Mr. Speaker, by direction of the Committee on Rules, I call up House Resolution 455 and ask for its immediate consideration. Mr. Speaker, for the purpose of debate only, I yield the customary 30…
Mr. Speaker, by direction of the Committee on Rules, I call up House Resolution 455 and ask for its immediate consideration.
Mr. Speaker, for the purpose of debate only, I yield the customary 30 minutes to gentleman from Colorado (Mr. Polis), pending which I yield myself such time as I may consume. During consideration of this resolution, all time yielded is for the purpose of debate only.
General Leave
Mr. Speaker, I ask unanimous consent that all Members have 5 legislative days to revise and extend their remarks.
Mr. Speaker, House Resolution 455 provides for the consideration of three important bills which were reported by the Energy and Commerce Committee: H.R. 2279, the Reducing Excessive Deadline Obligations Act of 2013; H.R. 3362, the Exchange Information Disclosure Act; and H.R. 3811, the Health Exchange Security and Transparency Act of 2014.
H.R. 2279 is a bill to address the burdensome and outdated deadlines for certain rulemaking activities conducted by the Environmental Protection Agency under the Solid Waste Disposal Act and the Comprehensive Environmental Response, Compensation, and Liability Act. This provides flexibility for the Environmental Protection Agency in order to streamline a process critical to cleaning up sites contaminated with certain toxic or hazardous chemicals.
It further requires the Environmental Protection Agency to evaluate existing State or other Federal financial insurance requirements to determine whether additional requirements are, in fact, necessary.
Finally, it requires the owner or operator of a chemical storage site to report the presence of such chemicals to the State emergency response commissions.
It is a commonsense piece of legislation to help clean up areas that have been polluted and allows for their reclamation or development. This could bring jobs and economic benefits to neighborhoods which have been so affected.
As the two health care-related pieces of legislation, these are targeted bills to address just a few of the massive problems the American public has witnessed over the last few months pertaining to the calamitous rollout of the Federal www.healthcare.gov Web site. The data obtained by www.healthcare.gov is one of the largest collections of personal information ever assembled. It links information between seven different Federal agencies, State agencies, and government contractors.
In promising lower costs and widespread health coverage for Americans, President Obama failed to mention that the Affordable Care Act's mandates and requirements will create large-scale disruption of the entire health insurance market. The resulting cancelation of insurance plans and high cost for employers to continue providing insurance for their workers has left millions of Americans with no choice other than to purchase health insurance through the Affordable Care Act's exchanges, subjecting their personal information to the vulnerable security infrastructure.
The initial launch of www.healthcare.gov on October 1, 2013, was plagued with glitches and errors. Not only did the administration fail to establish basic functionality of the Web site, but the initial problems really only break the surface of the deeper security threats in the underlying law. A multitude of gaps remain in the Web site's security infrastructure, making the Web site a wide-open target for hackers and identity thieves. These flaws continue to pose a threat to the security of Americans' personal data.
Mr. Speaker, it wasn't that the administration was not alerted to these security concerns on the Web site prior to the launch. MITRE Corporation, a contractor for the Department of Health and Human Services, alerted the agency that 19 unaddressed security vulnerabilities plagued the Web site prior to its launch on October 1. Top officials at the Centers for Medicare and Medicaid Services, including the chief information security officer, Teresa Fryer, along with the Web site's project manager, Tony Trenkle, both refused to sign the Authority to Operate license that was necessary to actually launch www.healthcare.gov. Despite these known issues, the director of the Centers for Medicare and Medicaid Services, Marilyn Tavenner, continued to launch the Web site.
This is much more than a faulty Web site. This is about the American people, who cannot trust their government to certify that their personal information will be safe on a government-run Web site.
The security threat goes beyond just an individual's primary application. Once an individual's personal information is entered into the system, the exchange has the ability to access information within the Department of Homeland Security, the Internal Revenue Service, Social Security, and the Treasury Department. The administration has opened numerous Federal agencies to data breaches and unauthorized access.
