Skip to main content
SENATE 3315119th CongressPlaced on Senate Legislative Calendar under General Orders. Calendar No. 365.

Health Care Cybersecurity and Resiliency Act of 2026

Last Action
3/23/2026

Actions

  • 2026-03-23Placed on Senate Legislative Calendar under General Orders. Calendar No. 365.
  • 2026-03-23Committee on Health, Education, Labor, and Pensions. Reported by Senator Cassidy with an amendment in the nature of a substitute. Without written report.
  • 2026-03-23Committee on Health, Education, Labor, and Pensions. Reported by Senator Cassidy with an amendment in the nature of a substitute. Without written report.
  • 2026-02-26Committee on Health, Education, Labor, and Pensions. Ordered to be reported with an amendment in the nature of a substitute favorably.
  • 2025-12-02Read twice and referred to the Committee on Health, Education, Labor, and Pensions.
  • 2025-12-02Introduced in Senate

CRS Summary

As of 2026-03-23 (25)

Health Care Cybersecurity and Resiliency Act of 2026

This bill expands federal requirements and resources for preventing and responding to cybersecurity incidents in the health care and public health sectors.

The bill directs the Department of Health and Human Services (HHS) to

  • require private health care-related entities to adopt minimum cybersecurity practices (e.g., multifactor authentication),
  • more specifically identify the standards for mitigating penalties relating to violations of health information privacy and security,
  • expand and update biennially a specified plan that details cybersecurity protocols for HHS personnel,
  • provide training and best practices to support the expansion of the workforce for health care cybersecurity, 
  • provide guidance on cybersecurity readiness to rural entities, and
  • designate one representative to lead oversight and coordination of cybersecurity activities within HHS.

Also, HHS and the Cybersecurity and Infrastructure Security Agency (CISA) must coordinate to improve health care cybersecurity, including by (1) providing resources for entities receiving information from HHS or CISA programs, and (2) establishing a joint cybersecurity capability plan to coordinate responses to significant incidents.

Additionally, the bill requires health care providers and plans to include the number of individuals affected when notifying individuals of unauthorized access to health information (i.e., a breach). 

Cosponsors (3)

  • Maggie Hassan (D-NH)
  • John Cornyn (R-TX)
  • Mark Warner (D-VA)

Subjects

  • Administrative law and regulatory procedures
  • Computer security and identity theft
  • Computers and information technology
  • Congressional oversight
  • Department of Health and Human Services
  • Employment and training programs
  • Government information and archives
  • Government studies and investigations
  • Health programs administration and funding
  • Public-private cooperation
  • Rural conditions and development
Read on Congress.gov

Sourced from Congress.gov (public domain).

This is legal information, not legal advice. Laws vary by jurisdiction and change frequently. Always verify current law with official sources and consult a licensed attorney in your jurisdiction for advice on your specific situation.