U.S. House of Representatives Passes Cybersecurity Bill with Data-Sharing Protections | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

U.S. House of Representatives Passes Cybersecurity Bill with Data-Sharing Protections

April 23, 2015
by Mark Hagland
| Reprints
The House of Representatives has passed a bill providing legal protections for companies that share cyberthreat information with each other and with the federal government

With strong bipartisan support, the U.S. House of Representatives on April 22 passed a cybersecurity bill that would provide legal liability protections for companies that share cyberthreat information with each other and with the federal government. The legislation, which was passed after years of delays and obstacles, is similar to a measure approved by the Senate Intelligence Committee, and which is headed towards a vote in the Senate this spring. The House measure, supported by the White House, passed 307 to 116.

As The New York Times reported Apr. 23, “Should the House and Senate come together on final legislation, it would be the federal government’s most aggressive response yet to a spate of computer attacks that helped sink a major motion picture release by Sony Pictures Entertainment, exposed the credit card numbers of tens of thousands of customers of Target stores and compromised the personal records of millions of people who did business with the health insurer Anthem.”

As Healthcare Informatics reported on Feb. 5, Anthem Blue Cross executives revealed publicly on Feb. 4 that their organization had experienced a massive cyberattack that had exposed the personal data of up to 80 million Anthem plan members and customers. That cyberattack has been the largest healthcare-related cyberattack to date, and one of the largest of any kind reported so far.

According to the Times article, under the legislation, “If a company shares information with the government, it would receive liability protection only if its data undergoes two rounds of washing out personal information—once by the company before it gives the data to the government and another round by the government agency that receives the data, which many experts believe is critical in getting companies to comply.

The Times article, written by Jennifer Steinhauer, quotes Sara Beth Groshart, director of government affairs at the Information Technology Industry Council, as saying, “Liability protection is something needed to help companies share. And only Congress can provide that.”

The Times also spoke with Paul Kurtz, CEO of TruStar, a company that helps companies with information-sharing, and someone who had worked on cybersecurity issues under the Clinton, Bush, and Obama administrations. Steinhauer quoted Kurtz as saying, “The gravity of the emergency we have in cyberspace is setting in with lawmakers. They now understand that companies can no longer fight the bad guys individually.”

The Times quoted Rep. Dutch Ruppersberger, Democrat of Maryland, as saying, “We are under attack as I speak. To do nothing is not an option.” Some in Congress feel the House bill does not go far enough on national security. “I do believe we will see a cybersecurity bill enacted and signed into law, Senator Susan Collins, Republican of Maine,” told the newspaper. “But it won’t be as strong as it should be to protect critical infrastructure.”

As for passage of the bill in the Senate, the Times reported that timing “may be impeded by time-consuming amendments,” noting that “That chamber is already snarled over a bill that would give congress more say in a nuclear deal with Iran and a major trade measure. The Highway Trust Fund is nearly broke and requires legislative action before the end of the month, and a national security program at issue also requires renewal.”

HCI will continue to update readers on developments in this area as they occur.

 

 

 

 

 

Get the latest information on Health IT and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More

Topics

News

Study will Leverage Connecticut HIE to Help Prevent Suicides

A new study will aim to leverage CTHealthLink, a physician-led health information exchange (HIE) in Connecticut, to help identify the factors leading to suicide and to ultimately help prevent those deaths.

Duke Health First to Achieve HIMSS Stage 7 Rating in Analytics

North Carolina-based Duke Health has become the first U.S. healthcare institution to be awarded the highest honor for analytic capabilities by HIMSS Analytics.

NIH Releases First Dataset from Adolescent Brain Development Study

The National Institutes of Health (NIH) announced the release of the first dataset from the Adolescent Brain Cognitive Development (ABCD) study, which will enable scientists to conduct research on the many factors that influence brain, cognitive, social, and emotional development.

Boston Children's Accelerates Data-Driven Approach to Clinical Research

In an effort to bring a more data-driven approach to clinical research, Boston Children’s Hospital has joined the TriNetX global health research network.

Paper Records, Films Most Common Type of Healthcare Data Breach, Study Finds

Despite the high level of hospital adoption of electronic health records and federal incentives to do so, paper and films were the most frequent location of breached data in hospitals, according to a recent study.

AHA Appoints Senior Advisor for Cybersecurity and Risk

The American Hospital Association (AHA) has announced that John Riggi has joined the association as senior advisor for cybersecurity and risk.