I thank the distinguished gentleman, and I thank the manager of this legislation, and I thank the good intentions of our colleagues. I want to pause for a moment, Mr. Pallone, and just simply say…
I thank the distinguished gentleman, and I thank the manager of this legislation, and I thank the good intentions of our colleagues.
I want to pause for a moment, Mr. Pallone, and just simply say that although these are important issues, as a member of the House Judiciary Committee, I helped draft the PATRIOT Act and business record 215, and we are now looking to constrain the collection of mega-data, and I accept the importance of privacy for the American people. But I pause for just a moment to ask my colleagues, we have enough time today to actually pass the extension of the unemployment benefits. There are 1.3 million people, 12,000 in my own community, who would like us to stay here and make sure that we get that done. I hope that my friends on the other side of the aisle will accept the challenge of Republicans putting an extension of the unemployment benefits on the floor to help unemployed Americans.
But this is an important issue as well, and I do want to say that our friends have not documented any breach on personal and private data of those individuals that have accessed the Affordable Care Act, which are 9 million plus, and growing. We have had 46 votes to repeal it. Now we come one by one with legislation that has not gone through regular order. It has not gone through the committee process. It has very good intentions; but, in actuality, it may be overly burdensome because, Mr. Speaker, there is no bar. There is no limit for HHS to provide notice for any possible breach within seconds or minutes or hours after the incident may have occurred.
Frankly, this legislation doesn't go far enough. Let me give you a few facts. The Affordable Care Act implementation of healthcare.gov is under the authority of HHS. HHS assigned the task for developing healthcare.gov to the agency's Center for Medicare and Medicaid Services. Under the Federal Privacy Act, all Federal agencies must draft regulations to protect personally identifiable information under their control.
The Federal Privacy Act was established by an act of Congress and concurrence of the executive branch to balance the government's need to maintain personal information on Americans with the right of individuals to be protected against unwarranted invasions of their privacy.
The Privacy Act came as a direct result of the work of the Church Committee following revelations that the government has routinely used records on citizens for political purposes to engage in surveillance or retaliatory activity. There were a series of laws
passed by Congress to protect the privacy of Americans.
Computer records management was of such grave concern to Members of Congress following investigations into disclosures that then-President Nixon had used his high office to seek out by means to exact retribution against political enemies by causing harm to careers, reputations as well as financial injury through IRS audits.
So we have had an intense interest since the report ``Records, Computers, and the Rights of Citizens'' was produced in 1973. HHS is chiefly responsible for why the United States became the first Nation in the world to draft a Federal privacy law. They know what to do. They developed the Code of Fair Information practices which have five principles, one of which says there must be no personal data recordkeeping systems whose very existence is secret, that is, to not use the data of people in the wrong way.
There is the CMS Policy for Privacy Act, and I offer this for the Record.
The baseline of my point is that HHS was at the core of developing privacy. There have been no known breaches. There is no bar for CMS and HHS to tell the American public or the individual immediately.
This bill will add burdensome requirements and may--it may--distract or take away from legal and lawful law enforcement investigations. I ask that we look at this together in a bipartisan manner. I believe in privacy. I hope we can work together, Mr. Pallone, and make this what it should be; but I think the American people are protected.
Mr. Speaker, I rise to speak on H.R. 3811, the Health Exchange Security and Transparency Act of 2014.
I would like to commend the author of the bill for the focus on privacy.
Privacy protection is a policy area that has strong bi-partisan agreement.
However, because H.R. 3811 did not go through regular order there was no opportunity for the Committees of jurisdiction to provide valuable input into its drafting.
I would like to offer a few facts that may make it clear that this bill, although well intentioned is not necessary in its current form.
The Affordable Care Act implementation of healthcare.gov is under the authority of the Department of Health and Human Services (HHS).
HHS assigned the task for developing healthcare.gov to the agency's Centers for Medicare & Medicaid Services (CMS).
Under the Federal Privacy Act all federal agencies must draft regulations to protect personally identifiable information under their control.
The Federal Privacy Act was established by an act of Congress and concurrence of the Executive Branch to balance the Government's need to maintain personal information on Americans with the right of individuals to be protected against unwarranted invasions of their privacy.
The Privacy Act came as a direct result of the work of the Church Committee following revelations that the government had routinely used records on citizens for political purposes to engage in surveillance or retaliatory activity a series of laws were passed by Congress to protect the privacy of Americans.
