Skip to main content
CivicGate

S 5522
Introduced Re-checks Congress.gov for new actions and updates the bill's status, and fills in any sponsors, committees, or related bills that are missing. It does not re-pull sponsors/cosponsors/committees/related — those rarely change — and it skips all work if nothing has changed upstream, so it's cheap to click.

Protecting Biological Data as Critical Infrastructure Act

To amend the Homeland Security Act of 2002 to require the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security to protect genetic and other sensitive biometric data, and for other purposes.

Introduced Sep 24, 2026

Latest action (Sep 24, 2026) Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

Sponsor (1)

1 cosponsor

Actions (2)

  1. Sep 24, 2026 Read twice and referred to the Committee on Homeland Security and Governmental Affairs. · senate
  2. Sep 24, 2026 Introduced in Senate

Text versions (1)

  • Introduced in Senate · Sep 24, 2026

Only one text version is on file, so there’s no earlier version to compare against yet.

Full text

IN THE SENATE OF THE UNITED STATES

September 24, 2026

Mr. Young (for himself and Ms. Hassan) introduced the following bill; which was read twice and referred to the Committee on Homeland Security and Governmental Affairs

A BILL

To amend the Homeland Security Act of 2002 to require the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security to protect genetic and other sensitive biometric data, and for other purposes.

Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled,

SECTION 1. SHORT TITLE.

This Act may be cited as the “Protecting Biological Data as Critical Infrastructure Act”.

SEC. 2. CISA PROTECTION OF GENETIC AND OTHER SENSITIVE BIOMETRIC DATA.

The Homeland Security Act of 2002 is amended—

(1) in section 2202 (6 U.S.C. 652)—

(A) in subsection (c)—

(i) in paragraph (13), by striking “and” after the semicolon;

(ii) by redesignating paragraph (14) as paragraph (17); and

(iii) by inserting after paragraph (13) the following new paragraphs:

“(14) oversee the planning, management, and coordination of duties related to security management of, and responsibilities associated with, genetic data systems that involve genomic sequences and other sensitive biometric data, including by ensuring sufficient staff of the Agency to carry out such duties;

“(15) provide training for relevant Federal personnel regarding protecting genetic data systems that involve genomic sequences and other sensitive biometric data, including addressing unique security challenges and ethical considerations;

“(16) take such actions as may be necessary to ensure the protection of biological data and critical biotechnology infrastructure, including genetic data systems that involve genomic sequences and other sensitive biometric data; and”; and

(B) in subsection (e)(1), by adding at the end the following new subparagraphs:

“(S) To treat as critical infrastructure genetic data systems that involve genomic sequences and other sensitive biometric data.

“(T) To consult with United States biotechnology sector stakeholders to gain input for the development of security protocols relating to the genetic data systems referred to in subparagraph (S), as well as relevant Federal agencies responsible for collecting and protecting such systems, such as the Office of Biometric Identity Management of the Department.

“(U) To collaborate with the United States biotechnology sector stakeholders referred to in subparagraph (T), as well as any additional United States stakeholders engaged in biosecurity policy development and enforcement, including by carrying out the following:

“(i) Facilitating engagements between the Agency and such biotechnology stakeholders and additional stakeholders to coordinate and synchronize regarding emerging security concerns, such as the digital-physical boundary between genetic sequence data and physical samples.

“(ii) Providing a secure line of communication to the Agency for such biotechnology stakeholders and additional stakeholders to raise concerns, report incidents, and request technical assistance.”; and

(2) in section 2211(b)(2) (6 U.S.C. 661(b)(2)), by adding at the end the following new subparagraph:

“(E) Genetic and biometric data security.”. <all>

Comments

Comments

Loading comments…