House Subcommittee on Health Examines Healthcare Cybersecurity Proposals
On September 15, 2026, the United States House Energy and Commerce Committee Subcommittee on Health held a legislative hearing on proposals to improve healthcare cybersecurity, reform Medicare provider payments, and other healthcare matters. At the hearing, titled Examining Legislative Proposals to Reform Medicare Provider Payment and Bolster Health Care Cybersecurity, the subcommittee discussed two bills that seek to improve healthcare cybersecurity – the Rural Hospital Cybersecurity Enhancement Act and the Healthcare Cybersecurity and Resiliency Act of 2026.
Healthcare data breaches have increased significantly in recent years. For the past five years, more than 700 data breaches affecting 500 or more individuals have been reported to the HHS’ Office for Civil Rights (OCR), and a new record was set in 2025, with 804 large data breaches currently listed on the OCR data breach portal. As of August 30, 2026, 496 large data breaches have been reported to OCR, indicating that 2026 will be another 700+ data breach year. So far this year, more than 74.6 million individuals have had their protected health information exposed. Last year, 140.5 million individuals were affected by large healthcare data breaches.
The increase in data breaches is largely driven by hacking and other IT incidents. Out of this year’s 496 large data breaches, 426 breaches are due to hacking and other IT incidents. That’s 86% of this year’s total, and accounts for 97.8% of the individuals whose protected health information has been breached this year. Healthcare organizations are required to comply with the HIPAA Rules, but with data breaches occurring at the current rate, it suggests either widespread noncompliance or ineffective regulations.
Healthcare breaches not only violate Americans’ privacy and put them at risk of identity theft and fraud; hacking incidents, especially ransomware attacks, cause massive operational disruption that affects the ability of healthcare providers to provide care. All too often, cyberattacks result in cancelled appointments, rescheduled surgeries, and delays to emergency care, which affect patient outcomes.
An update to the HIPAA Security Rule has been proposed that includes a raft of new security requirements to improve healthcare cybersecurity; however, the proposed rule was heavily criticized by industry groups, health systems, and hospitals. The final rule has been delayed until at least July 2027, although a decision has yet to be made about whether a final rule will be issued. Even if it is, the requirements will not need to be implemented until at least early 2028.
Implementing more robust cybersecurity measures comes at a cost, and that is especially problematic for rural healthcare providers, many of whom are already facing significant financial challenges without having to commit additional funds to improving cybersecurity. Each dollar spent on cybersecurity improvements is a dollar lost to patient care. The relative lack of cybersecurity resources and personnel makes rural and other resource-constrained healthcare providers soft targets for hackers, and cyberattacks that disrupt patient care can result in dangerous delays to healthcare services, as alternative facilities may be hundreds of miles away.
The Rural Hospital Cybersecurity Enhancement Act, a bipartisan bill co-sponsored by Representatives Erin Houchin (R-IN) and Rep. Kim Schrier (D-WA), was introduced to better protect rural healthcare providers against cyber threats by improving the cybersecurity workforce and improving resources. That includes mandates for the HHS to provide free instructional materials to help rural healthcare providers train existing staff, targeted educational criteria aimed at improving cybersecurity training in rural educational institutions, and a workforce development strategy to expand the rural healthcare IT workforce.
The other key healthcare cybersecurity bill under consideration is the bipartisan Health Care Cybersecurity and Resiliency Act of 2026, which was introduced by Senate Health, Education, Labor & Pensions (HELP) Committee Chair, Sen. Bill Cassidy (R-LA), and co-sponsored by Sens. Mark Warner (D-VA), Maggie Hassan (D-NH), and John Cornyn (R-TX). The aim of the bill is to better protect patient health data, improve coordination between the HHS and the Cybersecurity and Infrastructure Security Agency (CISA), and strengthen overall cybersecurity defenses within the healthcare and public health sector.
At the hearing, the subcommittee heard testimony from Greg Garcia, Executive Director for Cybersecurity at the Healthcare and Public Health Sector Coordinating Council (HSCC) Cybersecurity Working Group, on the state of healthcare cybersecurity and the pending two healthcare cybersecurity bills. Garcia warned that the nation’s rural and resource-constrained healthcare providers are the most vulnerable in the sector and are unprepared to protect against evolving cyber threats and technological innovation, including beneficial and adversarial uses. He called for “a concerted, multi-pronged combination of government programs, assistance and funding with market-based mutual support and community defense.”
Garcia made several recommendations, including workforce training on cybersecurity, especially at rural and low-resourced healthcare providers where it is desperately needed. Garcia said it is essential that grants are made available to allow rural and resource-constrained healthcare providers to make the necessary upgrades to cybersecurity, such as replacing end-of-life medical devices that lack the capacity to be made secure. Garcia also recommended that the HHS official appointed as responsible for coordinating cybersecurity internally and across the sector should be designated at the deputy assistant secretary level or higher, and for that individual to have the authority to influence policy and program decisions.
He advised against implementing regulations that require specific security technologies such as encryption and multifactor authentication, such as the mandatory measures in the proposed update to the HIPAA Security Rule, as it will be far more effective to address risks through evolving industry cybersecurity frameworks. Garcia suggested that the proposed HIPAA Security Rule update should be reset or abandoned, as it “did not demonstrate sufficient insight to the complexities of achieving effective cybersecurity protections for the health sector, nor acknowledge the considerable work the sector and government partners have accomplished in good faith and urgency over the past 6 years to build a collective cyber defense.”
Garcia also requested that HSCC be involved in cybersecurity policy decisions and should be included in threat information sharing and incident response advisories, as it is the primary cross-sector healthcare advisory council focused exclusively on critical infrastructure cybersecurity

