Senate Passes Healthcare Cybersecurity Bill for the House
The Senate unanimously passed a bipartisan healthcare cybersecurity bill that now awaits House action.
The U.S. Senate unanimously passed a bipartisan healthcare cybersecurity bill and sent it to the House. SecurityWeek calls it the Health Care Cybersecurity and Resilience Act, reintroduced in December 2025 by Senators Cassidy, Hassan, Cornyn, and Warner after it failed in 2024; The Record calls it the Health Care Cybersecurity and Resiliency Act of 2026, introduced by Sen. Bill Cassidy with bipartisan co-sponsors and American Hospital Association backing. Both reports say the measure would strengthen HHS-CISA coordination through an incident or joint cyber response plan. SecurityWeek says it would fund prevention and response, support rural clinics, update security requirements, name ASPR the sector risk management agency, and formalize a CISA threat-intelligence pipeline, citing more than 730 healthcare breaches affecting over 270 million Americans last year and incidents at Anthem, Ascension, and Change Healthcare. The Record says HHS must require minimum cybersecurity standards, including multifactor authentication, for private healthcare entities, expand workforce training, and require breach notices to state total victim counts, framing the bill as a response to the Change Healthcare ransomware breach that exposed data on 190 million people.
- The U.S. Senate passed the bill by unanimous consent; it now goes to the House.
- Sources disagree on the name: SecurityWeek says Health Care Cybersecurity and Resilience Act; The Record says Health Care Cybersecurity and Resiliency Act of 2026.
- SecurityWeek says it was reintroduced in December 2025 by Senators Cassidy, Hassan, Cornyn, and Warner after failing in 2024.
- The Record says Sen. Bill Cassidy introduced it with bipartisan co-sponsors and American Hospital Association backing.
- Reported provisions include prevention and response funding, rural-clinic support, updated or minimum security requirements including multifactor authentication, an HHS or joint HHS-CISA response plan, ASPR as sector risk management…
- SecurityWeek says sponsors cite more than 730 healthcare breaches affecting over 270 million Americans last year, plus incidents at Anthem, Ascension, and Change Healthcare.
- The Record says the bill responds to the Change Healthcare ransomware breach that exposed data on 190 million people.
Coverage timelineoldest first · each row is one article
- · 5d agoSenate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity
SecurityWeek· 58
The US Senate passed the Health Care Cybersecurity and Resilience Act, sending it to the House.
- · 3d agoSenate passes healthcare cybersecurity bill after 190 million impacted by Change Healthcare breach
The Record· 58
U.S. Senate unanimously passed the Health Care Cybersecurity and Resiliency Act of 2026, mandating HHS cyber standards after Change Healthcare's 190-million-person breach.