These reporting duties add to other Federal reporting duties
What the document says“The cybersecurity incident reporting requirements under this subsection shall supplement, and not supplant, cybersecurity incident reporting requirements under other provisions of applicable Federal law that are in effect on the date of the enactment of the SUPPORT for Patients and Communities Reauthorization Act of 2025.”
The new subsection states that its reporting requirements add to, rather than replace, cybersecurity incident reporting requirements under other Federal law in effect on the date this Act was enacted.
What the document actually says“The cybersecurity incident reporting requirements under this subsection shall supplement, and not supplant, cybersecurity incident reporting requirements under other provisions of applicable Federal law that are in effect on the date of the enactment of the SUPPORT for Patients and Communities Reauthorization Act of 2025.”
These new reports do not take the place of old ones. They are added on top. Other federal rules still apply.
More than one federal law can ask for a report on the same attack. This line settles that the new duty does not cancel the others.
No action is recorded against this proposal. That is not evidence that none has been taken, and nobody has yet read it against the record. See what the tracker does not yet cover.