Computer records management was of such grave concern to members of Congress following investigations into disclosures that then President Nixon had used his high office to seek out means to exact retribution against political enemies by causing harm to careers, reputations as well as financial injury through IRS audits.
In 1973, a report ``Records, Computers, and the Rights of Citizens'' was produced by the former Federal Department of Health Education and Welfare (HEW), which today exists as two agencies one of which is the Department of Health and Human Services (HHS) established the first federal agency privacy policies for information held on Americans.
HHS is chiefly responsible for why the United States became the first nation in the world to draft a federal privacy law.
HHS developed the Code of Fair Information practices which later became the basis for the Federal Privacy Act.
The Code of Fair Information Practices has five principles:
There must be no personal data record-keeping systems whose very existence is secret.
There must be a way for a person to find out what information about the person is in a record and how it is used.
There must be a way for a person to prevent information about the person that was obtained for one purpose from being used or made available for other purposes without the person's consent.
There must be a way for a person to correct or amend a record of identifiable information about the person.
Any organization creating, maintaining, using, or disseminating records of identifiable personal data must assure the reliability of the data for their intended use and must take precautions to prevent misuses of the data.
The Federal Privacy Act protects all personal information managed by Federal agencies.
We know that not all agencies do a good job at protecting the personal information of citizens so today's focus on privacy is relevant and important.
However, our focus should be much broader and better informed regarding the work of each agency in this area.
Committee hearings would have been beneficial in informing the drafters of H.R. 3811, prior to its introduction on the Floor of the House for a vote.
For example, authors of the bill may have taken a different approach if it was acknowledged that the CMS has several policy documents specific to the topic of protecting personal identifiable information of medical records data:
CMS Policy for Privacy Act Implementation & Breach Notification (7/ 23/07)
Risk Management Handbook Volume III Standard 7.1 (12/6/12)
Incident Handling and Breach Notification
CMS Privacy Policy is written to meet obligations established by the Federal Privacy Act of 1974 (5 U.S.C., 552a), the Computer Matching and Privacy Protection Act of 1988 (Public Law 100-503) and the Department of Health and Human Services Privacy Act Regulations (45 C.F.R. Part 5b).
I want to assure my colleagues that under the Federal Privacy Act all Federal agencies must ``develop an effective response to [breaches] that requires disclosure of information regarding the breach to those individuals affected by it, as well as to persons and entities in a position to cooperate, either by assisting in notification to affected individuals or playing a role in preventing or minimizing harms from the breach.''
All agencies, which include CMS, must report all incidents involving personally identifiable information to US-Computer Readiness Team or (US-CERT).
The US-CERT reporting requirement does not distinguish between potential and confirmed breaches--all must be reported within 1 hour of discovery/detection.
The CMS policy on breach notification has 5 criteria to determine if a breach has occurred:
Nature of the Data Elements Breached
Number of Individuals Affected
Likelihood the Information is Accessible and Usable
Likelihood the Breach May Lead to Harm
Ability of the Agency to Mitigate the Risk of Harm
CMS is directed to provide notification without unreasonable delay following the discovery of a breach, consistent with the needs of law enforcement and any measures necessary for CMS to determine the scope of the breach and, if necessary, to restore the integrity of the computerized system.
The consideration of Law-enforcement in government agency breaches is very important because this type of crime can take place in seconds or it may occur over hours, days, weeks or months.
Law-enforcement in investigation of data breaches attempts to identify the culprit(s) and others who may be involved.
To avoid impeding the efforts of law-enforcement or national security H.R. 3811, the Health Exchange Security and Transparency Act of 2014 should have included a law-enforcement exception.
Responsibility for information on individuals whose personally identifiable information has been breached is the CMS Administrator the highest official of the agency.
However, if the data breach is under 50, the notice may also be issued by the CMS Chief Information Officer or Senior Official for Privacy.
CMS Breach Notification to individuals must be in writing that should be ``concise, conspicuous, and in plain language'' and include the following:
Brief description of what happened, including date(s) and its discovery;
Description of the types of information involved in the breach;
Whether the information was encrypted or protected by other means when determined the information may be useful or compromise the security of the system;
What steps individuals should take to protect themselves from potential harm;
What the agency is doing; and
Who affected individuals should contact
There is no evidence that healthcare.gov had a breach of personal information.
