Showing posts with label S 4697. Show all posts
Showing posts with label S 4697. Show all posts

Saturday, June 20, 2026

S 4697 – HALO Act and Cybersecurity

Earlier this month, I mentioned-in-passing the introduction of S 4697, a bill to provide for design and safety requirements for autonomous and semi-autonomous weapon systems. I do not normally spend much time following weapons development legislation, but I did read the text of this bill after it was published yesterday. And I am glad that I did, because it contains cybersecurity provisions that deserve a brief discussion here. 

Paragraph 3(d)(2) requires that an autonomous weapon system or semi-autonomous weapon system is designed with system safety, anti-tamper mechanisms, and cybersecurity in accordance with Department instructions and military standards governing cybersecurity and system safety. Those standards are not described further in this bill, nor are they further referenced by statute or regulation. While making it difficult to evaluate what standards are required, it does provide DOD with a certain amount of leeway to select the most appropriate cybersecurity standards for such weapons. 

Later, in subsection 6(e) the legislation addresses the need to periodically test these autonomous and semi-autonomous weapons. It requires DOD to conduct quarterly cyber tests and evaluations to verify that the system is resilient and survivable in contested cyberspace. It is not clear whether that quarterly testing would be done on each deployed weapon system, a statistically significant number of randomly selected systems, or a lab maintained representative system. The first option would be the most expensive and would present additional problems when dealing with currently deployed weapon systems. The second option would conform to standards for quality assurance testing, but that kind of testing is not applicable for systems that are at potential of cyber-attack. The last would be pro forma testing to ensure that there are no design issues that allow system degradation over time. 

The final item of interest here is found in subsection 10(a). That subsection notes that the requirements of this legislation do not apply to autonomous or semi-autonomous cyberspace capabilities. The term ‘cyberspace capabilities’ is not one of the terms defined in §2, but I would expect that they are referring to cyberattacks on computer systems (IT and OT) rather than kinetic attacks that could physically damage structures, equipment or personnel. Interestingly, the definitions of ‘autonomous weapon system’ and ‘semi-autonomous weapon system’ do not differentiate between kinetic and virtual attacks. This really needs additional clarification, especially where such cyberspace capability attacks result in kinetic effects because of loss of control in operational systems. 

Thursday, October 3, 2024

Review - HR 9412 Introduced – Healthcare Cybersecurity

Back in August, Rep Crow (D,CO) introduced HR 9412, the Healthcare Cybersecurity Act of 2024. The bill establishes requirements for: CISA-HHS coordination, CISA healthcare cybersecurity training, HHS developed sector security plans, and requires HHS to develop criteria for identifying high-risk covered assets. The bill would specifically prohibit additional funding to support these efforts.

This bill is very similar to S 4697 [removed from paywall] which was introduced in July by Sen Rosen (D,NV). That bill was considered by the Senate on July 31st, 2024. The bill was amended and recommended reported favorably by a vote of 10 to 1 {Sen Paul (R,KY) was the dissenting vote}. That report (and the amended version) has not yet been published. Paul’s opposition almost assures that the S 4697 will not be considered by the full Senate.

Moving Forward

Neither Crow, nor his three cosponsors, are members of the House Homeland Security Committee to which this bill was assigned for primary consideration. This means that there will probably not be sufficient influence to see the bill considered in Committee. With the funding exclusion added to the bill, I see nothing that would engender any organized opposition. I suspect that there would be some level of bipartisan support for the bill were it to be considered. Whether it would be sufficient to see the bill considered under the suspension of the rules process before the Full House remains to be seen.

 

For more information on this bill and its differences from S 4697, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-9412-introduced - subscription required.

