Healthcare cybersecurity bill passes US Senate, heads to House

Healthcare cybersecurity bill passes US Senate, heads to House

The US Senate has approved the Health Care Cybersecurity and Resilience Act, a bipartisan bill designed to help hospitals, clinics and other healthcare organizations better withstand cyberattacks.

Senators Bill Cassidy, Maggie Hassan, John Cornyn and Mark Warner introduced the bill. It passed by unanimous consent, a Senate procedure that approves a measure without a recorded vote as long as no senator objects. The legislation now goes to the US House of Representatives.

This is the bill's second attempt. It was first introduced in 2024 but did not pass before that congressional term ended. The senators reintroduced it in December 2025.

"Cyberattacks on our healthcare sector not only put patients' sensitive health data at risk but can delay life-saving care. This bipartisan legislation ensures health institutions can safeguard Americans' health data against increasing cyber threats," said Cassidy.

A sector under constant pressure

Healthcare is one of the main targets for cybercriminals. Last year, more than 730 breaches affected over 270 million Americans, and the average breach cost $10 million.

Several incidents have become reference points for the industry:

  • Anthem (2015): The breach compromised the personal information and health records of 78.8 million customers and cost more than $115 million.
  • Ascension (2024): A ransomware attack disrupted clinical operations and electronic health records across 11 US states.
  • Change Healthcare (2024): The attack is believed to have exposed the data of over 190 million people. It also caused significant delays in care and electronic prescribing.

Ransomware combined with double extortion is the main weapon used against the sector. In double extortion, attackers both encrypt systems and threaten to leak stolen data. Pure data extortion, where attackers only steal and threaten to publish, is becoming more common.

This puts hospitals in a difficult position. The government advises against paying ransoms, but providers must also protect their patients. Attackers rely on this conflict and expect victims to pay rather than put patient health at risk.

What the bill contains

The Act includes:

  • grants to improve attack prevention and response, plus training in cybersecurity best practices
  • more support for rural health clinics
  • better coordination between the Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA)
  • updates to existing regulations so they reflect current best practices
  • a requirement for the HHS Secretary to develop and implement a cybersecurity incident response plan

The bill also aims to provide central guidance in a field already covered by several existing frameworks. One notable change concerns the Administration for Strategic Preparedness and Response (ASPR), an office within HHS. The Act formally makes ASPR the Sector Risk Management Agency for healthcare, meaning the federal body responsible for the sector's security. It also sets up a direct channel through which CISA can deliver tailored, actionable threat intelligence.

"Patients deserve absolute confidence that their sensitive medical data stored online is protected and shielded from cybersecurity breaches or ransomware attacks," Cornyn said. "This legislation would strengthen interagency coordination and improve security practices for rural providers, ensuring Texans' health care is not delayed or compromised by cyberattacks."

Mixed reactions

The healthcare sector has largely welcomed the bill. Voices from the security industry are more cautious. They point out that its success will depend on how consistently the rules are enforced. There are also concerns about the cost of compliance if federal funding and technical assistance do not keep up with the new requirements.

In practice, the Act adds a new layer of compliance for healthcare organizations. It will only work if both the government and the providers do their part.

Our Take

The bill's focus on rural clinics and on clearer roles for ASPR and CISA suggests that lawmakers recognize a key problem: many attacks hit organizations with little security staff or budget. Grants and threat intelligence sharing could help these providers, but only if the money and support actually reach them. Otherwise, smaller providers may face new obligations they cannot afford to meet.

The approach also contrasts with a recent proposal for voluntary telecom cyber rules, which relies on industry cooperation rather than updated regulation. Since this bill has already stalled once, it is worth watching whether the House moves faster this time. Another open question is how HHS will turn the planned regulatory updates into concrete requirements for providers.