28 | 28 | | ATIONALSUICIDEPREVENTIONLIFELINEPRO-3 |
---|
29 | 29 | | GRAM.—Section 520E–3(b) of the Public Health Service 4 |
---|
30 | 30 | | Act (42 U.S.C. 290bb–36c(b)) is amended— 5 |
---|
31 | 31 | | (1) in paragraph (4), by striking ‘‘and’’ at the 6 |
---|
32 | 32 | | end; 7 |
---|
33 | 33 | | (2) in paragraph (5), by striking the period at 8 |
---|
34 | 34 | | the end and inserting ‘‘; and’’; and 9 |
---|
35 | 35 | | (3) by adding at the end the following: 10 |
---|
36 | 36 | | ‘‘(6) coordinating with the Chief Information 11 |
---|
37 | 37 | | Security Officer of the Department of Health and 12 |
---|
38 | 38 | | Human Services to take such steps as may be nec-13 |
---|
39 | 39 | | essary to ensure the program is protected from cy-14 |
---|
40 | 40 | | bersecurity incidents and eliminates known cyberse-15 |
---|
41 | 41 | | curity vulnerabilities.’’. 16 |
---|
42 | 42 | | (b) R |
---|
43 | 43 | | EPORTING.—Section 520E–3 of the Public 17 |
---|
44 | 44 | | Health Service Act (42 U.S.C. 290bb–36c) is amended— 18 |
---|
45 | 45 | | (1) by redesignating subsection (f) as sub-19 |
---|
46 | 46 | | section (g); and 20 |
---|
47 | 47 | | (2) by inserting after subsection (e) the fol-21 |
---|
48 | 48 | | lowing: 22 |
---|
49 | 49 | | ‘‘(f) C |
---|
50 | 50 | | YBERSECURITYREPORTING.— 23 |
---|
51 | 51 | | ‘‘(1) I |
---|
52 | 52 | | N GENERAL.— 24 |
---|
53 | 53 | | ‘‘(A) I |
---|
54 | 54 | | N GENERAL.—The program’s net-25 |
---|
55 | 55 | | work administrator receiving Federal funding 26 |
---|
56 | 56 | | VerDate Sep 11 2014 03:47 Mar 26, 2025 Jkt 059200 PO 00000 Frm 00002 Fmt 6652 Sfmt 6201 E:\BILLS\S1007.IS S1007 |
---|
57 | 57 | | ssavage on LAPJG3WLY3PROD with BILLS 3 |
---|
58 | 58 | | •S 1007 IS |
---|
59 | 59 | | pursuant to subsection (a) shall report to the 1 |
---|
60 | 60 | | Assistant Secretary, in a manner that protects 2 |
---|
61 | 61 | | personal privacy, consistent with applicable 3 |
---|
62 | 62 | | Federal and State privacy laws— 4 |
---|
63 | 63 | | ‘‘(i) any identified cybersecurity 5 |
---|
64 | 64 | | vulnerabilities to the program within 24 6 |
---|
65 | 65 | | hours of identification of such a vulner-7 |
---|
66 | 66 | | ability; and 8 |
---|
67 | 67 | | ‘‘(ii) any identified cybersecurity inci-9 |
---|
68 | 68 | | dents to the program within 24 hours of 10 |
---|
69 | 69 | | identification of such incident. 11 |
---|
70 | 70 | | ‘‘(B) L |
---|
71 | 71 | | OCAL AND REGIONAL CRISIS CEN -12 |
---|
72 | 72 | | TERS.—Local and regional crisis centers par-13 |
---|
73 | 73 | | ticipating in the program shall report to the 14 |
---|
74 | 74 | | program’s network administrator described in 15 |
---|
75 | 75 | | subparagraph (A), in a manner that protects 16 |
---|
76 | 76 | | personal privacy, consistent with applicable 17 |
---|
77 | 77 | | Federal and State privacy laws— 18 |
---|
78 | 78 | | ‘‘(i) any identified cybersecurity 19 |
---|
79 | 79 | | vulnerabilities to the program within 24 20 |
---|
80 | 80 | | hours of identification of such vulner-21 |
---|
81 | 81 | | ability; and 22 |
---|
82 | 82 | | ‘‘(ii) any identified cybersecurity inci-23 |
---|
83 | 83 | | dents to the program within 24 hours of 24 |
---|
84 | 84 | | identification of such incident. 25 |
---|
85 | 85 | | VerDate Sep 11 2014 03:47 Mar 26, 2025 Jkt 059200 PO 00000 Frm 00003 Fmt 6652 Sfmt 6201 E:\BILLS\S1007.IS S1007 |
---|
86 | 86 | | ssavage on LAPJG3WLY3PROD with BILLS 4 |
---|
87 | 87 | | •S 1007 IS |
---|
