Fauci Testimony — Senate HELP Committee (20 Jul 2021, CHRG-117shrg46775) (Part 3 of 3)

Fauci Files — DNI Gabbard Release + Rand Paul Diaries (2026)

Covid 19 Origins

Congressional Testimony

100

3

2021-07-20

Document text

China? 
Answer 2. ASPR is leveraging the authorities delegated to the Secretary under 
the Defense Production Act (DPA) to ensure that private sector partners making life-saving products are able to acquire raw materials, retool their machinery, scale their production facilities, train their workforces, and ultimately deliver their prod-uct. Throughout the COVID–19 response, ASPR has used the DPA authority to issue 46 priority ratings for U.S. Government (USG) contracts for health resources, 8 priority ratings for USG contracts for industrial expansion, and 3 priority ratings of specific purchase orders for companies manufacturing critical lifesaving health re-sources that have been impacted by COVID–19 response demands. ASPR is also continuing to build capacity and partnerships with private industry toward the shared goal of ending the COVID–19 pandemic. ASPR is also working to support efforts in expanding the domestic industrial base. These industrial base expansion (IBx) efforts seek to reduce supply chain vulnerabilities and generate a domestic ‘‘warm-base’’ for manufacturing that can be leveraged in a crisis. 
Supporting domestic vaccine development and manufacturing efforts, BARDA has 
invested $1.256B in the advanced research and development of Moderna’s mRNA– 1273 vaccine candidate, supporting clinical trials and manufacturing scale up and validation. The investments in a mRNA vaccine will support new vaccine production platforms in the future that will improve the efficiency and reduce the timeline to develop vaccines for other biodefense threats and emerging infectious diseases. Plat-form technologies, such as the mRNA approach, can provide flexible and rapid re-sponse and have many advantages with potential to revolutionize the way vaccines and therapeutics are produced for known and newly emerging threats. 
Question 3 . Will the Administration commit to using some of this funding for the 
raw materials, including medical-grade meltblown, needed to produce N95 and N99 masks so that we are not dependent on countries like China for this material? 
Answer 3. ASPR has invested over $20.5 million in several companies to increase 
and sustain melt-blown fiber production in the U.S., producing enough raw material to manufacture the equivalent of approximately 171 million N95 or 400 million sur-gical masks a month. In addition, utilizing the $10 billion received via the American Rescue Plan Act to support industrial base expansion, ASPR has been working to establish and maintain domestic capacities for N95 manufacturing. 
93 
SENATOR BURR  
Question 1 . As we saw during the early stages of the COVID–19 response, quickly 
identifying and containing the spread of a new pathogen is a significant challenge. In preparing for the next public health threat, how is HHS taking into account addi-tional capacity for testing in health care facilities as a result of health systems’ in-vestments in high throughput instruments during the COVID–19 response? 
Answer 1. HHS monitors the testing supply chain through collaboration with di-
agnostic manufacturers. Ten of the major manufacturers send shipment data, install base data, and supply projections on a regular basis. HHS integrates this data into HHS Protect, a platform that overlays epidemiological data, hospital clinical data, COVID–19 testing data, and other public health metrics. Of the three main data reports, the install base data gives HHS visibility into the locations and quantity and utilization of all the high-throughput machines for a specific company. This in-formation allows HHS to monitor how additional capacity for testing has increased since the beginning of the pandemic. 
Question 2 . T-cell testing adds a critical dimension to how we measure immune 
response. How can these tests be used to inform both individual clinical decisions and a population-based, public health response, and what steps is HHS taking to include T-cell testing in planning for future public health threats? 
Answer 2. T cells are an important component of the immune response to viruses, 
including SARS-CoV–2, the virus that causes COVID–19. Existing T cell testing technologies available for widespread use can be used to aid in identifying individ-uals with an adaptive T cell immune response to a virus, indicating recent or prior infection. For example, the T-Detect COVID Test, which was developed by Adaptive Biotechnologies and received an emergency use authorization (EUA) from the FDA, can help determine if a person previously had COVID–19. This test may be useful for people who have exhibited symptoms previously but have not tested positive for COVID–19 using a molecular or antigen diagnostic test. At this time, the test has only been authorized to detect prior infection by SARS-CoV–2, and cannot be used to indicate the degree of protection induced by COVID–19 vaccination or infection. 
It is important to note that antibody or serum-based commercial assays are read-