If such a breach had occurred it would not be secret and members of this body would have been briefed.
First, the most important rule for cyber security is following the example of the professionals who work in this fast paced area: truth comes before beauty. The truth is that there is no computer system that is 100 percent secure from hostile cyber attacks, natural disasters, structural failures or human errors.
Second, the Internet is a rough neighborhood--the best we can do is to design the best systems possible provide the resources necessary to follow through on good security and privacy designs and ignore the politics of the moment. The most dangerous threats to cyber security do not care about anyone's political party they may care very much about your nation of origin.
Third, cyber security is not about the 14 year old with a laptop, but the botnet attack from a coordinate effort that brings to the discussion significant threats to networks. There is no evidence that nothing occurred that would suggest that the website experienced anything of this nature.
Congress should use regular order to consider means and methods of securing all federal data that is categorized as personally identifiable information.
Attempts to misinform or frighten Americans regarding the healthcare.gov or the Patient Protection and Affordable Care Act implementation mechanisms are unwarranted.
CMS has a detailed and well managed program for ensuring that personally identifiable information is secure and when questions arise they have a top level ``Incident Handling'' protocol that is through in investigating issues and uncovering the facts regarding suspected breaches.
CMS relies upon US-CERT, which is part of DHS' National Cybersecurity and Communications Integration Center (NCCIC) to address breaches of data it manages.
The Department of Homeland Security's United States Computer Emergency Readiness Team (US-CERT) leads efforts to improve the nation's cybersecurity posture, coordinate cyber information sharing, and proactively manage cyber risks to the Nation while protecting the constitutional rights of Americans.
CMS informs US-CERT within an hour of a suspected breach incident.
However, a report does not mean that an incident occurred an investigation must proceed to determine if the report is valid.
It is important note that premature breach notices being sent to consumers regarding their personally identifiable information could have unintended and adverse outcomes for several reasons:
Notice fatigue--too many notices and people stop paying attention;
Increased cost of administering a program due to additional communications that inform people that the initial breach notice was a false alarm;
Giving notice to cyber criminals or terrorists that they have been discovered before law enforcement or national security can assess how the extent of the threat, the target or objective of the attack and trace the source of the threat with the goal of identifying the culprits; and
Correcting the problem that allowed the breach to occur
HHS should only collect the personally identifiable information that is necessary, used it for the purpose of the collection and promptly discarded that data so no database or system of records is created.
I commend my colleagues for the focus on Privacy and hope that we can work together to improve the protection of personal information on Americans throughout the Federal Government.
I strongly recommend that my colleagues vote to send this bill back for committee consideration so that its goal of improving privacy protection can be better matched to the reality of what CMS is currently doing in the area of breach notification, which conforms to what Americans need and law-enforcement as well as national security must have to protect federal agency computer networks.
1 Introduction
CMS must be able to respond to computer security-related
and/or privacy-related incidents in a manner that protects
its own information and helps to protect the information of
others that might be affected by the incident.
This Risk Management Handbook Volume III, Standard 7.1,
Incident Handling and Breach Notification standard, along
with the companion procedures of the RMH Volume II, Procedure
7.2, Incident Handling, supersedes the CMS Information
Security (IS) Incident Handling and Breach Analysis/
Notification Procedure dated December 3, 2010.
1.1 Background
1.1.1 SECURITY EVENT
A Security Event is an observable occurrence in a network
or system (e.g., known or suspected penetrations of
information Technology (IT) resources, probes, infections,
log reviews), or any occurrence that potentially could
threaten CMS data confidentiality, integrity, or
availability.
1.1.2 REPORTABLE EVENT
A Reportable Event is any activity or occurrence that
involves:
A matter that a reasonable person would consider a
violation of criminal, civil, or administrative laws
applicable to any Medicare contract or federal health care
program.
Integrity violations, including any known, probable, or
suspected violation of any Medicare contract term or
provision.
A matter considered to have an ``adverse'' impact on the IT
system/infrastructure or CMS data confidentiality, integrity,
or availability. Examples of specific events that should be
reported include (but are not limited to):
Unauthorized access to or use of sensitive data for illegal
purposes.
Unauthorized altering of data, programs, or hardware.
Loss of mission-essential data (i.e., patient, financial,
benefits, legal, etc.).
Environmental damage/disaster (greater than $10,000)
causing loss of IT services or data, or which may be less
than $10,000 in damage yet affect CMS' ability to continue
any day-to-day functions and operations.
