H.R. 498 — what changed
9–8–8 Lifeline Cybersecurity Responsibility Act
From Introduced in House to Reported in House. 1 section amended between Introduced in House and Reported in House.
Sec. 2 Protecting suicide prevention lifeline from cybersecurity incidents
“(6) coordinating with the Chief Information Security Officer of the Department of Health and Human Services to take such steps as may be necessary to ensure the program is protected from cybersecurity incidents and eliminates known cybersecurity vulnerabilities.”
“(f) Cybersecurity reporting
changed
“(1) In general—The program’s network administrator receiving Federal funding pursuant to subsection (a) shall report to the Assistant Secretary, in a manner that protects personal privacy, consistent with applicable Federal and State privacy laws—general
changed
“(A) any identified cybersecurity vulnerabilities In general—The program’s network administrator receiving Federal funding pursuant to subsection (a) shall report to the National Suicide Prevention Lifeline; andAssistant Secretary, in a manner that protects personal privacy, consistent with applicable Federal and State privacy laws—
changed
“(B) “(i) any identified cybersecurity incidents or potential incidents vulnerabilities to the National Suicide Prevention Lifeline.program immediately upon identification of such a vulnerability; and
changed
“(2) Notification—If an entity described in paragraph (1) discovers a “(ii) any identified cybersecurity vulnerability, incident, or potential incident, such entity shall immediately report that discovery incidents to the Assistant Secretary.program immediately upon identification of such incident.
changed
“(3) Clarification—The cybersecurity incident reporting requirements under this subsection shall supplement, “(B) Local and not supplant, cybersecurity incident reporting requirements under other provisions of applicable Federal law that are regional crisis centers—Local and regional crisis centers participating in effect on the date of the enactment of program shall report to the 9–8–8 Lifeline Cybersecurity Responsibility Act.”program’s network administrator identified in subparagraph (A), in a manner that protects personal privacy, consistent with applicable Federal and State privacy laws—
added “(i) any identified cybersecurity vulnerabilities to the program immediately upon identification of such vulnerability; and
added “(ii) any identified cybersecurity incidents to the program immediately upon identification of such incident.
added “(2) Notification—If the program’s network administrator receiving funding pursuant to subsection (a) discovers, or is informed by a local or regional crisis center pursuant to paragraph (1)(B) of, a cybersecurity vulnerability or incident, such entity shall immediately report that discovery to the Assistant Secretary.
added “(3) Clarification
added “(A) Oversight
added “(i) Local and regional crisis center—Except as provided in clause (ii), local and regional crisis centers participating in the program shall oversee all technology each center employs in the provision of services as a participant in the program.
added “(ii) Network administrator—The program’s network administrator receiving Federal funding pursuant to subsection (a) shall oversee the technology each crisis center employs in the provision of services as a participant in the program if such oversight responsibilities are established in the applicable network participation agreement.
added “(B) Supplement, not supplant—The cybersecurity incident reporting requirements under this subsection shall supplement, and not supplant, cybersecurity incident reporting requirements under other provisions of applicable Federal law that are in effect on the date of the enactment of the 9–8–8 Lifeline Cybersecurity Responsibility Act.”