ily available to the public and are easier and less expensive to perform than T cell assays. Antibody or serum-based tests also are generally sufficient to indicate cur-rent or previous infection/vaccination. Techniques to examine T cells are labor inten-sive, relatively expensive, and require specialized equipment and sample collection. Laboratories that perform the T-Detect test for commercial purposes also must be specifically designated by the company and have obtained specialized certification. For these reasons, monitoring of T cell responses to COVID–19—or other infectious disease threats—is only possible on a small scale at this time. Nonetheless, scientific studies of T cells can provide important insights into COVID–19 progression, protec-tion against SARS-CoV–2 variants, and durability of immunity. HHS, through the National Institute of Allergy and Infectious Diseases (NIAID), is supporting re-search to improve understanding of the role of T cells in protecting against COVID– 19 as well as in COVID–19 progression. These efforts may lead to improved T cell tests and help support the public health response to COVID–19. 
NIAID also conducts and supports basic and clinical immune research, including 
on T cell responses, to improve understanding of SARS-CoV–2. NIAID supported a collaborative longitudinal study by researchers at Emory University and the Fred Hutchinson Cancer Research Center that demonstrated that T cells were detectable for up to 8 months in patients after mild to moderate COVID–19. NIAID also sup-ported two separate studies—one led by researchers from NIAID and Johns Hopkins Hospital and another by scientists from the La Jolla Institute—that examined the T cell responses in recovered COVID–19 patients and individuals vaccinated against COVID–19 and found robust immune responses to the original strain—as well as multiple variants—of SARS-CoV–2 in both groups. In another NIH-supported study, researchers uncovered features of T cells that distinguish fatal from non-fatal cases of severe COVID–19, which could lead to new treatments for this disease. 
NIAID also is funding a number of basic research studies that will inform how 
T-cell based approaches could be incorporated into future countermeasures. This in-cludes assays that measure the magnitude of T cell responses in individuals who receive the currently authorized COVID–19 vaccines. Understanding how T cells re-spond to SARS-CoV–2 infection and vaccination may help improve protection af-forded by future vaccines. Additional monitoring of T cell responses to SARS-CoV– 2 may also improve our understanding of the extent and longevity of immunological protection against SARS-CoV–2. 
94 
Question 3 . Health systems have experienced a spike in cyber-attacks during the 
pandemic. For example, Universal Health Services, Inc. experienced a cybersecurity attack in September 2020, which forced hospital systems offline for weeks. Pursuant to the 2020 National Defense Authorization Act Section 9002, the ASPR was des-ignated as the sector risk management agency for the health care and public health sector. 
Question 3(a) . What work does ASPR perform as the sector risk management 
agency? Of this work, what proportion is specific to cybersecurity? 
Answer 3 & 3(a). This past year has been full of challenges, and HHS has found 
ourselves responding to increased quantities and new types of cyber-attacks against the Healthcare and Public Health Sector. In ASPR, the Division of Critical Infra-structure Protection (CIP) serves as the hub for HHS as the sector-specific agency. Based on authorities included in the 2021 National Defense Authorization Act (NDAA), CIP is now the focal point for HHS as the sector risk management agency. The goal of sector risk management agencies is to look at the entire sector—in this case, health care and public health—for all hazards. CIP works closely with govern-ment and private sector partners through the structure of the Critical Infrastruc-ture Partnership Advisory Council to identify and address risks across the sector— working with hospitals, pharmacies, manufacturers, distributors, health IT pro-viders, insurance plans, and mass fatality managers. Over the past 5 years, CIP has been focused on four main areas of risks management: 
1. Identifying risks at facilities across the sector in an objective data driven 
manner through our Risk Identification and Site Criticality Tool (RISC), currently in development of an enhanced, web-based version. The RISC tool identifies cyber risks alongside natural hazard and other manmade risks, unlike many other tools used in the sector, thus promoting conversation be-tween IT security staff and emergency managers. The tool was released 2 years ago and has been downloaded in all 50 states and utilized by at least 1,400 individuals. 
2. Monitoring supply chain challenges in the health sector, including de-
pendence on foreign sourcing and challenges of just-in-time-distribution; 
3. Overall mitigation of risks before, during, and after disasters—with a 
focus on planning for and communicating during responses, including Hur-ricane Maria and the WannaCry and Petya/notPetya cyber incidents of 2017, wildfires, hurricanes, and the COVID–19 pandemic; and 
4. Coordinating with the White House, DHS, and the FBI to enhance HHS’ 
