| 1 | Representative(s) Garcia offered the following: |
| 2 |
|
| 3 | Amendment (with title amendment) |
| 4 | Between lines 792 and 793, insert: |
| 5 | Section 17. For the purpose of protecting and ensuring the |
| 6 | safety and security of the data held by the Agency for Health |
| 7 | Care Administration, as described in s. 408.061, Florida |
| 8 | Statutes, the agency shall be responsible for ensuring that data |
| 9 | and data backup systems are housed at a secure facility that |
| 10 | meets or exceeds the following requirements: |
| 11 | (a) The facility must be located in the state; |
| 12 | (b) The facility must be designated as a critical facility |
| 13 | by the county emergency management agency, under s. 252.38, |
| 14 | Florida Statutes, in the county where the facility is located; |
| 15 | (c) The facility must be designed to withstand a category |
| 16 | 5 hurricane and be outside the 500-year flood zone established |
| 17 | by the Federal Emergency Management Agency; |
| 18 | (d) The facility must have six or more tier?one |
| 19 | telecommunication carriers deployed at the facility; |
| 20 | (e) The facility must have commercial power supplied by at |
| 21 | least two separate substation feeders and must be able to |
| 22 | operate continuously for at least 5 days on its own power |
| 23 | generation systems without refueling should such commercial |
| 24 | power be interrupted; and |
| 25 | (f) The facility has successfully undergone a Statement on |
| 26 | Auditing Standards (SAS) No. 70 review, representing that the |
| 27 | facility has been through an in-depth review of the security and |
| 28 | information technology control process relating to its |
| 29 | operation. |
| 30 |
|
| 31 | ======= T I T L E A M E N D M E N T ======= |
| 32 | Between lines 39 and 40, insert: |
| 33 | providing responsibility of the Agency for Health Care |
| 34 | Administration for security of certain data and backup systems; |
| 35 | providing requirements for a secure storage facility; |