Skip to content
TECH CEO Daily

Senate passes healthcare cybersecurity bill that would mandate MFA and encryption

S. 3315 passed by unanimous consent on September 30; it would make HHS mandate minimum security controls for providers, health plans and their vendors.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1The Senate passed S. 3315 by unanimous consent on September 30, 2026; the bill now goes to the House.
  • 2HHS would have to require MFA, encryption and penetration testing for covered entities and business associates.
  • 3Those mandates would take effect 36 months after enactment; breach notices would have to state how many were affected.

The news

The U.S. Senate on September 30 passed a bipartisan healthcare cybersecurity bill that would direct federal regulators to require multifactor authentication, encryption and penetration testing across hospitals, health plans and their technology vendors. The measure now goes to the House.

The Health Care Cybersecurity and Resiliency Act of 2026 (S. 3315) passed by unanimous consent, according to Congress.gov. Sen. Bill Cassidy (R-La.) introduced it on December 2, 2025, with Sens. Maggie Hassan (D-N.H.), John Cornyn (R-Texas) and Mark Warner (D-Va.). Sens. Cindy Hyde-Smith (R-Miss.) and Angus King (I-Maine) later joined as cosponsors.

The bill's central mandate is in Section 8. It directs the Department of Health and Human Services (HHS) to update the HIPAA Security Rule, the federal standard for protecting electronic health data, so that covered entities, their business associates and other non-government organizations in the health sector must adopt minimum risk-based cybersecurity practices. Those include multifactor authentication, encryption of protected health information and monitoring that includes penetration testing.

The practices would be based on national frameworks such as those from the National Institute of Standards and Technology (NIST), the Health Sector Coordinating Council's cybersecurity performance goals and health-care-specific goals from the Cybersecurity and Infrastructure Security Agency (CISA). The requirements would take effect 36 months after enactment, and HHS could use enforcement discretion for entities facing extraordinary circumstances.

The Senate-passed text also requires breach notices to individuals to state how many people were affected. It gives HHS a year to write rules on how it will weigh recognized security practices when setting fines or ending audits early, creates a grant program for federally qualified health centers, Indian Health Service facilities, nonprofit hospitals and rural health clinics, and directs HHS and CISA to build a joint plan within a year for responding to major incidents.

Cassidy said cyberattacks on the sector put patients' data at risk and "can delay life-saving care," SecurityWeek reported. The HELP Committee advanced the bill 22-1 on February 26, with Sen. Rand Paul (R-Ky.) casting the only no vote, CyberScoop reported at the time.

The numbers

Senate passage (September 30, 2026)
Unanimous consent
Senate HELP Committee vote (February 26, 2026)
22-1
When the new HIPAA security mandates would take effect
36 months after enactment
Deadline for joint HHS-CISA incident response plan
1 year after enactment
Maximum length of a cybersecurity grant
3 years
Health breaches in the prior year cited by Sen. Cassidy (Feb. 2026)
730+ affecting 270 million+ Americans

Why CEOs should care

For health-tech companies, the key phrase is business associates. Under HIPAA that covers vendors that handle protected health information for providers and health plans, so the mandate would reach many records, billing and cloud suppliers. CEOs and product leaders should check now whether every system supports multifactor authentication, whether patient data is encrypted, and whether penetration tests are run and documented. Large customers may start asking for those controls in contracts well before any deadline.

CFOs and compliance chiefs should watch Section 7. If HHS writes rules on how recognized security practices count toward lower fines, earlier closing of audits or milder remedies, documented controls become worth money. Keep dated evidence of the frameworks you follow, and make sure breach-response playbooks can produce an accurate count of affected people for every notice.

Boards of nonprofit hospitals, rural clinics and federally qualified health centers should track the grant program, which can pay for security hires, cloud migration, risk and vulnerability assessments, and incident response plans for up to three years. The Senate-passed text does not set a dollar amount for the grants, so funding would depend on later decisions by Congress. Directors should also ask whether the organization could meet the authentication, encryption and testing rules now, and what closing any gap would cost.

The bigger picture

Lawmakers cited the 2024 ransomware attack on Change Healthcare as a major driver of the bill, CyberScoop reported in February, when Cassidy said there had been more than 730 cyber breaches affecting over 270 million Americans the previous year. The measure would turn controls drawn from NIST and CISA guidance into legal requirements for much of the health sector.

The bill also tackles a common complaint from industry: overlapping incident reporting rules. Section 12 would have HHS convene a working group with CISA, the Securities and Exchange Commission, the FBI, the Federal Trade Commission, the Office of the National Cyber Director, state attorneys general, state health departments and private health care entities to find ways to cut duplicative reporting.

What’s next

The bill must pass the House before it can go to the president, and as of October 5 Congress.gov listed no House action. If it becomes law, most HHS deadlines would run one year from enactment, a GAO study of rural providers would follow within three years, and the new security mandates would apply after 36 months.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Health Care Cybersecurity and Resiliency ActBill CassidyHHSCISAHIPAA

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.