The network administrator must report vulnerabilities and incidents
What the document says“The program's network administrator receiving Federal funding pursuant to subsection (a) shall report to the Assistant Secretary, in a manner that protects personal privacy, consistent with applicable Federal and State privacy laws--”
The section adds subsection (f) to section 520E-3 of the Public Health Service Act. The new subsection requires the network administrator to report identified cybersecurity vulnerabilities and incidents to the Assistant Secretary within a reasonable amount of time, in a way that protects personal privacy.
What the document actually says“The program's network administrator receiving Federal funding pursuant to subsection (a) shall report to the Assistant Secretary, in a manner that protects personal privacy, consistent with applicable Federal and State privacy laws--”
The group that runs the network must report trouble. It reports to a senior official. It must guard people's private facts when it does.
There are two kinds of trouble to report. A weak spot is a hole nobody has used yet. An incident is an attack that has already happened.
No action is recorded against this proposal. That is not evidence that none has been taken, and nobody has yet read it against the record. See what the tracker does not yet cover.