Infection of sensitive systems, firmware, or software by
malicious code (i.e., Viruses, Worms and Trojan Horses,
etc.).
Perpetrated theft, fraud, vandalism, and other criminal
computer activity that did, or may, affect the organization's
capabilities to continue day-to-day functions and operations.
Telecommunications/network security violations, i.e.,
networks (including local area networks [LANs], metropolitan
area networks [MANs], and wide area networks [WANs]) that
experience service interruptions that cause an impact to an
indefinite number of end users.
Unauthorized access to data when in transmission over
communications media.
Loss of system availability affecting the ability of users
to perform the functions required to carry out day-to-day
responsibilities.
Root-level attacks on networking infrastructure, critical
systems, or large, multi-purpose, or dedicated servers.
Compromise (or disclosure of account access information) of
privileged accounts on computer systems.
Compromise (or disclosure of account access information) of
individual user accounts or desktop (single-user) systems.
Denial-of-service attacks on networking infrastructure and
systems.
Attacks launched on others from within organizational
boundaries or systems.
Scans of internal organizational systems originating from
the Internet or from within the organizational boundaries.
Any criminal act that may have been committed using
organizational systems or resources.
Disclosure of protected data, including paper disclosure,
email release, or inadvertent posting of data on a web site.
Suspected information-technology policy violation.
A Reportable Event may be the result of an isolated event
or a series of occurrences. Reportable Events under these
procedures include events that occur at CMS federal sites,
contractor/subcontractor sites/systems, consultants, vendors
or agents. If the Reportable Event results in an overpayment
relating to either Trust Fund payments or administrative
costs, the report must describe the overpayment with as much
specificity as possible, as of the time of the due date for
the submission of the report.
Security events that may consist of an observable
occurrence in a network or system (e.g., detected probes,
infections prevented, log reviews, etc.), that do not
threaten system integrity, are not considered Reportable
Events unless they may be reasonably associated with other
incidents, Reportable Events, or breaches. CMS categorizes
these events in a monthly report to the Department of Health
and Human Services (HHS) (hereafter referred to as the
``Department'' or ``HHS'') Cybersecurity Program as follows:
Malicious Code Prevented: Viruses were prevented and did
not cause any harm to any system.
Probes and Reconnaissance Scans Detected: Probes and scans
were detected but did not pose a serious threat to a CMS
system.
Inappropriate Usage: Misuse of computing resources by an
otherwise authorized individual.
Other: Cannot be categorized under any of the above and do
not threaten system integrity.
There are many events that may be flagged as inappropriate
use of resources, but reflect situations that do not fall
under the definitions associated with incidents, Reportable
Events, or breaches. In such cases, reporting should be made
through applicable contractual resources, or through
appropriate Federal Fraud, Waste, and Abuse reporting
channels.
1.1.3 PRIVACY INFORMATION
Privacy is the right of an individual to control their own
personal information, and not have it disclosed or used by
others without permission. At CMS, we are charged with
protecting other people's private information--that of every
citizen (or legal resident) beneficiary utilizing benefits
the vast Medicare/Medicaid program, as well as many
subsidiary programs.
Confidentiality is the obligation of another party to
respect privacy by protecting personal information they
receive, and preventing it from being used or disclosed
without the subject's knowledge and permission.
Again, at CMS we are charged with protecting the
confidentiality of other people's citizen-beneficiary
information. A breach of that confidentiality is not simply a
failure of a ``technical control'', it is a basic failure of
CMS to meet its obligation to protect the individual citizen.
Moreover, unlike the banking industry where financial
compensation is a readily-available remedy to a breach,
private medical information cannot be simply replaced with
something of ``similar value'', or by simply closing an
account, and opening a new (better protected) one. Once a
privacy breach occurs, the ramifications can be far-reaching
and long lasting--with no readily available ``patch'' to undo
the damage (we cannot simply replace one violated health
record with a brand new one.)
Security is the means used to protect the confidentiality
of personal information through physical, technical, and
administrative safeguards.
Privacy is the ``business objective'' of security. The core
of the relationship between information security and
information privacy lies in the fact that security, or lack
of it, is the determinant of the level of privacy that a
system or infrastructure can assure. If there is a breach of
computer security, it has a corresponding negative effect on
the confidentiality, integrity, and availability of the
information therein. Inadequate security leads directly to
loss of privacy. Therefore, if privacy is the ``business
objective'', then security is the ``functional requirements''
necessary for an IT system to meet those ``business
objectives''.
