NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Senate Unanimously Passes the Health Care Cybersecurity and Resiliency Act

A bipartisan bill that seeks to improve healthcare cybersecurity and resilience has been unanimously passed by the U.S. Senate. The bill – The Health Care Cybersecurity and Resiliency Act (S.B. 3315) – calls for healthcare providers to implement cybersecurity best practices and key cybersecurity measures, and authorizes grants for rural hospitals and under-resourced healthcare providers to help them make the necessary cybersecurity improvements.

The Health Care Cybersecurity and Resiliency Act was initially proposed in 2025 by Senator Bill Cassidy (R-LA) and is co-sponsored by Senators Mark Warner (D-VA), John Cornyn (R-TX), and Maggie Hassan (D-NH). The bill was introduced following the ransomware attack on Change Healthcare, which caused massive disruption across the U.S. healthcare system, and seeks to strengthen cyber defenses, improve threat-sharing, establish workforce development and employee cybersecurity training programs, and provide better cybersecurity-related resources to help rural and low-resource healthcare providers bolster their defenses.

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has already proposed an update to the HIPAA Security Rule that includes extensive cybersecurity requirements for HIPAA-regulated entities; however, the final rule has been pushed back until at least July 2027, and it may not even progress to a final rule. A final decision has yet to be made by the Trump Administration about whether a final rule will be published.

The Health Care Cybersecurity and Resiliency Act requires certain cybersecurity measures to be adopted, such as encryption of electronic protected health information, implementation of multifactor authentication, ongoing monitoring for cyber events, and penetration tests. The bill also requires the adoption of cybersecurity best practices in line with national cybersecurity frameworks such as the NIST Cybersecurity Framework.

The bill requires the HHS to develop a cybersecurity incident response plan and designates the Administration for Strategic Preparedness and Response as the Sector Risk Management Agency. The bill recognizes the importance of adopting recognized security practices and requires more transparency about data breaches. The public would be able to see, via updated fields on the OCR breach portal, whether the reporting entity had implemented recognized security practices prior to a data breach occurring, and whether any corrective action was taken by OCR against a regulated entity in response to a data breach.

The Senate Health, Education, Labor, and Pensions (HELP) Committee voted 22-1 in favor to advance the bill, and on October 1, 2026, the full U.S. Senate unanimously passed the bill. It will now head to the U.S. House of Representatives for consideration. While the bill proposes a grant program to help low-resource healthcare organizations make the necessary cybersecurity changes, the bill does not stipulate how much will be made available. That will be a matter for the House and Senate Appropriations Committees to decide.

“My bipartisan bill, the Health Care Cybersecurity and Resiliency Act, would ensure health institutions can safeguard Americans’ health data against increasing attacks,” said Sen. Cassidy. “At a time when cyberattacks not only put patients’ sensitive health data at risk but can delay lifesaving care, we need to do more to provide support.”

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist