Healthcare Cybersecurity Has a Problem. This Bill Wants to Fix It
Two years after the largest healthcare cybersecurity incident in history, the senate has passed The Health Care Cybersecurity and Resiliency Act of 2025.

Two years after the largest healthcare cybersecurity incident in history, the senate has passed The Health Care Cybersecurity and Resiliency Act of 2025.
October 7, 2026 | 4 min read

The Senate has approved a bill that aims to improve the cybersecurity of the healthcare sector by providing grants, training, and best practices to rural health clinics and other providers on cybersecurity breach prevention, resilience, and coordination with federal agencies.
The Health Care Cybersecurity and Resiliency Act of 2025 is a response to major cybersecurity intrusions that have impacted the healthcare sector — including, most notably, the Change Healthcare attack in 2024, the largest healthcare cybersecurity incident in history. The ransomware attack disrupted healthcare payments, electronic prescriptions, and medical care nationwide and ultimately impacted around 190 million people.
The bill was first introduced in December 2025 and is sponsored by Sens. Bill Cassidy (R-LA), Maggie Hassan (D-NH), John Cornyn (R-TX) and Mark Warner (D-VA).
“Cyberattacks can shut down hospitals and expose patients' private medical records,” said Dr. Cassidy in a statement last week. “At a time when hostile actors are increasingly using sophisticated tactics to breach health care systems, the Health Care Cybersecurity and Resilience Act will help health care providers strengthen their defenses against cyber threats and protect patients’ health data.”
The heart of the bill is outlining requirements for the U.S. Department of Health and Human Services (HHS) – in charge of the private healthcare system – to implement various cybersecurity improvements. This includes a cybersecurity incident response plan and a data breach portal that would track organizations affected by a breach, along with the corrective and security measures they have taken in response.
“Cyberattacks can shut down hospitals and expose patients' private medical records."
One part of the bill directs HHS to update the Health Insurance Portability and Accountability Act (HIPAA) regulations and require organizations to use updated cybersecurity practices: such as multi-factor authentication (MFA), safeguards for encrypting protected health information, requirements to conduct audits (like pentesting) to ensure system security, and various other security standards.
The bill directs HHS to also award grants to various “eligible entities” for use to hire personnel, update their electronic data systems, join cybersecurity threat information sharing organizations, and reduce the use of legacy systems.
The bill also outlines a broad plan for “rural cybersecurity readiness.” Health clinics in rural areas are resource- and budget-strained in particular when it comes to cybersecurity. This puts them at an extra disadvantage in defending against costly and damaging threats – and in a handful of publicly reported cases, cyberattacks have in part led to the closure of hospitals impacted by incidents, such as St. Margaret’s Health in Spring Valley, Illinois.
For rural hospitals, the bill said it would require “guidance to rural entities on best practices to improve cyber readiness”, including for improving cyber infrastructure, employee preparation for mitigating security risks, or facilitating mandatory incident reporting requirements.
However, the potential effectiveness of the bill, if passed into law, is yet to be seen. Beau Woods, founder and CEO of Stratigos Security, pointed to areas of the bill that are still vague and need better and more clear definitions.
“While the bill updates HIPAA to include additional security requirements (encryption, multi factor, penetration testing), it still leaves where and how to apply them to a ‘risk-based’ judgment it doesn't define,” said Woods. “And it expands an enforcement escape clause that allows breached organizations to cite voluntary security practices or ‘investments’ (without defining what those are) to reduce fines and cut audits short, effectively buying a discount on enforcement. That disproportionately advantages wealthier companies, as compared with ones like rural critical access hospitals that can’t afford the security staff or legal teams to argue their case.”
“While the bill updates HIPAA to include additional security requirements... it still leaves where and how to apply them to a ‘risk-based’ judgment it doesn't define."
The Health Care Cybersecurity and Resiliency Act of 2025 is still not close to becoming law: while it has been cleared by the Senate, it still needs to pass the House and be signed by the president.
It’s also one of several responses by senators to cyberattacks involving critical systems affiliated with the healthcare sector. Even beyond the wide-ranging impacts of the Change Healthcare incident, healthcare organizations have long struggled with a particularly difficult cybersecurity environment. Hospitals and medical facilities use large, complex networks that touch sensitive data and critical systems. Many hospitals use legacy medical devices that are difficult to patch due to the workplace's sensitivity to downtime. These organizations also rely heavily on third-party vendors and interconnected systems. All of this sets healthcare entities up for major disruption during ransomware attacks.
The Health Infrastructure Security and Accountability Act, introduced in 2024 (and reintroduced September 2026) by Sens. Warner and Ron Wyden (D-OR) aims to strengthen and enforce cybersecurity requirements for healthcare organizations. Last year, Wyden also sent a letter to the FTC urging it to investigate Microsoft on the heels of the 2024 ransomware attack against Ascension, one of the largest U.S. nonprofit healthcare systems.
If there's one common denominator between all these different efforts, it's that they show a resounding lesson from the Change Healthcare incident two years ago. Cyberattacks impacting the healthcare sector are a very real and formidable issue -- and it's a problem that we need to tackle with urgency.
October 7, 2026 | 4 min read
Lindsey O’Donnell-Welch is an award-winning journalist who strives to shed light on how security issues impact not only businesses and defenders on the front line, but also the daily lives of consumers.