Just before the holidays, the entire Nation saw firsthand what a massive security breach looks like. Over 40 million Target customers, their personal data was compromised by computer hackers who pilfered personal financial information and identification.
Target has gone out of their way to alert customers of the security breach. Unfortunately, the Federal Government has no such obligation under the law. This is a point that I don't think most people are aware of. It is not required. It is not a mandate that you have a Target charge card or that you shop at Target, but it is certainly required and a mandate that you buy your insurance through www.healthcare.gov. This is a coercive Federal policy that now is pulling people into its Web site and refuses to provide them the very same protection that we demand that the private sector do for a voluntary purchase.
Instead of following the same requirements placed on the private sector, the Federal Government has gone out of their way to avoid imposing this basic due diligence in their own exchanges. Even when a notification requirement was specifically requested during the rulemaking process on the exchanges, the administration just simply refused.
In the March 27, 2012, Federal Register, Department of Health and Human Services responded, stating:
We do not plan to include the specific notification
procedures in the final rule. Consistent with this approach,
we did not include specific policies for investigation of
data breaches in this final rule.
Furthermore, State laws required that many of the 14 State-run insurance exchanges, that they do disclose such information. No such law exists for the federally run exchange. Mr. Speaker, I would remind you that 36
States rely upon the federally run exchange.
Look, we have spent hundreds of millions of dollars, taxpayer dollars. The American people deserve to know that their personal information is protected and to be notified if that protection lapses.
Let's be honest: www.healthcare.gov is the most talked about Web site in years. The massive amounts of personal information that is collected through www.healthcare.gov and its ability to access multiple government databases creates the perfect environment for targeting by hackers.
Over 16 attempts to hack into the system have already been reported, not to mention the many stories that have been reported in the press on the mishandling and sharing of individuals' data. Identity theft is a threat not only to an individual's credit rating and personal finances but also to overall United States security. Most Americans would be shocked to learn that this level of protection is not already in place for an initiative the size of the Affordable Care Act. Well, today the House is working to correct this injustice, protecting Americans when the administration has refused to do so.
The Obama administration has consistently refused to disclose detailed data on how many Americans have actually completed the Obama Care enrollment process. Now it is more than 3 months after the launch of the exchanges, and we just simply do not know how many Americans are enrolled in the exchange plan.
It was the administration who initially defined the success of the exchange as the number of Americans who actually enroll in the program. The number of enrollments are the only way to evaluate whether the more than $1 trillion that was spent on this thing by the administration is actually working.
The President's commitment to an open and transparent government, repeated so many times during the passage of the Affordable Care Act, represents yet one more broken promise in a long string of broken promises.
Where this administration has failed, the bill before us will require the Secretary of the Department of Health and Human Services to provide detailed weekly reports to the American people about the enrollment number on healthcare.gov. The American people deserve to know what they are getting for their hard-earned tax dollars that they have spent on the demands of this administration.
It is the American people who are suffering because of the mismanagement and failures of this administration. Today--today--we have the opportunity to provide transparency and protect Americans' personal information.
The rule before us today provides for 1 hour of debate equally divided between the majority and the minority for each of the bills contained in the rule. The minority is further afforded the customary motion to recommit on each piece of legislation.
I want to encourage my colleagues to vote ``yes'' on the rule and ``yes'' on the underlying bills and stand with the millions of Americans who are asking and who are demanding that we protect their privacy.
Mr. Speaker, I reserve the balance of my time.
Mr. Speaker, I now would like to yield 4 minutes to the gentleman from Georgia, Dr. Collins.
Mr. Speaker, may I inquire as to the time remaining?
Mr. Speaker, I yield myself 2 minutes.
Mr. Speaker, it is often said those who don't remember their history are doomed to repeat it.
The Rules Committee is an important function of this House. It is an important function of this body. Prior to 3 years ago, the Rules Committee was under the jurisdiction of the Democrats. They controlled the Rules Committee throughout the entirety of the 111th Congress. You may recall, that was the first 2 years of the first Obama term. In those 2 years under Speaker Pelosi, this was the first Congress in history--the first Congress in the history of the Republic--not to have a single bill considered under an open rule process.