1.1.3.1 PERSONALLY IDENTIFIABLE INFORMATION (PII)
Personally Identifiable Information (PII) is information
which can be used to distinguish or trace an individual's
identity, such as their name, social security number,
biometric records, etc. alone, or when combined with other
personal or identifying information which is linked or
linkable to a specific individual, such as date and place of
birth, mother's maiden name, etc. PII also includes
individually identifiable health information as defined by
the Health Insurance Portability and Accountability Act
(HIPAA) of 1996, Privacy Rule (45 CFR Section 164.501. PII is
also often referred to as personally identifiable data or
individually identifiable information.
1.1.3.2. Protected Health Information (PHI)
Protected Health Information (PHI) is individually
identifiable health information held or transmitted by a
covered entity or its business associate, in any form or
media, whether electronic, paper, or oral.
Individually Identifiable Health Information is a subset of
health information, including demographic data collected
concerning an individual that:
Is created or received by a healthcare provider, health
plan, employer, or healthcare clearinghouse.
Relates to the past, present or future physical or mental
health or condition of an individual; the provision of
healthcare to an individual; or the past, present, or future
payment for the provision of healthcare to an individual, and
meets either of the following:
Identifies the individual.
There is a reasonable basis to believe the information can
be used to identify the individual.
The HIPAA Privacy Rule excludes from the definition of PHI
individually identifiable health information that is
maintained in education records covered by the Family
Educational Right and Privacy Act (as amended, 20 U.S.C.
1232g) and records described at 20 U.S.C. 1232g(a)(4)(B)(iv),
and employment records containing individually identifiable
health information that are held by a covered entity in its
role as an employer.
The HIPAA Privacy Rule covers PHI in any medium (including
paper) while the HIPAA Security Rule covers PHI in electronic
form (ePHI) only.
1.1.3.3 DE-IDENTIFIED HEALTH INFORMATION
With those definitions in place, what information (or data)
elements comprise PHI such that, if they were removed, the
above definition of individually identifiable health
information would not apply? The answer is in the HIPAA de-
identification use standard and its two implementation
specifications of the HIPAA Privacy Rule.
There are no restrictions on the use or disclosure of de-
identified health information. De-identified health
information neither identifies nor provides a reasonable
basis to identify an individual. There are two specifications
for de-identifying individually identifiable health
information; either: 1) a formal determination by a qualified
statistician; or 2) the removal of specified identifiers of
the individual and of the individual's relatives, household
members, and employers is required, and is adequate only if
the covered entity has no actual knowledge that the remaining
information could be used to identify the individual.
The following identifiers of the individual or of
relatives, employers, or household members of the individual
must be removed to achieve the safe harbor method of de-
identification:
1. Names
2. All geographic subdivisions smaller than a State,
including street address, city, county, precinct, zip code,
and their equivalent geocodes, except for the initial three
digits of a zip code if, according to the current publicly
available data from the Bureau of Census:
a. The geographic units formed by combining all zip codes
with the same three initial digits contains more than 20,000
people.
b. The initial three digits of a zip code for all such
geographic units containing 20,000 or fewer people is changed
to 000.
3. All elements of dates (except year) for dates directly
related to the individual, including birth date, admission
date, discharge date, date of death; and all ages over 89 and
all elements of dates (including year) indicative of such
age, except that such ages and elements may be aggregated
into a single category of age 90 or older.
4. Telephone numbers
5. Fax numbers
6. Electronic mail addresses
7. Social security numbers
8. Medical record numbers
9. Health plan beneficiary numbers
10. Account numbers
11. Certificate/license numbers
12. Vehicle identifiers and serial numbers, including
license plate numbers
13. Device identifiers and serial numbers
14. Web Universal Resource Locators (URLs)
15. Internet Protocol (IP) address numbers
16. Biometric identifiers, including finger and voiceprints
17. Full face photographic images and any comparable
images.
18. Any other unique identifying number, characteristic, or
code, except as permitted for re-identification purposes
provided certain conditions are met
In addition to the removal of the above-stated identifiers,
the covered entity may not have actual knowledge that the
remaining information could be used alone or in combination
with any other information to identify an individual who is
subject of the information.