Wednesday, July 31, 2024

HSGA Takes Action on 3 Bills of Interest –

Today, the Senate’s Homeland Security and Governmental Affairs Committee held the continuation of last week’s Business Meeting. While not all of the bills listed on the agenda were addressed today, the three bills that I identified as being of potential interest here were amended and recommended reported favorably by a vote of 10 to 1 in all three instances. There were four additional yeah votes cast by proxy, but those are only reported, not counted in the official vote tally. The three bills were:

S 4630, Streamlining Federal Cybersecurity Regulations Act,

S 4697, Healthcare Cybersecurity Act of 2024, and

S 4715, Federal Cyber Workforce Training Act of 2024

The Committee does not typically publish substitute language, or other amendments. We will have to wait for the publication of the Committee’s reports on the bills to see what changes have been made.

In all three cases, the Committee adopted substitute language from the original author. For S 4630 and S 4697, that language was further modified by unanimous consent. The one Nay vote for each of the bills came from Sen Paul (R,KY). Paul’s opposition practically means that there is little chance of the bill being considered under the Senate’ unanimous consent process, as he is quick to use his objection to thwart the consideration of bills that he opposes. Since Paul is the Ranking Member, he has effective veto of these bills being considered as amendments to bills being considered on the floor of the Senate.


Monday, July 29, 2024

HSGA Committee Announces Continuation of Markup Hearing – 7-31-24

Today, the Senate Homeland Security and Governmental Affairs Committee announced that it had rescheduled last week’s business meeting for Wednesday. Last week’s meeting only ended up covering one bill (S 1171, the ETHICS Act) out of the 33 scheduled. There are three bills of interest here that are on the list of bills to be considered:

S 4630, Streamlining Federal Cybersecurity Regulations Act,

S 4697, Healthcare Cybersecurity Act of 2024, and

S 4715, Federal Cyber Workforce Training Act of 2024.

Review - S 4697 Introduced – Healthcare Cybersecurity

Earlier this month, Sen Rosen (D,NV) introduced S 4697, the Healthcare Cybersecurity Act of 2024. The bill establishes requirements for: CISA-HHS coordination, CISA healthcare cybersecurity training, CISA developed sector security plans, and developing criteria for identifying high-risk covered assets. No new funding is authorized by this legislation.

Moving Forward

Rosen and one of her cosponsors {Sen Ossoff (D,GA)} are members of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. This means that there could be sufficient influence to see the bill considered in Committee. I suspect that there would be some level of bipartisan support for this bill, but the Ranking Member {Sen Paul (R,KY)} would be expected to oppose the bill. This would complicate passage in Committee.

Commentary

There is no discussion, or even mention, of the role cybersecurity vulnerabilities in medical software and devices have in the abetting the malicious cyberattacks discussed in the §3 findings. This bill would be the ideal place to formalize which agency (FDA or CISA) would be responsible for receiving, coordinating and publishing reports about vulnerabilities in medical software and devices. The FDA has the benefit of being the regulatory agency responsible for oversight of the safety and efficacy of such systems, thus lending gravitas to their potential coordination efforts. Meanwhile, CISA has the technical expertise and experience (and the current de facto responsibility) to manage this effort. I would suggest inserting a new §4(c) into the bill:

“(c) The Agency will assist the Department with establishing within the Food and Drug Administration an office to receive, coordinate, and make public information related to security vulnerabilities (as defined in 6 U.S.C. 650) in medical software and devices.”

 

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-4697-introduced - subscription required.

Monday, July 22, 2024

Review - Congressional Hearings – Week of 7-21-24

This week, with both the House and Senate back in Washington (and looking forward to their August Recess). In addition to some high-profile hearings (not covered here) on the attempted Trump assassination, there is a full slate of hearings in both bodies. Spending bills are being teed up in the House with a Rules Committee hearing. There are two transportation related hearings in the House. There is one cybersecurity regulatory panel scheduled.

Spending Bills

The House Rules Committee will meet today to formulate the rule for the consideration of four spending bills (FinServices, IER, EWR, and ARD).

The Senate Appropriations Committee will hold a hearing on Thursday to mark up four spending bill; CJS, IER, State, and Thud.

