ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

42 U.S.C. § 242v–1Securing identifiable, sensitive information and addressing other national security risks related to research

submitted 4 years ago by Pub. L. 117-328 to r/title-42-THE-PUBLIC-HEALTH-AND-WELFARE · 566 words · no verdicts yet

in plain englishAI-generated · not legal advice

HHS must make sure NIH-funded biomedical research properly considers national security risks, especially around genomic data and other sensitive information, working with intelligence and defense agencies. Within two years, HHS must build a framework for assessing these risks, including security controls, funding safeguards, and a one-year deadline to implement compliance and vetting controls, plus a two-year deadline to update data-sharing policies on genomic data. HHS must also brief Congress within a year.

This section requires HHS to manage national security risks in biomedical research. (a) In general. Working with the Director of National Intelligence, the Secretaries of State and Defense, and other national security experts as needed, the Secretary must make sure NIH-funded and other HHS-supported biomedical research properly accounts for national security risks — including risks from human genome sequencing and from collecting, analyzing, or storing sensitive identifiable information (as defined in section 241(d)(4)), and the risk that data gets misused. Within 2 years of December 29, 2022, working with agency heads, national security experts, and the Department's Office of National Security, the Secretary must make sure NIH and other relevant HHS units: (1) build — or review and update — a full framework and policy for assessing and managing these risks, including: (A) criteria for when and how to assess national security risk in a project; (B) security controls and training for researchers or entities (including peer reviewers) who handle data with national security risk; and (C) ways to build risk mitigation into funding decisions and to monitor research after funding, including changing funding terms as needed; (2) within 1 year of finishing that framework, build and put in place controls to make sure: (A) researchers and entities working on reviewed projects — including those with access to sensitive identifiable data — are actually following the framework's requirements; (B) funding decisions for risky projects consider whether the country where the research happens threatens the integrity of U.S. biomedical research; and (C) data access committees reviewing risky data requests include members who understand current and emerging national security threats; and (3) within 2 years of finishing the framework, update data access and sharing policies for human genomic data based on current and emerging security threats. (b) Congressional briefing. Within 1 year of December 29, 2022, the Secretary must brief the Senate health and intelligence committees and the House energy/commerce and intelligence committees on this work.
the actual law source: uscode.house.gov ↗public domain
(a) In general

The Secretary of Health and Human Services, in consultation with the Director of National Intelligence, the Secretary of State, the Secretary of Defense, and other national security experts, as appropriate, shall ensure that biomedical research conducted or supported by the National Institutes of Health and other relevant agencies and offices within the Department of Health and Human Services is conducted or supported in a manner that appropriately considers national security risks, including national security implications related to research involving the sequencing of human genomic information, and collection, analysis, or storage of identifiable, sensitive information, as defined in section 241(d)(4) of this title, and the potential misuse of such data. Not later than 2 years after December 29, 2022, the Secretary shall ensure that the National Institutes of Health and other relevant agencies and offices within the Department of Health and Human Services, in consultation with the heads of agencies and national security experts, including the Office of the National Security within the Department of Health and Human Services—

(1)

develop a comprehensive framework and policies for assessing and managing such national security risks that includes, or review and update, as appropriate, the current (as of the date of review) such framework and policies to include—

(A)

criteria for how and when to conduct risk assessments for projects that may have national security implications;

(B)

security controls and training for researchers or entities, including peer reviewers, that manage or have access to such data that may present national security risks; and

(C)

methods to incorporate risk mitigation in the process for funding such projects that may have national security implications and monitor associated research activities following issuance of an award, including changes in the terms and conditions related to the use of such funds, as appropriate;

(2)

not later than 1 year after the framework and policies are developed or reviewed and updated, as applicable, under paragraph (1), develop and implement controls to ensure that—

(A)

researchers or entities involved in projects reviewed under the framework and relevant policies, including such projects that manage or have access to sensitive, identifiable information, have complied with the requirements of paragraph (1) and ongoing requirements with such paragraph;

(B)

consideration of funding for projects that may have national security implications takes into account the extent to which the country in which the proposed research will be conducted or supported poses a risk to the integrity of the United States biomedical research enterprise; and

(C)

data access committees reviewing data access requests for projects that may have national security risks, as appropriate, include members with expertise in current and emerging national security threats, in order to make appropriate decisions, including related to access to such identifiable, sensitive information; and

(3)

not later than 2 years after the framework and relevant policies are developed or reviewed and updated, as applicable, under paragraph (1), update data access and sharing policies related to human genomic data, as applicable, based on current and emerging national security threats.

(b) Congressional briefing

Not later than 1 year after December 29, 2022, the Secretary shall provide a briefing to the Committee on Health, Education, Labor, and Pensions and the Select Committee on Intelligence of the Senate and the Committee on Energy and Commerce and the Permanent Select Committee on Intelligence of the House of Representatives on the activities required under subsection (a).

Source credit: (Pub. L. 117–328, div. FF, title II, § 2322, Dec. 29, 2022, 136 Stat. 5765.)

history & why it existsrecord from the source credit
  • 2022Enacted · Pub. L. 117-328 · 136 Stat. 5765

A history note hasn’t been published yet. The record shows enactment by Pub. L. 117-328 on 2022-12-29.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case