Senate Unanimously Passes Health Care Cybersecurity and Resiliency Act
The U.S. Senate passed S. 3315, the Health Care Cybersecurity and Resiliency Act of 2026, by unanimous consent on September 30, 2026, sending the bipartisan bill to the U.S. House of Representatives. The legislation directs the Department of Health and Human Services (HHS) to modernize the two-decade-old HIPAA Security Rule, mandates that healthcare organizations adopt baseline cybersecurity controls — including multifactor authentication (MFA), encryption of electronic protected health information, continuous monitoring, and penetration testing — and funds grants for rural and under-resourced providers to get there. Sponsors cited a sharp rise in attacks on the sector: more than 730 cyber breaches affected over 270 million Americans last year, with breaches costing an average of $10 million each.
Details
| Attribute | Value |
|---|---|
| Bill | S. 3315 — Health Care Cybersecurity and Resiliency Act of 2026 (119th Congress) |
| Lead sponsor | Sen. Bill Cassidy (R-LA), chairman, Senate HELP Committee |
| Cosponsors | Sen. Maggie Hassan (D-NH), Sen. John Cornyn (R-TX), Sen. Mark Warner (D-VA) |
| Committee vote | Senate HELP Committee advanced the bill 22-1 on February 26, 2026 |
| Floor vote | Passed Senate by unanimous consent, with an amendment, on September 30, 2026 |
| Next step | Referred to the U.S. House of Representatives for consideration |
| Catalyst statistic | 730+ breaches affecting 270M+ Americans last year; avg. cost $10 million per breach |
| Prior history | First introduced 2024; failed to advance; reintroduced December 2025 |
What the Bill Mandates
The Act's core aim is to close long-standing gaps in healthcare cybersecurity regulation that predate the modern threat landscape. It requires HHS to modernize the HIPAA Security Rule, which has not been substantially updated in roughly two decades, so that covered entities and business associates must implement current best practices rather than the rule's original, now-outdated baseline. Regulated organizations would need to show evidence of MFA, encryption of electronic protected health information (ePHI), continuous monitoring for cyber events, and regular penetration testing, aligned with the NIST Cybersecurity Framework. The bill also directs HHS to update breach-reporting portal fields so the public can see whether a breached entity had implemented recognized security practices before the incident occurred — a transparency measure aimed at exposing which organizations were taking preparedness seriously.
Federal Coordination and Incident Response
The legislation formally designates the Administration for Strategic Preparedness and Response (ASPR) within HHS as the Sector Risk Management Agency for healthcare and public health, giving it lead responsibility for coordinating sector-wide cyber defense. It requires the HHS Secretary to develop a cybersecurity incident response plan for the sector and to formalize coordination channels between HHS and the Cybersecurity and Infrastructure Security Agency (CISA), creating a more direct threat-intelligence pipeline between federal cyber defenders and healthcare providers than currently exists.
Grants for Rural and Under-Resourced Providers
Recognizing that smaller hospitals and rural health clinics often lack the budget or staff to meet stronger security requirements, the Act authorizes grant programs to help under-resourced providers fund cybersecurity upgrades, incident-response planning, and staff training on best practices. Actual funding levels will depend on downstream appropriations decisions, which the bill itself does not set.
Why Now: A Pattern of Catastrophic Breaches
Lawmakers pointed to a string of high-impact incidents as justification for the bill. The Change Healthcare ransomware attack in 2024 is believed to have exposed data on more than 190 million people and caused widescale disruption to claims processing and electronic prescribing nationwide. The Ascension ransomware attack, also in 2024, disrupted clinical operations and electronic health records across 11 U.S. states. Further back, the 2015 Anthem breach compromised personal and health records for 78.8 million customers and ultimately cost the insurer more than $115 million. Those incidents, combined with the broader statistic of 730+ breaches affecting 270 million Americans in the past year alone, framed the Senate's case that voluntary guidance has not kept pace with the threat.
Impact Assessment
| Impact Area | Description |
|---|---|
| Regulatory burden | Hospitals and health systems face new compliance requirements for MFA, encryption, monitoring, and penetration testing once HHS finalizes updated HIPAA Security Rule provisions |
| Rural and small providers | Grant funding is intended to offset upgrade costs, but actual dollar amounts depend on future appropriations, leaving near-term funding uncertain |
| Federal coordination | Designating ASPR as Sector Risk Management Agency and formalizing HHS-CISA coordination should speed threat-intelligence sharing with providers |
| Transparency | Updated breach-portal fields will let patients, researchers, and media see which breached entities had implemented recognized security practices beforehand |
| Legislative uncertainty | The bill's fate now rests with the House, which has not yet signaled a timeline for taking it up alongside broader HIPAA and regulatory reform discussions |
Recommendations
For Hospital and Health System IT/Security Leaders
- Begin gap-mapping current security controls against the NIST Cybersecurity Framework and the MFA, encryption, monitoring, and penetration-testing requirements referenced in the bill — don't wait for HHS's final rule to start remediation.
- Inventory which systems still rely on single-factor authentication for access to ePHI and prioritize MFA rollout for the highest-risk systems first (EHR access, remote VPN, admin accounts).
- Document existing security practices now, since the bill's breach-portal transparency provision will make pre-incident posture publicly visible after any future breach.
For Rural and Under-Resourced Providers
- Track the bill's progress through the House and any associated appropriations language — grant eligibility and amounts will be defined there, not in S. 3315 itself.
- Engage with state hospital associations and HHS regional offices now to understand anticipated grant application processes once funding is authorized.
- Prioritize low-cost, high-impact controls (MFA, patching, backup isolation) that don't depend on grant funding arriving on a specific timeline.
For Security Vendors and Consultants Serving Healthcare
- Expect increased demand for HIPAA Security Rule gap assessments, penetration testing services, and MFA deployment support as covered entities prepare for the modernized rule.
- Help under-resourced clients build a realistic compliance roadmap that doesn't assume grant funding will arrive before enforcement deadlines are set.
Key Takeaways
- The Senate passed S. 3315, the Health Care Cybersecurity and Resiliency Act of 2026, by unanimous consent on September 30, 2026; it now moves to the House.
- The bill directs HHS to modernize the HIPAA Security Rule and mandates MFA, encryption, continuous monitoring, and penetration testing aligned with the NIST Cybersecurity Framework.
- It designates ASPR as the healthcare sector's Sector Risk Management Agency and formalizes HHS-CISA coordination on cyber threats.
- Grant programs for rural and under-resourced providers are authorized but not yet funded — appropriations will determine actual dollar amounts.
- Sponsors cited 730+ breaches affecting 270 million+ Americans last year, at an average cost of $10 million per breach, plus the Change Healthcare, Ascension, and Anthem incidents, as justification.
- The bill's path through the House — and whether it moves alongside broader HIPAA reform — remains uncertain despite unanimous Senate support.