88 | 88 | | ‘‘(2) NOTIFICATION.—If the program’s network 1 |
---|
89 | 89 | | administrator receiving funding pursuant to sub-2 |
---|
90 | 90 | | section (a) discovers, or is informed by a local or re-3 |
---|
91 | 91 | | gional crisis center pursuant to paragraph (1)(B) of, 4 |
---|
92 | 92 | | a cybersecurity vulnerability or incident described in 5 |
---|
93 | 93 | | such paragraph, within 24 hours of such discovery 6 |
---|
94 | 94 | | or receipt of information, such entity shall report the 7 |
---|
95 | 95 | | vulnerability or incident to the Assistant Secretary. 8 |
---|
96 | 96 | | ‘‘(3) C |
---|
97 | 97 | | LARIFICATION.— 9 |
---|
98 | 98 | | ‘‘(A) O |
---|
99 | 99 | | VERSIGHT.— 10 |
---|
100 | 100 | | ‘‘(i) L |
---|
101 | 101 | | OCAL AND REGIONAL CRISIS 11 |
---|
102 | 102 | | CENTER.—Except as provided in clause 12 |
---|
103 | 103 | | (ii), local and regional crisis centers par-13 |
---|
104 | 104 | | ticipating in the program shall oversee all 14 |
---|
105 | 105 | | technology each center employs in the pro-15 |
---|
106 | 106 | | vision of services as a participant in the 16 |
---|
107 | 107 | | program. 17 |
---|
108 | 108 | | ‘‘(ii) N |
---|
109 | 109 | | ETWORK ADMINISTRATOR .— 18 |
---|
110 | 110 | | The program’s network administrator re-19 |
---|
111 | 111 | | ceiving Federal funding pursuant to sub-20 |
---|
112 | 112 | | section (a) shall oversee the technology 21 |
---|
113 | 113 | | each crisis center employs in the provision 22 |
---|
114 | 114 | | of services as a participant in the program 23 |
---|
115 | 115 | | if such oversight responsibilities are estab-24 |
---|
116 | 116 | | VerDate Sep 11 2014 03:47 Mar 26, 2025 Jkt 059200 PO 00000 Frm 00004 Fmt 6652 Sfmt 6201 E:\BILLS\S1007.IS S1007 |
---|
117 | 117 | | ssavage on LAPJG3WLY3PROD with BILLS 5 |
---|
118 | 118 | | •S 1007 IS |
---|
119 | 119 | | lished in the applicable network participa-1 |
---|
120 | 120 | | tion agreement. 2 |
---|
121 | 121 | | ‘‘(B) S |
---|
122 | 122 | | UPPLEMENT, NOT SUPPLANT.—The 3 |
---|
123 | 123 | | cybersecurity incident reporting requirements 4 |
---|
124 | 124 | | under this subsection shall supplement, and not 5 |
---|
125 | 125 | | supplant, cybersecurity incident reporting re-6 |
---|
126 | 126 | | quirements under other provisions of applicable 7 |
---|
127 | 127 | | Federal law that are in effect on the date of the 8 |
---|
128 | 128 | | enactment of the 9–8–8 Lifeline Cybersecurity 9 |
---|
129 | 129 | | Responsibility Act.’’. 10 |
---|
130 | 130 | | (c) S |
---|
131 | 131 | | TUDY.—Not later than 180 days after the date 11 |
---|
132 | 132 | | of the enactment of this Act, the Comptroller General of 12 |
---|
133 | 133 | | the United States shall— 13 |
---|
134 | 134 | | (1) conduct and complete a study that evaluates 14 |
---|
135 | 135 | | cybersecurity risks and vulnerabilities associated 15 |
---|
136 | 136 | | with the 9–8–8 National Suicide Prevention Lifeline; 16 |
---|
137 | 137 | | and 17 |
---|
138 | 138 | | (2) submit a report of the findings of such 18 |
---|
139 | 139 | | study to the Committee on Energy and Commerce of 19 |
---|
140 | 140 | | the House of Representatives and the Committee on 20 |
---|
141 | 141 | | Health, Education, Labor, and Pensions of the Sen-21 |
---|
142 | 142 | | ate. 22 |
---|
143 | 143 | | Æ |
---|
144 | 144 | | VerDate Sep 11 2014 03:47 Mar 26, 2025 Jkt 059200 PO 00000 Frm 00005 Fmt 6652 Sfmt 6301 E:\BILLS\S1007.IS S1007 |
---|
145 | 145 | | ssavage on LAPJG3WLY3PROD with BILLS |
---|