Now, since Republicans resumed the majority at the beginning of 2011, 31 bills have come under an open rule. The track record may not be perfect, but it is inestimably better than what preceded it.
I reserve the balance of my time.
Mr. Speaker, I tire of going through this history lesson every time we come down to the floor, but may I remind you that when the now-Affordable Care Act was passed into law, this was a bill that came over to the House from the Senate. Sure enough, the House had sent the bill over to the Senate in July of 2009, H.R. 3590. It was a bill that dealt with housing. The bill that dealt with housing was amended. The amendment read, ``Strike all after the enacting clause and insert,'' and the health care language, which was de novo, the health care language was inserted.
Now, to be sure, the House had considered a health care reform bill, H.R. 3200. H.R. 3200 has gone to the ether of history. H.R. 3590 passed in the Senate, a 60-vote margin on Christmas Eve in 2009, and then was thrown over to the House of Representatives. Did we have a hearing on H.R. 3590 in the Committee on Energy and Commerce? No, we did not. Did they have a hearing in the appropriate subcommittee of Ways and Means on H.R. 3590, as amended? No, they did not.
The bill came to the Rules Committee. It came to the Rules Committee. I attempted to offer amendments. I was told, No, thank you. The bill was perfect the way it is, doesn't need any changes. This bill that affects every man, woman, and child in this country for the next three decades in a very unfavorable way was passed without any input from the then-minority, the Republicans in the House of Representatives.
So it is beyond comprehension that we can continue to have these arguments about closed processes. This, after all, is the granddaddy of all closed processes. And the consequence, the drafting errors, the problems embedded in the structure, could not be dealt with during the normal legislative process, which is why so much authority has been transferred to the executive branch, to the agencies, and why they are now essentially writing the laws that affect so many Americans.
I reserve the balance of my time.
Mr. Speaker, I yield myself 1 minute.
I would point out this bill before us today does not--does not-- change the Superfund, but it does allow States the flexibility to deal with problems in their States as they see fit.
Mr. Speaker, I reserve the balance of my time.
Mr. Speaker, I would like to inquire, does the gentleman have any other speakers? If not, I am prepared to close.
Mr. Speaker, I yield myself the balance of my time.
Mr. Speaker, one of the questions for people who have been watching this debate, I'm sure one of the questions that they have, is there any difference as to how the private sector is treated if and when a data breach occurs versus a Federal agency? The simple fact of the matter is there is a difference.
The private sector is governed under State laws and, yes, by some Federal regulations as well.
In fact, earlier this month, in a publication called The Hill, entitled, ``Target's data breach sparks calls for action,'' there was significant discussion about, perhaps, there being more activity on the part of the Federal Trade Commission in protecting consumers who have been exposed to a data breach.
What are the protections for people harmed with a data breach by the Federal Government?
In fact, for that, there is not legislation, there is not a law that was signed by any administration, but there is an executive order of the President's, dating from May 22, 2007, a so-called OMB Circular.
The OMB Circular dealing with data breaches under the section ``Timeliness of the Notification'' reads:
Agencies should provide notification without unreasonable
delay following the discovery of a breach, consistent with
the needs of law enforcement and national security and any
measures necessary for your agency to determine the scope of
the breach and, if applicable, to restore the reasonable
integrity of the computerized data system compromise.
Decisions to delay notification should be made by the agency
head.
You get the impression that this is, perhaps, a rather open-ended or diffuse or poorly defined timeliness of notification for our constituents who are harmed by a data breach by a Federal agency. So that is one of the problems that we are here today to correct.
Today's rule provides for the consideration of a critical jobs bill and critical security bills to clean up our environment and to protect Americans' personal data.
I certainly want to thank Mr. Gardner, Mr. Terry and Chairman Pitts for their thoughtful bills.
I urge my colleagues to support both the rule and the underlying pieces of legislation.
Mr. Speaker, I urge an ``aye'' vote on the previous question. I yield back the balance of my time, and I move the previous question on the resolution.