Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Health Data Security topic

No spam. Unsubscribe anytime.

Sponsor says bill would require health records technology to be maintained in U.S. or Canada after recent cyberattacks

2809454 · March 20, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Legislative director Marla Braun read Representative Jamie Thompson's written testimony on House Bill 4242, which would require medical-record technology to be physically maintained in the U.S. or Canada to limit foreign access. The sponsor cited recent cyberattacks on health systems and urged urgent action to protect patient data.

Marla Riley Braun, legislative director for Representative Jamie Thompson, read Thompson's written testimony before the House Committee on Government Operations on House Bill 4242. Thompson, who was unable to appear in person, described the bill as a step to shield patient health data from foreign adversaries by requiring that medical‑record technology be physically maintained in the United States or Canada.

Thompson’s letter, read into the record by Braun, cited several recent incidents to underscore urgency: a May cyberattack that hit “140 [entities] across 10 states,” forcing return to paper records, and a September attack on the University of Michigan Academic Medical Center that exposed the data of nearly 58,000 patients. Thompson wrote that if patient records fell into the hands of a foreign adversary, “the results could be tragic.”

Her written testimony noted that on the federal level, the Department of Health and Human Services is responsible for reporting breaches; at the state level, Thompson said Michigan’s laws lag behind. The bill would require that relevant medical‑record technology be physically maintained in the United States or Canada; Thompson said she intends to pursue additional legislation as cyberattacks on hospitals, medical centers and pharmacies continue.

Committee members asked no substantive follow‑up questions during the reading of the letter. Thompson’s office offered to provide sources for the breach data (the testimony cited the Department of Health and Human Services’ breach records) and to submit additional written materials to the clerk for the committee record.

Ending

The committee accepted the sponsor’s written testimony and invited any additional documentation the sponsor’s office could provide. No vote on House Bill 4242 was recorded in the transcript.