The news
The U.S. Senate on September 30 passed a bipartisan healthcare cybersecurity bill that would direct federal regulators to require multifactor authentication, encryption and penetration testing across hospitals, health plans and their technology vendors. The measure now goes to the House.
The Health Care Cybersecurity and Resiliency Act of 2026 (S. 3315) passed by unanimous consent, according to Congress.gov. Sen. Bill Cassidy (R-La.) introduced it on December 2, 2025, with Sens. Maggie Hassan (D-N.H.), John Cornyn (R-Texas) and Mark Warner (D-Va.). Sens. Cindy Hyde-Smith (R-Miss.) and Angus King (I-Maine) later joined as cosponsors.
The bill's central mandate is in Section 8. It directs the Department of Health and Human Services (HHS) to update the HIPAA Security Rule, the federal standard for protecting electronic health data, so that covered entities, their business associates and other non-government organizations in the health sector must adopt minimum risk-based cybersecurity practices. Those include multifactor authentication, encryption of protected health information and monitoring that includes penetration testing.
The practices would be based on national frameworks such as those from the National Institute of Standards and Technology (NIST), the Health Sector Coordinating Council's cybersecurity performance goals and health-care-specific goals from the Cybersecurity and Infrastructure Security Agency (CISA). The requirements would take effect 36 months after enactment, and HHS could use enforcement discretion for entities facing extraordinary circumstances.
The Senate-passed text also requires breach notices to individuals to state how many people were affected. It gives HHS a year to write rules on how it will weigh recognized security practices when setting fines or ending audits early, creates a grant program for federally qualified health centers, Indian Health Service facilities, nonprofit hospitals and rural health clinics, and directs HHS and CISA to build a joint plan within a year for responding to major incidents.
Cassidy said cyberattacks on the sector put patients' data at risk and "can delay life-saving care," SecurityWeek reported. The HELP Committee advanced the bill 22-1 on February 26, with Sen. Rand Paul (R-Ky.) casting the only no vote, CyberScoop reported at the time.
The numbers
- Senate passage (September 30, 2026)
- Unanimous consent
- Senate HELP Committee vote (February 26, 2026)
- 22-1
- When the new HIPAA security mandates would take effect
- 36 months after enactment
- Deadline for joint HHS-CISA incident response plan
- 1 year after enactment
- Maximum length of a cybersecurity grant
- 3 years
- Health breaches in the prior year cited by Sen. Cassidy (Feb. 2026)
- 730+ affecting 270 million+ Americans
Why CEOs should care
For health-tech companies, the key phrase is business associates. Under HIPAA that covers vendors that handle protected health information for providers and health plans, so the mandate would reach many records, billing and cloud suppliers. CEOs and product leaders should check now whether every system supports multifactor authentication, whether patient data is encrypted, and whether penetration tests are run and documented. Large customers may start asking for those controls in contracts well before any deadline.
CFOs and compliance chiefs should watch Section 7. If HHS writes rules on how recognized security practices count toward lower fines, earlier closing of audits or milder remedies, documented controls become worth money. Keep dated evidence of the frameworks you follow, and make sure breach-response playbooks can produce an accurate count of affected people for every notice.
Boards of nonprofit hospitals, rural clinics and federally qualified health centers should track the grant program, which can pay for security hires, cloud migration, risk and vulnerability assessments, and incident response plans for up to three years. The Senate-passed text does not set a dollar amount for the grants, so funding would depend on later decisions by Congress. Directors should also ask whether the organization could meet the authentication, encryption and testing rules now, and what closing any gap would cost.
The bigger picture
Lawmakers cited the 2024 ransomware attack on Change Healthcare as a major driver of the bill, CyberScoop reported in February, when Cassidy said there had been more than 730 cyber breaches affecting over 270 million Americans the previous year. The measure would turn controls drawn from NIST and CISA guidance into legal requirements for much of the health sector.
The bill also tackles a common complaint from industry: overlapping incident reporting rules. Section 12 would have HHS convene a working group with CISA, the Securities and Exchange Commission, the FBI, the Federal Trade Commission, the Office of the National Cyber Director, state attorneys general, state health departments and private health care entities to find ways to cut duplicative reporting.
What’s next
The bill must pass the House before it can go to the president, and as of October 5 Congress.gov listed no House action. If it becomes law, most HHS deadlines would run one year from enactment, a GAO study of rural providers would follow within three years, and the new security mandates would apply after 36 months.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error