Transportation Hearings

On Tuesday, the Subcommittee on Railroads, Pipelines, and Hazardous Materials of the House Transportation and Infrastructure Committee will hold a hearing on “Examining the State of Rail Safety in the Aftermath of the Derailment in East Palestine, Ohio”.

On Wednesday, the Subcommittee on Highways and Transit of the House Transportation and Infrastructure Committee will hold a hearing on “Examining the Department of Transportation’s Regulatory and Administrative Agenda”.

will not be a DOT spokesperson on the panel.

Cybersecurity

On Thursday, the Subcommittee on Cybersecurity, Information Technology, and Government Innovation of the House Oversight and Accountability Committee will hold a hearing on “Enhancing Cybersecurity by Eliminating Inconsistent Regulations”.

Markup Hearings

On Wednesday, the Senate Homeland Security and Governmental Affairs Committee will hold a business meeting. The bills of interest here include:

S 4630, Streamlining Federal Cybersecurity Regulations Act,

S 4697, Healthcare Cybersecurity Act of 2024, and

S 4715, Federal Cyber Workforce Training Act of 2024

On the Floor

In addition to the two spending bills described above, The House will be taking up 20 bills under the suspension of the rules process, including the following bill of interest here: HR 8812, Water Resources Development Act. That will be considered today, though a final vote (if needed) may not happen until later this week.

 

For more details about these hearings, including witness lists, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/congressional-hearings-week-of-7 - subscription required.

Friday, July 12, 2024

Bills Introduced – 7-11-24

With both the House and Senate in Washington (and the House leaving for a district week), there were 106 bills introduced yesterday. Ten of those bills may receive additional coverage in this blog:

HR 8996 To enhance safety requirements for trains transporting hazardous materials, and for other purposes. Nehls, Troy E. [Rep.-R-TX-22]

HR 8997 Making appropriations for energy and water development and related agencies for the fiscal year ending September 30, 2025, and for other purposes. Fleischmann, Charles J. "Chuck" [Rep.-R-TN-3]

HR 8998 Making appropriations for the Department of the Interior, environment, and related agencies for the fiscal year ending September 30, 2025, and for other purposes. Simpson, Michael K. [Rep.-R-ID-2]

HR 9026 Commerce, Justice, Science, and Related Agencies Appropriations Act, 2025 Rogers, Harold [Rep.-R-KY-5]

S 4677 An original bill making appropriations for military construction, the Department of Veterans Affairs, and related agencies for the fiscal year ending September 30, 2025, and for other purposes. Sinema, Kyrsten [Sen.-I-AZ]

S 4678 An original bill making appropriations for the Legislative Branch for the fiscal year ending September 30, 2025, and for other purposes. Reed, Jack [Sen.-D-RI] 

S 4690 An original bill making appropriations for Agriculture, Rural Development, Food and Drug Administration, and Related Agencies for the fiscal year ending September 30, 2025, and for other purposes. Heinrich, Martin [Sen.-D-NM]

S 4697 A bill to enhance the cybersecurity of the Healthcare and Public Health Sector. Rosen, Jacky [Sen.-D-NV]

S 4715 A bill to require the National Cyber Director to submit to Congress a plan to establish an institute within the Federal Government to serve as a centralized resource and training center for Federal cyber workforce development. Rounds, Mike [Sen.-R-SD]

S 4719 A bill to provide the Secretary of Energy with the authority to enter into contracts and cooperative agreements to improve the security and resilience of defense critical electric infrastructure and reduce the vulnerability of critical defense facilities to the disruption of the supply of energy to those facilities, and for other purposes. Cortez Masto, Catherine [Sen.-D-NV]

I will be covering the six spending bills (HR 8997, HR 8998, HR 9026, S 4677, S 4678, and S 4690).

I will be covering HR 8996, S 4715, and S 4719.

I will be watching S 4697 for language and definitions that would specifically include medical devices and other operational technologies used in the healthcare sector. 

 
/* Use this with templates/template-twocol.html */