ability to identify and share cyber hygiene best practices; promote sharing of cyber incident information; engage in discussion and coordination with the private sector on priority education, policy, and communications activi-ties; and exercise existing and new cyber plans among government and pri-vate sector partners. 
As cybersecurity is such a threat to the Healthcare and Public Health Sector, CIP 
makes sure to incorporate that risk into a majority of projects to both raise aware-ness and encourage all those involved in the partnership to recognize their potential role in preventing or responding to cyber incidents. 
Question 3(b) . How has ASPR been executing its cybersecurity responsibilities as 
part of this role and/or how does ASPR plan to execute these responsibilities? If the latter, what is ASPR’s timeline for putting into place this plan? 
Answer 3(b). ASPR led the development of a ‘‘strategy for public health prepared-
ness and response to address cybersecurity threats’’ that was required by section 703(a)(1) of the Pandemic and All-Hazards Preparedness and Advancing Innovation Act of 2019. This strategy was delivered to the HELP Committee on August 2, 2021 by Secretary Becerra. This strategy identifies duties, functions, preparedness and response goals for which HHS is responsible for the Healthcare and Public Health (HPH) Sector. It also includes strategies to address identified gaps and strengthen public health emergency preparedness and response capabilities. 
ASPR will direct and monitor implementation of this strategy through the CIP Di-
vision, relying on expertise and activity from many HHS Operating and Staff Divi-sions, including the FDA for medical devices, OCR for privacy and security, ONC for health IT, and OCIO for the HC3 and 405d programs. ASPR also manages the Critical Infrastructure Partnership Advisory Council Joint Cybersecurity Working Group, with hundreds of members. The group bases its work on the recommenda-tions of the 2018 Healthcare Industry Cybersecurity Task Force and is currently de-veloping CY2022 joint priorities. 
95 
ASPR CIP has led the development of the HPH sector Incident Response plan, 
which will be appended as an annex to the all hazard plan. The plan describes the full spectrum of the USG response to HPH cyber incidents, including coordination of tactical activities among HHS, FBI and CISA; development of an assessment of the effect of cyber incidents on delivery of care, on supply chains, and on system integrity; engagement of ESF–8 as necessary; and development of post-incident re-porting and of after-action plans. 
Question 3(c) . How many FTEs and resources are dedicated to cybersecurity at 
ASPR? 
Answer 3(c). For the management of the Sector Risk management Agencies 
(SRMA) role for external HPH Sector Cybersecurity (which excludes internal HHS/ ASPR IT security), ASPR has one dedicated staff member supporting cybersecurity preparedness across the health care and public health (HPH) sector, partial time of a second staffer and two contractor positions currently waiting to be filled. In addi-tion, ASPR staff greatly leverage external resources of HHS, DHS, and the private sector to ensure comprehensive risk management for the HPH Sector. Specific ac-tivities include: 
•Co-chairing the Joint Cybersecurity Working Group comprised of 15 sub-
ject-specific Task Groups and over 300 organizations represented; 
•Leading efforts of Federal, state, local, tribal and territorial entities to de-
velop and disseminate Sector-wide recommendations and guidance to pre-
pare and better secure the sector from Cyber threats, to identify risks from cyber threats, lead response efforts to HPH-wide cyber events, and promote mitigation and resiliency strategies; 
•Collaborating with private sector and Federal, state, local, territorial, and 
tribal partners to establish and lead work groups to address rec-ommendations made by the Healthcare Industry Cybersecurity Task Force Report for improving healthcare cybersecurity, released in June 2017; 
•Leading collaborative interagency and other HPH sector efforts to iden-
tify emerging cyber risks in HPH, including risks associated with emerg-ing technologies such as artificial intelligence and machine learning- based tools, as well as risks associated with new care delivery models such as telehealth; 
•Leading tracking and assessment efforts during the Federal response to 
Cyber Incidents; 
•Developing and implementing mitigation strategies as well as incident 
and after action reports to inform and advise on future response oper-ations; and, 
•Creating a bi-weekly bulletin on cybersecurity topics that reaches ap-
proximately 3,000 subscribers. Topics discussed in the bulletin include in-formation pertinent to understanding and mitigating cybersecurity risks across all critical infrastructure sectors, identification and analysis of trends in cyberattacks and vulnerabilities, best practices for general cyberhygiene, and specific recommendations for addressing significant cyber threats. 
Question 3(d) . How does ASPR coordinate with the Cybersecurity and Infrastruc-
ture Security Agency and the Federal Bureau of Investigations? 
Response: One of the ways ASPR collaborates with CISA is by promoting their 
