NEWS

Senate Passes Healthcare Cybersecurity Bill After 190 Million Impacted by Change Healthcare Breach

The Senate unanimously passed a bill setting minimum cybersecurity standards for healthcare entities, driven by the Change Healthcare breach.

Dylan H.

News Desk

October 7, 2026
4 min read
Senate Passes Healthcare Cybersecurity Bill After 190 Million Impacted by Change Healthcare Breach

A Response to the Industry's Worst Breach

The US Senate has passed the Health Care Cybersecurity and Resiliency Act of 2026 (S.3315) by unanimous consent, a bipartisan response to the Change Healthcare/UnitedHealth ransomware attack disclosed in February 2024 that exposed sensitive health data belonging to roughly 190 million people and triggered widespread disruption to US pharmacy and billing systems.

The bill was introduced by Senate HELP Committee chair Sen. Bill Cassidy (R-LA) in 2025, with co-sponsors Maggie Hassan (D-NH), John Cornyn (R-TX), Mark Warner (D-VA), Cindy Hyde-Smith (R-MS), and Angus King (I-ME).


What the Bill Does

ProvisionDetail
Minimum standardsDirects HHS to require baseline cybersecurity controls for healthcare entities, including multifactor authentication and encryption of electronic protected health information (ePHI)
Testing requirementsMandates penetration testing and ongoing cyber monitoring
Incident responseRequires HHS to develop a formal cybersecurity incident-response plan and coordinate joint incident response with CISA
OversightDesignates a dedicated cybersecurity oversight coordinator within HHS
FundingAuthorizes grants to help rural and under-resourced hospitals fund security upgrades
WorkforceMandates cybersecurity training programs for healthcare staff
TransparencyRequires breach notifications to disclose total victim counts

The bill does not appear to set a specific numeric incident-reporting deadline (such as a "72-hour" rule) in the provisions reported so far — that detail may be clarified as implementing guidance from HHS develops.


Still a Long Way From Law

Passing the Senate by unanimous consent is a significant bipartisan signal, but the bill is not yet law. It now moves to the House of Representatives, which had not acted on companion legislation as of publication — House leadership did not respond to requests for comment on a timeline. The bill would still need House passage and a presidential signature before taking effect.


Industry Reaction

The American Hospital Association, representing roughly 5,000 US hospitals and health systems, voiced support for the bill — particularly the grant funding for smaller and rural facilities that often lack dedicated security budgets. The AHA also pushed for clarity on whether third-party vendors handling health data would face the same security and privacy obligations as direct providers, a gap that was central to how the original Change Healthcare breach unfolded and propagated across the broader healthcare payment ecosystem.


Why This Matters

Change Healthcare processes a vast share of US medical claims and prescriptions; its 2024 compromise didn't just leak data — it froze payment processing for providers and pharmacies nationwide for weeks, illustrating how a single point of failure in healthcare's technology supply chain can cascade into a public-health-adjacent crisis. This bill is Congress's first major legislative attempt to convert that lesson into enforceable baseline requirements, rather than relying on voluntary guidance.

Whether it ultimately becomes law — and how strictly HHS defines "minimum" standards and third-party obligations — will determine whether it meaningfully reduces the industry's exposure to the next large-scale ransomware or extortion incident.


  1. Healthcare organizations should treat the bill's provisions (MFA, ePHI encryption, penetration testing) as a preview of likely future compliance requirements and begin gap assessments now rather than waiting for a final signed law
  2. Third-party vendors and SaaS integrators serving healthcare clients should anticipate being pulled into scope as the House version and implementing rules develop
  3. Security and compliance teams should track HHS's forthcoming incident-response plan and coordinator role, which will likely shape future breach-notification expectations
  4. Rural and smaller providers should monitor for grant program details, which may offer funding relief for required upgrades