(a) A medical facility or research facility shall not store genetic sequencing data within a foreign adversary. The medical facility or research facility shall not allow remote access to genetic sequencing data storage within its direction or control, other than open data, to a foreign adversary, unless approved in writing by the commissioner of health.
(b) Medical facilities, research institutions, and other companies and entities storing genetic sequencing data, including through contracts with third-party data storage companies, must ensure the security of genetic sequencing data using reasonable encryption methods, restrictions on access, and other cybersecurity best practices.