tools and resources and sharing info that could help our sector partners. ASPR serves as a conduit between the Healthcare and Public Health (HPH) Sector and CISA. Confronting cybersecurity threats requires contributions from across the Fed-eral Government, including CISA, the FBI’s National Cyber Investigative Joint Task Force, and other stakeholders. ASPR participates in weekly calls with CISA col-leagues and our health sector partners. ASPR also works closely with CISA through the Federal Senior Leadership Council Roles and Responsibilities work, through which we have negotiated mechanisms of sharing information between SRMAs, CISA, and the FBI. 
Question 3(e) . Please describe ASPR’s coordination with the health care and public 
health sector specifically related to cybersecurity. 
Answer 3(e). As described above, ASPR holds weekly calls with sector partners 
to discuss cybersecurity threats. During these calls, ASPR is able to provide both the specialized knowledge regarding cybersecurity as well as sector-specific knowl-edge to assist partners in preventing and responding to incidents like a ransomware 
96 
attack. ASPR is also able to create private sector partnerships that have a Federal 
Advisory Committee Act (FACA) exemption so that we can meet with the same pri-vate sector partners and request consensus advice and recommendations from them in a closed setting. Last, ASPR holds joint sector working groups with private sector and government sector partners to identify topics to work on, analyze best practices, and develop products to release to the private sector. 
SENATOR BRAUN  
Question 1 . Can you please provide specific updates on your plans to ensure that 
nursing home staff and residents have sufficient point of care molecular diagnostics and access to the most appropriate prophylactics and treatments? 
Answer 1. You should be aware that HHS has and continues to distribute approxi-
mately 3 million point of care tests to long term care facilities on a weekly basis. In addition, HHS monitors the testing supply chain through collaboration with diag-nostic manufacturers. Ten of the major manufacturers send shipment data, install base data, and supply projections on a regular basis. HHS integrates this data into HHS Protect, a platform that overlays epidemiological data, hospital data, testing data, and other public health metrics. Of the three main data reports, the install base data gives HHS visibility into the locations and quantity of all the high- throughput machines for a specific company. This information allows HHS to mon-itor how additional capacity for testing has increased since the beginning of the pan-demic. 
SENATOR TUBERVILLE  
Question 1 . Funds in part from NIH/NIAID helped build the 12 Regional Bio-
containment Laboratories (RBLs) and 2 National Biocontainment Laboratories (NBL) to support high consequence infectious disease research after 9/11 and the anthrax scares in 2001. However, unlike the NBL facilities, the RBL facilities re-ceived no further direct support until last year when Congress provided enhanced investment through NIH/NIAID, targeted specifically to RBL facilities, one of which is at the University of Alabama at Birmingham (UAB) in my state. Nevertheless, it seems as though the RBL infrastructure, most importantly the highly trained staff these facilities maintain and produce is something that falls within the pur-view of the HHS ASPR, considering among other things the UAB RBL has had col-laborations with Altimmune and ImmunityBio for COVID19 vaccine development, and supported BARDA contractors. This type of work strongly aligns with numerous ASPR Strategic Goals, such as Fostering Strong Leadership, and Sustaining Robust and Reliable Public Health Security Capabilities. The RBL infrastructure and per-sonnel is expensive to maintain and operate, and perhaps should not solely rest on either the shoulders of the host University or the NIH/NIAID. 
Question 1(a) . Therefore, is support from Assistant Secretary for Preparedness 
and Response (ASPR) something under consideration? 
Answer 1(a). NIAID provided funding in 2003 and 2005 for the construction of Na-
tional Biocontainment Laboratories (NBLs) and Regional Biocontainment Labora-tories (RBLs). The NBLs and RBLs are designed to complement and support the re-search activities of NIAID-funded biodefense and emerging infectious diseases re-search as well as assist national, state, and local public health efforts. The NBLs and RBLs achieve this mission by providing safe and secure state-of-the-art BSL– 3/4 laboratory space to the scientific community to advance research on biodefense pathogens and emerging infectious diseases. NIAID’s mission to support the devel-opment of medical products to counter bioterrorism and emerging and reemerging infectious diseases is part of a larger national strategy that involves many agencies. 
The majority of Federal oversight of U.S. BSL3/4 labs is done on those conducting 
select agent research, and falls under the purview of CDC and USDA through the Select Agent Program. Additional certification and oversight responsibilities for BSL3/4 labs is handled at the level of the institution. As such, NIH and ASPR over-sight is generally limited to oversight of funded research. 
Question 1(b) . If not, why not, and if so what is needed to facilitate that conversa-
tion? 
Answer 1(b). See response to 1(a). 
[Whereupon, at 12:24 p.m., the hearing was adjourned.] 
Æ